Re: Bacula.org APT repo fails on Debian trixie due to SHA1 policy (sqv)
Rob Gerber <[email protected]> Wed, 11 Feb 2026 17:33:31 -0600
| Newsgroups | gmane.comp.bacula.user,gmane.comp.sysutils.backup.bacula.devel |
|---|---|
| Message-ID | <CAMKi9mQb9QEx9wr+qkA2FNqZcS2EQ+GZ7d6UfRLZf0BOO1dGfA@mail.gmail.com> |
--===============0449684924928528766== Content-Type: multipart/alternative; boundary="000000000000e917aa064a94cead" --000000000000e917aa064a94cead Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Elias, If anyone from the project is reading this, I do think it is important that we address this issue soon. Because of the outdated SHA1 signature, it is essentially impossible to install bacula in more modern operating systems without overriding or weakening security policies. I do not speak for the bacula CE project, but I can say that I have ran into this issue with Rocky Linux 9 and Alma Linux 9. This was brought up with the project at that time at least a year ago, and so far no action. The only solutions that I was aware of were: 1. Globally allow SHA1 for package signing (not great). 2. Disable signature checking altogether for the bacula CE repo only. (not sure if this is better or worse than globally allowing SHA1 for package signing). At least, option 2 is more granular. Once you install bacula, you're unlikely to need to do signature verification again, and the official installation method locks you to a certain version at the repo level. I think the latest version of Debian may have bacula 15.x packages in the official repos, but I haven't personally confirmed this. I do think that there were a few confusing configuration changes made, to make bacula default to a 'safe' local only configuration. I would not normally advise the use of distribution repos to install bacula, but if the signature situation is unacceptable to you or your organization, that may be the only option besides making your own repo. Regards, Robert Gerber 402-237-8692 [email protected] On Wed, Feb 11, 2026 at 12:15=E2=80=AFPM Elias Pereira <[email protected]>= wrote: > Hi all, > > On Debian trixie (APT using sqv/Sequoia), apt update fails for the > Bacula.org repository with an error similar to: > > =E2=80=9CSigning key =E2=80=A6E9DF3643 is not bound =E2=80=A6 Policy reje= cted non-revocation > signature (PositiveCertification) requiring second pre-image resistance = =E2=80=A6 > SHA1 is not considered secure since 2026-02-01=E2=80=9D. > > This seems related to SHA1 being rejected by policy on newer systems, so > the repo is effectively unusable on trixie without weakening signature > verification. > > Is there an updated Bacula Distribution Verification Key (or re-signed > Release/InRelease) available that avoids SHA1, or any official > guidance/workaround planned for Debian trixie? > > Thanks, > -- > Elias Pereira > _______________________________________________ > Bacula-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/bacula-users > --000000000000e917aa064a94cead Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Elias,</div><div><br></div><div>If anyone from the pr= oject is reading this, I do think it is important=20 that we address this issue soon. Because of the outdated SHA1 signature, it is essentially impossible to install bacula in more modern operating systems without overriding or weakening security policies.</div><div><br><= /div><div>I do not speak for the bacula CE project, but I can say that I ha= ve ran into this issue with Rocky Linux 9 and Alma Linux 9. This was brough= t up with the project at that time at least a year ago, and so far no actio= n. The only solutions that I was aware of were:</div><div><br></div><div>1.= Globally allow SHA1 for package signing (not great).</div><div>2. Disable = signature checking altogether for the bacula CE repo only. (not sure if thi= s is better or worse than globally allowing SHA1 for package signing).=C2= =A0</div><div><br></div><div>At least, option 2 is more granular. Once you = install bacula, you're unlikely to need to do signature verification ag= ain, and the official installation method locks you to a certain version at= the repo level.=C2=A0</div><div><br></div><div>I think the latest version = of Debian may have bacula 15.x packages in the official repos, but I haven&= #39;t personally confirmed this. I do think that there were a few confusing= configuration changes made, to make bacula default to a 'safe' loc= al only configuration. I would not normally advise the use of distribution = repos to install bacula, but if the signature situation is unacceptable to = you or your organization, that may be the only option besides making your o= wn repo.</div><div><br></div><div><br></div><div><br></div><div><br></div><= div><div dir=3D"ltr" class=3D"gmail_signature" data-smartmail=3D"gmail_sign= ature"><div>Regards,</div><div>Robert Gerber</div><div>402-237-8692</div><d= iv><a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a></= div></div></div><br></div><br><div class=3D"gmail_quote gmail_quote_contain= er"><div dir=3D"ltr" class=3D"gmail_attr">On Wed, Feb 11, 2026 at 12:15=E2= =80=AFPM Elias Pereira <<a href=3D"mailto:[email protected]">empbilly@g= mail.com</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D= "margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-le= ft:1ex"><div dir=3D"ltr"><div><div class=3D"gmail_default" style=3D"font-fa= mily:tahoma,sans-serif"><span style=3D"font-family:Arial,Helvetica,sans-ser= if">Hi all,</span></div> <p>On Debian trixie (APT using <code>sqv</code>/Sequoia), <code>apt update<= /code> fails for the Bacula.org repository with an error similar to:</p> <p>=E2=80=9CSigning key =E2=80=A6E9DF3643 is not bound =E2=80=A6 Policy rej= ected non-revocation signature (PositiveCertification) requiring second pre= -image resistance =E2=80=A6 SHA1 is not considered secure since 2026-02-01= =E2=80=9D.</p> <p>This seems related to SHA1 being rejected by policy on newer systems, so= the repo is effectively unusable on trixie without weakening signature ver= ification.</p> <p>Is there an updated Bacula Distribution Verification Key (or re-signed R= elease/InRelease) available that avoids SHA1, or any official guidance/work= around planned for Debian trixie?</p> <p>Thanks,</p></div><span class=3D"gmail_signature_prefix">-- </span><br><d= iv dir=3D"ltr" class=3D"gmail_signature">Elias Pereira</div></div> _______________________________________________<br> Bacula-users mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">Bac= [email protected]</a><br> <a href=3D"https://lists.sourceforge.net/lists/listinfo/bacula-users" rel= =3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/listi= nfo/bacula-users</a><br> </blockquote></div> --000000000000e917aa064a94cead-- --===============0449684924928528766== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============0449684924928528766== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Bacula-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/bacula-users --===============0449684924928528766==--