On Fri, Apr 08, 2016 at 01:34:24AM -0500, Endi Sukma Dewata wrote:
 For backward compatibility the pki pkcs12-import has been modified
 to generate default nicknames and trust flags for CA certificates
 if they are not specified in the PKCS #12 file. The PKCS12Util was
 also modified to find the certificate corresponding to a key more
 accurately using the local ID instead of the subject DN.
 
 The configuration servlet has been modified to provide better
 debugging information when updating the security domain.
 
 
https://fedorahosted.org/pki/ticket/2255
 
 -- 
 Endi S. Dewata
 
ACK.  This patch has made my dreams** come true.
** lightweight CA key replication