Hello,
I'm posting this thread because right now google has an older post from 19.7 forums that comes in #1. The reply in that post does not work. Today, we have two options now.
1. Quick and easy, introduced in 21.1 (https://github.com/opnsense/core/issues/4567):
configctl webgui restart renew
2. The longer Path.
Setup Self-Signed Certificate Chains with OPNsense (https://docs.opnsense.org/manual/how-tos/self-signed-chain.html)
The default Web GUI TLS certificate is created on the first install. I don't believe updates renew this cert, but I could be wrong. My cert was localhost.opnsense.local.