Hi,
Did you distribute and publish the CA Certificate to the clients? As the clients might still be using old Certificate so you need to distribute and publish in AD, also you need to publish the CRL to the distribution points - CRL and AA.
Hope this helps.
JS
==
Please accept as answer and do a Thumbs-up to upvote this response if you are satisfied with the community help. Your upvote will be beneficial for the community users facing similar issues.