[salt.minion.cert] Improve certificates management

1. Remove implicit creation of "local_trusted_symlink".
   To install a system-wide certificates the linux.system.cert
   state or 'trusted_ca_minion' option must be used.

2. A ca-cert file may exist on a file-system and
   not be pulled from mine. So, in this case
   the following state be incorrect:

   - watch:
     - x509: ca_file

   To support this case, we need to replace `watch` statement
   with `watch_in`.

Change-Id: If41d050b56913d72da1ef7981f30780fec5d6d95
1 file changed