if (cacert == null) {
// This is an initial root CA, since no CA-certificate exists
// (I don't think we can ever get here!!!)
X509NameEntryConverter converter = null;
if (getUsePrintableStringSubjectDN()) {
converter = new PrintableStringEntryConverter();
} else {
converter = new X509DefaultEntryConverter();
}
X509Name caname = CertTools.stringToBcX509Name(getSubjectDN(), converter, getUseLdapDNOrder());