Ensure that the name in the principal is lower-case. The realm is upper-case by convention but it isn’t required.
The principal is validated at this point.
ipaserver.plugins.service.check_required_principal
ipaserver.plugins.service.rename_ipaallowedtoperform_from_ldap