Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
So I was actually able to fix this with a combination of removing the current cert, creaing a new cert, new ca, new trustpoint, and binding the cert: no ip http secure-server crypto key zeroize crypto key generate rsa label somename-rsa modulus 2048 ...