RSA signature validation gap in CI.dll for grandfathered drivers
A legacy validation path checked certificate chains, hashes, and timestamps while accepting a zeroed RSA signature. I broke each component separately to find out where enforcement stopped.