hashicorp/terraform · error
authentication signature from unknown issuer
Error message
authentication signature from unknown issuer
What it means
Thrown by findSigningKey after every key in s.Keys has been tried and none matched the signature issuer. The package is therefore unsigned by any registry-listed key, which is treated as a terminal authentication failure rather than a soft warning.
Solutions
- Update the registry/provider metadata so the signing key is published
- Confirm the provider version is the official release (not a fork or manual build)
- Use a curated mirror that publishes the correct signing_keys for the provider
- If signing locally, ensure the signing key is registered with the registry
Defensive patterns
Strategy: try-catch
Type guard
func HasAnyValidSignature(keys []SigningKey, sig []byte) bool {
// Returns false only to flag that all keys are exhausted; full check
// still belongs to findSigningKey.
return len(keys) > 0 && len(sig) > 0
} Try / catch
_, _, err := auth.findSigningKey()
if err != nil && strings.Contains(err.Error(), "unknown issuer") {
return fmt.Errorf("provider %s is not signed by any registry-listed key", provider)
} Prevention
- Ensure the registry publishes the signing key for every provider version you install
- For community providers, register their signing key with the registry before relying on it
When it happens
Trigger: The loop over s.Keys completed without returning: for each key either openpgp returned ErrUnknownIssuer (continue) or the signature was issued by a key absent from the registry-supplied list.
Common situations: Provider was signed by a key the registry does not publish; signing key was rotated upstream but the registry's signing_keys is stale; registry misconfiguration returning an empty or wrong key set; a genuinely unsigned community package presented where a signature was required.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- error checking signature
- error verifying trust signature
- error creating HashiCorp keyring
- error creating HashiCorp Partners keyring
- error decoding signing key
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/881d43d8c3bab201.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/package_authentication.go:563
}
// Any other signature error is terminal.
if err != nil {
return nil, "", fmt.Errorf("error checking signature: %s", err)
}
keyID := "n/a"
if entity.PrimaryKey != nil {
keyID = entity.PrimaryKey.KeyIdString()
}
log.Printf("[DEBUG] Provider signed by %s", entityString(entity))
return &key, keyID, nil
}
// If none of the provided keys issued the signature, this package is
// unsigned. This is currently a terminal authentication error.
return nil, "", fmt.Errorf("authentication signature from unknown issuer")
}
// entityString extracts the key ID and identity name(s) from an openpgp.Entity
// for logging.
func entityString(entity *openpgp.Entity) string {
if entity == nil {
return ""
}
keyID := "n/a"
if entity.PrimaryKey != nil {
keyID = entity.PrimaryKey.KeyIdString()
}
var names []string
for _, identity := range entity.Identities {
names = append(names, identity.Name)
}View on GitHub (pinned to d32a084675)