hashicorp/terraform · critical

error creating HashiCorp Partners keyring

Error message

error creating HashiCorp Partners keyring: %s

What it means

Thrown by signatureAuthentication.AuthenticatePackage when openpgp.ReadArmoredKeyRing fails to parse the compiled-in HashicorpPartnersKey constant. This key validates trust signatures that promote a third-party-signed provider to 'partner' status. As with the official key, this constant is embedded at build time, so a parse failure is a build/binary/library defect rather than a runtime-input problem.

Solutions

  1. Use an official unmodified build; if reproducing only on a fork, fix the embedded HashicorpPartnersKey constant.
  2. Add a unit test asserting openpgp.ReadArmoredKeyRing(HashicorpPartnersKey) succeeds in CI.
  3. Pin/upgrade go-crypto/openpgp to a version compatible with the embedded armored key.
  4. Report upstream if a stock build reproduces.
Defensive patterns

Strategy: try-catch

Validate before calling

func checkHashicorpPartnersKey() error {
    _, err := openpgp.ReadArmoredKeyRing(strings.NewReader(getproviders.HashicorpPartnersKey))
    return err
}

Try / catch

_, err := auth.AuthenticatePackage(loc)
if err != nil && strings.Contains(err.Error(), "error creating HashiCorp Partners keyring") {
    return fmt.Errorf("embedded HashiCorp Partners key failed to parse; use an official build: %w", err)
}

Prevention

When it happens

Trigger: AuthenticatePackage reaches the partners-keyring branch (signingKey.TrustSignature != '') at package_authentication.go:432-434 and ReadArmoredKeyRing(HashicorpPartnersKey) returns err. Only hit when verifying a provider whose signing key carries a trust signature.

Common situations: A fork/custom build altered the HashicorpPartnersKey constant; an openpgp dependency bump broke armored parsing; constant truncated during build; verifying a partner provider (e.g. AWS official partner) on a corrupted binary.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/b0cfb0f3980d009c. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/package_authentication.go:434

	}

	// Verify the signature using the HashiCorp public key. If this succeeds,
	// this is an official provider.
	hashicorpKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPublicKey))
	if err != nil {
		return nil, fmt.Errorf("error creating HashiCorp keyring: %s", err)
	}
	_, err = s.checkDetachedSignature(hashicorpKeyring, bytes.NewReader(s.Document), bytes.NewReader(s.Signature), nil)
	if err == nil {
		return &PackageAuthenticationResult{result: officialProvider, KeyID: keyID}, nil
	}

	// If the signing key has a trust signature, attempt to verify it with the
	// HashiCorp partners public key.
	if signingKey.TrustSignature != "" {
		hashicorpPartnersKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPartnersKey))
		if err != nil {
			return nil, fmt.Errorf("error creating HashiCorp Partners keyring: %s", err)
		}

		authorKey, err := openpgpArmor.Decode(strings.NewReader(signingKey.ASCIIArmor))
		if err != nil {
			return nil, fmt.Errorf("error decoding signing key: %s", err)
		}

		trustSignature, err := openpgpArmor.Decode(strings.NewReader(signingKey.TrustSignature))
		if err != nil {
			return nil, fmt.Errorf("error decoding trust signature: %s", err)
		}

		_, err = s.checkDetachedSignature(hashicorpPartnersKeyring, authorKey.Body, trustSignature.Body, nil)
		if err != nil {
			return nil, fmt.Errorf("error verifying trust signature: %s", err)
		}

		return &PackageAuthenticationResult{result: partnerProvider, KeyID: keyID}, nil

View on GitHub (pinned to d32a084675)