Did you import the new intermediates and root into the Trust list?
And it may be needed to remove the previous versions.
It could be that certificates are cross-signed during the transition of root/intermediates at the CA. If there is (also) a signature from the previous root/intermediate, that path could be picked from the trust list during the import.