Title: #62: Configure Anonymous PKINIT on server install
Regarding requesting certificate for krbtgt, we plan to fix cert-request in a
more systematic manner to allow requesting certificate for any principal in IPA
realm (see https://fedorahosted.org/freeipa/ticket/6295) so hopefully the
cert-request fixes would not be needed eventually.
As a side question is the separate profile needed due to some custom extensions
required for PKINIT certificate?
See the full comment at
Manage your subscription for the Freeipa-devel mailing list:
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code