{"record":{"id":"31f044c394a75aec","repo":"hashicorp/terraform","slug":"error-checking-signature-s","errorCode":null,"errorMessage":"error checking signature: %s","messagePattern":"error checking signature: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":549,"sourceCode":"// the future.\nfunc (s signatureAuthentication) findSigningKey() (*SigningKey, string, error) {\n\tfor _, key := range s.Keys {\n\t\tkeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(key.ASCIIArmor))\n\t\tif err != nil {\n\t\t\treturn nil, \"\", fmt.Errorf(\"error decoding signing key: %s\", err)\n\t\t}\n\n\t\tentity, err := s.checkDetachedSignature(keyring, bytes.NewReader(s.Document), bytes.NewReader(s.Signature), nil)\n\n\t\t// If the signature issuer does not match the key, keep trying the\n\t\t// rest of the provided keys.\n\t\tif err == openpgpErrors.ErrUnknownIssuer {\n\t\t\tcontinue\n\t\t}\n\n\t\t// Any other signature error is terminal.\n\t\tif err != nil {\n\t\t\treturn nil, \"\", fmt.Errorf(\"error checking signature: %s\", err)\n\t\t}\n\n\t\tkeyID := \"n/a\"\n\t\tif entity.PrimaryKey != nil {\n\t\t\tkeyID = entity.PrimaryKey.KeyIdString()\n\t\t}\n\n\t\tlog.Printf(\"[DEBUG] Provider signed by %s\", entityString(entity))\n\t\treturn &key, keyID, nil\n\t}\n\n\t// If none of the provided keys issued the signature, this package is\n\t// unsigned. This is currently a terminal authentication error.\n\treturn nil, \"\", fmt.Errorf(\"authentication signature from unknown issuer\")\n}\n\n// entityString extracts the key ID and identity name(s) from an openpgp.Entity\n// for logging.","sourceCodeStart":531,"sourceCodeEnd":567,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L531-L567","documentation":"Thrown by findSigningKey when checkDetachedSignature returns a terminal (non-unknown-issuer) error while verifying the checksums signature against a candidate key. Unlike ErrUnknownIssuer (which advances to the next key), any other failure halts key search immediately.","triggerScenarios":"checkDetachedSignature(keyring, Document, Signature, nil) returned an error that is not openpgpErrors.ErrUnknownIssuer (e.g. malformed signature packet, hash mismatch, structural openpgp error).","commonSituations":"Corrupted or truncated SHA256SUMS.sig file served by the registry; checksum document that does not correspond to the signature; mismatch between the armored key and the signature packet; openpgp library rejecting a structurally invalid detached signature.","solutions":["Re-download the provider to obtain a fresh signature document","Confirm the registry is serving the signature that matches the published SHA256SUMS file","Check whether a mirror is mismatching checksums and signature artifacts","Report a persistently broken signature to the registry operator"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"if _, err := auth.AuthenticatePackage(meta.Location); err != nil {\n    if errors.Is(err, openpgpErrors.ErrUnknownIssuer) || strings.Contains(err.Error(), \"checking signature\") {\n        return fmt.Errorf(\"provider %s signature verification failed: %w\", meta.Provider, err)\n    }\n    return err\n}","preventionTips":["Do not disable signature verification to work around this error; treat it as a security signal","Pin provider versions so a known-good signature is reused"],"tags":["pgp","signature","checksum","authentication","provider"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}