hashicorp/terraform · error
error checking signature
Error message
error checking signature: %s
What it means
Thrown by findSigningKey when checkDetachedSignature returns a terminal (non-unknown-issuer) error while verifying the checksums signature against a candidate key. Unlike ErrUnknownIssuer (which advances to the next key), any other failure halts key search immediately.
Solutions
- Re-download the provider to obtain a fresh signature document
- Confirm the registry is serving the signature that matches the published SHA256SUMS file
- Check whether a mirror is mismatching checksums and signature artifacts
- Report a persistently broken signature to the registry operator
Defensive patterns
Strategy: try-catch
Try / catch
if _, err := auth.AuthenticatePackage(meta.Location); err != nil {
if errors.Is(err, openpgpErrors.ErrUnknownIssuer) || strings.Contains(err.Error(), "checking signature") {
return fmt.Errorf("provider %s signature verification failed: %w", meta.Provider, err)
}
return err
} Prevention
- Do not disable signature verification to work around this error; treat it as a security signal
- Pin provider versions so a known-good signature is reused
When it happens
Trigger: checkDetachedSignature(keyring, Document, Signature, nil) returned an error that is not openpgpErrors.ErrUnknownIssuer (e.g. malformed signature packet, hash mismatch, structural openpgp error).
Common situations: Corrupted or truncated SHA256SUMS.sig file served by the registry; checksum document that does not correspond to the signature; mismatch between the armored key and the signature packet; openpgp library rejecting a structurally invalid detached signature.
Related errors
- authentication signature from unknown issuer
- error verifying trust signature
- error creating HashiCorp keyring
- error creating HashiCorp Partners keyring
- error decoding signing key
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/31f044c394a75aec.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/package_authentication.go:549
// the future.
func (s signatureAuthentication) findSigningKey() (*SigningKey, string, error) {
for _, key := range s.Keys {
keyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(key.ASCIIArmor))
if err != nil {
return nil, "", fmt.Errorf("error decoding signing key: %s", err)
}
entity, err := s.checkDetachedSignature(keyring, bytes.NewReader(s.Document), bytes.NewReader(s.Signature), nil)
// If the signature issuer does not match the key, keep trying the
// rest of the provided keys.
if err == openpgpErrors.ErrUnknownIssuer {
continue
}
// Any other signature error is terminal.
if err != nil {
return nil, "", fmt.Errorf("error checking signature: %s", err)
}
keyID := "n/a"
if entity.PrimaryKey != nil {
keyID = entity.PrimaryKey.KeyIdString()
}
log.Printf("[DEBUG] Provider signed by %s", entityString(entity))
return &key, keyID, nil
}
// If none of the provided keys issued the signature, this package is
// unsigned. This is currently a terminal authentication error.
return nil, "", fmt.Errorf("authentication signature from unknown issuer")
}
// entityString extracts the key ID and identity name(s) from an openpgp.Entity
// for logging.View on GitHub (pinned to d32a084675)