Bacula.org APT repo fails on Debian trixie due to SHA1 policy (sqv)

Elias Pereira <[email protected]> Wed, 11 Feb 2026 15:13:40 -0300
Newsgroups gmane.comp.sysutils.backup.bacula.devel,gmane.comp.bacula.user
Message-ID <CAHdxDAHg=-x7fGQax6NgYdUd+mVpwAVZUGRPOSeLy=rQcFpm=g@mail.gmail.com>
Hi all,

On Debian trixie (APT using sqv/Sequoia), apt update fails for the
Bacula.org repository with an error similar to:

“Signing key …E9DF3643 is not bound … Policy rejected non-revocation
signature (PositiveCertification) requiring second pre-image resistance …
SHA1 is not considered secure since 2026-02-01”.

This seems related to SHA1 being rejected by policy on newer systems, so
the repo is effectively unusable on trixie without weakening signature
verification.

Is there an updated Bacula Distribution Verification Key (or re-signed
Release/InRelease) available that avoids SHA1, or any official
guidance/workaround planned for Debian trixie?

Thanks,
-- 
Elias Pereira

_______________________________________________
Bacula-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/bacula-devel