hashicorp/terraform · error

error checking signature

Error message

error checking signature: %s

What it means

Thrown by findSigningKey when checkDetachedSignature returns a terminal (non-unknown-issuer) error while verifying the checksums signature against a candidate key. Unlike ErrUnknownIssuer (which advances to the next key), any other failure halts key search immediately.

Solutions

  1. Re-download the provider to obtain a fresh signature document
  2. Confirm the registry is serving the signature that matches the published SHA256SUMS file
  3. Check whether a mirror is mismatching checksums and signature artifacts
  4. Report a persistently broken signature to the registry operator
Defensive patterns

Strategy: try-catch

Try / catch

if _, err := auth.AuthenticatePackage(meta.Location); err != nil {
    if errors.Is(err, openpgpErrors.ErrUnknownIssuer) || strings.Contains(err.Error(), "checking signature") {
        return fmt.Errorf("provider %s signature verification failed: %w", meta.Provider, err)
    }
    return err
}

Prevention

When it happens

Trigger: checkDetachedSignature(keyring, Document, Signature, nil) returned an error that is not openpgpErrors.ErrUnknownIssuer (e.g. malformed signature packet, hash mismatch, structural openpgp error).

Common situations: Corrupted or truncated SHA256SUMS.sig file served by the registry; checksum document that does not correspond to the signature; mismatch between the armored key and the signature packet; openpgp library rejecting a structurally invalid detached signature.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/31f044c394a75aec. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/package_authentication.go:549

// the future.
func (s signatureAuthentication) findSigningKey() (*SigningKey, string, error) {
	for _, key := range s.Keys {
		keyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(key.ASCIIArmor))
		if err != nil {
			return nil, "", fmt.Errorf("error decoding signing key: %s", err)
		}

		entity, err := s.checkDetachedSignature(keyring, bytes.NewReader(s.Document), bytes.NewReader(s.Signature), nil)

		// If the signature issuer does not match the key, keep trying the
		// rest of the provided keys.
		if err == openpgpErrors.ErrUnknownIssuer {
			continue
		}

		// Any other signature error is terminal.
		if err != nil {
			return nil, "", fmt.Errorf("error checking signature: %s", err)
		}

		keyID := "n/a"
		if entity.PrimaryKey != nil {
			keyID = entity.PrimaryKey.KeyIdString()
		}

		log.Printf("[DEBUG] Provider signed by %s", entityString(entity))
		return &key, keyID, nil
	}

	// If none of the provided keys issued the signature, this package is
	// unsigned. This is currently a terminal authentication error.
	return nil, "", fmt.Errorf("authentication signature from unknown issuer")
}

// entityString extracts the key ID and identity name(s) from an openpgp.Entity
// for logging.

View on GitHub (pinned to d32a084675)