hashicorp/terraform · error

this version of Terraform does not support any of the…

Error message

this version of Terraform does not support any of the checksum formats given for this provider

What it means

Thrown by packageHashAuthentication.AuthenticatePackage when RequiredHashes is empty, meaning PreferredHashes filtered the supplied validHashes down to zero hashes this build recognizes. The constructor NewPackageHashAuthentication(platform, validHashes) keeps hashes the current Terraform/OpenTofu supports; if none of the lock-file/registry hashes match a known scheme (e.g. only 'h1:' hashes are present but this code path expected 'zh:', or vice-versa, or the hashes are malformed), authentication cannot proceed.

Solutions

  1. Upgrade the running Terraform/OpenTofu binary to a version that supports the hash scheme present in the lock file.
  2. Delete the hashes block for the affected provider in .terraform.lock.hcl and re-run init to regenerate hashes in a supported scheme.
  3. Ensure the source/mirror provides hashes in a recognized scheme (h1: base64 SHA-256 of unpacked dir, or zh: base64 SHA-256 of the zip).
  4. Align all team members on the same tool version so the lock file uses a single scheme.

Example fix

// before: lock file only has a scheme this binary does not prefer
//   version = "5.0.0"
//   hashes = [
//     "zh:deadbeef..."
//   ]

// after: regenerate after `terraform init -upgrade` on a current binary
//   hashes = [
//     "h1:abcdef...=",
//     "zh:deadbeef..."
//   ]
Defensive patterns

Strategy: validation

Validate before calling

// Before constructing NewPackageHashAuthentication, confirm at least one
// hash survives PreferredHashes for this build.
import "github.com/hashicorp/terraform/internal/getproviders"

func hasRecognizedHash(validHashes []getproviders.Hash) error {
    if len(getproviders.PreferredHashes(validHashes)) == 0 {
        return fmt.Errorf("no hash in a scheme this build supports; upgrade or regenerate the lock file")
    }
    return nil
}

Try / catch

// Wrap auth so callers can surface a clearer message and choose to
// regenerate the lock file rather than abort.
result, err := auth.AuthenticatePackage(loc)
if err != nil && strings.Contains(err.Error(), "does not support any of the checksum formats") {
    log.Printf("lock file uses an unsupported hash scheme; run `terraform init -upgrade` to regenerate")
}
return result, err

Prevention

When it happens

Trigger: Calling NewPackageHashAuthentication with a hash set whose every entry uses a scheme PreferredHashes drops, then AuthenticatePackage. Common when a lock file from a newer tool version (with a newer hash scheme) is read by an older binary, or when hashes are non-standard/corrupt strings that fail scheme parsing.

Common situations: Version skew between team members — one developer upgrades and writes 'zh:' (zip) hashes into .terraform.lock.hcl while another runs an older binary that only understands 'h1:'; a hand-edited lock file with malformed hashes; a custom mirror serving hashes in an unrecognized format.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/5fe39f44e9b839b7. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/package_authentication.go:247

// This uses the hash algorithms implemented by functions PackageHash and
// MatchesHash. The PreferredHashes function will select which of the given
// hashes are considered by Terraform to be the strongest verification, and
// authentication succeeds as long as one of those matches.
func NewPackageHashAuthentication(platform Platform, validHashes []Hash) PackageAuthentication {
	requiredHashes := PreferredHashes(validHashes)
	return packageHashAuthentication{
		RequiredHashes: requiredHashes,
		AllHashes:      validHashes,
		Platform:       platform,
	}
}

func (a packageHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {
	if len(a.RequiredHashes) == 0 {
		// Indicates that none of the hashes given to
		// NewPackageHashAuthentication were considered to be usable by this
		// version of Terraform.
		return nil, fmt.Errorf("this version of Terraform does not support any of the checksum formats given for this provider")
	}

	matches, err := PackageMatchesAnyHash(localLocation, a.RequiredHashes)
	if err != nil {
		return nil, fmt.Errorf("failed to verify provider package checksums: %s", err)
	}

	if matches {
		return &PackageAuthenticationResult{result: verifiedChecksum}, nil
	}
	if len(a.RequiredHashes) == 1 {
		return nil, fmt.Errorf("provider package doesn't match the expected checksum %q", a.RequiredHashes[0].String())
	}
	// It's non-ideal that this doesn't actually list the expected checksums,
	// but in the many-checksum case the message would get pretty unweildy.
	// In practice today we typically use this authenticator only with a
	// single hash returned from a network mirror, so the better message
	// above will prevail in that case. Maybe we'll improve on this somehow

View on GitHub (pinned to d32a084675)