After LE cert is installed and the self-signed cert is deleted, the admin UI and TLS are still signed by the latter

What more is required on top of uploading the pubkey.pem and fullchain.pem and flagging them as default?