Hello Mel,
The fact that the newer KDC certificate is installed but appears lower in the enumeration does not by itself mean that the KDC will permanently continue using the older certificate.
However, I would not rely on the old certificate simply expiring as the mechanism for switching to the new certificate. The KDC needs a valid certificate that meets the requirements for domain controller/Kerberos authentication, and Windows certificate selection is based on the certificates available in the computer certificate store and their properties. Microsoft documents multiple certificate types that can be used by a domain controller for KDC authentication.
Since you have already restarted KDC and rebooted the affected DCs, I would compare the old and new certificates rather than focusing only on their enumeration numbers:
Confirm both certificates are in Local Computer → Personal → Certificates.
Verify the new certificate has the required private key.
Compare EKUs, especially KDC Authentication / Server Authentication, depending on the certificate template being used.
Check the Subject/SAN values and validity period.
Verify the certificate chain and revocation status.
Confirm the new certificate was issued from the intended domain-controller/Kerberos certificate template.
You can use certutil to inspect the certificates and verify their properties/chains; Microsoft documents certutil as a tool for viewing and verifying certificates and their chains.
I would also avoid manually changing or deleting certificate-store entries just to force the enumeration order. First determine why the newer certificate is not being selected.
If you can provide the output of the following from one affected DC (with names/identifiers redacted), it would help identify the selection issue:
certutil -store My
certutil -dcinfo
Also compare the old and new certificate's EKU, SAN, Key Usage, validity dates, and private-key presence.
So, in short: the new certificate should become usable when it satisfies the KDC certificate-selection requirements, but I would not treat expiration of the old certificate as a guaranteed or recommended way to trigger the change. The safer approach is to establish why the new certificate is currently not being selected before the old one expires.