Re: Invalid signature for the apt repository

"'Lars Erik Wik' via help-cfengine" <[email protected]> Mon, 9 Feb 2026 02:23:29 -0800 (PST)
Newsgroups gmane.comp.sysutils.cfengine.general
Message-ID <[email protected]>
------=_Part_368_336370834.1770632609911
Content-Type: multipart/alternative; 
	boundary="----=_Part_369_256566038.1770632609911"

------=_Part_369_256566038.1770632609911
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi bronto,

thanks for reporting this. It appears signature verification tool on Debian=
=20
13 has deprecated signature packet v3. This means that we (the=20
maintainers), need to re-sign our packages with a newer version. I created=
=20
a ticket in our bug tracker to make this happen=20
(see https://northerntech.atlassian.net/browse/CFE-4634).

In the meanwhile you can download packages from=20
here: https://cfengine.com/downloads/cfengine-community/

Although, not recommended. You can also add `[trusted=3Dyes]` to=20
`/etc/apt/sources.list.d/cfengine-community.list` to skip the signature=20
verification. It will look like this `deb [trusted=3Dyes]=20
https://cfengine-package-repos.s3.amazonaws.com/pub/apt/packages stable=20
main`.

Best regards,
- Lars

On Monday, February 9, 2026 at 9:55:57=E2=80=AFAM UTC+1 brontolinux wrote:

> Hello there
>
> I am having trouble on my policy hub (Debian 13) with CFEngine's apt=20
> repository. The signature of the repository is being rejected. I have als=
o=20
> explicitly trusted /etc/apt/trusted.gpg.d but it didn't help, the problem=
=20
> is in the signature itself:
>
> Get:1 file:/etc/apt/mirrors/debian.list Mirrorlist [38 B]
> Get:2 file:/etc/apt/mirrors/debian-security.list Mirrorlist [47 B]       =
                            =20
> Hit:3 https://cdn-aws.deb.debian.org/debian trixie InRelease             =
                            =20
> Get:4 https://cdn-aws.deb.debian.org/debian trixie-updates InRelease [47.=
3 kB]
> Get:5 https://cdn-aws.deb.debian.org/debian trixie-backports InRelease [5=
4.0 kB]
> Hit:6 https://cdn-aws.deb.debian.org/debian-security trixie-security InRe=
lease
> Get:7 https://cdn-aws.deb.debian.org/debian trixie-backports/main Sources=
.diff/Index [63.3 kB]
> Get:8 https://cdn-aws.deb.debian.org/debian trixie-backports/main Sources=
 T-2026-02-09-0800.45-F-2026-02-09-0800.45.pdiff [945 B]
> Get:8 https://cdn-aws.deb.debian.org/debian trixie-backports/main Sources=
 T-2026-02-09-0800.45-F-2026-02-09-0800.45.pdiff [945 B]
> Get:9 https://cfengine-package-repos.s3.amazonaws.com/pub/apt/packages st=
able InRelease [6648 B]
> Err:9 https://cfengine-package-repos.s3.amazonaws.com/pub/apt/packages st=
able InRelease
>   Sub-process /usr/bin/sqv returned an error code (1), error message is: =
Error: Policy rejected packet type  Caused by:     Signature Packet v3 is n=
ot considered secure since 2026-02-01T00:00:00Z
> Warning: https://cfengine-package-repos.s3.amazonaws.com/pub/apt/packages=
/dists/stable/InRelease: Loading /etc/apt/trusted.gpg from deprecated optio=
n Dir::Etc::Trusted
> Warning: OpenPGP signature verification failed: https://cfengine-package-=
repos.s3.amazonaws.com/pub/apt/packages stable InRelease: Sub-process /usr/=
bin/sqv returned an error code (1), error message is: Error: Policy rejecte=
d packet type  Caused by:     Signature Packet v3 is not considered secure =
since 2026-02-01T00:00:00Z
> Error: The repository 'https://cfengine-package-repos.s3.amazonaws.com/pu=
b/apt/packages stable InRelease' is not signed.
> Notice: Updating from such a repository can't be done securely, and is th=
erefore disabled by default.
> Notice: See apt-secure(8) manpage for repository creation and user config=
uration details.
>
>
> Can you help with fixing the signature, pretty pretty please please? ;-)
>
> Ciao,
> -- bronto
>

