{"record":{"id":"213503b22cfbe5e7","repo":"hashicorp/terraform","slug":"failed-to-create-signer-from-raw-private-key-q","errorCode":null,"errorMessage":"failed to create signer from raw private key %q: %s","messagePattern":"failed to create signer from raw private key %q: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/communicator/ssh/provisioner.go","lineNumber":410,"sourceCode":"\n\treturn conf, nil\n}\n\n// Create a Cert Signer and return ssh.AuthMethod\nfunc signCertWithPrivateKey(pk string, certificate string) (ssh.AuthMethod, error) {\n\trawPk, err := ssh.ParseRawPrivateKey([]byte(pk))\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to parse private key %q: %s\", pk, err)\n\t}\n\n\tpcert, _, _, _, err := ssh.ParseAuthorizedKey([]byte(certificate))\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to parse certificate %q: %s\", certificate, err)\n\t}\n\n\tusigner, err := ssh.NewSignerFromKey(rawPk)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to create signer from raw private key %q: %s\", rawPk, err)\n\t}\n\n\tucertSigner, err := ssh.NewCertSigner(pcert.(*ssh.Certificate), usigner)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to create cert signer %q: %s\", usigner, err)\n\t}\n\n\treturn ssh.PublicKeys(ucertSigner), nil\n}\n\nfunc readPrivateKey(pk string) (ssh.AuthMethod, error) {\n\t// We parse the private key on our own first so that we can\n\t// show a nicer error if the private key has a password.\n\tblock, _ := pem.Decode([]byte(pk))\n\tif block == nil {\n\t\treturn nil, errors.New(\"Failed to read ssh private key: no key found\")\n\t}\n\tif block.Headers[\"Proc-Type\"] == \"4,ENCRYPTED\" {","sourceCodeStart":392,"sourceCodeEnd":428,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/communicator/ssh/provisioner.go#L392-L428","documentation":"After parsing both the private key and certificate, ssh.NewSignerFromKey is called to create a signer from the raw private key. This fails if the key type does not support signing through this API path, or if the parsed key object is of an unexpected underlying type. SECURITY NOTE: the error interpolates the rawPk object via %q, which may dump key internals into logs.","triggerScenarios":"The parsed private key is of a type that ssh.NewSignerFromKey cannot handle (e.g., a multi-key or a key subtype not covered by the switch in x/crypto/ssh). Also triggered if ParseRawPrivateKey returned a valid but unsupported key algorithm for signer construction.","commonSituations":"Using an exotic or very new key algorithm that the linked golang.org/x/crypto version doesn't support for signing. Using a key that parsed but is a certificate key being passed where a plain key is expected. Version mismatch between the key generation tool and the x/crypto library.","solutions":["Regenerate the key using a well-supported algorithm (RSA 2048/4096 or ECDSA).","Update golang.org/x/crypto to the latest version to support newer key types.","Verify the private_key value is a plain private key, not a key+certificate bundle.","If using ed25519, ensure both the Go toolchain and x/crypto are recent enough for ed25519 signer support."],"exampleFix":"# before — exotic or unsupported key algorithm\nconnection {\n  private_key = var.exotic_key\n}\n\n# after — use standard RSA or ECDSA key\nssh-keygen -t rsa -b 4096 -f ~/.ssh/tf_id_rsa\nconnection {\n  private_key = file(\"~/.ssh/tf_id_rsa\")\n}","handlingStrategy":"try-catch","validationCode":"// Test signer creation from the parsed key before full setup\nfunc canCreateSigner(pk string) error {\n    rawPk, err := ssh.ParseRawPrivateKey([]byte(pk))\n    if err != nil {\n        return err\n    }\n    _, err = ssh.NewSignerFromKey(rawPk)\n    return err\n}","typeGuard":null,"tryCatchPattern":"signer, err := ssh.NewSignerFromKey(rawPk)\nif err != nil {\n    return nil, fmt.Errorf(\"cannot create signer from key (unsupported type?): %w\", err)\n}","preventionTips":["Use standard RSA or ECDSA keys to maximize signer compatibility.","Update golang.org/x/crypto when adopting newer key algorithms.","Avoid exotic or experimental key types for infrastructure provisioning."],"tags":["ssh","crypto","private-key","signer","algorithm"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}