{"record":{"id":"881d43d8c3bab201","repo":"hashicorp/terraform","slug":"authentication-signature-from-unknown-issuer","errorCode":null,"errorMessage":"authentication signature from unknown issuer","messagePattern":"authentication signature from unknown issuer","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":563,"sourceCode":"\t\t}\n\n\t\t// Any other signature error is terminal.\n\t\tif err != nil {\n\t\t\treturn nil, \"\", fmt.Errorf(\"error checking signature: %s\", err)\n\t\t}\n\n\t\tkeyID := \"n/a\"\n\t\tif entity.PrimaryKey != nil {\n\t\t\tkeyID = entity.PrimaryKey.KeyIdString()\n\t\t}\n\n\t\tlog.Printf(\"[DEBUG] Provider signed by %s\", entityString(entity))\n\t\treturn &key, keyID, nil\n\t}\n\n\t// If none of the provided keys issued the signature, this package is\n\t// unsigned. This is currently a terminal authentication error.\n\treturn nil, \"\", fmt.Errorf(\"authentication signature from unknown issuer\")\n}\n\n// entityString extracts the key ID and identity name(s) from an openpgp.Entity\n// for logging.\nfunc entityString(entity *openpgp.Entity) string {\n\tif entity == nil {\n\t\treturn \"\"\n\t}\n\n\tkeyID := \"n/a\"\n\tif entity.PrimaryKey != nil {\n\t\tkeyID = entity.PrimaryKey.KeyIdString()\n\t}\n\n\tvar names []string\n\tfor _, identity := range entity.Identities {\n\t\tnames = append(names, identity.Name)\n\t}","sourceCodeStart":545,"sourceCodeEnd":581,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L545-L581","documentation":"Thrown by findSigningKey after every key in s.Keys has been tried and none matched the signature issuer. The package is therefore unsigned by any registry-listed key, which is treated as a terminal authentication failure rather than a soft warning.","triggerScenarios":"The loop over s.Keys completed without returning: for each key either openpgp returned ErrUnknownIssuer (continue) or the signature was issued by a key absent from the registry-supplied list.","commonSituations":"Provider was signed by a key the registry does not publish; signing key was rotated upstream but the registry's signing_keys is stale; registry misconfiguration returning an empty or wrong key set; a genuinely unsigned community package presented where a signature was required.","solutions":["Update the registry/provider metadata so the signing key is published","Confirm the provider version is the official release (not a fork or manual build)","Use a curated mirror that publishes the correct signing_keys for the provider","If signing locally, ensure the signing key is registered with the registry"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":"func HasAnyValidSignature(keys []SigningKey, sig []byte) bool {\n    // Returns false only to flag that all keys are exhausted; full check\n    // still belongs to findSigningKey.\n    return len(keys) > 0 && len(sig) > 0\n}","tryCatchPattern":"_, _, err := auth.findSigningKey()\nif err != nil && strings.Contains(err.Error(), \"unknown issuer\") {\n    return fmt.Errorf(\"provider %s is not signed by any registry-listed key\", provider)\n}","preventionTips":["Ensure the registry publishes the signing key for every provider version you install","For community providers, register their signing key with the registry before relying on it"],"tags":["pgp","signature","unsigned","authentication","provider"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}