This was reported by radz for a (not-hardened) Okular 26.04 version but it's of course the same for our own builds.
In a PDF signed with an OpenPGP certificate go to the signature tab, right-click -> Properties, then "View Certificate". The fingerprints shown there are not the correct fingerprints of the certificate, instead they are the sha-sums of the file you can export with the button below:
