After posting this trick, I subsequently got an error about invalid certificates (see <a
this thread for the complete run down).
It boils down to: delete the cert8.db file from your profile, restart Thunderbird, and attempt reconnect, and you should be prompted, again, to match the mis-matched domains.
CAUTION: if you delete your cert8.db file from your profile, and you have added other certificates to your profile, you will lose those as well.