When setting up a mutual certificate based AWS client vpn the instructions show how to make the client and server certs together, shown here, for example.
I understand how to make multiple client certs, one for each user, at the time the server cert is created, but how do I create a new cert later on, without replacing the existing cert and forcing those users to install new client certs?