Update failed - signatures couldn't be verified

Details:

  • Date | 2026-09-08 06:33:26
  • Program name | DietPi-Update
  • Command | apt-get -y -eany update
  • Exit code | 100
  • DietPi version | v9.9.0 (MichaIng/master)
  • Distro version | bookworm (ID=7,RASPBIAN=0)
  • Kernel version | Linux loxberry 6.6.62+rpt-rpi-2712 #1 SMP PREEMPT Debian 1:6.6.62-1+rpt1 (2024-11-25) aarch64 GNU/Linux
  • Architecture | arm64
  • Hardware model | RPi 5 Model B (aarch64) (ID=5)
  • Power supply | (EG: RAVPower 5V 1A)
  • SD card | (EG: SanDisk Ultra 16 GB)

Steps to reproduce:

  1. …
  2. …

Expected behaviour:

  • …

Actual behaviour:

  • …

Extra details:

  • …

Additional logs:

Ign:1 https://repo.ebusd.eu/apt/default/bookworm bookworm InRelease
Get:2 https://packages.sury.org/php bookworm InRelease [6136 B]
Hit:3 https://deb.debian.org/debian bookworm InRelease
Hit:4 https://deb.debian.org/debian bookworm-updates InRelease
Get:5 https://dl.yarnpkg.com/debian stable InRelease
Hit:6 https://deb.debian.org/debian-security bookworm-security InRelease
Hit:7 https://deb.debian.org/debian bookworm-backports InRelease
Hit:8 https://dietpi.com/apt bookworm InRelease
Err:2 https://packages.sury.org/php bookworm InRelease
  The following signatures were invalid: EXPKEYSIG B188E2B695BD4743 DEB.SURY.ORG Automatic Signing Key <deb@sury.org>
Hit:9 https://dietpi.com/apt all InRelease
Hit:10 https://archive.raspberrypi.com/debian bookworm InRelease
Hit:11 https://pkg.cloudflare.com/cloudflared any InRelease
Err:5 https://dl.yarnpkg.com/debian stable InRelease
  The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 62D54FD4003F6525
Ign:1 https://repo.ebusd.eu/apt/default/bookworm bookworm InRelease
Ign:1 https://repo.ebusd.eu/apt/default/bookworm bookworm InRelease
Err:1 https://repo.ebusd.eu/apt/default/bookworm bookworm InRelease
  Something wicked happened resolving 'repo.ebusd.eu:https' (-5 - No address associated with hostname)
Fetched 22.7 kB in 7s (3207 B/s)
Reading package lists...
W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: https://pack   ages.sury.org/php bookworm InRelease: The following signatures were invalid: EXPKEYSIG B188E2B695BD4743 DEB.SURY.ORG Automatic Signing Key <deb@sury.org   >
W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: https://dl.y   arnpkg.com/debian stable InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 62D54FD4003F6525
E: Failed to fetch https://repo.ebusd.eu/apt/default/bookworm/dists/bookworm/InRelease  Something wicked happened resolving 'repo.ebusd.eu:https' (-5 -    No address associated with hostname)
E: Failed to fetch https://packages.sury.org/php/dists/bookworm/InRelease  The following signatures were invalid: EXPKEYSIG B188E2B695BD4743 DEB.SURY.OR   G Automatic Signing Key <deb@sury.org>
E: Failed to fetch https://dl.yarnpkg.com/debian/dists/stable/InRelease  The following signatures couldn't be verified because the public key is not ava   ilable: NO_PUBKEY 62D54FD4003F6525
E: Some index files failed to download. They have been ignored, or old ones used instead.

You are using a Loxberry system? Might be good to get in touch with these guys.

Anyway you have multiple issues or challanges

These version is nearly 2 years old, from December 2024

Within you source configuration you have a couple of old/incorrect sources defined

We don’t use sury php repository since ages, not sure if this is specific thing of Loxberry

This doesn’t seems to be setup by DietPi. At least I’m not able to find it in our code. Not sure if this is specific thing of Loxberry

same goes for this repository. This even did not exist anymore

Best ist to check with Loxberry guys first if these repositories have been setup intentionally.

Thanks for the fast response. I will talk to the Loxberry devs. If I can’t get the update to work are there any security relevant changes from my version to the newest one or could I still live with my current version if the upgrade issue can’t be solved?

theoretically things could be fixed. But first to check with Loxberry if these repositories have been setup intentionally.

