There is a bug in certutil, the fingerprint it displays is garbage for 
certs living on a token (as the builtin certs do).  As for the value PSM 
shows, that matches with what 4.7x shows for the certs I looked at.  I 
don't know how IE computes their "thumbprint", but I would be suprised 
to learn it is different.  Are you sure you're comparing the same exact 
certs, not (for example) two certs with the same key but different 
validity periods (a reissue)?

-Ian


Reply via email to