Read nsCertType extension, write EnrollmentProfile
Read the nsCertType extension from certificates and cache it, and learn
to generate a nsCertType extension request. Don't expose it in the UI
or over the bus, at least not yet, since the extension itself is
deprecated. We may need it for the sake of OpenVPN use cases.
When we have a template/profile name, go ahead and add it as a requested
value for the enrollment certificate type in signing requests, in case
it ends up being needed for implementing IPA ticket #57. It _should_ be
ignored, like other extension requests, otherwise.