You should definitely solve those issues ASAP, as with such an old package state, your system is at high risk, and possibly a risk for other systems across the Internet, as part of a botnet or similar. APT upgrades should be done at a weekly, better daily basis, especially in times of AI tools being able to find and exploit security vulnerabilities within hours.

If you did not add those 3 APT repositories by yourself, then yes, at best talk to Loxberry whether they were added their end, and how to update the keys, and what to replace repo.ebusd.eu with (which does not exist anymore).

If you did add those repos by yourself, then check back whether your really still need those, and for what:

  • yarn is a Node.js package/dependency manager, which can be installed via npm and alike directly. It is uncommon to install it via APT repository.
  • The PHP repository is reasonable only if you require a specific different PHP version on your Debian version. But using it has some risks, since it ships a bunch of other system libraries, which can cause incompatibilities. Usually I’d recommend to stick with the native Debian PHP packages, upgrade Debian itself if you need a newer PHP version, and stop using software which requires older PHP to run (as this means it is badly maintained, and possibly a security issue by itself).
  • If repo.ebusd.eu was for eBUSd, then that repo was shut down. Remove it and follow current install instructions, which means to download and install the matching DEB package from their releases on GitHub manually: GitHub - john30/ebusd: daemon for communication with eBUS heating systems · GitHub

I didn’t added any of these packages myself I already reached out to the Loxberry developers. Assuming they cannot help what are my best options?

Regarding repo.ebusd.eu: I guess this repo is for the ebusd-plugin in loxberry. The big advantage is it has a GUI where you can check the ebus values directly. But if that’s the issue I guess I have to just delete the repo?

can you link the topic you created at Loxberry? So we can follow.

EDIT:
found it Update von DietPi schlägt fehl - loxforum.com (German speaking forum)

ok did some research using claude.ai

  • Sury PHP
    part of the Loxberry installation script

A potential fix could be

curl -sL https://packages.sury.org/php/apt.gpg | gpg --dearmor | sudo tee /usr/share/keyrings/deb.sury.org-php.gpg >/dev/null
  • Yarn
    part of the Loxberry installation script

A potential fix could be

curl -sL https://dl.yarnpkg.com/debian/pubkey.gpg | gpg --dearmor | sudo tee /usr/share/keyrings/yarnkey.gpg >/dev/null

A potential fix could be

sudo rm /etc/apt/sources.list.d/*ebusd*

For the PHP repo, the better solution which also Loxberry does in the meantime:

cd /tmp
wget 'https://packages.sury.org/debsuryorg-archive-keyring.deb'
dpkg -i debsuryorg-archive-keyring.deb

From that point on, APT upgrades should keep the key up-to-date automatically.

Thank you both!
The log now looks like this:

Get:1 https://packages.sury.org/php bookworm InRelease \[6136 B\]
Ign:2 https://repo.ebusd.eu/apt/default/bookworm bookworm InRelease
Get:3 https://dl.yarnpkg.com/debian stable InRelease
Hit:4 https://deb.debian.org/debian bookworm InRelease
Get:5 https://deb.debian.org/debian bookworm-updates InRelease \[55.4 kB\]
Get:6 https://deb.debian.org/debian-security bookworm-security InRelease \[34.8 kB\]
Get:7 https://deb.debian.org/debian bookworm-backports InRelease \[59.4 kB\]
Get:8 https://packages.sury.org/php bookworm/main arm64 Packages \[289 kB\]
Hit:9 https://dietpi.com/apt bookworm InRelease
Hit:10 https://dietpi.com/apt all InRelease
Get:11 https://pkg.cloudflare.com/cloudflared any InRelease \[5039 B\]
Get:12 https://archive.raspberrypi.com/debian bookworm InRelease \[55.0 kB\]
Get:13 https://deb.debian.org/debian-security bookworm-security/main arm64 Packages \[335 kB\]
Get:14 https://pkg.cloudflare.com/cloudflared any/main arm64 Packages \[375 B\]
Get:15 https://archive.raspberrypi.com/debian bookworm/main arm64 Packages \[581 kB\]
Ign:2 https://repo.ebusd.eu/apt/default/bookworm bookworm InRelease
Ign:2 https://repo.ebusd.eu/apt/default/bookworm bookworm InRelease
Err:2 https://repo.ebusd.eu/apt/default/bookworm bookworm InRelease
Something wicked happened resolving 'repo.ebusd.eu:https' (-5 - No address associated with hostname)
Fetched 1439 kB in 7s (202 kB/s)
Reading package lists...
E: Failed to fetch https://repo.ebusd.eu/apt/default/bookworm/dists/bookworm/InRelease  Something wicked happened resolving 'repo.ebusd.eu:https' (-5 - No address associated with hostname)
E: Some index files failed to download. They have been ignored, or old ones used instead.

