For anyone else who may come across this issue, the steps below were successful for me...
1. Backup either the full system, or download/backup the current certs
2. Regenerate tomcat.pem
3. Restart tomcat service
4. Regenerate ipsec.pem
5. Regenrate callmanager.pem
6. Regenerate capf.pem
7. (if cluster) Follow the above steps on all the other servers starting with Publisher and then on subs
8. Run the CTL client and update CTL
9. Reboot servers, starting with Pub, then Subs
10. (Using BAT) Set all phones back to...
a. Certificate Operation: install/upgrade
b. Authentication Mode: by null string
c. Save, Apply Config and reset
11. (Using BAT) Set Security-Profile on all phones back to Secure Profile. Save, Apply, Reset.