When searching a pkcs#11 token store pkinit expects that the CKA_ID of a private key will match that of a certificate. If pktool is used to store previously generated certificates and private keys it will store the private keys with no CKA_ID. The certificates are stored with a correct CKA_ID.
I've attached a mail conversation with Wyllys which should help to explain the situation better.
|