I *think* it's in Global Properties, Remote Access. If not, go through the gateway properties and SmartCenter properties. It's pretty obvious.
Make sure your end users have "write" rights into that folder as well.
If you did not assign a site nick name, the R55 ones should still renew. The bug I mentioned in SecureClient caused the certificate renewal attempt to go to
http://nick name
instead of
http://<ip-address-of-gateway>
Ray