URL:
https://github.com/SSSD/sssd/pull/5762
Title: #5762: krb5: add support for oauth2 challenge (wip)
pbrezina commented:
"""
If the radius server is not running, then the prompt falls back to
password authentication, is it expected?
```
[vagrant(a)master.client.vm ~]$ su - tuser
Password:
```
Yes, it is expected. If the RADIUS server is not running, Kerberos won't get
Access-Challenge reply therefore it falls back to password auth.
"""
See the full comment at
https://github.com/SSSD/sssd/pull/5762#issuecomment-909073108