You need to import a created certificate from a Trusted Certificate Authority into the Enforce Server console.
There are 2 methods to update the keystore.
Method 1: Use a CSR and have your CA sign it, then import it into the a keystore for use with DLP. That process is outlined in the following KB:
Method 2: Get a new certificate pair right from your CA in a .pfx keystore format and then import it into the a keystore for use with DLP
Enforce should now be using the newly created certificates.