Your certificate proves you hold a key. It does not prove who you are
until we have enrolled it against your name.
So enrol it once, from your own account, before you are asked to sign
anything with it. A signature from a certificate nobody enrolled is
refused, however good the signature is.
Go to My signing keys and add the certificate. You paste the
certificate itself, never the private key. LEAT never asks for a private
key, and any page that does is not LEAT.
Enrolling grants you nothing. What you are allowed to approve comes from
the scheme of delegation, separately. Somebody can hold a certificate and
be allowed to approve nothing at all.
When you are asked to decide, LEAT gives you a short document to sign. It
names the thing being approved, the exact version, and your decision. You
sign that document with your own software and send back the signature.
You cannot sign something else and have it accepted. The document is
generated by LEAT for that one decision, and the signature is checked
against it.
A certificate signature comes back as one of three things, and the middle
one is the one people find surprising.
The third is not a softer version of the second. It means nobody can say
either way, and treating it as a pass would be recording an approval we
never verified.
Withdraw the old one from My signing keys and enrol the new one.
Decisions you already made with the old certificate stay on the record:
withdrawing it stops it being used again, and changes nothing about what
it already signed.