[GH-ISSUE #1401] debian repro key is still using SHA1 #986

Closed
opened 2026-05-07 00:29:22 +02:00 by BreizhHardware · 5 comments

Originally created by @lduesing on GitHub (Jul 25, 2025).
Original GitHub issue: https://github.com/binwiederhier/ntfy/issues/1401

🐞 Describe the bug
installing on debian trixie warns about rejecting SHA1 keys.

💻 Components impacted
debian repro https://archive.heckel.io/apt debian main key

💡 Screenshots and/or logs

Warning: https://archive.heckel.io/apt/dists/debian/InRelease: Policy will reject signature within a year, see --audit for details
Audit: https://archive.heckel.io/apt/dists/debian/InRelease: Sub-process /usr/bin/sqv returned an error code (1), error message is:
   Signing key on CF871F1E8399DAEF470832661D5B8EDFB2476E53 is not bound:
              No binding signature at time 2025-07-10T19:29:57Z
     because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance
     because: SHA1 is not considered secure since 2026-02-01T00:00:00Z

🔮 Additional context
Sorry, no.

Originally created by @lduesing on GitHub (Jul 25, 2025). Original GitHub issue: https://github.com/binwiederhier/ntfy/issues/1401 :lady_beetle: **Describe the bug** installing on debian trixie warns about rejecting SHA1 keys. :computer: **Components impacted** debian repro https://archive.heckel.io/apt debian main key :bulb: **Screenshots and/or logs** ``` Warning: https://archive.heckel.io/apt/dists/debian/InRelease: Policy will reject signature within a year, see --audit for details Audit: https://archive.heckel.io/apt/dists/debian/InRelease: Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on CF871F1E8399DAEF470832661D5B8EDFB2476E53 is not bound: No binding signature at time 2025-07-10T19:29:57Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00Z ``` :crystal_ball: **Additional context** Sorry, no.
BreizhHardware 2026-05-07 00:29:22 +02:00
  • closed this issue
  • added the
    🪲 bug
    label
Author
Owner

@CrazyWolf13 commented on GitHub (Aug 25, 2025):

@binwiederhier this needs fixing, thanks for looking into it!

<!-- gh-comment-id:3220081226 --> @CrazyWolf13 commented on GitHub (Aug 25, 2025): @binwiederhier this needs fixing, thanks for looking into it!
Author
Owner

@binwiederhier commented on GitHub (Aug 25, 2025):

Yeah I know. I think I'll just make a brand new repo elsewhere instead of trying to migrate or dual sign it. It'll be easier than that way.

Unless somebody knows how to do a seamless transition with aptly

<!-- gh-comment-id:3220088435 --> @binwiederhier commented on GitHub (Aug 25, 2025): Yeah I know. I think I'll just make a brand new repo elsewhere instead of trying to migrate or dual sign it. It'll be easier than that way. Unless somebody knows how to do a seamless transition with aptly
Author
Owner

@binwiederhier commented on GitHub (Sep 23, 2025):

WIP: https://github.com/binwiederhier/ntfy-ansible/pull/5/files

<!-- gh-comment-id:3322052196 --> @binwiederhier commented on GitHub (Sep 23, 2025): WIP: https://github.com/binwiederhier/ntfy-ansible/pull/5/files
Author
Owner

@binwiederhier commented on GitHub (Sep 23, 2025):

Can be tried out here: https://archive.ntfy.sh/apt/ (test server, will be replaced)

<!-- gh-comment-id:3322053458 --> @binwiederhier commented on GitHub (Sep 23, 2025): Can be tried out here: https://archive.ntfy.sh/apt/ (test server, will be replaced)
Author
Owner

@binwiederhier commented on GitHub (Sep 23, 2025):

Dup of #1357

<!-- gh-comment-id:3322054711 --> @binwiederhier commented on GitHub (Sep 23, 2025): Dup of #1357
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/ntfy#986
No description provided.