Spotlight Diagnostic Server Port 40403 Certificate

The SDS service on 40403 port comes with a default certificate, is there a procedure to change it? this because we are PCI certified and PCI recomends thal all certificates should be  changed and not use default certificates.