Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Debian Repository - Signature by key 2C…99 uses weak digest algorithm (SHA1) #117

Open
vsespb opened this issue May 9, 2016 · 4 comments

Comments

@vsespb
Copy link
Owner

vsespb commented May 9, 2016

@ChrisChiappa from twitter reports:


@mtglacier Can the debian repos be updated? W: dl.mt-aws.com/debian/current…: Signature by key 2C…99 uses weak digest algorithm (SHA1)


not sure how to reproduce. Tried Debian 8 (adding key, apt-get update), and no warning.

@CChiappa
Copy link

CChiappa commented May 9, 2016

I'm on Debian unstable. It looks like deprecation of SHA-1 is a somewhat new apt change:
https://juliank.wordpress.com/2016/03/14/dropping-sha-1-support-in-apt/

@vsespb
Copy link
Owner Author

vsespb commented May 9, 2016

Thanks! I need to think what to do

@johanneskloos
Copy link

The issue is still standing: The problem is the that InRelease file (at least) uses a SHA-1 hash by default, which modern APT does not like. I suppose you need to update your repository administration tools.

@johanneskloos
Copy link

See https://wiki.debian.org/Teams/Apt/Sha1Removal for dealing with this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants