Once again, a CA with *ONLY* rfc822Name constraints should not be able to able issue EE certificates with SmtpUtf8Name altNames that conflict with its rfc822Name constraints.
How about if a CA with only rfc822Name constraints can't issue certs with SmtpUTF8Names at all, and of course vice versa. If you want both kinds of names, the CA has to constrain both. R's, John