4a01114 cainstance: use correct profile for lightweight CA certificates

3 files Authored by jcholast 6 years ago, Committed by dkupka 6 years ago,
    cainstance: use correct profile for lightweight CA certificates
    
    Use Dogtag's `caCACert` CA certificate profile rather than the
    `ipaCACertRenewal` virtual profile for lightweight CA certificates.
    
    The `ipaCACertRenewal` virtual profile adds special handling of externally
    signed CA certificates and LDAP replication of issued certificates on top
    of `caCACert`, neither of which is relevant for lightweight CA
    certificates.
    
    Remove all of the special casing of lightweight CA certificates from
    dogtag-ipa-ca-renew-agent-submit.
    
    Make sure existing lightweight CA certmonger tracking requests are updated
    on server upgrade.
    
    https://pagure.io/freeipa/issue/5799
    
    Reviewed-By: David Kupka <dkupka@redhat.com>
    Reviewed-By: Stanislav Laznicka <slaznick@redhat.com>