Option 1: Create a renewal CSR using the Exchange Admin Center (EAC) GUI
Open the EAC and navigate to Servers > Certificates. From the Select server dropdown list, select the name of the Exchange server that contains the SSL/TLS certificate that you would like to renew.
From the details pane, select the certificate from the list that you want to renew, and click Renew. The Renew Exchange certificate view opens
In theSave the certificate request to the following filefield, enter the path and filename for the renewal Certificate Signing Request (CSR) file. For instance,\\FileServer10\Data\certrequest.txt. ClickOK when you're done. The renewal CSR should show up in the list of Exchange certificates with a status of Pending.
Open the Certificate Signing Request (CSR) text file you just created in a simple text editor such as Notepad (do not open in Word). Below is an example of what your CSR will look like. You will be asked to paste the entire contents (including the BEGIN and END lines) when renewing your certificate.