Hello Евгений Котляревский,
Thank you for posting in Q&A forum.
If the certificates (root CA certificates and issuing CA certificates) are not expired, you can not delete any of them. If the root certificate or issuing certificates doesn't expire, you delete it, and there will be problems with the entire PKI.
If one or more of them are expired, you can delete the expired certificates.
For the root CA certificate, if it is expired, you can delete the old CA certificate from the Certification Authorities tab.
- Start pkiview.msc.
- Right-click Enterprise PKI, and then click Manage AD Containers.
- Click the Certification Authorities tab.
- Select the old root CA certificate and then delete it.
I hope the information above is helpful.
If you have any questions or concerns, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.