mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-02-05 00:29:55 +03:00
NginxProxyManager - fail APT broken package openresty #2425
Open
opened 2026-02-05 04:47:40 +03:00 by OVERLORD
·
19 comments
No Branch/Tag Specified
main
github-action-update-changelog
pr-update-app-files
docker_deb13
feat/cloudinit-sshkeys
feat/sqlserver2025
automated/update-github-versions
add-script-opencloud-1770212555
add-script-openclaw-1770212634
github-action-archive-changelog
update_apps_tool
add-script-wishlist-1770193085
MickLesk-patch-2
add-script-writefreely-1770188758
add-script-wealthfolio-1770143943
fix/vaultwarden-update-script
remove_memos
disable_npm
feature/codeberg-functions-forgejo-readeck
add-script-rustypaste-1770019426
add-script-kitchenowl-1770017260
fix/2fauth-php-version
tools_func_addcodeberg
CrazyWolf13-patch-2
add-script-shelfmark-1769790178
CrazyWolf13-patch-1
add-script-ampache-1769790139
add-script-languagetool-1769790155
remove_php_deps
ref_koilection
fix/php-module-improvements
tremor021-patch-1
fix/open-archiver-meilisearch-migration
cloudflare_dns
MickLesk-patch-1
michelroegl-brunner-patch-2
fix/version-display
fix/debian13-root-ownership
feat/interactive_prompts
feature/smart-error-recovery
core_stable
update_docs
refactor/tools-func-stability
certbot_npm
2026-02-03
2026-02-02
2026-02-01
2026-01-31
2026-01-30
2026-01-29
2026-01-28
2026-01-27
2026-01-26
2026-01-25
2026-01-24
2026-01-23
2026-01-22
2026-01-21
2026-01-20
2026-01-19
2026-01-18
2026-01-17
2026-01-16
2026-01-15
2026-01-14
2026-01-13
2026-01-12
2026-01-11
2026-01-10
2026-01-09
2026-01-08
2026-01-07
2026-01-06
2026-01-05
2026-01-04
2026-01-03
2026-01-02
2026-01-01
2025-12-31
2025-12-30
2025-12-29
2025-12-28
2025-12-27
2025-12-26
2025-12-25
2025-12-24
2025-12-23
2025-12-22
2025-12-21
2025-12-20
2025-12-19
2025-12-18
2025-12-17
2025-12-16
2025-12-15
2025-12-14
2025-12-13
2025-12-12
2025-12-11
2025-12-10
2025-12-09
2025-12-08
2025-12-07
2025-12-06
2025-12-05
2025-12-04
2025-12-03
2025-12-02
2025-12-01
2025-11-30
2025-11-29
2025-11-28
2025-11-27
2025-11-26
2025-11-25
2025-11-24
2025-11-23
2025-11-22
2025-11-21
2025-11-20
2025-11-19
2025-11-18
2025-11-17
2025-11-16
2025-11-15
2025-11-14
2025-11-13
2025-11-12
2025-11-11
2025-11-10
2025-11-09
2025-11-08
2025-11-07
2025-11-06
2025-11-05
2025-11-04
2025-11-03
2025-11-02
2025-11-01
2025-10-31
2025-10-30
2025-10-29
2025-10-28
2025-10-27
2025-10-26
2025-10-25
2025-10-24
2025-10-23
2025-10-22
2025-10-21
2025-10-20
2025-10-19
2025-10-18
2025-10-17
2025-10-16
2025-10-15
2025-10-14
2025-10-13
2025-10-12
2025-10-11
2025-10-10
2025-10-09
2025-10-08
2025-10-07
2025-10-06
2025-10-05
2025-10-04
2025-10-03
2025-10-02
2025-10-01
2025-09-30
2025-09-29
2025-09-28
2025-09-27
2025-09-26
2025-09-25
2025-09-24
2025-09-23
2025-09-22
2025-09-21
2025-09-20
2025-09-19
2025-09-18
2025-09-17
2025-09-16
2025-09-15
2025-09-14
2025-09-13
2025-09-12
2025-09-11
2025-09-10
2025-09-09
2025-09-08
2025-09-07
2025-09-06
2025-09-05
2025-09-04
2025-09-03
2025-09-02
