> regardless of authentication, client updates to DNS zones are still a
> risk and a rogue app or user can still perform direct updates to zones,
> leading to impersonation/interception of services, denial of service
> attacks and more.  endpoints, or their users, should not be trusted to
> make updates to DNS zones.  TSIG signed updates from servers are still
> preferred over authenticated updates from endpoints or users.

Not really. With the default ipa configuration (grant ZONE.COM krb5-self
* A) the worst that could do the administrator of a workstation, with
access to the host keytab, is point the A record of her workstation to a
wrong address. 

Please note that someone able to read the host keytab (root on the
workstation) could simply skip dhcp negotiation and assign to her
workstation any address she likes.

With the default ipa configuration a workstation can only set _its_ A,
AAAA and SSHFP records. No less and no more.

