Hello
I understand that you’re trying to clean up your CA server and you’re seeing two CA certificates, one of which is expired. Here are some steps you can take to clean this up:
Open pkiview.msc: Right-click on the Enterprise PKI node and select "Manage AD Containers".
Switch to the “Certification Authorities” tab: From here, you can remove expired CA certificates and leave the most recent CA certificate.
Use certutil command: You can use the certutil command along with the deleterow parameter to delete certain types of records. For example, to delete all failed and pending requests submitted by a certain date, you can use the command Certutil -deleterow mm/dd/yyyy Request.
https://learn.microsoft.com/en-us/answers/questions/691536/deleting-expired-certificate