2025-09-01
2025-08-31
2025-08-30
2025-08-29
2025-08-28
2025-08-27
2025-08-26
2025-08-25
2025-08-24
2025-08-23
2025-08-22
2025-08-21
2025-08-20
2025-08-19
2025-08-18
2025-08-17
2025-08-16
2025-08-15
2025-08-14
2025-08-13
2025-08-12
2025-08-11
2025-08-10
2025-08-09
2025-08-08
2025-08-07
2025-08-06
2025-08-05
2025-08-04
2025-08-03
2025-08-02
2025-08-01
2025-07-31
2025-07-30
2025-07-29
2025-07-28
2025-07-27
2025-07-26
2025-07-25
2025-07-24
2025-07-23
2025-07-22
2025-07-21
2025-07-20
2025-07-19
2025-07-18
2025-07-17
2025-07-16
2025-07-15
2025-07-14
2025-07-11
2025-07-10
2025-07-09
2025-07-08
2025-07-07
2025-07-06
2025-07-05
2025-07-04
2025-07-03
2025-07-02
2025-07-01
2025-06-30
2025-06-29
2025-06-28
2025-06-27
2025-06-26
2025-06-25
2025-06-24
2025-06-23
2025-06-22
2025-06-21
2025-06-20
2025-06-19
2025-06-18
2025-06-17
2025-06-16
2025-06-15
2025-06-14
2025-06-13
2025-06-12
2025-06-11
2025-06-10
2025-06-09
2025-06-08
2025-06-07
2025-06-06
2025-06-05
2025-06-04
2025-06-03
2025-06-02
2025-06-01
2025-05-31
2025-05-30
2025-05-29
2025-05-28
2025-05-27
2025-05-26
2025-05-25
2025-05-24
2025-05-23
2025-05-22
2025-05-21
2025-05-20
2025-05-19
2025-05-18
2025-05-17
2025-05-16
2025-05-15
2025-05-14
2025-05-13
2025-05-12
2025-05-11
2025-05-10
2025-05-09
2025-05-08
2025-05-07
2025-05-06
2025-05-05
2025-05-04
2025-05-03
2025-05-02
2025-05-01
2025-04-30
2025-04-29
2025-04-28
2025-04-27
2025-04-26
2025-04-25
2025-04-24
2025-04-23
2025-04-22
2025-04-20
2025-04-21
2025-04-19
2025-04-18
2025-04-17
2025-04-15
2025-04-16
2025-04-14
2025-04-13
2025-04-12
2025-04-11
2025-04-10
2025-04-09
2025-04-08
2025-04-07
2025-04-06
2025-04-05
2025-04-04
2025-04-03
2025-04-02
2025-04-01
2025-03-31
2025-03-30
2025-03-29
2025-03-28
2025-03-27
2025-03-26
2025-03-25
2025-03-24
2025-03-23
2025-03-22
2025-03-21
2025-03-20
2025-03-19
2025-03-18
2025-03-17
2025-03-16
2025-03-15
2025-03-14
2025-03-13
2025-03-12
2025-03-11
2025-03-10
2025-03-09
2025-03-08
2025-03-07
2025-03-06
2025-03-05
2025-03-04
2025-03-03
2025-03-02
2025-03-01
2025-02-28
2025-02-27
2025-02-26
2025-02-25
2025-02-24
2025-02-23
2025-02-21
2025-02-20
2025-02-19
2025-02-18
2025-02-17
2025-02-16
2025-02-15
2025-02-14
2025-02-13
2025-02-12
2025-02-11
2025-02-10
2025-02-09
2025-02-08
2025-02-07
2025-02-06
2025-02-05
2025-02-04
2025-02-03
2025-02-02
2025-02-01
2025-01-31
2025-01-30
2025-01-29
2025-01-28
2025-01-27
2025-01-26
2025-01-24
2025-01-23
2025-01-22
2025-01-21
2025-01-20
2025-01-19
2025-01-18
2025-01-17
2025-01-16
2025-01-15
2025-01-14
2025-01-13
2025-01-11
2025-01-10
2025-01-09
2025-01-08
2025-01-07
2025-01-06
2025-01-05
2025-01-04
2025-01-03
2025-01-02
2025-01-01
2024-12-31
2024-12-30
2024-12-29
2024-12-28
2024-12-27
2024-12-26
2024-12-25
2024-12-23
2024-12-21
2024-12-20
2024-12-19
2024-12-18
2024-12-17
2024-12-16
2024-12-13
2024-12-12
2024-12-09
2024-12-08
2024-12-07
2024-12-06
2024-12-05
2024-12-04
2024-12-03
2024-12-02
2024-11-30
2024-11-29
2024-11-28
2024-11-27
2024-11-26
2024-11-25
2024-11-24
2024-11-23
Labels
Clear labels
