When your CA-signed server certificate (public key and private key) expires, renew it by using this procedure.
You can use DSCC to perform this task. For information, see Directory Service Control Center Interface and the DSCC online help.
Obtain an updated CA-signed server certificate from your Certificate Authority.
After you receive the updated certificate, install it.
$ dsadm renew-cert instance-path cert-alias cert-file