With the change in
SERVER-2268, SANs signing is only a global setting. This opens the potential for any client to submit a CSR with SANs that gets signed when allow-dns-alt-names is enabled. This is desirable in some deployments, but not all deployments. In a typical deployment, most of the nodes that require a SAN will be infrastructure nodes so the number of nodes requiring this setting will be low. It would be nice to be able to have allow-dns-alt-names disabled, but sign a single certificate with SANs with a CLI argument, or API parameter.
In PE, DNS alt names are suggested for MoMs and Compile Masters: https://puppet.com/docs/pe/2018.1/installing_compile_masters.html#install-compile-masters