The trusted toy root key is the starting point for the chain.

highlighted = computed this step

Trust starts at a root

The client begins with a trusted toy root key, not with the leaf certificate alone.

trusted root key\text{trusted root key}
Public toy rootThe toy root-to-leaf chain is recomputed from the signed digest.Public toy root - root verifies leafToy Root CAn=55, e=3Leaf cert binds share 19digest=33, sig=22

The root key is public

The toy root public key has modulus n=55 and exponent e=3.

n=55,e=3n=55,\quad e=3
Public toy rootThe toy root-to-leaf chain is recomputed from the signed digest.Public toy root - root verifies leafToy Root CAn=55, e=3Leaf cert binds share 19digest=33, sig=22

The root checks signatures

A leaf is accepted here only if its signature opens to the digest under that root key.

signature opens under root key\text{signature opens under root key}
Public toy rootThe toy root-to-leaf chain is recomputed from the signed digest.Public toy root - root verifies leafToy Root CAn=55, e=3Leaf cert binds share 19digest=33, sig=22

Summary

The root key is the trust anchor for this toy chain.

root modulus=55\text{root modulus}=55
Public toy rootThe toy root-to-leaf chain is recomputed from the signed digest.Public toy root - root verifies leafToy Root CAn=55, e=3Leaf cert binds share 19digest=33, sig=22