Implemented in VED waiting push to Main
breaking change
bug
bug
bugfix
deferred
delete script
dependencies
enhancement
external
feature
github
help wanted
in project pipeline
invalid
investigation
json
maintenance
needs triage
new script
new script
nice to have
not a script issue
not planned
organization
pull-request
question
refactor
rename script
security
update script
website
wontdo
🛑 Failure to comply with the guidelines
Mirrored from GitHub Pull Request
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/ProxmoxVE#2425
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @lubbertkramer on GitHub (Feb 1, 2026).
✅ Have you read and understood the above guidelines?
yes
🔎 Did you run the script with verbose mode enabled?
Yes, verbose mode was enabled and the output is included below
📜 What is the name of the script you are using?
nginxproxymanager
📂 What was the exact command used to execute the script?
bash -c "$(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/ct/cloudflare-ddns.sh)"
⚙️ What settings are you using?
🖥️ Which Linux distribution are you using?
Debian 13
📈 Which Proxmox version are you on?
9.1.4
📝 Provide a clear and concise description of the issue.
⚙️ Using User Defaults (default.vars) on node pve1
💡 PVE Version 9.1.4 (Kernel: 6.17.4-2-pve)
🆔 Container ID: 100
🖥️ Operating System: debian (13)
📦 Container Type: Unprivileged
💾 Disk Size: 8 GB
🧠 CPU Cores: 2
🛠️ RAM Size: 2048 MiB
🚀 Creating a Nginx Proxy Manager LXC using the above default settings
✔️ Storage space validated
✔️ Storage local (Free: 817.8GB Used: 1.4GB) [Template]
✔️ Storage local-zfs (Free: 817.8GB Used: 71.9GB) [Container]
✔️ Storage 'local-zfs' (zfspool) validated
✔️ Template storage 'local' validated
✔️ Cluster is quorate
✔️ Template search completed
✔️ Template debian-13-standard_13.1-2_amd64.tar.zst [local]
✔️ LXC Container 100 was successfully created.
✔️ Started LXC Container
✔️ Network in LXC is reachable (ping)
✔️ Customized LXC Container
✔️ Set up Container OS
✔️ Network Connected: 192.168.1.226
✔️ IPv4 Internet Connected
✖️ IPv6 Internet Not Connected
✔️ Git DNS: github.com:(✔️ ) raw.githubusercontent.com:(✔️ ) api.github.com:(✔️ ) git.community-scripts.org:(✔️ )
✔️ Updated Container OS
✔️ Installed Dependencies
✔️ Installed Python Dependencies
✔️ Set up Certbot
✖️ in line 51: exit code 100 (APT: Package manager error (broken packages / dependency problems))
→ apt update
--- Last 10 lines of silent log ---
Hit:1 http://deb.debian.org/debian trixie InRelease
Hit:2 http://deb.debian.org/debian trixie-updates InRelease
Hit:3 http://security.debian.org trixie-security InRelease
Get:4 http://openresty.org/package/debian bookworm InRelease [2,596 B]
Err:4 http://openresty.org/package/debian bookworm InRelease
Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on E52218E7087897DC6DEA6D6D97DB7443D5EDEB74 is not bound: No binding signature at time 2025-12-13T01:36:05Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00Z
Reading package lists...
