Chapter 12. Step 9: Renewing Certificate System Server Certificates

Chapter 12. Step 9: Renewing Certificate System Server Certificates

12.1. Renewing a CA SSL Server Certificate by Signing It with the CA Signing Certificate
12.2. Renewing a CA SSL Server Certificate by Issuing an SSL Server Certificate Request
12.3. Renewing a DRM, OCSP, or TKS SSL Server Certificate

If the new Certificate System server is on a different machine than the old Certificate System, the SSL server certificate associated with each newly-migrated Certificate System server instance must be renewed.

There are three procedures to generate new server certificates, depending on the subsystem: generating self-signed CA server certificates; generating CA certificate requests which is signed by another CA; and generating DRM, OCSP, or TKS server certificates.