See https://www.icinga.com/docs/icinga2/snapshot/doc/16-upgrading-icinga-2/ - you must update database schema (as common for 2.n -> 2.n+1 update) - you don't need to do anything special with cert location if you use standard icinga cli/wizards, but should update deployment tools/scripts if you use them to provision certificates. (Regarding cert migration: patch added to new api.conf to work around pkg_add's behaviour of updating config files if there are no local changes).