尝试更新Ubuntu到23.10时遭遇PPA证书验证错误求助
尝试更新Ubuntu到23.10时遭遇PPA证书验证错误求助
先把你遇到的错误日志贴出来,方便大家定位问题:
Hit:1 http://archive.ubuntu.com/ubuntu lunar InRelease Ign:2 https://ppa.launchpad.net/gnome3-team/gnome3-staging/ubuntu lunar InRelease Hit:3 http://archive.ubuntu.com/ubuntu lunar-updates InRelease Hit:4 http://archive.ubuntu.com/ubuntu lunar-backports InRelease Hit:5 https://ppa.launchpadcontent.net/kisak/turtle/ubuntu lunar InRelease Hit:6 http://archive.ubuntu.com/ubuntu lunar-security InRelease Ign:2 https://ppa.launchpad.net/gnome3-team/gnome3-staging/ubuntu lunar InRelease Ign:2 https://ppa.launchpad.net/gnome3-team/gnome3-staging/ubuntu lunar InRelease Err:2 https://ppa.launchpad.net/gnome3-team/gnome3-staging/ubuntu lunar InRelease Certificate verification failed: The certificate is NOT trusted. The name in the certificate does not match the expected. Could not handshake: Error in the certificate verification. [IP: some ip lol] Reading package lists... Done Building dependency tree... Done Reading state information... Done All packages are up to date. W: Failed to fetch https://ppa.launchpad.net/gnome3-team/gnome3-staging/ubuntu/dists/lunar/InRelease Certificate verification failed: The certificate is NOT trusted. The name in the certificate does not match the expected. Could not handshake: Error in the certificate verification. [IP: some ip lol] W: Some index files failed to download. They have been ignored, or old ones used instead.
看你折腾了好几天都没搞定,这种证书名称不匹配的问题,大概率是这个PPA的GPG密钥没正确导入,或者本地系统的证书存储出了异常。给你几个实用的解决步骤,你可以挨个试试:
先移除有问题的PPA,保证基础更新正常
先把这个出问题的gnome3-staging PPA暂时移除,避免它拖整个更新流程的后腿:sudo add-apt-repository --remove ppa:gnome3-team/gnome3-staging之后运行
sudo apt update,看看是不是能正常完成系统更新了。如果还需要这个PPA,重新添加并导入密钥
要是你确实需要这个PPA里的软件包,移除之后重新添加一次,系统会自动帮你导入对应的GPG密钥:sudo add-apt-repository ppa:gnome3-team/gnome3-staging添加完成后再运行
sudo apt update,应该就能正常获取源数据了。检查系统时间是否正确
证书验证对系统时间要求很高,如果你的系统时间和实际时间偏差太大,会被判定证书无效。你可以打开系统设置里的「日期和时间」,确保开启了自动同步;或者用终端命令强制开启网络时间同步:sudo timedatectl set-ntp true同步完成后重启系统,再试一次更新。
重置本地证书存储
要是本地的证书缓存出了问题,也会导致验证失败,你可以重新安装证书包并更新缓存:sudo apt install --reinstall ca-certificates sudo update-ca-certificates完成后再运行
sudo apt update试试。应急方案(不推荐长期使用)
如果以上方法都不管用,你可以临时把这个PPA的HTTPS改成HTTP(注意这样安全性会降低,只是临时应急):
编辑PPA的源文件:sudo nano /etc/apt/sources.list.d/gnome3-team-ubuntu-gnome3-staging-lunar.list把里面的
https://改成http://,按Ctrl+O保存,Ctrl+X退出,之后再运行sudo apt update。
备注:内容来源于stack exchange,提问作者zyzz
相关产品推荐
相关产品推荐

