RYZHOV / Linux
Troubleshooting · APT

Fix conflicting Signed-By values in APT

APT stops before downloading an index when overlapping repository definitions disagree about Signed-By. Find the duplicate, decide which definition to keep, and preserve signature verification.

Tested scope

The source conflict and three parser repairs below were reproduced with APT 2.6.1 in an isolated Debian 12 amd64 container on 19 September 2026. The lab tested source parsing offline. It did not authenticate a live repository, install packages, or change the host's APT configuration. Other releases may phrase errors differently.

1. Recognize the conflict

In the lab, a legacy .list file and a newer .sources file both declared the same repository and suite, using different keyring paths. The parser reported:

E: Conflicting values set for option Signed-By regarding source
https://packages.example.invalid/debian/ bookworm:
/etc/apt/keyrings/example.gpg != /etc/apt/keyrings/example-old.gpg

This is a configuration conflict. It is different from an unknown signing key, an expired signature, or an unreachable server. Importing another key does not remove the overlapping declarations. In our test, the conflict occurred without fetching anything from the network.

packages.example.invalid is a deliberately non-working example address. Use the repository URL and suite from your own error when diagnosing your machine.

2. Locate overlapping entries

Record your environment, then inspect source definitions. The following commands read configuration; the final command searches both supported filename extensions:

cat /etc/os-release
apt-get --version
dpkg --print-architecture

sudo grep -nH -E '^[[:space:]]*deb(-src)?[[:space:]]' \
  /etc/apt/sources.list
sudo grep -nH -E '^[[:space:]]*(deb(-src)?[[:space:]]|Types:|URIs:|Suites:|Components:|Architectures:|Signed-By:|Enabled:)' \
  /etc/apt/sources.list.d/*.list /etc/apt/sources.list.d/*.sources

A missing sources.list or unmatched glob can produce “No such file” messages. That does not invalidate matches from files that exist. Read each matching file in full, including stanza boundaries and continuation lines. An embedded signing key spans multiple lines. Avoid sharing private repository URLs or credentials in diagnostic output.

Compare the URI and suite first, then the key settings. In this lab, these two definitions overlap:

Old file: example-old.list
deb [signed-by=/etc/apt/keyrings/example-old.gpg] https://packages.example.invalid/debian bookworm main
New file: example.sources
Types: deb
URIs: https://packages.example.invalid/debian
Suites: bookworm
Components: main
Signed-By: /etc/apt/keyrings/example.gpg

Do not assume the newest filename is correct. Compare with the publisher's current installation instructions and your intended distribution. Check whether configuration management or a vendor package owns a file before editing it; otherwise a later run may recreate the conflict.

3. Keep one intended configuration

Back up the source configuration before editing. Run these together in the same shell and note the printed backup directory:

apt_backup=$(sudo mktemp -d /root/apt-sources-backup.XXXXXX) &&
sudo cp -a /etc/apt/sources.list.d "$apt_backup/" &&
if [ -f /etc/apt/sources.list ]; then
  sudo cp -a /etc/apt/sources.list "$apt_backup/"
fi &&
printf 'Source backup: %s\n' "$apt_backup"

If the old one-line entry is redundant, edit its actual file with sudoedit and comment out that specific line with #. Leave unrelated repositories in the same file alone.

If a Deb822 stanza is redundant, add Enabled: no inside that stanza, without a blank line before it. A blank line begins another stanza. Disable only the duplicate stanza, not every source in the file.

If both entries are intentional—for example, separate binary and source-package entries—make their signing policy consistent. In the lab, giving both the same keyring path removed the conflict, but duplicate binary entries still produced warnings. Consolidating redundant entries gives a clearer result.

Keep the expected repository-specific key restriction. Do not use trusted=yes, disable authentication, or delete all source files to silence this error. A key file also needs to be readable by APT's restricted download user; use the publisher's key installation instructions and verify its fingerprint through a trusted source.

4. Verify the result

First, ask APT to parse the source configuration without refreshing the repository:

apt-get indextargets >/dev/null

In the isolated test, the conflicted configuration failed and each corrected configuration parsed successfully. A successful parse only resolves this layer of the problem; it does not prove the key, network, or repository contents are valid.

Next refresh indexes normally. This command contacts configured repositories and updates local package lists; it does not upgrade installed packages:

sudo apt-get update

Read the output as well as the exit status. Confirm that the intended repository updated, there are no authentication failures, and duplicate-target warnings are gone. Investigate a new NO_PUBKEY, TLS, or suite error on its own terms. Then use apt-cache policy PACKAGE_NAME, replacing the placeholder, to check the candidate version and origin before installing.

To undo your edit, restore only the changed source file from the recorded backup and inspect it again. A rollback restores the old configuration, including any conflict it contained.

5. Reproduce it safely

The test used a disposable container with networking disabled, no host mounts, a read-only root filesystem, and a writable temporary directory. Temporary Dir::Etc::sourcelist, Dir::Etc::sourceparts, Dir::State, and cache options directed APT to the fixture files.

  • Two keyring paths for the same URI and suite: parsing failed.
  • Comment out the redundant one-line entry: parsing passed.
  • Re-enable it and disable the duplicate Deb822 stanza: parsing passed.
  • Align the keyring paths but retain identical targets: parsing passed with duplicate-target warnings.

The source and reproducible test are maintained with this site's infrastructure. These results establish the configuration behavior of the tested APT version; signature validation remains a separate check.

Primary references