    Best way to refresh self signed cert

      We have a two server array running SGD 4.5. We enabled security with the automatic configuration method and now we want to generate new certs. Is it best to generate them and them self sign them and then install or can I simply turn security off and then back on again. I know that you aren't supposed to use automatic security configuration in an active array so going that route would require breaking the array and then rebuilding it. If I do the cert generation/selfsign/install procedure, would I need to break the array as well? I assume I need to do this on both of the servers in the array.

      Are there any gottchas I need to look out for while doing this? The Admin guide has the procedure but very little advice on the best way to proceed.