{"record":{"id":"d9cbc59d258d17ab","repo":"hashicorp/terraform","slug":"error-creating-hashicorp-keyring-s","errorCode":null,"errorMessage":"error creating HashiCorp keyring: %s","messagePattern":"error creating HashiCorp keyring: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"internal/getproviders/package_authentication.go","lineNumber":422,"sourceCode":"\t\tDocument:  document,\n\t\tSignature: signature,\n\t\tKeys:      keys,\n\t}\n}\n\nfunc (s signatureAuthentication) AuthenticatePackage(location PackageLocation) (*PackageAuthenticationResult, error) {\n\t// Find the key that signed the checksum file. This can fail if there is no\n\t// valid signature for any of the provided keys.\n\tsigningKey, keyID, err := s.findSigningKey()\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\n\t// Verify the signature using the HashiCorp public key. If this succeeds,\n\t// this is an official provider.\n\thashicorpKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPublicKey))\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"error creating HashiCorp keyring: %s\", err)\n\t}\n\t_, err = s.checkDetachedSignature(hashicorpKeyring, bytes.NewReader(s.Document), bytes.NewReader(s.Signature), nil)\n\tif err == nil {\n\t\treturn &PackageAuthenticationResult{result: officialProvider, KeyID: keyID}, nil\n\t}\n\n\t// If the signing key has a trust signature, attempt to verify it with the\n\t// HashiCorp partners public key.\n\tif signingKey.TrustSignature != \"\" {\n\t\thashicorpPartnersKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPartnersKey))\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error creating HashiCorp Partners keyring: %s\", err)\n\t\t}\n\n\t\tauthorKey, err := openpgpArmor.Decode(strings.NewReader(signingKey.ASCIIArmor))\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error decoding signing key: %s\", err)\n\t\t}","sourceCodeStart":404,"sourceCodeEnd":440,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L404-L440","documentation":"Thrown by signatureAuthentication.AuthenticatePackage when openpgp.ReadArmoredKeyRing fails to parse the compiled-in HashicorpPublicKey constant into a keyring. This is the official-provider signing key embedded in the binary; a parse failure indicates the embedded armored key is malformed or the openpgp library rejected it. Because the key is a build-time constant, this is almost always a build/binary or library-version defect, not user input.","triggerScenarios":"AuthenticatePackage reaches the HashiCorp keyring construction at package_authentication.go:420-422 and ReadArmoredKeyRing returns err. Reproduces on every official-provider signature verification for that build.","commonSituations":"A fork or custom build edited/replaced the HashicorpPublicKey constant incorrectly; an openpgp library version bump changed armored-key parsing strictness; the constant was truncated by a build/templating step; binary corruption.","solutions":["Use an official, unmodified build of the tool — if it reproduces only on a custom build, the embedded key constant is the culprit.","If forking, keep HashicorpPublicKey exactly as upstream and verify it round-trips through openpgp.ReadArmoredKeyRing in a unit test.","Pin or update the go-crypto/openpgp dependency to a version compatible with the embedded armored key.","Report upstream if a stock build reproduces — the compiled-in key must always parse."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// Smoke-test the compiled-in key at startup / in tests.\nfunc checkHashicorpKey() error {\n    _, err := openpgp.ReadArmoredKeyRing(strings.NewReader(getproviders.HashicorpPublicKey))\n    return err\n}","typeGuard":null,"tryCatchPattern":"_, err := auth.AuthenticatePackage(loc)\nif err != nil && strings.Contains(err.Error(), \"error creating HashiCorp keyring\") {\n    // build/binary defect: fall back to an official build, do not skip signing verification\n    return fmt.Errorf(\"embedded HashiCorp signing key failed to parse; use an official build: %w\", err)\n}","preventionTips":["Use official, unmodified builds of the tool.","In forks, add a CI test asserting ReadArmoredKeyRing(HashicorpPublicKey) succeeds.","Pin go-crypto/openpgp to a version compatible with the embedded key."],"tags":["authentication","signature","pgp","openpgp","build","keyring"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}