如何阻止GPG包含SHA1?解决APT签名验证失败问题
I've run into this exact confusing issue before—especially when working with CentOS-signed Debian package repositories on Debian 9. You verify the InRelease file with GPG and confirm it's properly signed, yet apt-get keeps throwing errors about invalid signatures or unsigned files.
What's Causing This?
Debian 9 enforces stricter rules around GPG digest algorithm preferences. If your GPG config still includes SHA-1 in its preferred digests, apt will reject signatures that rely on older algorithms (even though GPG itself can validate them), leading to the false error messages.
Step-by-Step Fix
Open your user's GPG configuration file with your favorite editor:
nano $HOME/.gnupg/gpg.conf(Feel free to swap
nanoforvimor any editor you prefer.)Locate the
personal-digest-preferencesline. If it doesn't exist, add it manually. Remove SHA-1 entirely from this line, leaving only modern, secure algorithms like:personal-digest-preferences SHA256 SHA384 SHA512Save the file and exit the editor. Now run your
aptcommand again—for example:apt-get updateThe signature errors should be gone.
Quick Notes
- If you're operating as the root user, you'll need to edit
/root/.gnupg/gpg.confinstead of the user-specific config in$HOME. - The mismatch between GPG's validation and
apt's error happens because GPG is more flexible about algorithm support, while Debian 9'saptprioritizes security by blocking outdated algorithms like SHA-1 when they're in your GPG preferences.
内容的提问来源于stack exchange,提问作者user1032531

