I'm not great with Debian-based systems but apt show python-pyasn1 should provide the version of pyasn1 that is installed.
IPA 4.6.x is python2-based.
The problem isn't the request it's an ASN.1 parsing error. I'm guessing that the CA is issuing the new cert ok but because of the parsing issue it is blow up inside IPA so it can't be further processed.
So solving the python-pyasn1 issue could just fix everything. You might try downgrading it.
RHEL-7, which has IPA 4.6.6 uses python2-pyasn1-0.1.9-7.el7.
Took a while to get pyasn downgraded, but I still get the same error. :(
Sean