Hi all,

On Debian trixie (APT using sqv/Sequoia), apt update fails for the
Bacula.org repository with an error similar to:

“Signing key …E9DF3643 is not bound … Policy rejected non-revocation
signature (PositiveCertification) requiring second pre-image resistance …
SHA1 is not considered secure since 2026-02-01”.

This seems related to SHA1 being rejected by policy on newer systems, so
the repo is effectively unusable on trixie without weakening signature
verification.

Is there an updated Bacula Distribution Verification Key (or re-signed
Release/InRelease) available that avoids SHA1, or any official
guidance/workaround planned for Debian trixie?

Thanks,
-- 
Elias Pereira
_______________________________________________
Bacula-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/bacula-users

Reply via email to