--=20
You received this message because you are subscribed to the Google Groups "=
help-cfengine" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to [email protected].
To view this discussion visit https://groups.google.com/d/msgid/help-cfengi=
ne/47ecb3ee-89f8-4cd8-94f8-7845612a73ban%40googlegroups.com.

------=_Part_369_256566038.1770632609911
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi=C2=A0bronto,<div><br /></div><div>thanks for reporting this. It appears =
signature verification tool on Debian 13 has deprecated signature packet v3=
. This means that we (the maintainers), need to re-sign our packages with a=
 newer version. I created a ticket in our bug tracker to make this happen (=
see=C2=A0https://northerntech.atlassian.net/browse/CFE-4634).</div><div><br=
 /></div><div>In the meanwhile you can download packages from here:=C2=A0ht=
tps://cfengine.com/downloads/cfengine-community/</div><div><br /></div><div=
>Although, not recommended. You can also add `[trusted=3Dyes]` to `/etc/apt=
/sources.list.d/cfengine-community.list` to skip the signature verification=
. It will look like this `deb [trusted=3Dyes] https://cfengine-package-repo=
s.s3.amazonaws.com/pub/apt/packages stable main`.</div><div><br /></div><di=
v>Best regards,</div><div>- Lars<br /><br /></div><div class=3D"gmail_quote=
"><div dir=3D"auto" class=3D"gmail_attr">On Monday, February 9, 2026 at 9:5=
5:57=E2=80=AFAM UTC+1 brontolinux wrote:<br/></div><blockquote class=3D"gma=
il_quote" style=3D"margin: 0 0 0 0.8ex; border-left: 1px solid rgb(204, 204=
, 204); padding-left: 1ex;"><u></u>

