We got this error on the clients's PolicyAgent.log: Everything looked fine, all certificates got issued, all clients trusted the new certificate, but still the ConfigMgr agent would not work.
However, after the new site signing certificate was issued and assigned to the site, all clients stopped getting policies. The renewal went smooth for the Document Signing. Recently, the site signing certificate for one of my sites is expiring and hence is required.
The ConfigMgr sites in where I work is running in Native Mode and this means that there will be certificates required for this.