Automatically renewing certs with macOS Server?

The actual certificates are stored in a macOS specific store. There's a long sudo security command to import them in this guide on the forum: