Clarification of SSL cert renewal on SDP 9.0 Build 9039 (Linux)??

Clarification of SSL cert renewal on SDP 9.0 Build 9039 (Linux)??

What are the correct steps to renew an SSL cert in SDP 9.0 build 9039 on Linux (including the creation of the CSR)?

I have a copy of the original saved sdp.keystore before any keys were imported into it, and it contains one entry for my server & domain:
[root@server bin]# ./keytool -list -keystore sdp.keystore.save
Enter keystore password:  

Keystore type: JKS
Keystore provider: SUN

Your keystore contains 1 entry

server.mydomain.com, Mar 20, 2015, PrivateKeyEntry, 
Certificate fingerprint (MD5): xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx

The instructions at https://www.manageengine.com/products/service-desk/faq-general-modules.html#ssl5 Step 6 say that when renewing and you have the saved keystore file, you should place a copy of that file in jre\bin and follow the instructions beginning with Step 3.  But Step 3 is installation... shouldn't I follow from Step 2, which is CSR creation?

Thanks

                  New to ADSelfService Plus?