12.3. Renewing a DRM, OCSP, or TKS SSL Server Certificate
Open the subsystem instance's administrative console. For example, for the DRM subsystem:
pkiconsole https://server.example.com:10043/kra
Select the newly-imported Certificate System instance, and log into the Console for the instance.
Select the System Keys and Certificates option from the menu on the left.
Click the Add/Renew button to launch the Certificate Setup Wizard.
In the Type of Operation panel, select the Request a certificate option (the default).
In the Certificate Selection panel, select SSL Server Certificate from the pull-down menu. An SSL server certificate request is generated, which can be submitted to a CA for approval.
In the Key-Pair Information for the SSL Server Certificate, select Create new key pair since the renewed SSL server certificate requires a change to the CN component of its DN. Fill in information in the other fields.
The next panel is Subject Name for the SSL Certificate. For the CN component, enter the fully qualified domain name of the Certificate System subsystem machine, such as omega.example.com. Fill in information in the other fields on this panel; it is strongly recommended that the O and C components also be filled in.
Click through the remaining panels in the Certificate Setup Wizard.
Obtain the SSL server certificate request, and store it in a base-64 file.
Submit the SSL server certificate request to a CA, and wait for approval of the request.
After the SSL server certificate is approved, click the Add/Renew button to relaunch the Certificate Setup Wizard.
In the Type of Operation panel, select the Install a certificate option.
In the Certificate Selection panel, select SSL Server Certificate from the pull-down menu.
Set the location information in the Location of Certificate if required.
Click through the remaining panels in the Certificate Setup Wizard to install the renewed SSL server certificate for the migrated Certificate System subsystem instance.
Restart the Certificate System subsystem instance.
/etc/init.d/rhpki-kra restart