Need a guide or instructions on how to update old internal expired ssl web certificate

Description

Forgive me if this post is in the wrong place and my ignorance. I have zero experience with RocketChat and some with Linux and Unix

I have inherited an old Rocketchat server. The server is currently functioning. Our server is isolated from the outside world and is only accessible via internal traffic. We have a small ad domain that does not have an external public ip again isolated with some internet access. Our web ssl certificate is expired and i want to get a new one so we can utilize ssl communication on the server. We have our own internal CA root and subordinate servers. i know we have ngix installed and openssl but I have not found a simple easy to follow instructions how to accomplish this. I am really just looking for a simple guide or can you point me in the right direction. Sorry to waste your time

Server Setup Information

  • Version of Rocket.Chat Server: 3.18.7
  • Operating System: Ubuntu 18.04.4 LTS
  • Deployment Method:
  • Number of Running Instances: 1
  • DB Replicaset Oplog:
  • NodeJS Version: v12.22.1
  • MongoDB Version: 3.6.14
  • Proxy:
  • Firewalls involved:none

Any additional Information

Numerous rocketchat guides and youtube videos , web searches.