How can a certificate be matched to a private key?
A certificate and private key match when the public key derived from the private key is identical to the public key embedded in the certificate. Comparing those values detects a common deployment failure in which a valid certificate is installed beside the wrong key.
Node-forge derives and compares the keys locally, so private-key material is not uploaded. A positive match proves only that the pair corresponds; it says nothing about certificate trust, hostname coverage, expiry, revocation, chain completeness, permissions, or whether the private key has already been exposed.