то>.acceptable PK alg (eg RSA vs ECDSA).The CRL is signed with an unacceptable key (eg bad curve, RSA too short).The certificate is signed with an unacceptable key (eg bad curve, RSA too short).The CRL is signed with an unacceptable hash.The certificate is signed with an unacceptable hash.The CRL is not correctly signed by the trusted CAThe certificate is not correctly signed by the trusted CAThe certificate Common Name (CN) does not match with the expected CNCertificate verification