Obtaining kerberos tickets with Keycloak

Is there any way to obtain a kerberos ticket from Keycloak federated with FreeIPA without SPNEGO delegation? Our users will not have a machine enrolled with FreeIPA or have any krb5.conf, so they will have to log in to Keycloak with username and password. But the application needs a TGT ticket on user’s behalf.