DNS/DHCP Server always has a single current certificate and the ability to revert to the factory installed certificate.
In certain situations, for example with Crossover High Availability (xHA), DNS/DHCP Server may create a new certificate and replace the factory-set certificate on both the server and client. If these certificates continue to match, you can deploy new configurations. However, if the certificates become mismatched, you may have to reset the appliance certificate to its factory-set value (the certificate that shipped with your appliance).
To reset the deployment certificate: