hashicorp/terraform · error

error verifying trust signature

Error message

error verifying trust signature: %s

What it means

Thrown during provider package authentication after a signing key with a non-empty TrustSignature was found. The author key and trust-signature blobs are decoded from ASCII armor, then the trust signature is verified against the embedded HashiCorpPartnersKey keyring via checkDetachedSignature. If that verification returns any error (other than tolerated key expiry), the provider cannot be elevated to partner status and this error surfaces.

Solutions

  1. Re-run the operation to rule out a transient corrupt registry response
  2. Verify the provider source address and version are the intended ones (a re-published/tampered artifact often fails here)
  3. If using a mirror or airgapped registry, confirm its signing_keys / trust_signature data matches the upstream registry exactly
  4. Report the provider and key ID to the registry operator if the failure persists across versions
Defensive patterns

Strategy: try-catch

Try / catch

result, err := auth.AuthenticatePackage(meta.Location)
if err != nil {
    if strings.Contains(err.Error(), "trust signature") {
        log.Printf("provider %s failed partner trust verification: %v", meta.Provider, err)
    }
    return err
}

Prevention

When it happens

Trigger: The registry returned a SigningKey whose TrustSignature field is non-empty, and openpgp.CheckDetachedSignature(hashicorpPartnersKeyring, authorKey.Body, trustSignature.Body, nil) returned a non-nil error (bad signature, structural PGP error, wrong issuer, etc.).

Common situations: Corrupted or truncated trust-signature blob in the registry response; partner key rotation where the bundled HashiCorpPartnersKey no longer matches the published trust signature; a tampered/re-published provider artifact; a community key mistakenly carrying a stale or foreign trust signature.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/813eb756dc400b65. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/package_authentication.go:449

	if signingKey.TrustSignature != "" {
		hashicorpPartnersKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPartnersKey))
		if err != nil {
			return nil, fmt.Errorf("error creating HashiCorp Partners keyring: %s", err)
		}

		authorKey, err := openpgpArmor.Decode(strings.NewReader(signingKey.ASCIIArmor))
		if err != nil {
			return nil, fmt.Errorf("error decoding signing key: %s", err)
		}

		trustSignature, err := openpgpArmor.Decode(strings.NewReader(signingKey.TrustSignature))
		if err != nil {
			return nil, fmt.Errorf("error decoding trust signature: %s", err)
		}

		_, err = s.checkDetachedSignature(hashicorpPartnersKeyring, authorKey.Body, trustSignature.Body, nil)
		if err != nil {
			return nil, fmt.Errorf("error verifying trust signature: %s", err)
		}

		return &PackageAuthenticationResult{result: partnerProvider, KeyID: keyID}, nil
	}

	// We have a valid signature, but it's not from the HashiCorp key, and it
	// also isn't a trusted partner. This is a community provider.
	return &PackageAuthenticationResult{result: communityProvider, KeyID: keyID}, nil
}

func (s signatureAuthentication) checkDetachedSignature(keyring openpgp.KeyRing, signed, signature io.Reader, config *packet.Config) (*openpgp.Entity, error) {
	entity, err := openpgp.CheckDetachedSignature(keyring, signed, signature, config)
	// FIXME: it's not clear what should be done with provider signing key
	// expiration. This check reverts the validation behavior to match that of
	// the original x/crypto/openpgp package.
	//
	// We don't force providers to update keys for older releases, so they may
	// have since expired. We are validating the original signature however,

View on GitHub (pinned to d32a084675)