This feature allows dm and admin passwords to be generated on the host. To ensure they stay secret, they never leave in an unencrypted form. They are generated, used for the installation, and then saved in a GPG encrypted file. The GPG encryption is done by telling ipa::server about your GPG key. This needs to be done independently, before the ipa::server setup. Any good admin that is worthy of managing an IPA server should already know how to use GPG and use it regularly.
dd4d5e1