You can use DSCC to perform this task. For information, see Directory Service Control Center Interface and the DSCC online help.
View the default self-signed certificate.
$ dpadm show-cert instance-path defaultservercert