Warning: OpenPGP signature verification failed: http://openresty.org/package/debian bookworm InRelease: Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on E52218E7087897DC6DEA6D6D97DB7443D5EDEB74 is not bound: No binding signature at time 2025-12-13T01:36:05Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00Z
Error: The repository 'http://openresty.org/package/debian bookworm InRelease' is not signed.
📋 View full log (853 lines): /root/.install-9cf7828d.log
✖️ Installation failed in container 100 (exit code: 100)
🔄 Steps to reproduce the issue.
Install with
bash -c "$(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/ct/cloudflare-ddns.sh)"
on Proxmox 9.1.4 results in the following error
❌ Paste the full error output (if available).
--- Last 10 lines of silent log ---
Hit:1 http://deb.debian.org/debian trixie InRelease
Hit:2 http://deb.debian.org/debian trixie-updates InRelease
Hit:3 http://security.debian.org trixie-security InRelease
Get:4 http://openresty.org/package/debian bookworm InRelease [2,596 B]
Err:4 http://openresty.org/package/debian bookworm InRelease
Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on E52218E7087897DC6DEA6D6D97DB7443D5EDEB74 is not bound: No binding signature at time 2025-12-13T01:36:05Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00Z
Reading package lists...
Warning: OpenPGP signature verification failed: http://openresty.org/package/debian bookworm InRelease: Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on E52218E7087897DC6DEA6D6D97DB7443D5EDEB74 is not bound: No binding signature at time 2025-12-13T01:36:05Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00Z
Error: The repository 'http://openresty.org/package/debian bookworm InRelease' is not signed.
📋 View full log (853 lines): /root/.install-9cf7828d.log
✖️ Installation failed in container 100 (exit code: 100)
🖼️ Additional context (optional).
No response
@phellarv commented on GitHub (Feb 1, 2026):
Same error on ProxMox 8.4.16
@MickLesk commented on GitHub (Feb 1, 2026):
Report it there:
https://github.com/openresty/openresty
@e4glenight commented on GitHub (Feb 1, 2026):
Same using a live LXC when apt-get update :
root@nginxproxymanager:~# apt-get update Hit:1 http://deb.debian.org/debian trixie InRelease Hit:2 http://security.debian.org trixie-security InRelease Hit:3 http://openresty.org/package/debian bookworm InRelease Err:3 http://openresty.org/package/debian bookworm InRelease Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on E52218E7087897DC6DEA6D6D97DB7443D5EDEB74 is not bound: No binding signature at time 2025-12-13T01:36:05Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00Z Hit:4 http://deb.debian.org/debian trixie-updates InRelease Hit:5 https://deb.nodesource.com/node_22.x nodistro InRelease Err:5 https://deb.nodesource.com/node_22.x nodistro InRelease Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on 6F71F525282841EEDAF851B42F59B5F99B1BE0B4 is not bound: No binding signature at time 2026-01-23T18:12:38Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00Z Reading package lists... Done W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. OpenPGP signature verification failed: http://openresty.org/package/debian bookworm InRelease: Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on E52218E7087897DC6DEA6D6D97DB7443D5EDEB74 is not bound: No binding signature at time 2025-12-13T01:36:05Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00Z W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. OpenPGP signature verification failed: https://deb.nodesource.com/node_22.x nodistro InRelease: Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on 6F71F525282841EEDAF851B42F59B5F99B1BE0B4 is not bound: No binding signature at time 2026-01-23T18:12:38Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00Z W: Failed to fetch https://deb.nodesource.com/node_22.x/dists/nodistro/InRelease Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on 6F71F525282841EEDAF851B42F59B5F99B1BE0B4 is not bound: No binding signature at time 2026-01-23T18:12:38Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00Z W: Failed to fetch http://openresty.org/package/debian/dists/bookworm/InRelease Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing key on E52218E7087897DC6DEA6D6D97DB7443D5EDEB74 is not bound: No binding signature at time 2025-12-13T01:36:05Z because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance because: SHA1 is not considered secure since 2026-02-01T00:00:00Z W: Some index files failed to download. They have been ignored, or old ones used instead.Hope they will update soon.
