I don't know about Linux, but I've been using KeePassX for Mac for about a year now. It only supports the older KeePass file format, and it's ugly, but it works great. There are also a few iOS apps you can use, my favorite of which is KyPass.
The way I read his tale, it sounds like VeriSign may have kept the signing keys for his intermediate CA, and their onsite secure terminal just submitted CSRs back to VeriSign and got the signed certificates back. VeriSign was then in a position to enforce the policy that no certs get signed for anything outside of the domains that should be signed.