I suppose that depends on the issue. Most of the time pkidiag was useful
for recreating old/expired certificates, and for that you can either use
'ndsconfig upgrade' or you can use the 'Repair Default Certificates' task
within iManager. For other troubleshooting, most of the time it is the
application which needs troubleshooting more than the certificates
themselves, so application logs/traces are appropriate.

