File: //lib/firewalld/services/freeipa-4.xml
<?xml version="1.0" encoding="utf-8"?>
<service>
  <short>FreeIPA 4 server</short>
  <description>FreeIPA is an integrated identity and authentication solution with Kerberos, LDAP, PKI, and web UI. Enable this option if you plan to provide a FreeIPA server. Enable the 'dns' service if this FreeIPA server provides DNS services, 'ntp' service if this FreeIPA server provides NTP services, and 'freeipa-trust' for cross-forest trusts with Active Directory.</description>
  <!-- CRL and OCSP -->
  <include service="http"/>
  <!-- API and web UI -->
  <include service="https"/>
  <include service="kerberos"/>
  <include service="kpasswd"/>
  <include service="ldap"/>
  <include service="ldaps"/>
</service>