PKI can fail operationally while cryptography is sound

Almost every real certificate failure is a process failure, not a mathematical one.

An expired certificate nobody renewed. A key on a laptop that left with an employee. A revocation nobody checks. An internal authority whose backup was never tested. The algorithms perform exactly as designed throughout. This is the same pattern as key management generally: the maths holds and the administration around it does not.

More on TLS and PKI