hashicorp/terraform · critical
error creating HashiCorp keyring
Error message
error creating HashiCorp keyring: %s
What it means
Thrown by signatureAuthentication.AuthenticatePackage when openpgp.ReadArmoredKeyRing fails to parse the compiled-in HashicorpPublicKey constant into a keyring. This is the official-provider signing key embedded in the binary; a parse failure indicates the embedded armored key is malformed or the openpgp library rejected it. Because the key is a build-time constant, this is almost always a build/binary or library-version defect, not user input.
Solutions
- Use an official, unmodified build of the tool — if it reproduces only on a custom build, the embedded key constant is the culprit.
- If forking, keep HashicorpPublicKey exactly as upstream and verify it round-trips through openpgp.ReadArmoredKeyRing in a unit test.
- Pin or update the go-crypto/openpgp dependency to a version compatible with the embedded armored key.
- Report upstream if a stock build reproduces — the compiled-in key must always parse.
Defensive patterns
Strategy: try-catch
Validate before calling
// Smoke-test the compiled-in key at startup / in tests.
func checkHashicorpKey() error {
_, err := openpgp.ReadArmoredKeyRing(strings.NewReader(getproviders.HashicorpPublicKey))
return err
} Try / catch
_, err := auth.AuthenticatePackage(loc)
if err != nil && strings.Contains(err.Error(), "error creating HashiCorp keyring") {
// build/binary defect: fall back to an official build, do not skip signing verification
return fmt.Errorf("embedded HashiCorp signing key failed to parse; use an official build: %w", err)
} Prevention
- Use official, unmodified builds of the tool.
- In forks, add a CI test asserting ReadArmoredKeyRing(HashicorpPublicKey) succeeds.
- Pin go-crypto/openpgp to a version compatible with the embedded key.
When it happens
Trigger: AuthenticatePackage reaches the HashiCorp keyring construction at package_authentication.go:420-422 and ReadArmoredKeyRing returns err. Reproduces on every official-provider signature verification for that build.
Common situations: A fork or custom build edited/replaced the HashicorpPublicKey constant incorrectly; an openpgp library version bump changed armored-key parsing strictness; the constant was truncated by a build/templating step; binary corruption.
Related errors
- error creating HashiCorp Partners keyring
- error decoding signing key
- error decoding trust signature
- authentication signature from unknown issuer
- error checking signature
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/d9cbc59d258d17ab.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/package_authentication.go:422
Document: document,
Signature: signature,
Keys: keys,
}
}
func (s signatureAuthentication) AuthenticatePackage(location PackageLocation) (*PackageAuthenticationResult, error) {
// Find the key that signed the checksum file. This can fail if there is no
// valid signature for any of the provided keys.
signingKey, keyID, err := s.findSigningKey()
if err != nil {
return nil, err
}
// Verify the signature using the HashiCorp public key. If this succeeds,
// this is an official provider.
hashicorpKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPublicKey))
if err != nil {
return nil, fmt.Errorf("error creating HashiCorp keyring: %s", err)
}
_, err = s.checkDetachedSignature(hashicorpKeyring, bytes.NewReader(s.Document), bytes.NewReader(s.Signature), nil)
if err == nil {
return &PackageAuthenticationResult{result: officialProvider, KeyID: keyID}, nil
}
// If the signing key has a trust signature, attempt to verify it with the
// HashiCorp partners public key.
if signingKey.TrustSignature != "" {
hashicorpPartnersKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPartnersKey))
if err != nil {
return nil, fmt.Errorf("error creating HashiCorp Partners keyring: %s", err)
}
authorKey, err := openpgpArmor.Decode(strings.NewReader(signingKey.ASCIIArmor))
if err != nil {
return nil, fmt.Errorf("error decoding signing key: %s", err)
}View on GitHub (pinned to d32a084675)