The primary EPM uses the default identity certificates to act as a certificate authority for the Experience Portal servers. The primary EPM uses the EP signing certificate to issue and sign identity certificates for all the Experience Portal servers.
Disable the EP signing certificate if you use a custom identity certificate. An external certificate authority must issue and sign the custom identity certificates for the Experience Portal servers.
An external or third-party certificate authority refers to any of the following:
Commercial certificate authorities.
An enterprise certificate authority.
The certificate authority of System Manager (SMGR).
Any certificate authority outside Experience Portal.