Could you describe what you mean by "updated" a certificate? If it was externally signed by Digicert, did you load in a PKCS#7 format, or just the signed cert itself? Did you generate new public-private key pair and a CSR from it (GENCERT, GENREQ) to be able to get it signed by Digicert, and then update (ADD) it back in to the same label? Before you started, did you already have both the older and newer intermediate certs installed in RACF as CERTAUTH, or just the older one?
The circumstances you started with, just before you did the "update", and how you did the update, could provide the explanation as to what you saw happen, but there may be different explanations depending on your path. Let us know please. Thanks.
------------------------------
Scott Tietjen CISSP
------------------------------