In the lab:
-Move CA service following Microsoft and PeteNetLive guides
-Republish enrollment agent and smartcard logon templates
-Reissue DC certificates
-Delete exising smartcard logon user certs
-Reissue Enrollment Agent certificates
We've tried deleting the cert cache on the RDS host per this Parallels KB:
https://kb.parallels.com/en/128635.
And checked for duplicate certs per
https://support.citrix.com/article/CTX238881.
The CA is online and reachable. In our latest test we noticed in the Enterprise PKI snap-in that the DeltaCRL Location #1 was expired and still pointing to the previous CA server, but we're still broken even after correcting that with certutil -crl and reissuing new certs to DCs, enrollment agents, and users.