What I recall from having to recreate MultiDomain SIC as the renewal didn't work at the point where whe did change the SIC for the Domain with a lot of VPN's we created an outage.
It was a short one as we had a team doing SIC reset like crazy and it was announced.
But if this was the issue with Domain SIC that was based on a new certificate.
Think of if like build a new CA and issueing certificates from it.
So I would schedulke an outage.
<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>