{"record":{"id":"f623e3903c65d17c","repo":"hashicorp/terraform","slug":"error-decoding-signing-key-s","errorCode":null,"errorMessage":"error decoding signing key: %s","messagePattern":"error decoding signing key: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/package_authentication.go","lineNumber":439,"sourceCode":"\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"error creating HashiCorp keyring: %s\", err)\n\t}\n\t_, err = s.checkDetachedSignature(hashicorpKeyring, bytes.NewReader(s.Document), bytes.NewReader(s.Signature), nil)\n\tif err == nil {\n\t\treturn &PackageAuthenticationResult{result: officialProvider, KeyID: keyID}, nil\n\t}\n\n\t// If the signing key has a trust signature, attempt to verify it with the\n\t// HashiCorp partners public key.\n\tif signingKey.TrustSignature != \"\" {\n\t\thashicorpPartnersKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPartnersKey))\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error creating HashiCorp Partners keyring: %s\", err)\n\t\t}\n\n\t\tauthorKey, err := openpgpArmor.Decode(strings.NewReader(signingKey.ASCIIArmor))\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error decoding signing key: %s\", err)\n\t\t}\n\n\t\ttrustSignature, err := openpgpArmor.Decode(strings.NewReader(signingKey.TrustSignature))\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error decoding trust signature: %s\", err)\n\t\t}\n\n\t\t_, err = s.checkDetachedSignature(hashicorpPartnersKeyring, authorKey.Body, trustSignature.Body, nil)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error verifying trust signature: %s\", err)\n\t\t}\n\n\t\treturn &PackageAuthenticationResult{result: partnerProvider, KeyID: keyID}, nil\n\t}\n\n\t// We have a valid signature, but it's not from the HashiCorp key, and it\n\t// also isn't a trusted partner. This is a community provider.\n\treturn &PackageAuthenticationResult{result: communityProvider, KeyID: keyID}, nil","sourceCodeStart":421,"sourceCodeEnd":457,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/package_authentication.go#L421-L457","documentation":"Thrown by signatureAuthentication.AuthenticatePackage when openpgpArmor.Decode fails to parse signingKey.ASCIIArmor (the registry-provided signing key) as OpenPGP ASCII-armored data. This branch runs only when the signing key carries a TrustSignature and the partners keyring was built. The registry returns the ASCII-armored public key of the signing identity; malformed armor (bad header, truncated, not actually armored) is rejected at package_authentication.go:437-439.","triggerScenarios":"A provider whose signing key has a non-empty trust_signature, where the ASCIIArmor field is not valid armored OpenPGP — bad BEGIN PGP block, missing checksum, base64 corruption, or the wrong content pasted into ascii_armor by a registry.","commonSituations":"A custom/private registry serving a signing key whose ascii_armor was copy-pasted incompletely or includes the wrapping header twice; a registry bug serializing the key; a proxy mangling the JSON/key payload; a key exported in binary instead of armored form.","solutions":["Have the registry serve a complete, valid ASCII-armored OpenPGP public key in the signing key's ascii_armor (full '-----BEGIN PGP PUBLIC KEY BLOCK-----' ... '-----END PGP PUBLIC KEY BLOCK-----').","Validate the key with gpg --dearmor or openpgpArmor.Decode before publishing to the registry.","If the key was exported in binary, re-export with --armor.","Check the registry JSON response for truncation or escaping issues around ascii_armor."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Validate a registry-returned signing key's armor parses before trusting it.\nfunc validSigningKeyArmor(k getproviders.SigningKey) error {\n    if k.TrustSignature == \"\" {\n        return nil // branch not reached; nothing to validate\n    }\n    if _, err := openpgpArmor.Decode(strings.NewReader(k.ASCIIArmor)); err != nil {\n        return fmt.Errorf(\"invalid signing key ascii_armor: %w\", err)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"_, err := auth.AuthenticatePackage(loc)\nif err != nil && strings.Contains(err.Error(), \"error decoding signing key\") {\n    // registry served a malformed signing key; re-fetch key metadata and retry\n    return err\n}","preventionTips":["Registries must serve full ASCII-armored OpenPGP public keys in ascii_armor.","Validate armor with gpg --dearmor before publishing a signing key.","Re-export binary keys with --armor."],"tags":["authentication","signature","pgp","openpgp","registry","signing-key"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}