If I interpret it correctly only the ebusd-repo is causing a problem. Am I right?
If I delete the repo I guess the plugin won’t work anymore as well will it?
Or is the repo only needed during installation for fetching the files? Because even if it is - unfortunately - not maintained anymore it is still working great on my end.

One question for my understanding: I have a ssd with two partitions. If I use dietpi-backup it will backup all files on both partitions and all the loxberry files etc. as well?

correct

Yes, exactly. Simply removing the repository won’t affect functionality. Keep in mind, however, that you won’t receive any further updates (it doesn’t work anymore anyway). This could lead to incompatibilities or security risks in the future. Maybe you should consider some alternatives :wink:

For now, best to remove the source file configuration

sudo rm /etc/apt/sources.list.d/*ebusd*

correct, the entire system should be backed up. There is one exception: the file systems /mnt/ and /media/ are not backed up, although /mnt/dietpi_userdata/ is included after all. I know it sounds complicated, or :slight_smile:

Thank you so much guys.

The update finished successfully and ebusd is still kinda working. But if I rerun dietpi-update I get an error:

APT update
│  - Command: apt-get -y -eany update
│  - Exit code: 100
│  - DietPi version: v10.6.2 (MichaIng/master) | HW_MODEL: 5 | HW_ARCH: 3 |
│ DISTRO: 7
│  - Error log:
│ Hit:1 https://deb.debian.org/debian bookworm InRelease
│ Hit:2 https://deb.debian.org/debian bookworm-updates InRelease
│ Hit:3 https://deb.debian.org/debian-security bookworm-security InRelease
│ Hit:4 https://deb.debian.org/debian bookworm-backports InRelease
│ Hit:5 https://packages.sury.org/php bookworm InRelease
│ Hit:6 https://dietpi.com/apt bookworm InRelease
│ Hit:7 https://dietpi.com/apt all InRelease
│ Hit:8 https://pkg.cloudflare.com/cloudflared any InRelease
│ Hit:9 https://dl.yarnpkg.com/debian stable InRelease

and the shell:
DietPi-Update
─────────────────────────────────────────────────────
Phase: Checking for available DietPi update

\[  OK  \] DietPi-Update | Checking IPv4 network connectivity
\[  OK  \] DietPi-Update | Checking IPv6 network connectivity
\[  OK  \] DietPi-Update | Checking DNS resolver
\[ INFO \] DietPi-Update | Getting latest version from: https://raw.githubusercont                                      ent.com/MichaIng/DietPi/master/.update/version
\[  OK  \] DietPi-Update | Got valid latest version: 10.6.2
\[  OK  \] DietPi-Update | No update required, your DietPi installation is already                                       up to date:
\[ INFO \] DietPi-Update | Current version : v10.6.2
\[ INFO \] DietPi-Update | Latest version  : v10.6.2
\[ INFO \] DietPi-Update | Checking for new available live patches
\[ INFO \] DietPi-Update | APT update, please wait...
Hit:1 https://deb.debian.org/debian bookworm InRelease
Hit:2 https://deb.debian.org/debian bookworm-updates InRelease
Hit:3 https://deb.debian.org/debian-security bookworm-security InRelease
Hit:4 https://deb.debian.org/debian bookworm-backports InRelease
Hit:5 https://packages.sury.org/php bookworm InRelease
Hit:6 https://dietpi.com/apt bookworm InRelease
Hit:7 https://dietpi.com/apt all InRelease
Hit:8 https://pkg.cloudflare.com/cloudflared any InRelease
Hit:9 https://dl.yarnpkg.com/debian stable InRelease
Hit:10 https://archive.raspberrypi.com/debian bookworm InRelease
Err:5 https://packages.sury.org/php bookworm InRelease
The following signatures couldn't be verified because the public key is not av                                      ailable: NO_PUBKEY B188E2B695BD4743
Reading package lists...
W: An error occurred during the signature verification. The repository is not up                                      dated and the previous index files will be used. GPG error: https://packages.sur                                      y.org/php bookworm InRelease: The following signatures couldn't be verified beca                                      use the public key is not available: NO_PUBKEY B188E2B695BD4743
E: Failed to fetch https://packages.sury.org/php/dists/bookworm/InRelease  The f                                      ollowing signatures couldn't be verified because the public key is not available                                      : NO_PUBKEY B188E2B695BD4743
E: Some index files failed to download. They have been ignored, or old ones used                                       instead.
\[FAILED\] DietPi-Update | APT update

* Command: apt-get -y -eany update
  \[FAILED\] DietPi-Update | Unable to continue, DietPi-Update will now terminate.

