Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] GPG key not valid with apt 2.9.21 #675

Open
Glandos opened this issue Jan 11, 2025 · 2 comments
Open

[BUG] GPG key not valid with apt 2.9.21 #675

Glandos opened this issue Jan 11, 2025 · 2 comments
Labels

Comments

@Glandos
Copy link

Glandos commented Jan 11, 2025

Describe the bug
With APT 2.9.21, the GPG key from https://packagecloud.io/go-graphite/stable/gpgkey isn't accepted anymore

Logs
Err :6 https://packagecloud.io/go-graphite/stable/debian bookworm InRelease
Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on 40B29610C48DA4E2152C4E5FA3C7D6C388AEDEA5 is not bound: primary key because: No binding signature at time 2023-11-09T12:47:22Z because: Policy rejected non-revocation signature (PositiveCertification) requiring collision resistance because: SHA1 is not considered secure since 2013-02-01T00:00:00Z

Go-carbon Configuration:
N/A

Metric retention and aggregation schemas
N/A

Simplified query (if applicable)
N/A

Additional context
APT is now using sqv instead of gnupg. There is a workaround for accepting SHA1, but it should be changed anyway

@Glandos Glandos added the bug label Jan 11, 2025
@deniszh
Copy link
Member

deniszh commented Jan 12, 2025

@Civil : maybe we need to regenerate packagecloud keys? I have no admin access there. Could you please do that?

@Civil
Copy link
Member

Civil commented Jan 13, 2025

@deniszh their open-source plan is weird, they are managing the keys (at least it seems so), but there is no button to regenrate them. For paid plans they allows you to upload your own keys to sign, but that is way too expensive in my opinion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants