Documentation/README should explain:
- You can't compare certificate fingerprints because precertificates have a different fingerprint.
- You don't want to compare serial numbers because malicious CAs could reuse the serial number.
- Ideally you compare the TBS hash, but there are zero tools for computing this.
- So comparing the public key fingerprint is the best bet.