We are revoking and reissuing our cross-signs of X2/YR by X1, and YE by X2.
You are not serving the correct certificate chain, 2nd intermediate is missing - see the "Extra download" from your screenshot (should also be "Sent by server").
You have to serve two intermediate certificates - see
EE ← YR2 ← Root YR ← ISRG Root X1 (Default)
Example (with YE2 and X2):
Path #1 is trusted - correct chain from server.
Path #2 is not trusted - Qualys uses old revoked certificate (but no effect on real clients unless certificate missing in chain from server).
