What versions of IPA packages are you running? See below for the current versions.
% rpm -q ipa-server idm-pki-ca certmonger
A valid ticket is good. A kinit working means the KDC is working.
I would review /var/log/httpd/error_log for errors. Unfortunately this message only says so much. If you can pull the errors being logged there, including any stack traces, that will help drill down into the issue you’re facing.