So upgrade of FAS is independent of the certificate. If your certificate is expiring then definitely you would need to upgrade it with the newer ones. As those will be managed by your Root CA. Upgrade process for FAS should be simpler but I would propose to follow the process of taking a snapshot and then proceeding with the upgrade per resource location.