Looks like Native OTP with encryption is in use? Encrypted OTP is enabled with „bind vpn global -userDataEncryptionKey certname“ so check show vpn global if your Cert is bound. Replacing means use the same private key or you have to re-encrypt all OTPs with a new Cert with the OTP Tool from NetScaler (
https://www.julianjakob.com/citrix-netscaler-otp-encryption-tool/ )