It was found that FreeIPA fails to check the CA ACLs properly, moreover the SAN name is incorrectly checked for service principals which means someone can request an arbitrary SAN name for services. The vulnerable code was added in the 4.4.0 release, which is not yet available in Fedora or RHEL.
Acknowledgments: Name: Simo Sorce (Red Hat)
Created attachment 1184610 [details] 0001-Fix-CA-ACL-Check-on-SubjectAltNames.patch
Upstream patch: https://git.fedorahosted.org/cgit/freeipa.git/commit/?id=25ed36fda14b30d6a50746a536939e3b428993cb