I recently learned mechanism of certificates. But I can't understand why a "thumbprint" is included in a certificate.
For intermediate and end-user certificates, it is verified by its issuer. so it can simply be calculated as the certificate itself is trusted.
For root/self-signed certificates, they're not trusted unless it is provided with the OS. So the thumbprint included is also not trusted.
I think that I just misunderstood something, can anyone point it out?