In the FAS replacement being rolled out in 2021, that uses freeipa and noggin, if a user has 2FA enabled, they need some extra configuration to get kinit working with 2FA.
Note that the commit message has a little more information, and there is also a docs PR in progress that covers for users how to use this. https://github.com/fedora-infra/fedora-accounts-docs/pull/1/files (this will need to be changed to remove the steps that this PR implements)
https://github.com/fedora-infra/fedora-accounts-docs/pull/1 has a bit more information on the reasons for doing this this way too.
In the FAS replacement being rolled out in 2021, that uses freeipa and noggin, if a user has 2FA enabled, they need some extra configuration to get kinit working with 2FA.
Note that the commit message has a little more information, and there is also a docs PR in progress that covers for users how to use this. https://github.com/fedora-infra/fedora-accounts-docs/pull/1/files (this will need to be changed to remove the steps that this PR implements)
https://github.com/fedora-infra/fedora-accounts-docs/pull/1 has a bit more information on the reasons for doing this this way too.