When executing binaries like /usr/bin/pki we should transition to adifferent dopmain so rules like allow execmem are only given to the specific bianry and not necesary for the whole custodia process. In general this wil allow to restrict what can access ther nss databases too.