{"record":{"id":"813eb756dc400b65","repo":"hashicorp/terraform","slug":"error-verifying-trust-signature-s","errorCode":null,"errorMessage":"error verifying trust signature: %s","messagePattern":"error verifying trust signature: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":449,"sourceCode":"\tif signingKey.TrustSignature != \"\" {\n\t\thashicorpPartnersKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPartnersKey))\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error creating HashiCorp Partners keyring: %s\", err)\n\t\t}\n\n\t\tauthorKey, err := openpgpArmor.Decode(strings.NewReader(signingKey.ASCIIArmor))\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error decoding signing key: %s\", err)\n\t\t}\n\n\t\ttrustSignature, err := openpgpArmor.Decode(strings.NewReader(signingKey.TrustSignature))\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error decoding trust signature: %s\", err)\n\t\t}\n\n\t\t_, err = s.checkDetachedSignature(hashicorpPartnersKeyring, authorKey.Body, trustSignature.Body, nil)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error verifying trust signature: %s\", err)\n\t\t}\n\n\t\treturn &PackageAuthenticationResult{result: partnerProvider, KeyID: keyID}, nil\n\t}\n\n\t// We have a valid signature, but it's not from the HashiCorp key, and it\n\t// also isn't a trusted partner. This is a community provider.\n\treturn &PackageAuthenticationResult{result: communityProvider, KeyID: keyID}, nil\n}\n\nfunc (s signatureAuthentication) checkDetachedSignature(keyring openpgp.KeyRing, signed, signature io.Reader, config *packet.Config) (*openpgp.Entity, error) {\n\tentity, err := openpgp.CheckDetachedSignature(keyring, signed, signature, config)\n\t// FIXME: it's not clear what should be done with provider signing key\n\t// expiration. This check reverts the validation behavior to match that of\n\t// the original x/crypto/openpgp package.\n\t//\n\t// We don't force providers to update keys for older releases, so they may\n\t// have since expired. We are validating the original signature however,","sourceCodeStart":431,"sourceCodeEnd":467,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L431-L467","documentation":"Thrown during provider package authentication after a signing key with a non-empty TrustSignature was found. The author key and trust-signature blobs are decoded from ASCII armor, then the trust signature is verified against the embedded HashiCorpPartnersKey keyring via checkDetachedSignature. If that verification returns any error (other than tolerated key expiry), the provider cannot be elevated to partner status and this error surfaces.","triggerScenarios":"The registry returned a SigningKey whose TrustSignature field is non-empty, and openpgp.CheckDetachedSignature(hashicorpPartnersKeyring, authorKey.Body, trustSignature.Body, nil) returned a non-nil error (bad signature, structural PGP error, wrong issuer, etc.).","commonSituations":"Corrupted or truncated trust-signature blob in the registry response; partner key rotation where the bundled HashiCorpPartnersKey no longer matches the published trust signature; a tampered/re-published provider artifact; a community key mistakenly carrying a stale or foreign trust signature.","solutions":["Re-run the operation to rule out a transient corrupt registry response","Verify the provider source address and version are the intended ones (a re-published/tampered artifact often fails here)","If using a mirror or airgapped registry, confirm its signing_keys / trust_signature data matches the upstream registry exactly","Report the provider and key ID to the registry operator if the failure persists across versions"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"result, err := auth.AuthenticatePackage(meta.Location)\nif err != nil {\n    if strings.Contains(err.Error(), \"trust signature\") {\n        log.Printf(\"provider %s failed partner trust verification: %v\", meta.Provider, err)\n    }\n    return err\n}","preventionTips":["Pin provider versions to releases you have previously verified","Maintain a lock file with known-good hashes so signature checks still gate downloads","For airgapped use, curate a private mirror with audited partner trust signatures"],"tags":["pgp","signature","authentication","trust","provider"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}