The certificate Server has been taken offline for security reasons or the client's certsrv can't locate the CRL's. By default, the Cert srv publishes a new revocation list every 7 days. If your root CA were taken offline and the new CRL wasn't published online to AD, your cert chain will be broken.
To resolve this issue execute the following steps:
Check if the Certificate Server is online and the CRL's can be located.