Update:
A third party asked the CA (DigiCert) to revoke the old cert and the CA agreed. Tomorrow the old cert becomes invalid. At the moment no custom clients can be generated. This leaves support teams using a custom client in limbo, as the custom client with the old cert should be rejected soon by the OS when the CRL (certificate revokation list) is updated.