For sury I did this:
cd /tmp
wget '``https://packages.sury.org/debsuryorg-archive-keyring.deb``'
dpkg -i debsuryorg-archive-keyring.deb

Check the respective list file in /etc/apt/sources.list.d/. There should be a “signed-by” value, like [signed-by=/usr/share/keyrings/deb.sury.org-php.gpg] or similar, but the path seems wrong. Change the path to /usr/share/keyrings/debsuryorg-archive-keyring.gpg.

I’ve adapted the php.list. It looks like this now:

image

That was the old one:

image

Unfortunately I still get an error:

Hit:1 https://deb.debian.org/debian bookworm InRelease
Get:2 https://deb.debian.org/debian bookworm-updates InRelease \[55.4 kB\]
Hit:3 https://deb.debian.org/debian-security bookworm-security InRelease
Get:4 https://deb.debian.org/debian bookworm-backports InRelease \[59.4 kB\]
Hit:5 https://packages.sury.org/php bookworm InRelease
Hit:6 https://dl.yarnpkg.com/debian stable InRelease
Hit:7 https://pkg.cloudflare.com/cloudflared any InRelease
Hit:8 https://dietpi.com/apt bookworm InRelease
Hit:9 https://dietpi.com/apt all InRelease
Err:5 https://packages.sury.org/php bookworm InRelease
The following signatures couldn't be verified because the public key is not available: NO_PUBKEY B188E2B695BD4743
Get:10 https://archive.raspberrypi.com/debian bookworm InRelease \[55.0 kB\]
Fetched 170 kB in 1s (163 kB/s)
Reading package lists...
W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: https://packages.sury.org/php bookworm InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY B188E2B695BD4743
E: Failed to fetch https://packages.sury.org/php/dists/bookworm/InRelease  The following signatures couldn't be verified because the public key is not available: NO_PUBKEY B188E2B695BD4743
E: Some index files failed to download. They have been ignored, or old ones used instead.

ok let’s see how it looks on your system

ls -la /etc/apt/sources.list.d/ | grep -i php
ls -la /usr/share/keyrings/ | grep -i sury
grep -ri sury /etc/apt/sources.list /etc/apt/sources.list.d/*.list 2>/dev/null
sudo apt-key list 2>/dev/null | grep -i -B2 sury

pls try to copy paste from your ssh shell to avoid screen prints.

Here’s the result:

root@loxberry:/opt/loxberry# ls -la /etc/apt/sources.list.d/ | grep -i php
-rw-r--r-- 1 root root  112 Sep 11 07:18 php.list
root@loxberry:/opt/loxberry# ls -la /usr/share/keyrings/ | grep -i sury
root@loxberry:/opt/loxberry# grep -ri sury /etc/apt/sources.list /etc/apt/sources.list.d/\*.list 2>/dev/null
/etc/apt/sources.list.d/php.list:deb \[signed-by=/usr/share/keyrings/debsuryorg-archive-keyring.gpg\] https://packages.sury.org/php/ bookworm main
root@loxberry:/opt/loxberry# apt-key list 2>/dev/null | grep -i -B2 sury
root@loxberry:/opt/loxberry#

The error is now:

Hit:1 https://packages.sury.org/php bookworm InRelease
Hit:2 https://deb.debian.org/debian bookworm InRelease
Get:3 https://deb.debian.org/debian bookworm-updates InRelease \[55.4 kB\]
Hit:4 https://deb.debian.org/debian-security bookworm-security InRelease
Get:5 https://deb.debian.org/debian bookworm-backports InRelease \[59.4 kB\]
Err:1 https://packages.sury.org/php bookworm InRelease
The following signatures couldn't be verified because the public key is not available: NO_PUBKEY B188E2B695BD4743
Hit:6 https://dietpi.com/apt bookworm InRelease
Hit:7 https://dietpi.com/apt all InRelease
Hit:8 https://pkg.cloudflare.com/cloudflared any InRelease
Hit:9 https://dl.yarnpkg.com/debian stable InRelease
Get:10 https://archive.raspberrypi.com/debian bookworm InRelease \[55.0 kB\]
Get:11 https://archive.raspberrypi.com/debian bookworm/main arm64 Packages \[581 kB\]
Fetched 751 kB in 2s (398 kB/s)
Reading package lists...
W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: https://packages.sury.org/php bookworm InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY B188E2B695BD4743
E: Failed to fetch https://packages.sury.org/php/dists/bookworm/InRelease  The following signatures couldn't be verified because the public key is not available: NO_PUBKEY B188E2B695BD4743
E: Some index files failed to download. They have been ignored, or old ones used instead.

