HashiCorp rotated the GPG signing key for all Linux packages, causing the fingerprint published on their website to become outdated and mismatched with the active signing key. The apt and rpm repositories, package signatures, and related documentation were all affected during the 7.3-hour incident. Engineers updated the repository keys and documentation, re-signed affected packages, and deployed a fix that was subsequently monitored for full resolution.
Trusted by 1,000+ teams
Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.
Our Engineering team has implemented a fix to resolve the issue. We are monitoring the situation closely and will post an update as soon as the issue is fully resolved.
Our engineers have identified the issue and are working through remaining packages.
We have updated the keys in the apt and rpm repos and the documentation. Our engineers are working to identify and re-sign packages signed with the older key
We are currently updating documentation and package verification guidance following an ongoing GPG key rotation for all HashiCorp Linux packages. The fingerprint currently displayed on our site is outdated and may not match the active signing key.
We are actively updating the published fingerprint information and related documentation. We will provide an update once the corrected fingerprint details are available.
With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.
Start free trialNo credit card required · Cancel anytime · 6320 services available
Integrations with