Hiya,
Usually there is a reference in the web.config file for each of the applications for this. However most applications has each their own unique way of dealing with replacement of the token signing certificate....
Its rarely handled on IIS server level.
Kind Regards
Jesper