For bug
Where is the code that generates the initial CA and server cert?
If I have to do a full ipa install to reproduce I will (btw, is the 2.0
install guide on correct?), but I'd rather have a smaller,
easily reproducible test case.

I assume you mean the self-signed CA. If that's the case then the CA is generated in ipaserver/install/

Server certs are generated in ipaserver/install/ and issue_server_cert()


