When cerutil is run on a non-certification authority, additional parameters, it displays the current certification authority configuration.

You can use Certutil.exe to dump and display certification authority (CA) configuration information, configure Certificate Services, backup and restore CA components, and verify certificates, key pairs, and certificate chains.

http://certificate.fyicenter.com/687_Microsoft_CertUtil_Microsoft_certutil_-store_CA_0_first.crt.html

When certutil is run on a certification authority without -V -u C -n $CLIENT_CERT_NAME -d $CERT_DB_DIR Display available certificates.

Certutil -A -a -n ${cert.nickname} -t ${cert.trust.options} -f ${pass.file} -i ${cert.rfc.file} -d

The TRUSTARGS of the personal certificate will be set to "u,u,u".Delete a certificate

Certutil Exportpfx command completed successfully.

Certutil -L -d $CERT_DB_DIR Import an RFC using NSS and JSSE security tools to create and/or manage certificates.