Information
The APT configuration option Acquire::AllowWeakRepositories controls whether APT accepts repositories signed with cryptographically weak algorithms. Weak signatures include those using MD5 or SHA-1 hashing algorithms, which are no longer considered cryptographically secure. When set to 1, APT treats repositories signed with these deprecated algorithms as trusted. This option should be explicitly set to 0 to enforce strong signature requirements.
MD5 and SHA-1 are cryptographically broken hash algorithms for which practical collision and preimage attacks exist. A repository signed with a weak algorithm cannot be trusted to authenticate the integrity of package metadata. An attacker who can produce a collision could craft malicious repository metadata that passes signature verification, enabling installation of tampered packages. Explicitly setting AllowWeakRepositories "0" ensures APT rejects repositories using deprecated cryptographic algorithms.
Solution
Create or append to a configuration file to explicitly disable weak repository signatures:
# printf '%s\n' "" 'Acquire::AllowWeakRepositories "0";' >> /etc/apt/apt.conf.d/99-no-insecure-repositories
Verify the setting has taken effect:
# apt-config dump | grep AllowWeakRepositories
Note: All configuration files under /etc/apt/apt.conf.d/ are processed in lexicographic order. Where conflicting settings exist, the last one takes precedence.
Impact:
Setting AllowWeakRepositories "0" will cause apt update to fail for any repository signed exclusively with weak algorithms (MD5 or SHA-1). Repositories using these algorithms must be migrated to strong signing keys (RSA-4096 or Ed25519 with SHA-256 or SHA-512) before this setting can be applied without disruption.