I have a policy rule "Protect with web server protection" for an HTTPS web server. Therefore in this policy rule there is a certificate configured.
When I try to upload a new certificate into the certificate object, I get the error "Certificate could not be updated as it is already used by HTTP-based policy".
If I reconfigure the webserver protection to use only http (and therefore no certificate), i can renew the certificate. After that, I have to reconfigure the web server protection again.