[Bug 1562733] Re: apt signature requierements prevent updates from some repositories

Sebastien Bacher seb128 at ubuntu.com
Fri May 6 14:42:30 UTC 2016

seemslike that's creating issues with gnome-software, the /var/lib/app-info/yaml/ symlinks are not refreshed when one of the repository has an error which leads to gnome-software to be empty...
we just debugged that with dholbach yesterday which got bitten by it, he had the spotify repo enabled and changed his mirror from "de" to "us", the appstream symlinks were still pointed to ".de" filenames which were not existant

** Tags added: rls-x-incoming

You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to apt in Ubuntu.

  apt signature requierements prevent updates from some repositories

Status in apt package in Ubuntu:
  In Progress

Bug description:
  Since xenial updated the requirements for the strength of PGP
  signatures of packages, packages from some repositories are no longer
  updated. Apt-get update reports these errors:

  E: Failed to fetch http://[...]/Release  No Hash entry in Release file /var/lib/apt/lists/partial/[...] which is considered strong enough for security purposes
  E: Some index files failed to download. They have been ignored, or old ones used instead.

  While the motivation for the change is valid, the result is a
  potential security problem, as the new versions of the packages that
  may fix recently discovered vulnerabilities are not automatically

  One less important but unfortunate effect is a scary message that is
  displayed to the user, without clear explanation that the problem
  needs to be addressed by the repository owner.

  Related: Bug #1558331

To manage notifications about this bug go to:

More information about the foundations-bugs mailing list