What is the central trust relationship represented by an X.509 certificate?
It replaces encryption by declaring all traffic trustworthy
It binds a public key to the identity named as the certificate subject
It records only the dates during which a server may run
It publishes the subject's private key so clients can reproduce signatures