Fraser,
I cannot pass the DN or CN as part of the subject on the command line
ipa-server-install
Ipa-server-install appears to set the CN to 'Certificate Authority' from the
openssl output. I believe the preferred for a subCA should be the FQDN of
the subCA server which is the ipa
>From old threads back in August 2016 I have been able to get closer to
>installing freeipa server as a subCA to our in house rootCA
https://www.redhat.com/archives/freeipa-users/2016-August/msg00269.html
Running the initial install command
ipa-server-install --external-ca --domain=camgian.com