This bug is created as a clone of upstream ticket:
It is defect of one usage of Sub-CAs - bug 1200731.
The DirectoryName SAN type should be allowed, provided the
value matches the principal's DN in the IPA directory.
Closing WONTFIX. See discussion at https://github.com/freeipa/freeipa/pull/228.