Bug#1088288: difficulties understanding the rejection in case of multiple hashes

Thomas Braun <[email protected]> Mon, 30 Mar 2026 02:38:21 +0200
Newsgroups gmane.linux.debian.apt.devel
Message-ID <f9f15a51ced5413e96f48a3d229e6f17501a17d1.camel__14571.2844257773$1774832733$gmane$org@byte-physics.de>
The elasticsearch package from [1] also triggers the SHA1 too-broken
message.

But what I don't understand is that the InRelease [2] file has
MD5Sum/SHA1/SHA256 hashes.

So what is the issue about SHA1 if we have a better one (SHA256)? And
why is there no complaint about MD5?

[1]:
https://www.elastic.co/docs/deploy-manage/deploy/self-managed/install-elasticsearch-with-debian-package
[2]:
https://artifacts.elastic.co/packages/9.x/apt/dists/stable/InRelease