Revert "Fix nameConstraints to allow subdomains."

This reverts commit f7b0885a.

The patch causes an error during second playbook run:

pki-authority: Error: failed to run verify -CAfile
issuer/subject/cert.pem -untrusted subject/cert.pem
cert.pem (Exitcode: 2)

Details: CN =
error 47 at 0 depth lookup: permitted subtree violation
error hcert.pem: verification failed
......@@ -130,7 +130,7 @@ get_openssl_name_constraints_directive () {
local name_constraints
case "${config['name_constraints']}" in
name_constraints="nameConstraints = critical, permitted;DNS:.${config_domain}"
name_constraints="nameConstraints = critical, permitted;DNS:${config_domain}"
