When setting up an Enterprise Login for a FreeIPA domain, type wrong password, and you often get a "Decrypt integrity check failed" message. This is the code that FreeIPA (and other non-AD KDCs) return for bad password. Upstream bug: https://bugzilla.gnome.org/show_bug.cgi?id=698266 From the test day: https://fedoraproject.org/wiki/Test_Day:2013-04-18_FreeIPA
Apart of this the control-center could give a hint what was wrong when the user add failed. E.g. if the given domain cannot be discovered, or the user credentials were wrong. I'm not sure if it it possible distinguish between wrong user name or wrong password, but the the incorrect domain.name can be seen in logs definitely.
Yes, that's the whole point of this bug. It works as expected against AD, but not against FreeIPA.
AD has richer error codes. IPA KDC does not add any usability on top of what vanilla MIT KDC returns in this case.
Patched upstream in both realmd and gnome-control-center.
control-center-3.8.1.5-1.fc19 has been submitted as an update for Fedora 19. https://admin.fedoraproject.org/updates/control-center-3.8.1.5-1.fc19
control-center 3.8.1.5 has been pushed to stable Fedora 19: https://admin.fedoraproject.org/updates/FEDORA-2013-7788/control-center-3.8.1.5-1.fc19