He is accessing CA server running locally on ASA in order to enroll. But he couldn't get authenticated against CA user database (LOCAL AAA method is used instead). That's why OTP doesn't work for him.
No (PAT is not supported with the fixup protocol rtsp) and No (you will need NAT to map the end of GRE tunnel; it will also compromise your security pix doesnt look inside tunnels payload).