Public bug reported:
Description:
When running apt update on Ubuntu 26.10 (Stonking Stingray) with
ddebs.ubuntu.com enabled, apt fails to verify the repository's InRelease file.
The sqv sub-process rejects the ddebs signing key
(F2EDC64DC5AEE1F6B9C621F0C8CAB6595FDFF622) because its binding signature
relies on SHA-1, which is rejected by the current sqv / Sequoia PGP
security policy.
Error message:
Sub-process /usr/bin/sqv returned an error code (1), error message is:
Signing key on F2EDC64DC5AEE1F6B9C621F0C8CAB6595FDFF622 is not bound:
No binding signature at time 2026-04-23T19:24:06Z
because: Policy rejected non-revocation signature
(PositiveCertification) requiring second pre-image resistance
because: SHA1 is not considered secure since 2026-02-01T00:00:00Z
** Affects: ubuntu-keyring (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163397
Title:
apt update fails for ddebs repository due to sqv SHA-1 policy
rejection on signing key binding
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ubuntu-keyring/+bug/2163397/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs