Sometimes people who need to renew service certificates use ipa-cacert-manage renew (the wrong command) and either don't solve the problem or get into a deeper mess.
Tweak the ipa-cacert-manage(1) man page to be very clear that the command should not be used when all they need to do is renew EE certs.
freeipa-devel discussion: https://lists.fedoraproject.org/archives/list/freeipa-devel@lists.fedorahosted.org/thread/GUDF2CNIVDB52X4LCXXFCQIJ4RKQ46N6/
Metadata Update from @pvoborni: - Issue set to the milestone: FreeIPA 4.7
Metadata Update from @rcritten: - Issue set to the milestone: FreeIPA 4.7.1 (was: FreeIPA 4.7)
FreeIPA 4.7 has been released, moving to FreeIPA 4.7.1 milestone