@MickLesk commented on GitHub (Feb 1, 2026):
If anyone create an Upstream issue 🤷🏼♂️😀
@coltc50 commented on GitHub (Feb 1, 2026):
Same here...
@jodur commented on GitHub (Feb 1, 2026):
I have exactly the same problem. I also tried an alternative install with a apline LXC container, but also stalled at openrestly install.
Problem is that the library is not updated for new OS.
see: https://github.com/openresty/openresty/issues/1094
I also found a post of someone who compiled oprestly to work on Debian trixie:
https://ramon.vanraaij.eu/nginx-proxy-manager-on-debian-trixie-the-upgrade-survival-guide/
@MickLesk commented on GitHub (Feb 1, 2026):
Thats wrong, we use the bookworm Repo of openresty, Not Trixie. Its clearly an gpg issue.
@e4glenight commented on GitHub (Feb 1, 2026):
i've got the same problems with node_22. is the same issues you think ?
@MickLesk commented on GitHub (Feb 1, 2026):
For Node gpg we have a Script in Discussions.
@e4glenight commented on GitHub (Feb 1, 2026):
so when its ready you can tell me here ? :)
@MickLesk commented on GitHub (Feb 1, 2026):
search in discussion -> guide. im on mobile
@MickLesk commented on GitHub (Feb 2, 2026):
https://github.com/openresty/openresty/issues/1097
@e4glenight commented on GitHub (Feb 2, 2026):
Hello, i've found if any ask :
don't know why but the scipt didn't detect the policy error, so i've remove the check for force the GPG refresh, and worked well then.
Hope Openrestry send an update soon !
Thanks again @MickLesk
@TheCustomFHD commented on GitHub (Feb 4, 2026):
Sorry for my uneducated question, but why do we need OpenResty? cant we just grab NGINX from Debian Mirrors for now instead of completly disabling the ability to install this?
And if not, this ticket shows a bit of config/scripts that would temporarly allow SHA-1 again, but i got no clue how to do this while using this script. am i meant to run/edit this on the host or where?
Another question, why was the script entirely disabled, instead of just putting a massive warning with an alternative script that temporarly adds [trusted=yes] or so to the affected mirror until this is fixed?
@MickLesk commented on GitHub (Feb 4, 2026):
Because NPM need openresty?
NPM isnt nGinx
I dont disable Sha value. So we disable the Script until its fixed.
@TheCustomFHD commented on GitHub (Feb 4, 2026):
Oh, i didnt know that, i could have sworn i read somewhere that it doesnt need anything more but normal NGINX, my bad.
Incase id need to install it, would adding a line at line 170-171 with
Trusted: yesbe enough? This seems to me like the easiest and cleanest workaround atm..Ive tried this, and i cant get this to work, so probably not.
@klein-hirn commented on GitHub (Feb 4, 2026):
As @TheCustomFHD pointed out, there are fixes / workarounds for this issue (re-enabling SHA1 signatures for apt repositories), see also this issue. I like this version as it's one line of code and time-limited.
It still does introduce a potential security risk, SHA1 was disabled in trixie for a reason. For a public-facing server, ignoring dependency updates might be the more serious issue.
@MickLesk commented on GitHub (Feb 4, 2026):
And NPM is the entrance for the most homelabs to www. If anyone need the dirty Hack, lets go, but we dont Support this.
Another Solution is to use Debian bookworm.
var_version=12 bash -c "$(curl -fsSL https://raw.....
@finnsloss commented on GitHub (Feb 5, 2026):
Thank you for the workaround with Debian bookworm, I need to get of of some old hardware fast!
Will do a rebuild when OpenResty is updated.