hashicorp/terraform · error
error verifying trust signature
Error message
error verifying trust signature: %s
What it means
Thrown during provider package authentication after a signing key with a non-empty TrustSignature was found. The author key and trust-signature blobs are decoded from ASCII armor, then the trust signature is verified against the embedded HashiCorpPartnersKey keyring via checkDetachedSignature. If that verification returns any error (other than tolerated key expiry), the provider cannot be elevated to partner status and this error surfaces.
Solutions
- Re-run the operation to rule out a transient corrupt registry response
- Verify the provider source address and version are the intended ones (a re-published/tampered artifact often fails here)
- If using a mirror or airgapped registry, confirm its signing_keys / trust_signature data matches the upstream registry exactly
- Report the provider and key ID to the registry operator if the failure persists across versions
Defensive patterns
Strategy: try-catch
Try / catch
result, err := auth.AuthenticatePackage(meta.Location)
if err != nil {
if strings.Contains(err.Error(), "trust signature") {
log.Printf("provider %s failed partner trust verification: %v", meta.Provider, err)
}
return err
} Prevention
- Pin provider versions to releases you have previously verified
- Maintain a lock file with known-good hashes so signature checks still gate downloads
- For airgapped use, curate a private mirror with audited partner trust signatures
When it happens
Trigger: The registry returned a SigningKey whose TrustSignature field is non-empty, and openpgp.CheckDetachedSignature(hashicorpPartnersKeyring, authorKey.Body, trustSignature.Body, nil) returned a non-nil error (bad signature, structural PGP error, wrong issuer, etc.).
Common situations: Corrupted or truncated trust-signature blob in the registry response; partner key rotation where the bundled HashiCorpPartnersKey no longer matches the published trust signature; a tampered/re-published provider artifact; a community key mistakenly carrying a stale or foreign trust signature.
Related errors
- authentication signature from unknown issuer
- error checking signature
- error creating HashiCorp keyring
- error creating HashiCorp Partners keyring
- error decoding signing key
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/813eb756dc400b65.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/package_authentication.go:449
if signingKey.TrustSignature != "" {
hashicorpPartnersKeyring, err := openpgp.ReadArmoredKeyRing(strings.NewReader(HashicorpPartnersKey))
if err != nil {
return nil, fmt.Errorf("error creating HashiCorp Partners keyring: %s", err)
}
authorKey, err := openpgpArmor.Decode(strings.NewReader(signingKey.ASCIIArmor))
if err != nil {
return nil, fmt.Errorf("error decoding signing key: %s", err)
}
trustSignature, err := openpgpArmor.Decode(strings.NewReader(signingKey.TrustSignature))
if err != nil {
return nil, fmt.Errorf("error decoding trust signature: %s", err)
}
_, err = s.checkDetachedSignature(hashicorpPartnersKeyring, authorKey.Body, trustSignature.Body, nil)
if err != nil {
return nil, fmt.Errorf("error verifying trust signature: %s", err)
}
return &PackageAuthenticationResult{result: partnerProvider, KeyID: keyID}, nil
}
// We have a valid signature, but it's not from the HashiCorp key, and it
// also isn't a trusted partner. This is a community provider.
return &PackageAuthenticationResult{result: communityProvider, KeyID: keyID}, nil
}
func (s signatureAuthentication) checkDetachedSignature(keyring openpgp.KeyRing, signed, signature io.Reader, config *packet.Config) (*openpgp.Entity, error) {
entity, err := openpgp.CheckDetachedSignature(keyring, signed, signature, config)
// FIXME: it's not clear what should be done with provider signing key
// expiration. This check reverts the validation behavior to match that of
// the original x/crypto/openpgp package.
//
// We don't force providers to update keys for older releases, so they may
// have since expired. We are validating the original signature however,View on GitHub (pinned to d32a084675)