Hi,
I've never had to do this before, but I have a server with expired
public key certificates. I know I need to run pkidiag to fix this but
I'm not sure which "fix" option to choose: the "default" KMO replacement
mode or the "update" default KMO mode.

Can someone tell me which mode is most appropriate?
Thanks,
KM