You will need to generate the request somewhere.
If you use the existing site that will mean the current certificate will have to be removed, and left off until the certificate request arrives. You cannot do the request then put the old certificate back.
The usual method is to create a second site in IIS manager, using another port. Run the request and response through that. Once complete you can then run through the Default Web Site and choose to remove the existing certificate and then replace it with another existing certificate (because your new certificate is in place).
Although I wouldn't use Verisign unless you are getting a massive discount. Overpriced in my opinion. When you can get a certificate with almost the same level of acceptance for US$30/year, paying Verisign's prices to protect Exchange is madness.
Simon.