FreeIPA and 389 Directory Server flaws let an anonymous client create an attacker-chosen Kerberos identity in the administrators group.