Potentially try restarting SmarterMail after the certificate change?
403.14 is usually an IIS error relating to Directory Browsing (which shouldn't be enabled) -- It sounds like IIS isn't connecting to the SmarterMail webserver proxy correctly anymore. (or SmarterMail isn't binding ports properly anymore because it doesn't like the certificate change).
Is there a bad bookmark? Are you being redirected to /interface/root#/login when you try to load the webmail?
MailEnable survivor / convert --