This is toy certificate-chain arithmetic, not production PKI.
highlighted = computed this step
What this toy chain shows
It shows one signed relationship: a root key verifies a leaf digest that binds a server share.
root to leaf to share
What it does not model
NOTE: toy-modulus; no-padding; no-side-channel; no-production; never-roll-your-own. Toy certificate chain only; not real certificate parsing, certificate policies, name validation, revocation, transparency logs, PKI operations, production RSA security, or browser TLS behavior.
toy certificate chain only
Summary
A trusted root can make a leaf checkable, but this book only models the tiny arithmetic shape.