• Bug#1092747: Switch to sqv breaks apt-secure overrides

    From =?UTF-8?B?0KPRgdGC0LjQvdC+0LIg0JDQu@21:1/5 to All on Sun May 18 01:20:02 2025
    This is a multi-part message in MIME format.
    Similar errors in sequoia:

    apt update --audit
    ...
    Warning: https://apt.syncthing.net/dists/syncthing/InRelease: Policy
    will reject signature within a year, see --audit for details
    Audit: https://apt.syncthing.net/dists/syncthing/InRelease: Sub-process /usr/bin/sqv returned an error code (1), error message is:
       Missing key FBA2E162F2F44657B38F0309E5665F9BD5970C47, which is
    needed to verify signature.
       Signing key on 37C84554E7E0A261E4F76E1ED26E6ED000654A3E is not bound:
                  No binding signature at time 2025-05-16T22:45:26Z
         because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance
         because: SHA1 is not considered secure since 2026-02-01T00:00:00Z Warning: https://dbeaver.io/debs/dbeaver-ce/InRelease: Policy will
    reject signature within a year, see --audit for details
    Audit: https://dbeaver.io/debs/dbeaver-ce/InRelease: Sub-process
    /usr/bin/sqv returned an error code (1), error message is:
       Signing key on 98F5A7CC1ABE72AC3852A007D33A1BD725ED047D is not bound:
                  No binding signature at time 2025-05-04T17:39:54Z
         because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance
         because: SHA1 is not considered secure since 2026-02-01T00:00:00Z Audit: Repositories should provide unencrypted signed InRelease file,
    but it was not found in
    http://linux.dropbox.com/debian/dists/trixie/InRelease.
    Warning: http://linux.dropbox.com/debian/dists/trixie/Release.gpg:
    Policy will reject signature within a year, see --audit for details
    Аудит: http://linux.dropbox.com/debian/dists/trixie/Release.gpg: Sub-process /usr/bin/sqv returned an error code (1), error message is:
       Signing key on 1C61A2656FB57B7E4DE0F4C1FC918B335044912E is not bound:
                  No binding signature at time 2024-04-17T23:48:26Z
         because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance
         because: SHA1 is not considered secure since 2026-02-01T00:00:00Z

    sqv -V
    sqv 1.3.0 (sequoia-openpgp 2.0.0, using Nettle 3.10 (Cv448: true, OCB:
    true))
    uname -r
    6.12.27-amd64

    --
    С уважением.
    Устинов Александр Евгеньевич

    <!DOCTYPE html>
    <html data-lt-installed="true">
    <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
    </head>
    <body style="padding-bottom: 1px;">
    <p>Similar errors in sequoia:</p>
    <p>apt update --audit<br>
    ...<br>
    Warning: <a class="moz-txt-link-freetext" href="https://apt.syncthing.net/dists/syncthing/InRelease">https://apt.syncthing.net/dists/syncthing/InRelease</a>:
    Policy will reject signature within a year, see --audit for
    details<br>
    Audit: <a class="moz-txt-link-freetext" href="https://apt.syncthing.net/dists/syncthing/InRelease">https://apt.syncthing.net/dists/syncthing/InRelease</a>:
    Sub-process /usr/bin/sqv returned an error code (1), error message
    is:<br>
       Missing key FBA2E162F2F44657B38F0309E5665F9BD5970C47, which is
    needed to verify signature.<br>
       Signing key on 37C84554E7E0A261E4F76E1ED26E6ED000654A3E is not
    bound:<br>
                  No binding signature at time 2025-05-16T22:45:26Z<br>
         because: Policy rejected non-revocation signature
    (PositiveCertification) requiring second pre-image resistance<br>
         because: SHA1 is not considered secure since
    2026-02-01T00:00:00Z<br>
    Warning: <a class="moz-txt-link-freetext" href="https://dbeaver.io/debs/dbeaver-ce/InRelease">https://dbeaver.io/debs/dbeaver-ce/InRelease</a>: Policy will
    reject signature within a year, see --audit for details<br>
    Audit: <a class="moz-txt-link-freetext" href="https://dbeaver.io/debs/dbeaver-ce/InRelease">https://dbeaver.io/debs/dbeaver-ce/InRelease</a>: Sub-process
    /usr/bin/sqv returned an error code (1), error message is:<br>
       Signing key on 98F5A7CC1ABE72AC3852A007D33A1BD725ED047D is not
    bound:<br>
                  No binding signature at time 2025-05-04T17:39:54Z<br>
         because: Policy rejected non-revocation signature
    (PositiveCertification) requiring second pre-image resistance<br>
         because: SHA1 is not considered secure since
    2026-02-01T00:00:00Z<br>
    Audit: Repositories should provide unencrypted signed InRelease
    file, but it was not found in
    <a class="moz-txt-link-freetext" href="http://linux.dropbox.com/debian/dists/trixie/InRelease">http://linux.dropbox.com/debian/dists/trixie/InRelease</a>.<br>
    Warning: <a class="moz-txt-link-freetext" href="http://linux.dropbox.com/debian/dists/trixie/Release.gpg">http://linux.dropbox.com/debian/dists/trixie/Release.gpg</a>:
    Policy will reject signature within a year, see --audit for
    details<br>
    Аудит: <a class="moz-txt-link-freetext" href="http://linux.dropbox.com/debian/dists/trixie/Release.gpg">http://linux.dropbox.com/debian/dists/trixie/Release.gpg</a>:
    Sub-process /usr/bin/sqv returned an error code (1), error message
    is:<br>
       Signing key on 1C61A2656FB57B7E4DE0F4C1FC918B335044912E is not
    bound:<br>
                  No binding signature at time 2024-04-17T23:48:26Z<br>
         because: Policy rejected non-revocation signature
    (PositiveCertification) requiring second pre-image resistance<br>
         because: SHA1 is not considered secure since
    2026-02-01T00:00:00Z<br>
    <br>
    sqv -V<br>
    sqv 1.3.0 (sequoia-openpgp 2.0.0, using Nettle 3.10 (Cv448: true,
    OCB: true))<br>
    uname -r<br>
    6.12.27-amd64<br>
    <br>
    </p>
    <pre class="moz-signature" cols="72">--
    С уважением.
    Устинов Александр Евгеньевич</pre>
    </body>
    <lt-container></lt-container>
    </html>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)