The KRA Agent is conceptually a separate user from the RA agent, so they should have separate certificates. Currently they sahre the same certificate.
Metadata Update from @simo: - Issue assigned to someone - Issue set to the milestone: FreeIPA 4.5 backlog
Login to comment on this ticket.