-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Labels
Description
Currently debian 9 does not like the generated InRelease file.
W: GPG error: https://x InRelease: The following signatures were invalid: x
Comment found on (https://unix.stackexchange.com/questions/387053/)
The cause of the problem is that with no update to the Debian wiki or other similar doco, and pretty much only a couple of largely Ubuntu-related announcements on a non-Debian personal WWW site, support for keys that state a preference for SHA-1 encryption has been turned off in APT as of Debian 9. (Specifically, it was turned off in APT version 1.4~beta1, and Debian 9 has version 1.4.7.)
The following works:
apt-ftparchive --md5 --sha256 release . > Release
gpg --digest-algo SHA256 --armor --output Release.gpg --detach-sign Release
gpg --digest-algo SHA256 --clearsign --output InRelease Release
Reactions are currently unavailable