Public bug reported:

Description:
When running apt update on Ubuntu 26.10 (Stonking Stingray) with 
ddebs.ubuntu.com enabled, apt fails to verify the repository's InRelease file.

The sqv sub-process rejects the ddebs signing key
(F2EDC64DC5AEE1F6B9C621F0C8CAB6595FDFF622) because its binding signature
relies on SHA-1, which is rejected by the current sqv / Sequoia PGP
security policy.

Error message:
Sub-process /usr/bin/sqv returned an error code (1), error message is: 
Signing key on F2EDC64DC5AEE1F6B9C621F0C8CAB6595FDFF622 is not bound: 
        No binding signature at time 2026-04-23T19:24:06Z 
        because: Policy rejected non-revocation signature 
(PositiveCertification) requiring second pre-image resistance 
        because: SHA1 is not considered secure since 2026-02-01T00:00:00Z

** Affects: ubuntu-keyring (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163397

Title:
  apt update fails for ddebs repository due to sqv SHA-1 policy
  rejection on signing key binding

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ubuntu-keyring/+bug/2163397/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to