This certificate is Created by PA locally. Auto signed.
Device >> Certificates >> Select PaloAltoRoot >> Renew >> Enter max amount of days 730 >> OK and Commit
Only need to renew on Active appliance. It will replicate to Passive.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POioCAG
Thanks,
Audel