Is the new apt.releases.hashicorp.com signing key (FC9CA96ACA026560) legitimate?

Hi all!

I noted this morning that since 2026-09-09 apt.releases.hashicorp com has a new signing key in use and I would like confirmation that it is genuine before we roll it out to our fleet.

apt.releases.hashicorp com/gpg now serves key FC9CA96ACA026560,
fingerprint D55C 0D1A C78A 8D81 26CB 631C FC9C A96A CA02 6560, created
2026-09-09. The noble and jammy InRelease files were re-signed with it on
2026-09-10, and apt.releases.hashicorp com lists the new fingerprint.

Plus, I noted that https://www.hashicorp.com/en/trust/security still lists the Linux package
signing key as 798A EC65 4E5C 1542 8C8E 42EE AA16 FCBC A621 E701 and does
not mention the new one.

I wasn’t able to find any announcement or news on this, can you share it if there’s one?

Can you confirm the new key is legitimate?

Thanks

Silvia

Lead SRE @37signals

Yes, can somebody please confirm this new key is the expected key? Our builds are broken and I can’t fix this until we know the new key is legit and not another attack.

See updates on: HCSEC-2026-33 - HashiCorp Linux Signing GPG Key Update (CA026560)

Same issue, any official communication on that?

The repo metadata and packages on rpm.releases.hashicorp.com for Amazon Linux aarch64 have not been re-signed or re-indexed since August 27, 2026. As a result, the repo config points to the new GPG key (0xCA026560), but the available RPM package (terraform-1.16.0-1.aarch64.rpm) remains signed with the old key (0xA621E701).

This should be fixed, please update this Discuss thread if you are still seeing this problem. Thanks!