Hey @Dave ,
I dont foresee any issues myself in such a scenario. I had done it many times in the lab and worked fine, all I had to do is distribute renewed cert to machine behind the firewall and that was it, worked like a charm afterwards.
I sort of compare it to if you say make bunch of changes in smart console, but only save it and dont install the policy...in case like that, firewalls would not be affected, since those changes would not have been pushed as of yet.
Makes sense?
If you need help with it, Im willing to do remote and show you in my lab.
Cheers mate.
Andy