I'm pondering the idea of leveraging a Extension Attribute that could theorietically report/verify the existence of a specific root CA certificate in the OS X System Keychain. Based on the results it yields, I could add/delete certificate(s) as needed via scripts/policies, etc.
Has anyone invented this wheel yet?
