getsops/sops · error

the key could not be decrypted with any of the PGP entries

Error message

the key could not be decrypted with any of the PGP entries

What it means

Error "the key could not be decrypted with any of the PGP entries" thrown in getsops/sops.

Source

Thrown at pgp/keysource.go:442

// placement of the files, and the generic fallback Decrypt uses, this raises
// the question of how widely utilized this method still is.
func (key *MasterKey) decryptWithOpenPGP() ([]byte, error) {
	ring, err := key.getSecRing()
	if err != nil {
		return nil, fmt.Errorf("could not load secring: %s", err)
	}
	block, err := armor.Decode(strings.NewReader(key.EncryptedKey))
	if err != nil {
		return nil, fmt.Errorf("armor decoding failed: %s", err)
	}
	md, err := openpgp.ReadMessage(block.Body, ring, key.passphrasePrompt(), nil)
	if err != nil {
		return nil, fmt.Errorf("reading PGP message failed: %s", err)
	}
	if b, err := io.ReadAll(md.UnverifiedBody); err == nil {
		return b, nil
	}
	return nil, fmt.Errorf("the key could not be decrypted with any of the PGP entries")
}

// decryptWithGnuPG attempts to obtain the data key from the EncryptedKey using
// GnuPG and returns the result. If DisableAgent is configured on the MasterKey,
// the GnuPG agent is not enabled. When the decryption command fails, it returns
// the error from stdout.
func (key *MasterKey) decryptWithGnuPG(ctx context.Context) ([]byte, error) {
	args := []string{
		"-d",
	}
	stdout, stderr, err := gpgExec(ctx, key.gnuPGHomeDir, args, strings.NewReader(key.EncryptedKey))
	if err != nil {
		return nil, fmt.Errorf("failed to decrypt sops data key with pgp: %s",
			strings.TrimSpace(stderr.String()))
	}
	result := stdout.Bytes()
	if len(result) == 0 {
		// This can happen if an older GnuPG version is used to decrypt a key encrypted with a

View on GitHub (pinned to 13442bb981)

When it happens

Trigger: Thrown at pgp/keysource.go:442 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of getsops/sops@13442bb981 (2026-09-01). Data as JSON: /api/errors/e457d095af9c22cc. Report an issue: GitHub.