I have discovered a system database at:
/var/db/SystemPolicyConfiguration/ExecPolicy
Which seems to contain the pertinent provenance information. I am hoping there is a command line tool that will reset values in this database so that I don't have to go wild and try hacking the file myself. But this gives me a lead at least! I'll try it in a VM first...
Topic:
Code Signing
SubTopic:
Entitlements
Tags: