When a client (like a web browser) connects to a server over SSL/TLS, the server presents its end-entity certificate to the client. The client then verifies this certificate by checking its signature ...