They may not have the private key of the certificate but they may control the (temporary) ACME account they need to create, so they can generate new certificates up to 30 days. Web browser based ACME clients
2 Likes