This concept is important to note when renewing the key pair on a CA since this is commonly done at around 50% of the CA's validity period meaning that certificates will need to access this path after key renewal occurs.

When a key pair is renewed on a CA the new certificate should not use the same path as the original certificate unless the private key for the CA and the authority key identifier (AKI) are not changed as part of the renewal.

Certificate validation is implemented differently based on the application validating the certificate, the type of identity being validated (i.e.

validating a certificate from a web server will differ from validating a signed e-mail), and configuration of the Windows computer performing the validation.

Out-of-the-box this provided options to identify the certificate owner in any of the following ways (ref:

Another example of this is when you receive a digitally signed e-mail; the e-mail signature is only valid if the sender's e-mail matches the e-mail address listed on the certificate (under RFC822 Name).

In the initial two versions of the X.509 standard the only way to assert an identity was to use the "Subject" field of the certificate.

Key usage can be specified in either the "Key Usage" or "Extended Key Usage" attribute based on the validation requirements of the application.