← All tools
Public-key
Certificate revocation: valid signature, still not trusted
Build the same real three-link ECDSA chain as the certificate chain builder, then revoke the intermediate and watch a mathematically perfect signature still get rejected.
What's happening under the hood →·Read the X.509 certificates & the PKI trust hierarchy module for the full explanation →·See the Running a PKI: how a certificate authority actually operates use case →
1. Generate a three-link chain
The same real ECDSA root → intermediate → leaf chain as the certificate chain builder — nothing about the signing changes here.