There can only be one! One Radius cert for your Clearpass cluster..
You say "It will be" - what does that mean?
That in the migration period you will have two separate CA's and end up with the new one only?
I'm assuming you are going from EAP-PEAP to EAP-TLS. That means you will have to update the GPO's for the clients to reflect this change.
Just for the baseline to get this to work (with security intact)
1. The clients will have to have the rootCA certificate of the Radius server certificate in their Trusted Root Auth cert-store
2. The clients will have to have a list of the radius server names they need to trust
3. The clients need to change their Auth method from EAP-PEAP to "Smartcard or other .."
If you are also changing RootCA then you would have to do this in several steps to ensure all clients are updated with the new RootCA in their Trusted Root certstore.
If so..
1. Update GPO's to push the new RootCA and most likely push client certs at the same time. This to prepare for the EAP-TLS transistion.
2. Update Clearpass Radius cert from the new RootCA using the same servername. Keeping the same name should make the clients keep trusting the Radius server, and since they trust the RootCA they will trust the certificate..
3. Update client GPO's to change 802.1x authentication to "Smartcard or other.."
.. I think ;)