Why Do I Get "Can't Find Client Principal USER@DOMAIN.LOCAL in Cache Collection" When Trying to Authenticate via Kerberos for WinRM in Ansible?

Solution Verified - Updated -


When using Kerberos to authenticate against a Windows host in Ansible/Ansible Tower, you may receive the following error:

kerberos: authGSSClientInit() failed: (('Unspecified GSS failure.  Minor code may provide more information', 851968), (\"Can't find client principal ansible@TEST.LOCAL in cache collection\", -1765328243))


  • Ansible Engine
  • Ansible Tower

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In