Package: mysql-5.5 Version: 5.5.47-0+deb7u1 If you download the following packages:
ftp://ftp.de.debian.org/debian/pool/main/m/mysql-5.5/mysql-5.5_5.5.47-0+deb7u1.dsc http://security.debian.org/debian-security/pool/updates/main/m/mysql-5.5/mysql-5.5_5.5.47-0+deb7u1.dsc you got different md5sum: 48c188a3e65f257316467e1fd067b225 mysql-5.5_5.5.47-0+deb7u1.dsc (from main) 833901bff84adb058c8fd3f8b4496004 mysql-5.5_5.5.47-0+deb7u1.dsc.1 (from security) main issue is that the first package got a Hash: SHA512 and the second one SHA256: ---cut --- mysql-5.5_5.5.47-0+deb7u1.dsc 2016-04-06 15:22:11.485887886 +0200 +++ mysql-5.5_5.5.47-0+deb7u1.dsc.1 2016-01-27 17:03:36.000000000 +0100 @@ -1,5 +1,5 @@ -----BEGIN PGP SIGNED MESSAGE----- -Hash: SHA512 +Hash: SHA256 Format: 3.0 (quilt) Source: mysql-5.5 @@ -39,17 +39,17 @@ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 -iQIcBAEBCgAGBQJWq3ueAAoJEAVMuPMTQ89EJ9wP/i/leT+0ya/YKWHFVf57ZL/7 -aUp010G6xYKpxJMHtnUzlWjhaZxL5vQeUfWowVVzDuoWMCr5EF0lcck4ikIWparU -EcCzrejjNHstrmAl44UMwTaF95aWnR+Gmf5nlornfjpCbL0FEFaagKCvAVJOGl9q -J5GM51xZpU+p6ixegHHcTTIqI/wXQyeVz6sFxjR6B0rXPNW/h65CYAkmPJn/wm7K -a3IUf6gVmg5L4dkL05xjk0DeK353dDLQjXraGeluD8D251IB22Dk3p3RyBwBTk1U -m7pYkgoMTSmdNn8IanKsrB3tBn6SV+q3vOi4ha/uj/kt5IjNN2UUvBA4IluKHISv -pCN5s6Wyh7kZoQOQnnlmsMgTaUvZOu0Cc3KgnlapB+Q38jsj/nrXeWe3gLAapTmj -Z8manJ9ChZ+S7Kvo7Z5F3M2s9QQS8Y0f67ObzBJS0nKzJk8Iwnome3X5oF3n5LLO -txiMuEjASuPTLO3gQd1ZntD7SvUbDSXA3LV/Mz0WrUVWUOkiSDJWj8qwhsppriRl -hwZgS7XmubdDW9tGJNIMWnRB07YimqN1aLSIo6EuUZuJoCMRvTT+/O165UGXsQzs -5Ty9i5km2qrNsRTp2UfEeW4NomyNMEg9nV+lY27017y3J2LVoG0qJaCBmONOoA1v -iYMfqRrS0hHoXLqSu96j -=2FqQ +iQIcBAEBCAAGBQJWqNJhAAoJEL/srsug59jD3IcQAI0mP/dydC9MWW8MT2dTNz8i +vXYiLpZrwVK/XkIVsgUXTkXaQOZV0vFKmNEyeOpFHcQFkDrRM0fFZ0Q3dXejT3yl +XJGoNVt5VYTw9i/SlLy+sRJU4KKzfgOqHZLJ8lAhIvBMj6sTIfOL3D0RpKTIE7nV +Me0pfwYmSPV/hOuQzXbAhNG1W3uIhlD3exjuHN7R11hs1n2MZYIU/ivGAV+G/Rxb +U9GeOQiE2tMBICkq8bK1xT7SZntalQVb/m3ORwCgfdGO1wJUdkFu9ZVWEjQ51Hp+ +9spu3azuval43mmORAwXlNRglLdjW0V/f/S+a11j/EnfgEUdRqwdcOuM7L6r2hAE +PPemD/6G3Z3LeP1C004oTq4jAmnY/rI4Bl/Mome6DLoOgDeYU0PgjwaJJ/7Kc6j+ +YNuzjHucrbeAjNPb7h+YbqOkhPw2p2VuSWW9C0xrQZCpOxl++WHQoRx2X8mrYcow +NxIGzxtCOP9BpVq5vv70WPoiM1bI4I/tWooD0uLdWOqUm3PL+FIaG+HE3zbR8zOF +d3RPtABq4sV0g0rYa2CWrFWJkZJuuNXBEAaPOGoR8Bd6HEFBZ8kWDHBJEs2OJXW+ +Qloz0+1HkBRx3JI8gL/2mxfrMVsEn9D8heifw95hmbk+lL9LT8ZuuRAqro85YcOn +1UkTJlgs8WedOk1Zo2XQ +=oAy3 -----END PGP SIGNATURE----- ---cut I suggest that the same version files on main and security should have the same md5sum. Distribution I use is wheezy.

