CentOS7用reprepro签deb包后,apt-get安装出警告求助(无需用户规避)
Hey there, let's get this sorted so your RPi3 users don't see any warnings when installing packages from your repo. Since you're managing the repo on CentOS 7 with reprepro 4.17.0-3.el7 and already set up a passphrase-protected GPG key, the warnings are almost certainly tied to how your repo is signed or how your key is configured—no need for users to run any workarounds on their end.
Here are the most likely fixes you can implement on your repo server:
1. Ensure Your GPG Public Key is Properly Distributed & Repro Uses It Correctly
First, double-check that your GPG public key is integrated correctly with your repo metadata:
- Export your public key in armored format and place it in the root of your repo (this ensures it's accessible if needed, though we won't force users to fetch it manually):
gpg --armor --export YOUR_KEY_ID > /path/to/your/repo/public-key.gpg - Verify your
conf/distributionsfile in reprepro explicitly references your key ID with theSignWithfield (avoid using just the key's name to prevent ambiguity):Origin: Your Repository Name Label: Your Repo Label Suite: stable Codename: YOUR_TARGET_CODENAME (match what your RPi3 clients use, e.g., buster) Architectures: armhf Components: main SignWith: YOUR_KEY_ID - Regenerate the repo metadata to apply these settings:
reprepro --export
2. Fix Weak Digest Algorithm Warnings
If the warning mentions a weak digest like SHA1, this happens because older GPG configurations default to SHA1 for signatures, and modern apt versions flag this as a risk. Update your GPG settings to use stronger algorithms:
- Edit your user's GPG config file (
~/.gnupg/gpg.conf) and add these lines:personal-digest-preferences SHA256 cert-digest-algo SHA256 default-preference-list SHA512 SHA384 SHA256 SHA224 AES256 AES192 AES CAST5 ZLIB BZIP2 ZIP Uncompressed - Update your key's internal preferences to match:
gpg --edit-key YOUR_KEY_ID # In the GPG interactive prompt, run: setpref SHA512 SHA384 SHA256 SHA224 AES256 AES192 AES CAST5 ZLIB BZIP2 ZIP Uncompressed save - Regenerate the repo metadata again to sign with the stronger algorithm:
reprepro --export
3. Validate Repo Metadata Signatures
Make sure your repo's Release files are correctly signed. On your server, run this check:
cd /path/to/your/repo/dists/YOUR_CODENAME gpg --verify Release.gpg Release
You should see a message confirming a "Good signature from..."—if not, double-check your SignWith setting in reprepro and ensure your GPG key is unlocked (use gpg-agent to cache the passphrase if you don't want to enter it every time you update the repo).
Since you confirmed both systems have synchronized time, timestamp-related issues are off the table. These fixes should eliminate the warnings entirely without requiring any action from your RPi3 users.
内容的提问来源于stack exchange,提问作者user1032531

