The attached patch addresses the following TRAC ticket:
*
https://fedorahosted.org/pki/ticket/667 TRAC Ticket #667 - provide
option for ca-less drm install
Unlike the previous patch which did not utilize a security domain and
utilized the legacy GUI panel configuration, this patch only pertains to
the non-GUI 'pkispawn' installation/configuration process as documented at:
*
http://pki.fedoraproject.org/wiki/Stand-alone_PKI_Subsystems
Using this code, I have successfully installed a stand-alone DRM
utilizing a separate PKI CA as my external CA for testing purposes.
Should this code be approved, I will add the following:
* update the 'pkispawn' man page
* add similar default values as parameters to OCSP
At this stage, this code has not been tested to see if a DRM can be
successfully cloned from a Stand-Alone DRM.
-- Matt