The credential's signature validated against a signer on the trust list.
The credential could not be confirmed. Deliberately one bucket: a tampered file, an untrusted signer and a certificate that simply aged out are not distinguished here, though the granular validation codes are retained.