TL;DR: tofu can't download the provider: the registry asked for auth credentials, or the connection failed. Read the tail of the message. `requires authentication credentials` on registry.opentofu.org has been a transient registry-side incident; TLS timeouts are your network. Retry first, then check proxy and mirrors.

```text
Error: Failed to install provider

Error while installing hashicorp/random v3.7.2: host registry.opentofu.org
requires authentication credentials
```

## Steps

1. Read the tail of the error (the part after the provider name and version). It distinguishes the causes:
   - `requires authentication credentials` / `403 Forbidden`: registry-side or proxy issue.
   - `TLS handshake timeout` / `could not connect`: your network.
   - `checksum mismatch`: lock file problem, different fix.
   Expected: you can name the cause.
2. Retry once. Registry-side blips and rate limits are transient.
   Expected: the second `tofu init` succeeds.
3. If it persists, check the path to the registry: proxy env vars (`HTTPS_PROXY`), egress firewall rules, and whether `curl -sI https://registry.opentofu.org` answers from the same machine.
   Expected: you find the broken hop.
4. For air-gapped or flaky networks, install via a filesystem mirror: download the provider zip once, unpack it under the documented local mirror directory layout, and re-run init.
   Expected: init uses the local copy without touching the network.

## When this applies

- `tofu init` fails on `Error while installing [provider] v[version]:` with a registry, auth, or network complaint.
- It worked before with no config change (points at transient/registry-side).

## When it doesn't apply

- `Error: Failed to query available provider packages` fails earlier, at version LISTING; this error fails at DOWNLOAD.
- Checksum mismatches (`doesn't match any of the checksums previously recorded`) are a lock-file problem; fix with `tofu providers lock`.

## Tool versions

All OpenTofu versions.

## Why it happens

Installing is a plain HTTPS download from the registry (or a mirror). Anything that breaks HTTPS here, broken proxy, egress block, expired CA bundle, registry incident, surfaces as this error, after version resolution already succeeded.

## Edge cases

- Corporate MITM proxies: the Go HTTP client needs the proxy CA in the system trust store, or every registry call fails TLS.
- Don't "fix" a 403 by adding registry credentials to your CLI config unless you actually use a private registry. The public registry needs no auth; a 403 there is an incident or a proxy mangling the request.
- CI runners with IPv6-only egress have hit discovery-document failures; forcing IPv4 or fixing egress is the fix, not the config.