You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何阻止GPG包含SHA1?解决APT签名验证失败问题

Fixing apt-get "Invalid Signature" / "InRelease is not signed" Error (Debian 9 + CentOS-signed deb Packages)

I've run into this exact confusing issue before—especially when working with CentOS-signed Debian package repositories on Debian 9. You verify the InRelease file with GPG and confirm it's properly signed, yet apt-get keeps throwing errors about invalid signatures or unsigned files.

What's Causing This?

Debian 9 enforces stricter rules around GPG digest algorithm preferences. If your GPG config still includes SHA-1 in its preferred digests, apt will reject signatures that rely on older algorithms (even though GPG itself can validate them), leading to the false error messages.

Step-by-Step Fix

  1. Open your user's GPG configuration file with your favorite editor:

    nano $HOME/.gnupg/gpg.conf
    

    (Feel free to swap nano for vim or any editor you prefer.)

  2. Locate the personal-digest-preferences line. If it doesn't exist, add it manually. Remove SHA-1 entirely from this line, leaving only modern, secure algorithms like:

    personal-digest-preferences SHA256 SHA384 SHA512
    
  3. Save the file and exit the editor. Now run your apt command again—for example:

    apt-get update
    

    The signature errors should be gone.

Quick Notes

  • If you're operating as the root user, you'll need to edit /root/.gnupg/gpg.conf instead of the user-specific config in $HOME.
  • The mismatch between GPG's validation and apt's error happens because GPG is more flexible about algorithm support, while Debian 9's apt prioritizes security by blocking outdated algorithms like SHA-1 when they're in your GPG preferences.

内容的提问来源于stack exchange,提问作者user1032531

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:19:37