Title: #355: Set up DS TLS on replica in CA-less topology
Running `ipa-certupdate` on all systems after `ipa-ca-install` is problematic.
But we can at least make sure that `ipa-ca-install` on replica will get
whatever is possible automatically at beginning (e.g. run equivalent of
`ipa-certupdate`) and also that it have usable state after finishing
`ipa-ca-install`, i.e., it will run IPA whatever IPA calls it needs and
possible. Anyway it is for other ticket. Maybe it already exists.
See the full comment at
Manage your subscription for the Freeipa-devel mailing list:
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code