Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-9781

apt-get reports "The repository is insufficiently signed by key 199369E5404BD5FC7D2FE43BCBCB082A1BB943DB (weak digest)" on Debian Testing AMD64

Details

    • Bug
    • Status: Closed (View Workflow)
    • Major
    • Resolution: Fixed
    • 10.1.12
    • 10.0.25, 10.1.14, 10.2.0
    • Packaging, Platform Debian
    • None

    Description

      Hello @ll,
      I hope, I have chosen the right project, component, severity, and the like ... If not, feel free to change

      I tried to upgrade my system today as usual with "apt-get update && apt-get upgrade", and got the error message

      W: gpgv:/var/lib/apt/lists/ftp.hosteurope.de_mirror_mariadb.org_repo_10.1_debian_dists_jessie_InRelease: The repository is insufficiently signed by key 199369E5404BD5FC7D2FE43BCBCB082A1BB943DB (weak digest)
      

      While searching the web for this message, I stumbled upon https://juliank.wordpress.com/2016/03/15/clarifications-and-updates-on-apt-sha1/, where I found a link to wiki.debian.org/Teams/Apt/Sha1Removal. In this wiki page, it says

      Fixing broken repositories

      Repository owners should make sure their release files and Packages files contain SHA256 or SHA512 fields. If they have Sources files, those should contain Checksums-Sha256.

      . I would like to ask if it would be possible to fix this bug as fast as possible to be able to use MariaDB's own repository to upgrade to newer versions.
      Thanks in advance
      Thomas.

      Attachments

        Issue Links

          Activity

            thackert We currently do not have repositories for Debian Stretch. Are you setting up the Sid repository on Stretch?

            dbart Daniel Bartholomew added a comment - thackert We currently do not have repositories for Debian Stretch. Are you setting up the Sid repository on Stretch?

            @Daniel: it seems I have not expressed that well, sorry ... I mean, that I tried to follow the instruction for Debian Jessie (8.x), which did not work. If I follow the instructions for sid (with the key mentioned there as well as the sources.list entry) it works. So yes, I set it up and have now installed MariaDB for sid on Stretch.
            I hope, this is a little bit clearer now ... If not, feel free to ask
            Have a nice evening
            Thomas.

            thackert Thomas Hackert added a comment - @Daniel: it seems I have not expressed that well, sorry ... I mean, that I tried to follow the instruction for Debian Jessie (8.x), which did not work. If I follow the instructions for sid (with the key mentioned there as well as the sources.list entry) it works. So yes, I set it up and have now installed MariaDB for sid on Stretch. I hope, this is a little bit clearer now ... If not, feel free to ask Have a nice evening Thomas.

            thackert: Yes. Using the Jessie instructions on Stretch will not work, you have to use the Sid instructions. Our Jessie repositories still use the old 0xcbcb082a1bb943db GPG key, not the new 0xF1656F24C74CD1D8 key required by Sid and Stretch.

            dbart Daniel Bartholomew added a comment - thackert : Yes. Using the Jessie instructions on Stretch will not work, you have to use the Sid instructions. Our Jessie repositories still use the old 0xcbcb082a1bb943db GPG key, not the new 0xF1656F24C74CD1D8 key required by Sid and Stretch.

            @dbart: thanks for your explanation Just out of interest: will there be a Stretch repo on a later time as well? And will this use the key for sid or another one?
            Have a nice evening
            Thomas.

            thackert Thomas Hackert added a comment - @dbart: thanks for your explanation Just out of interest: will there be a Stretch repo on a later time as well? And will this use the key for sid or another one? Have a nice evening Thomas.

            Yes, there will be a Stretch repository eventually. It will use the same key we're now using for Sid.

            dbart Daniel Bartholomew added a comment - Yes, there will be a Stretch repository eventually. It will use the same key we're now using for Sid.

            People

              dbart Daniel Bartholomew
              thackert Thomas Hackert
              Votes:
              1 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.