{"record":{"id":"d3d2d58f96a8c202","repo":"hashicorp/terraform","slug":"error-decoding-trust-signature-s","errorCode":null,"errorMessage":"error decoding trust signature: %s","messagePattern":"error decoding trust signature: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":444,"sourceCode":"\t\treturn &PackageAuthenticationResult{result: officialProvider, KeyID: keyID}, nil\n\t}\n\n\t// If the signing key has a trust signature, attempt to verify it with the\n\t// HashiCorp partners public key.\n\tif signingKey.TrustSignature != \"\" {\n\t\thashicorpPartnersKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPartnersKey))\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error creating HashiCorp Partners keyring: %s\", err)\n\t\t}\n\n\t\tauthorKey, err := openpgpArmor.Decode(strings.NewReader(signingKey.ASCIIArmor))\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error decoding signing key: %s\", err)\n\t\t}\n\n\t\ttrustSignature, err := openpgpArmor.Decode(strings.NewReader(signingKey.TrustSignature))\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error decoding trust signature: %s\", err)\n\t\t}\n\n\t\t_, err = s.checkDetachedSignature(hashicorpPartnersKeyring, authorKey.Body, trustSignature.Body, nil)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error verifying trust signature: %s\", err)\n\t\t}\n\n\t\treturn &PackageAuthenticationResult{result: partnerProvider, KeyID: keyID}, nil\n\t}\n\n\t// We have a valid signature, but it's not from the HashiCorp key, and it\n\t// also isn't a trusted partner. This is a community provider.\n\treturn &PackageAuthenticationResult{result: communityProvider, KeyID: keyID}, nil\n}\n\nfunc (s signatureAuthentication) checkDetachedSignature(keyring openpgp.KeyRing, signed, signature io.Reader, config *packet.Config) (*openpgp.Entity, error) {\n\tentity, err := openpgp.CheckDetachedSignature(keyring, signed, signature, config)\n\t// FIXME: it's not clear what should be done with provider signing key","sourceCodeStart":426,"sourceCodeEnd":462,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L426-L462","documentation":"Thrown by signatureAuthentication.AuthenticatePackage when openpgpArmor.Decode fails to parse signingKey.TrustSignature as ASCII-armored OpenPGP data. This runs inside the partner-verification branch (signingKey.TrustSignature != ''), immediately after successfully decoding the signing key itself. The trust_signature is a signature by the registry operator (HashiCorp Partners key) over the author key; if its armor is malformed, partner verification aborts at package_authentication.go:442-444.","triggerScenarios":"A provider whose signing key has a non-empty trust_signature whose value is not valid armored OpenPGP — bad armor header, truncated base64, or the wrong field value placed into trust_signature by the registry.","commonSituations":"A registry bug placing the key body or a binary signature into trust_signature instead of the armored trust signature; a copy-paste/truncation when configuring a private registry's signing metadata; a proxy mangling the JSON field.","solutions":["Have the registry populate trust_signature with a complete, valid ASCII-armored OpenPGP signature (full BEGIN/END PGP SIGNATURE block).","If the provider should not be a partner, leave trust_signature empty rather than set to invalid data.","Validate trust_signature with gpg --list-packets or openpgpArmor.Decode before publishing.","Inspect the registry JSON to confirm trust_signature is not truncated or escaped incorrectly."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"func validTrustSignatureArmor(k getproviders.SigningKey) error {\n    if k.TrustSignature == \"\" {\n        return nil\n    }\n    if _, err := openpgpArmor.Decode(strings.NewReader(k.TrustSignature)); err != nil {\n        return fmt.Errorf(\"invalid trust_signature armor: %w\", err)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"_, err := auth.AuthenticatePackage(loc)\nif err != nil && strings.Contains(err.Error(), \"error decoding trust signature\") {\n    // registry served a malformed trust signature; re-fetch key metadata and retry\n    return err\n}","preventionTips":["Only set trust_signature when it is a valid armored OpenPGP signature.","Leave trust_signature empty for non-partner (community) providers.","Validate trust_signature with gpg --list-packets before publishing."],"tags":["authentication","signature","pgp","openpgp","registry","trust-signature","partner"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}