Please repeat this:

cd /tmp
wget 'https://packages.sury.org/debsuryorg-archive-keyring.deb'
sudo dpkg -i debsuryorg-archive-keyring.deb

And check whether it throws errors. If that package is installed successfully, the file /usr/share/keyrings/debsuryorg-archive-keyring.gpg should exist.

Here’s the result:

root@loxberry:/opt/loxberry# cd /tmp
root@loxberry:/tmp# wget 'https://packages.sury.org/debsuryorg-archive-keyring.d                                                                 eb'
--2026-09-11 14:41:00--  https://packages.sury.org/debsuryorg-archive-keyring.de                                                                 b
Resolving packages.sury.org (packages.sury.org)... 2a04:4e42:8e::820, 140.248.14                                                                 3.52
Connecting to packages.sury.org (packages.sury.org)|2a04:4e42:8e::820|:443... co                                                                 nnected.
HTTP request sent, awaiting response... 200 OK
Length: 7180 (7.0K) \[application/octet-stream\]
Saving to: ‘debsuryorg-archive-keyring.deb’

debsuryorg-archive- 100%\[===================>\]   7.01K  --.-KB/s    in 0s

2026-09-11 14:41:00 (97.6 MB/s) - ‘debsuryorg-archive-keyring.deb’ saved \[7180/7                                                                 180\]

root@loxberry:/tmp# dpkg -i debsuryorg-archive-keyring.deb
Selecting previously unselected package debsuryorg-archive-keyring.
(Reading database ... 88422 files and directories currently installed.)
Preparing to unpack debsuryorg-archive-keyring.deb ...
Unpacking debsuryorg-archive-keyring (2025.11.18) ...
Setting up debsuryorg-archive-keyring (2025.11.18) ...
root@loxberry:/tmp#

It actually seems to work now:

DietPi-Update
─────────────────────────────────────────────────────
Phase: Checking for available DietPi update

\[  OK  \] DietPi-Update | Checking IPv4 network connectivity
\[  OK  \] DietPi-Update | Checking IPv6 network connectivity
\[  OK  \] DietPi-Update | Checking DNS resolver
\[ INFO \] DietPi-Update | Getting latest version from: https://raw.githubusercontent.com/MichaIng/DietPi/master/.update/version
\[  OK  \] DietPi-Update | Got valid latest version: 10.6.2
\[  OK  \] DietPi-Update | No update required, your DietPi installation is already up to date:
\[ INFO \] DietPi-Update | Current version : v10.6.2
\[ INFO \] DietPi-Update | Latest version  : v10.6.2
\[ INFO \] DietPi-Update | Checking for new available live patches
\[ INFO \] DietPi-Update | APT update, please wait...
Hit:1 https://deb.debian.org/debian bookworm InRelease
Hit:2 https://deb.debian.org/debian bookworm-updates InRelease
Hit:3 https://deb.debian.org/debian-security bookworm-security InRelease
Hit:4 https://packages.sury.org/php bookworm InRelease
Hit:5 https://deb.debian.org/debian bookworm-backports InRelease
Hit:6 https://dl.yarnpkg.com/debian stable InRelease
Hit:7 https://dietpi.com/apt bookworm InRelease
Hit:8 https://dietpi.com/apt all InRelease
Hit:9 https://pkg.cloudflare.com/cloudflared any InRelease
Get:10 https://archive.raspberrypi.com/debian bookworm InRelease \[55.0 kB\]
Get:11 https://archive.raspberrypi.com/debian bookworm/main arm64 Packages \[581 kB\]
Fetched 636 kB in 2s (338 kB/s)
Reading package lists...
\[  OK  \] DietPi-Update | APT update
\[ INFO \] DietPi-Update | Storing number of available APT upgrades to file: /run/dietpi/.apt_updates
root@loxberry:/tmp#

How can I configure the update application to do the APT upgrade daily but not bigger dietpi upgrades?

Great!

This will do via daily cron job:

G_CONFIG_INJECT 'CONFIG_CHECK_APT_UPDATES=' 'CONFIG_CHECK_APT_UPDATES=2' /boot/dietpi.txt

Logs of the last package upgrade call can be found in /var/lib/dietpi/logs/dietpi-upgrade_apt.log.