Hello
Thank you for your question and reaching out.
They can still be used to validate anything signed before their expiration if the expired certificates aren't revoked. Otherwise, you can delete them.
The certificate loses its validity when it expires. Therefore, you can safely remove a certificate from the CA database after it has expired. The only situation where this is not true is when Key Archival is set up on the CA. It's possible that you shouldn't delete expired CA certificates from the CA database if you're archiving private keys.
Before deleting any certificates from the database, make a backup of the CA, including the database and log files.
--If the reply is helpful, please Upvote and Accept as answer--