Vault configuration should be possible only in one location in config files - on top level between </extensions> <management>. We recommend that it should be removed from security subsystem domain model, because of redundancy.
A removal of existing configuration would cause backwards compatibility issues, I am not sure how this could be considered until EAP 7.
This would break backwards comparability. Wcan consider for EAP 7 with a plan around migrating configurations to compensate.
Closing as won't fix for EAP 6.x due to required backward compatibility.