 =20

   =20
 =20
  <div>
    <p><font face=3D"Cantarell">Hello there</font></p>
    <p><font face=3D"Cantarell">I am having trouble on my policy hub
        (Debian 13) with CFEngine&#39;s apt repository. The signature of th=
e
        repository is being rejected. I have also explicitly trusted
        /etc/apt/trusted.gpg.d but it didn&#39;t help, the problem is in th=
e
        signature itself:</font></p>
    <pre>Get:1 <a rel=3D"nofollow">file:/etc/apt/mirrors/debian.list</a> Mi=
rrorlist [38 B]
Get:2 <a rel=3D"nofollow">file:/etc/apt/mirrors/debian-security.list</a> Mi=
rrorlist [47 B]=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=C2=A0
Hit:3 <a href=3D"https://cdn-aws.deb.debian.org/debian" target=3D"_blank" r=
el=3D"nofollow" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den&=
amp;q=3Dhttps://cdn-aws.deb.debian.org/debian&amp;source=3Dgmail&amp;ust=3D=
1770717034257000&amp;usg=3DAOvVaw1ABKlkIX4dsfIid0zcNhK9">https://cdn-aws.de=
b.debian.org/debian</a> trixie InRelease=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=C2=A0
Get:4 <a href=3D"https://cdn-aws.deb.debian.org/debian" target=3D"_blank" r=
el=3D"nofollow" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den&=
amp;q=3Dhttps://cdn-aws.deb.debian.org/debian&amp;source=3Dgmail&amp;ust=3D=
1770717034257000&amp;usg=3DAOvVaw1ABKlkIX4dsfIid0zcNhK9">https://cdn-aws.de=
b.debian.org/debian</a> trixie-updates InRelease [47.3 kB]
Get:5 <a href=3D"https://cdn-aws.deb.debian.org/debian" target=3D"_blank" r=
el=3D"nofollow" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den&=
amp;q=3Dhttps://cdn-aws.deb.debian.org/debian&amp;source=3Dgmail&amp;ust=3D=
1770717034257000&amp;usg=3DAOvVaw1ABKlkIX4dsfIid0zcNhK9">https://cdn-aws.de=
b.debian.org/debian</a> trixie-backports InRelease [54.0 kB]
Hit:6 <a href=3D"https://cdn-aws.deb.debian.org/debian-security" target=3D"=
_blank" rel=3D"nofollow" data-saferedirecturl=3D"https://www.google.com/url=
?hl=3Den&amp;q=3Dhttps://cdn-aws.deb.debian.org/debian-security&amp;source=
=3Dgmail&amp;ust=3D1770717034257000&amp;usg=3DAOvVaw1QQURiuuvFjFM9Npxo41GA"=
>https://cdn-aws.deb.debian.org/debian-security</a> trixie-security InRelea=
se
Get:7 <a href=3D"https://cdn-aws.deb.debian.org/debian" target=3D"_blank" r=
el=3D"nofollow" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den&=
amp;q=3Dhttps://cdn-aws.deb.debian.org/debian&amp;source=3Dgmail&amp;ust=3D=
1770717034257000&amp;usg=3DAOvVaw1ABKlkIX4dsfIid0zcNhK9">https://cdn-aws.de=
b.debian.org/debian</a> trixie-backports/main Sources.diff/Index [63.3 kB]
Get:8 <a href=3D"https://cdn-aws.deb.debian.org/debian" target=3D"_blank" r=
el=3D"nofollow" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den&=
amp;q=3Dhttps://cdn-aws.deb.debian.org/debian&amp;source=3Dgmail&amp;ust=3D=
1770717034257000&amp;usg=3DAOvVaw1ABKlkIX4dsfIid0zcNhK9">https://cdn-aws.de=
b.debian.org/debian</a> trixie-backports/main Sources T-2026-02-09-0800.45-=
F-2026-02-09-0800.45.pdiff [945 B]
Get:8 <a href=3D"https://cdn-aws.deb.debian.org/debian" target=3D"_blank" r=
el=3D"nofollow" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den&=
amp;q=3Dhttps://cdn-aws.deb.debian.org/debian&amp;source=3Dgmail&amp;ust=3D=
1770717034257000&amp;usg=3DAOvVaw1ABKlkIX4dsfIid0zcNhK9">https://cdn-aws.de=
b.debian.org/debian</a> trixie-backports/main Sources T-2026-02-09-0800.45-=
F-2026-02-09-0800.45.pdiff [945 B]
Get:9 <a href=3D"https://cfengine-package-repos.s3.amazonaws.com/pub/apt/pa=
ckages" target=3D"_blank" rel=3D"nofollow" data-saferedirecturl=3D"https://=
www.google.com/url?hl=3Den&amp;q=3Dhttps://cfengine-package-repos.s3.amazon=
