Chapter 12. Step 9: Renewing Certificate System Server Certificates
If the new Certificate System server is on a different machine than the old Certificate System, the SSL server certificate associated with each newly-migrated Certificate System server instance must be renewed.
There are three procedures to generate new server certificates, depending on the subsystem: generating self-signed CA server certificates; generating CA certificate requests which is signed by another CA; and generating DRM, OCSP, or TKS server certificates.