Bacula.org APT repo fails on Debian trixie due to SHA1 policy (sqv)
Elias Pereira <[email protected]> Wed, 11 Feb 2026 15:13:40 -0300
| Newsgroups | gmane.comp.sysutils.backup.bacula.devel,gmane.comp.bacula.user |
|---|---|
| Message-ID | <CAHdxDAHg=-x7fGQax6NgYdUd+mVpwAVZUGRPOSeLy=rQcFpm=g@mail.gmail.com> |
--===============2749681082587858859== Content-Type: multipart/alternative; boundary="000000000000134ec3064a90572a" --000000000000134ec3064a90572a Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi all, On Debian trixie (APT using sqv/Sequoia), apt update fails for the Bacula.org repository with an error similar to: =E2=80=9CSigning key =E2=80=A6E9DF3643 is not bound =E2=80=A6 Policy reject= ed non-revocation signature (PositiveCertification) requiring second pre-image resistance =E2= =80=A6 SHA1 is not considered secure since 2026-02-01=E2=80=9D. This seems related to SHA1 being rejected by policy on newer systems, so the repo is effectively unusable on trixie without weakening signature verification. Is there an updated Bacula Distribution Verification Key (or re-signed Release/InRelease) available that avoids SHA1, or any official guidance/workaround planned for Debian trixie? Thanks, --=20 Elias Pereira --000000000000134ec3064a90572a Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div><div class=3D"gmail_default" style=3D"font-family:tah= oma,sans-serif"><span style=3D"font-family:Arial,Helvetica,sans-serif">Hi a= ll,</span></div> <p>On Debian trixie (APT using <code>sqv</code>/Sequoia), <code>apt update<= /code> fails for the Bacula.org repository with an error similar to:</p> <p>=E2=80=9CSigning key =E2=80=A6E9DF3643 is not bound =E2=80=A6 Policy rej= ected non-revocation signature (PositiveCertification) requiring second pre= -image resistance =E2=80=A6 SHA1 is not considered secure since 2026-02-01= =E2=80=9D.</p> <p>This seems related to SHA1 being rejected by policy on newer systems, so= the repo is effectively unusable on trixie without weakening signature ver= ification.</p> <p>Is there an updated Bacula Distribution Verification Key (or re-signed R= elease/InRelease) available that avoids SHA1, or any official guidance/work= around planned for Debian trixie?</p> <p>Thanks,</p></div><span class=3D"gmail_signature_prefix">-- </span><br><d= iv dir=3D"ltr" class=3D"gmail_signature" data-smartmail=3D"gmail_signature"= >Elias Pereira</div></div> --000000000000134ec3064a90572a-- --===============2749681082587858859== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============2749681082587858859== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Bacula-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/bacula-devel --===============2749681082587858859==--