GetNextCACert ----------> <---------- New CA certificate PKCSReq* ----------> CA issues certificate with new key <---------- CertRep SUCCESS Client stores certificate for installation when existing certificate expires.