Static ReadonlyEST_Every name EST reads as a label: the issued profiles and the refused ones. A trust realm may not be called any of these.
Static ReadonlyPROFILE_The nine certificate profiles an enrollment protocol may issue.
Static ReadonlyREFUSED_The five profiles an enrollment protocol never issues, each with the reason drawn on every protocol page and returned by every refusal.
The certificate profiles an enrollment protocol names, as data only.
The nine profiles ACME, EST and SCEP issue and the five they never do, kept in a leaf that requires nothing so that
common/realms.jscan read the names. The decisions themselves are incommon/cert_enrollment.ts.