b49e075 Allow for configuration of all three PKINIT variants when deploying KDC

1 file Authored by mbabinsk 6 years ago, Committed by jcholast 6 years ago,
    Allow for configuration of all three PKINIT variants when deploying KDC
    
    The PKINIT setup code now can configure PKINIT using IPA CA signed
    certificate, 3rd party certificate and local PKINIT with self-signed
    keypair. The local PKINIT is also selected as a fallback mechanism if
    the CSR is rejected by CA master or `--no-pkinit` is used.
    
    http://www.freeipa.org/page/V4/Kerberos_PKINIT
    https://pagure.io/freeipa/issue/6830
    
    Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
    Reviewed-By: Jan Cholasta <jcholast@redhat.com>
    Reviewed-By: Martin Basti <mbasti@redhat.com>
    Reviewed-By: Simo Sorce <ssorce@redhat.com>