I am referring to this container: https://www.turnkeylinux.org/mattermost 

Would replacing the certificates be as simple as replacing nginx's certificates or is there more involved?

AFAIK it should be as simple as replacing the Nginx cert. Although that won't stop Webshell and Webmin from still using the self signed cert. If you want them to use your new cert too, you'll need to adjust stunnel (both are behind stunnel in v14.x apps).

