hashicorp/terraform · critical

error creating HashiCorp keyring

Error message

error creating HashiCorp keyring: %s

What it means

Thrown by signatureAuthentication.AuthenticatePackage when openpgp.ReadArmoredKeyRing fails to parse the compiled-in HashicorpPublicKey constant into a keyring. This is the official-provider signing key embedded in the binary; a parse failure indicates the embedded armored key is malformed or the openpgp library rejected it. Because the key is a build-time constant, this is almost always a build/binary or library-version defect, not user input.

Solutions

  1. Use an official, unmodified build of the tool — if it reproduces only on a custom build, the embedded key constant is the culprit.
  2. If forking, keep HashicorpPublicKey exactly as upstream and verify it round-trips through openpgp.ReadArmoredKeyRing in a unit test.
  3. Pin or update the go-crypto/openpgp dependency to a version compatible with the embedded armored key.
  4. Report upstream if a stock build reproduces — the compiled-in key must always parse.
Defensive patterns

Strategy: try-catch

Validate before calling

// Smoke-test the compiled-in key at startup / in tests.
func checkHashicorpKey() error {
    _, err := openpgp.ReadArmoredKeyRing(strings.NewReader(getproviders.HashicorpPublicKey))
    return err
}

Try / catch

_, err := auth.AuthenticatePackage(loc)
if err != nil && strings.Contains(err.Error(), "error creating HashiCorp keyring") {
    // build/binary defect: fall back to an official build, do not skip signing verification
    return fmt.Errorf("embedded HashiCorp signing key failed to parse; use an official build: %w", err)
}

Prevention

When it happens

Trigger: AuthenticatePackage reaches the HashiCorp keyring construction at package_authentication.go:420-422 and ReadArmoredKeyRing returns err. Reproduces on every official-provider signature verification for that build.

Common situations: A fork or custom build edited/replaced the HashicorpPublicKey constant incorrectly; an openpgp library version bump changed armored-key parsing strictness; the constant was truncated by a build/templating step; binary corruption.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/d9cbc59d258d17ab. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/package_authentication.go:422

		Document:  document,
		Signature: signature,
		Keys:      keys,
	}
}

func (s signatureAuthentication) AuthenticatePackage(location PackageLocation) (*PackageAuthenticationResult, error) {
	// Find the key that signed the checksum file. This can fail if there is no
	// valid signature for any of the provided keys.
	signingKey, keyID, err := s.findSigningKey()
	if err != nil {
		return nil, err
	}

	// Verify the signature using the HashiCorp public key. If this succeeds,
	// this is an official provider.
	hashicorpKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPublicKey))
	if err != nil {
		return nil, fmt.Errorf("error creating HashiCorp keyring: %s", err)
	}
	_, err = s.checkDetachedSignature(hashicorpKeyring, bytes.NewReader(s.Document), bytes.NewReader(s.Signature), nil)
	if err == nil {
		return &PackageAuthenticationResult{result: officialProvider, KeyID: keyID}, nil
	}

	// If the signing key has a trust signature, attempt to verify it with the
	// HashiCorp partners public key.
	if signingKey.TrustSignature != "" {
		hashicorpPartnersKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPartnersKey))
		if err != nil {
			return nil, fmt.Errorf("error creating HashiCorp Partners keyring: %s", err)
		}

		authorKey, err := openpgpArmor.Decode(strings.NewReader(signingKey.ASCIIArmor))
		if err != nil {
			return nil, fmt.Errorf("error decoding signing key: %s", err)
		}

View on GitHub (pinned to d32a084675)