There is another problem. At least until F8, the OpenSSL config file in /etc/pki/tls/openssl.cnf
If you look at the [ CA_default ] section you'll find that the directories listed do not match the
ones that are actually installed with the package.
So if you use openssl command to create a cert you'll need to override the defaults or muck around w/ the config.