aws.com/pub/apt/packages&amp;source=3Dgmail&amp;ust=3D1770717034257000&amp;=
usg=3DAOvVaw3cfa_896DQux8DuQKXABad">https://cfengine-package-repos.s3.amazo=
naws.com/pub/apt/packages</a> stable InRelease [6648 B]
Err:9 <a href=3D"https://cfengine-package-repos.s3.amazonaws.com/pub/apt/pa=
ckages" target=3D"_blank" rel=3D"nofollow" data-saferedirecturl=3D"https://=
www.google.com/url?hl=3Den&amp;q=3Dhttps://cfengine-package-repos.s3.amazon=
aws.com/pub/apt/packages&amp;source=3Dgmail&amp;ust=3D1770717034257000&amp;=
usg=3DAOvVaw3cfa_896DQux8DuQKXABad">https://cfengine-package-repos.s3.amazo=
naws.com/pub/apt/packages</a> stable InRelease
=C2=A0 Sub-process /usr/bin/sqv returned an error code (1), error message i=
s: Error: Policy rejected packet type=C2=A0 Caused by:=C2=A0 =C2=A0 =C2=A0S=
ignature Packet v3 is not considered secure since 2026-02-01T00:00:00Z
Warning: <a href=3D"https://cfengine-package-repos.s3.amazonaws.com/pub/apt=
/packages/dists/stable/InRelease" target=3D"_blank" rel=3D"nofollow" data-s=
aferedirecturl=3D"https://www.google.com/url?hl=3Den&amp;q=3Dhttps://cfengi=
ne-package-repos.s3.amazonaws.com/pub/apt/packages/dists/stable/InRelease&a=
mp;source=3Dgmail&amp;ust=3D1770717034257000&amp;usg=3DAOvVaw008jXF2804Dfpq=
xyu3zXnf">https://cfengine-package-repos.s3.amazonaws.com/pub/apt/packages/=
dists/stable/InRelease</a>: Loading /etc/apt/trusted.gpg from deprecated op=
tion Dir::Etc::Trusted
Warning: OpenPGP signature verification failed: <a href=3D"https://cfengine=
-package-repos.s3.amazonaws.com/pub/apt/packages" target=3D"_blank" rel=3D"=
nofollow" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den&amp;q=
=3Dhttps://cfengine-package-repos.s3.amazonaws.com/pub/apt/packages&amp;sou=
rce=3Dgmail&amp;ust=3D1770717034257000&amp;usg=3DAOvVaw3cfa_896DQux8DuQKXAB=
ad">https://cfengine-package-repos.s3.amazonaws.com/pub/apt/packages</a> st=
able InRelease: Sub-process /usr/bin/sqv returned an error code (1), error =
message is: Error: Policy rejected packet type=C2=A0 Caused by:=C2=A0 =C2=
=A0 =C2=A0Signature Packet v3 is not considered secure since 2026-02-01T00:=
00:00Z
Error: The repository &#39;<a href=3D"https://cfengine-package-repos.s3.ama=
zonaws.com/pub/apt/packages" target=3D"_blank" rel=3D"nofollow" data-safere=
directurl=3D"https://www.google.com/url?hl=3Den&amp;q=3Dhttps://cfengine-pa=
ckage-repos.s3.amazonaws.com/pub/apt/packages&amp;source=3Dgmail&amp;ust=3D=
1770717034257000&amp;usg=3DAOvVaw3cfa_896DQux8DuQKXABad">https://cfengine-p=
ackage-repos.s3.amazonaws.com/pub/apt/packages</a> stable InRelease&#39; is=
 not signed.
Notice: Updating from such a repository can&#39;t be done securely, and is =
therefore disabled by default.
Notice: See apt-secure(8) manpage for repository creation and user configur=
ation details.
</pre>
    <p><font face=3D"Cantarell"><br>
      </font></p>
    <p><font face=3D"Cantarell">Can you help with fixing the signature,
        pretty pretty please please? ;-)</font></p>
    <p><font face=3D"Cantarell">Ciao,<br>
        -- bronto</font></p>
  </div>

</blockquote></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;help-cfengine&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">help-=
[email protected]</a>.<br />
To view this discussion visit <a href=3D"https://groups.google.com/d/msgid/=
help-cfengine/47ecb3ee-89f8-4cd8-94f8-7845612a73ban%40googlegroups.com?utm_=
medium=3Demail&utm_source=3Dfooter">https://groups.google.com/d/msgid/help-=
cfengine/47ecb3ee-89f8-4cd8-94f8-7845612a73ban%40googlegroups.com</a>.<br /=
>

------=_Part_369_256566038.1770632609911--

------=_Part_368_336370834.1770632609911--