Replace certificates

You can’t edit or update certificates. You must re-create and then replace them.

If you assigned a certificate to a particular service, or to all services as a group, you can replace those certificates. You might replace the default self-signed certificate with one that’s been signed by a third party, or you might need to replace an expired certificate. See Obtain a trusted certificate.

If you receive a signed certificate from a third party, it should have an extension of .cer, .crt, or .p12.

  1. Select Certificates in the Server app sidebar.

  2. Select the certificate that’s being replaced, then click Remove remove.

  3. Click Add add, then choose “Get a trusted certificate.”

    You can also choose to import a certificate or create a self-signed certificate.

  4. Follow the directions in the Certificate Assistant.