We get S/MIME user certificates for functional addresses (e.g. support@example.com) from a commercial provider that do not contain a Common Name, but just E-Mail in the DN and in the SAN. When rolling over to a new certificate, you have at least two of them in your Mozilla cert-store. If you have several functional addresses configured in your TB, it is impossible to find the correct certificate to change to, without seeing that e-mail-address (for those certificates without a CN). That means your only solution is to click yourself through every valid certificate in your list, until you find the right one. To avoid this senseless task, the table of "your certificates" should also display the e-mail from the SAN. Windows provides a workaround for the same problem in Outlook, by allowing you to set a "display name" for each of your user certificates in certmgr.