On 8/19/2016 4:26 PM, Endi Sukma Dewata wrote:
 The CA signing CSR is already stored in request record which will
 be imported as part of migration process, so it's not necessary to
 export and reimport the CSR file again for migration.
 To allow optional CSR, the pki-server subsystem-cert-validate
 CLI has been modified to no longer check the CSR in CS.cfg. The
 ConfigurationUtils.loadCertRequest() has been modified to ignore
 the missing CSR in CS.cfg.
 
https://fedorahosted.org/pki/ticket/2440 
ACKed by alee (thanks!). Pushed to master (10.4).
-- 
Endi S. Dewata