easiest is to take another user.id and add that to the admin group / give sufficient access to names.nsf, certlog.nsf, admin4.nsf etc. and use that id to recertify the admin user.id.
(don't forget to remove that other id from the admin group when you're done)
Woonjas
IRC: #notes on EFNet