A successful renewal proves that a certificate authority issued a new certificate and that some file or certificate store changed. It does not prove that the TLS endpoint reached by a client loaded that certificate. An old certificate can remain live because the active process still holds ...