This is toy certificate-chain arithmetic, not production PKI.

highlighted = computed this step

What this toy chain shows

It shows one signed relationship: a root key verifies a leaf digest that binds a server share.

root to leaf to share\text{root to leaf to share}
Toy boundaryThe toy root-to-leaf chain is recomputed from the signed digest.Toy boundary - root verifies leafToy Root CAn=55, e=3Leaf cert binds share 19digest=33, sig=22

What it does not model

NOTE: toy-modulus; no-padding; no-side-channel; no-production; never-roll-your-own. Toy certificate chain only; not real certificate parsing, certificate policies, name validation, revocation, transparency logs, PKI operations, production RSA security, or browser TLS behavior.

toy certificate chain only\text{toy certificate chain only}
Toy boundaryThe toy root-to-leaf chain is recomputed from the signed digest.Toy boundary - root verifies leafToy Root CAn=55, e=3Leaf cert binds share 19digest=33, sig=22

Summary

A trusted root can make a leaf checkable, but this book only models the tiny arithmetic shape.

arithmetic shape only\text{arithmetic shape only}
Toy boundaryThe toy root-to-leaf chain is recomputed from the signed digest.Toy boundary - root verifies leafToy Root CAn=55, e=3Leaf cert binds share 19digest=33, sig=22