The system diagnose check in UMC or on command line will report issues about all certificates found in /etc/univention/ssl/ucsCA/certs even if they are not longer used. We should either update/ renew these certs properly (best in an automated way, see bug #50723) or ignore these certificates from the check as they are not used at all.
This is still an issue.
Added another ticket
Next customer reported that. Ticket 2024022421000055
Again #Ticket 2025020421000055
Again in 2025081421000123