A digital certificate may be withdrawn or revoked by CA's if it comes to light that
the 'embedded relationship' between a key and the identity is incorrect or has changed e.g. or has changed employers. In addition, in security breaches, where the privacy of the issued certificates is compromised (i.e. it is reported that more than one person has attempted to use the key) similar actions may be taken. Such occasions of revocation are rare, but it means that even 'trusted' certificates should be checked for their current validity or 'expiry' status. Although it is the job of the PKI to check and update its certificates, in practice it is not always done. Third party protocols like (Online status certificate protocol OSCP) queries the certificate issuing server to check the validity instead.