hashicorp/terraform · error

authentication signature from unknown issuer

Error message

authentication signature from unknown issuer

What it means

Thrown by findSigningKey after every key in s.Keys has been tried and none matched the signature issuer. The package is therefore unsigned by any registry-listed key, which is treated as a terminal authentication failure rather than a soft warning.

Solutions

  1. Update the registry/provider metadata so the signing key is published
  2. Confirm the provider version is the official release (not a fork or manual build)
  3. Use a curated mirror that publishes the correct signing_keys for the provider
  4. If signing locally, ensure the signing key is registered with the registry
Defensive patterns

Strategy: try-catch

Type guard

func HasAnyValidSignature(keys []SigningKey, sig []byte) bool {
    // Returns false only to flag that all keys are exhausted; full check
    // still belongs to findSigningKey.
    return len(keys) > 0 && len(sig) > 0
}

Try / catch

_, _, err := auth.findSigningKey()
if err != nil && strings.Contains(err.Error(), "unknown issuer") {
    return fmt.Errorf("provider %s is not signed by any registry-listed key", provider)
}

Prevention

When it happens

Trigger: The loop over s.Keys completed without returning: for each key either openpgp returned ErrUnknownIssuer (continue) or the signature was issued by a key absent from the registry-supplied list.

Common situations: Provider was signed by a key the registry does not publish; signing key was rotated upstream but the registry's signing_keys is stale; registry misconfiguration returning an empty or wrong key set; a genuinely unsigned community package presented where a signature was required.

Understand the failure class

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/881d43d8c3bab201. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/package_authentication.go:563

		}

		// Any other signature error is terminal.
		if err != nil {
			return nil, "", fmt.Errorf("error checking signature: %s", err)
		}

		keyID := "n/a"
		if entity.PrimaryKey != nil {
			keyID = entity.PrimaryKey.KeyIdString()
		}

		log.Printf("[DEBUG] Provider signed by %s", entityString(entity))
		return &key, keyID, nil
	}

	// If none of the provided keys issued the signature, this package is
	// unsigned. This is currently a terminal authentication error.
	return nil, "", fmt.Errorf("authentication signature from unknown issuer")
}

// entityString extracts the key ID and identity name(s) from an openpgp.Entity
// for logging.
func entityString(entity *openpgp.Entity) string {
	if entity == nil {
		return ""
	}

	keyID := "n/a"
	if entity.PrimaryKey != nil {
		keyID = entity.PrimaryKey.KeyIdString()
	}

	var names []string
	for _, identity := range entity.Identities {
		names = append(names, identity.Name)
	}

View on GitHub (pinned to d32a084675)