Need to see if your shared folder is taking up space on your dropbox 👨💻? Find out how to check here.
Forum Discussion
Verwijs
6 months agoHelpful | Level 6
OpenPGP signature verification failed with Debian Trixie.
Warning: OpenPGP signature verification failed: http://linux.dropbox.com/debian trixie Release: The following signatures were invalid: BADSIG FC918B335044912E Dropbox Automatic Signing Key <linux@dropbox.com>
Error: The package repository 'http://linux.dropbox.com/debian trixie Release' is not signed.
please add new key to: https://linux.dropboxstatic.com/debian/dists/trixie/
22 Replies
- maurom3 months agoNew member | Level 2
I fully agree with the previous posters. While it is technically possible to relax the cryptographic policies of our platforms to keep using the Dropbox repository with its deprecated SHA-1 signature, Debian and other modern distributions are flagging said signatures as insecure for good reasons. This is quickly becoming a blocking problem for those who want to keep Dropbox integrated without compromising our system security.
Having said that, we appreciate that this issue has been escalated internally, and we'd be very grateful if it could be prioritized so the repository is re-signed with a stronger algorithm, ensuring continued compatibility and security across all supported platforms.
Thanks in advance.
- Orange F.3 months agoNew member | Level 2
I am having the same issue, and I find the use of the SHA1 signatures very concerning in terms of trusting the security commitments of Dropbox. As a loyal customer who has been paying for Dropbox for twenty years or so, I hope this issue is given priority as a security concern.
- Hannah4 months ago
Dropbox Community Moderator
I understand where you're coming from, daves415 and you as well slimy_asparagus. I did pass your feedback along to our team, so your comments are very appreciated.
Let us know if you need anything else.
- slimy_asparagus4 months agoHelpful | Level 5
I am having the same issues. I would rather stop using the dropbox app than stop using Debian.
- daves4154 months agoHelpful | Level 5
"I'm afraid that if the minimum system requirements are not met, issues like this are kind of expected."
That is a disjoint reply. Are you saying that accepting obsolete SHA1 signatures is a "minimum system requirement"?
- Hannah4 months ago
Dropbox Community Moderator
Thanks for your update here, steinarb.
I'm afraid that if the minimum system requirements are not met, issues like this are kind of expected.
I did, however, pass your comments and feedback along to our team about this.
Let us know if you have any other questions.
- steinarb4 months agoNew member | Level 2
I don't have neither Ubuntu, nor Fedora (as listed in the requirements) and no intentions of switching to either.
I do have debian, on which Ubuntu is based, and I do have a much newer debian than what Ubuntu 18 is based on (debian 13 "trixie", the current debian stable, which was released on August 9 2025).
The Dropbox debian package for Ubuntu has worked well for me on debian stable, since at least 2016, and still works.
But I am currently getting daily nags from debian APT because the APT archive of the debian package is signed which SHA1, which is not considered secure anymore, and because of this debian APT (and possibly later Ubuntu APT as well...?) will start rejecting the archive in less than one year.
So what you should do(and that you should do in any case...) is to upgrade the key used for signing your APT archive.
I.e. no changes to the code, just a change to the archive (including resigning of the packages, I guess...?). - Nancy4 months ago
Dropbox Community Moderator
Hey steinarb, as a first, can you make sure that your device is following all the supported requirements mentioned here? Feel free to also check out this Help Center article.
We'll go from there.
- steinarb4 months agoNew member | Level 2
I get this message once a day after upgrading to debian 13 "trixie" on August 12 2025.
W: http://linux.dropbox.com/debian/dists/sid/Release.gpg: Policy will reject signature within a year, see --audit for detailsThe relevant output from "apt update --policy", is:
Warning: http://linux.dropbox.com/debian/dists/sid/Release.gpg: Policy will reject signature within a year, see --audit for details Audit: http://linux.dropbox.com/debian/dists/sid/Release.gpg: Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on 1C61A2656FB57B7E4DE0F4C1FC918B335044912E is not bound: No binding signature at time 2020-03-04T23:26:35Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00ZLooks like you're signing with SHA1 and that will be forbidden by debian APT policy in a year from now.
- Megan6 months ago
Dropbox Community Moderator
Hey maurom, thank you so much for the heads up!
Your info here will be valuable, and helpful for other users facing the same thing, and hopefully will also resolve Verwijs issue too.
In any case, I'll be one post away!
About Apps and Installations
Have a question about a Dropbox app or installation? Reach out to the Dropbox Community and get solutions, help, and advice from members.
The Dropbox Community team is active from Monday to Friday. We try to respond to you as soon as we can, usually within 2 hours.
If you need more help you can view your support options (expected response time for an email or ticket is 24 hours), or contact us on X, Facebook or Instagram.
For more info on available support options for your Dropbox plan, see this article.
If you found the answer to your question in this Community thread, please 'like' the post to say thanks and to let us know it was useful!