krb5 now (krb5-1.16-17) has support for single-factor SPAKE, which makes password brute-forces infeasible and reduces reliance on timestamps. To enable it, we need a two-line change on Kerberos setup, as per https://github.com/freeipa/freeipa/pull/1747 Thanks!
freeipa-4.6.90.pre2-3.fc28 has been submitted as an update to Fedora 28. https://bodhi.fedoraproject.org/updates/FEDORA-2018-93dfeefc68
freeipa-4.6.90.pre2-3.fc28 has been pushed to the Fedora 28 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-93dfeefc68
freeipa-4.6.90.pre2-3.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.