Currently the default profile (used when no --profile-id argument given to cert-request) is `caIPAserviceCert' for all principal types, with no option to change this.
Admins may wish to specify a different default profile for users, or indeed override the default for hosts/services as well.
Metadata Update from @ftweedal: - Issue assigned to someone - Issue set to the milestone: FreeIPA 4.5 backlog
Indeed, having a default issuer (sub-CA / lightweight CA) for a given principal/group would be useful too.
Metadata Update from @ftweedal: - Issue close_status updated to: None