Hi Barry,
It's been a while since the last time I got my hands on a SSLM but I think this procedure should help =)
1- Go to the SSLM and look for the serial number of the old CA:
1. SSLM-1#show crypto ca certificate
Certificate
Status Available
Certificate Serial Number: 759FD8F9B32200D70A01F10D5C0166
2- SSLM-1 (config)#crypto ca certificate chain my_trustpoint
3- SSLM-1 (config-cert-chain)#no certificate 759FD8F9F9B32200D70A01F10D5C0166
Are you sure you want to remove the certificate? [yes/no]: y
%The certificate has been deleted/unassociated for trustpoint my_trustpoint
4- SSLM-1 # (config-cert-chain)#exit
%STE-6-PKI_CERT_ROLLOVER_BEGIN: The process of rolling over the certificate without the sudden loss of services has begun for the proxy service: mycommnet
5- SSLM-1(config)#crypto ca import my_trustpoint certificate
copy and paste your new cert
HTH
__ __
Pablo