Otherwise, client certificates issued before a new CA is used get rejected once the new CA becomes current.