Apt update

Ubuntu Version:
22.04 LTS

Problem Description:
Trying to install updates I am getting this error via the gui or apt update

Conflicting values set for option Signed-By regarding source https://repository.veeam.com/backup/linux/agent/dpkg/debian/public/ stable: /etc/apt/trusted.gpg.d/DEB-9BB5AC67.gpg != -----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBFcsgx4BEADkpnt0RWXf//OW3b/HFihzD98oJVgr59aQl9mAue1rN+APvTne
HzYco32jcR1wf2c+nkXbuDyHi4B9gqRsIi4HA1/9GD0FiS/qtqq3nRo6Xnol1wqS
jHYEaXzZAAKmyM9tKaDpyvrgDZeHrbWj5YAXQpPJn88VTu70yrd+38N6HQRBqbfA
WbqHT0ifQ9E5MXrZ7XfkiunoXJMCNxjfHmTSk2N5YbZ+LVPY+MdG+/fqZcU5VWnt
LxHMC3ITil1GdNOc0ZXz3A3ZNNEK8jVz9NVG/CcQBwTKpA0ghYlaXRqNVDXoqzlf
Xz2nSuWx3WTqbAJevCCQuNcUsfPWNvHFbrWWlT2dZlAjVe3a6Bme++emSjYNJrSE
+QA9VKe3xkf7MuM4BvrTP21WTrclqf0V6Rnj9LNRdclSwqcBMVyhZKHObmOAeDPI
JbE/eEV8qpldgn/Rw66XxUIai++zfc5pxy+zVo9HN9IcohZI9pq7rZfukrswQ9QN
0RXwGW6VyOgFznkaqNBGB3JoJMBRoWZ0WbrkUQ3UkMIEkUAEDscXCnaBfpP7X6Uy
XTASzcK6w87PcC18gplqhEvMViSZTLouj33tnhABJB6W5bq9hX4umT7Jh5m9YtkM
KlU8oAvSvYYcY5tek1F9UjByXv1bAK49mLDkSScRQAS9Zg4d1nIM3sfJEwARAQAB
tDFWZWVhbSBTb2Z0d2FyZSBSZXBvc2l0b3J5IGtleSA8c3VwcG9ydEB2ZWVhbS5j
b20+iQI9BBMBCgAnAhsDBQsJCAcDBRUKCQgLBRYCAwEAAh4BAheABQJl9GEFBQkS
ikTnAAoJEHr97rj7+KWQSoQP/2aj6PctLQrMx1RqKQpFT4PRzIyDu76vVTZevFu2
Gs7sVuppnGvw3eEFzwhxHarS/RrnWF3Lx6SNNG/ObQhiIbZXbfz+2UHvS+ZUKP5P
IwwXrrfscDiBEERvQbqoCejhh8i8OvH5bjN82xbHfe/5XcAeeixm0K434H1yYHuk
cV0KUKqFXcOXd/dVqVo2Vf4R14rozBasnXbSOMtB8nXjmrR36BNtLtDRypQZXl46
1AEZ2cNjGeUv/hm+6e6J9d/LumfbetQybaWgFnYkNLVX3+r/4nVl8TWferHLK6IB
gD0YtxvO8rjJFDFsuJK7my4rEtgZr+ZNuiPHkBOcXaxYzCKq/9patwPF61kg2bVD
hfQCAGLEosjumY5FZdBBLuNICiuoz5k9n8AK9uXZHnptFEawuFNSP9zKVg8nTOzq
erNdCaSX5dSXmv9pRD6kCipnkWN+A5ZwuJ05ylwwMHLdhhPjKIEnn4gC4WkS/MXc
3FzLTnPWYO/wNEyIbcpjTWcCqbA4BHC56+uLMdPwekAMRucz8Zx9nONzx4nvZQa+
nauKoSo+NDvhU5OMubXYrWC9+Dozlqm9btfZSD2BAx8yDhLf5eyFpdt8rNi6I8qm
Jdhk4rnbkekMMWiudsQd/MO2exMj109UjHmsbYVIqDarc1qyWkwwx/B1Vc1BEbH0
ESgIuQINBFrV6aEBEADPacYIcWTi1r+Uq242TVtj2uAJo/yEwj/3yCU1YUbtSRHt
hTO2HxekyRdoVWxiLXIxDJNXgMYJy6cNAlSEbI4Z+mOhuI052YFR298U60jCgDqN
Bn/5wofu76MREHZSsUQT6LO0A9JUecgcPnfMZGfUanmLIE2tVGbU8QgUXtAWMgtd
wx2+Z4iQzf9gcLz/IVFA8/3skGOK7b57uMHkixe7nllKXehW018iuzpHNBZjH1p0
GeFMvq/kKxj1uc17g2QVRP7+naxjqLIkcb2NVfcRM+PO3PgpqyuHhhmNeLlQmOB1
zuXXLg3S5qCb1AxuYGxJ99qfhVpfK02gtXuxNY2wtKUQoq6vMe2w9KPbAfrBAiaY
HOGLvfNd2qnSS1J55dibPIoV79rv95IVz5exf576O/qjM1URsOjQd5SoR4uQ4FzX
ZTWzkx3pTq/Yl1Gq0d6vnN8ZsQy197VOGprULjtM9yTQ2Frj14241ZarTziE/iDW
wgmigNmnL37gw61+XewKTge3cuoLx6mQYGzYh64M+QsTb+P3IyMERzULloBDSjcN
m1+M+Bk5JiC8f2K82XAw8Lein/iSQgpxrMDPZDeLHKBpZ5ca1VAQov/7kntIClQX
zAc4CFUTXTCla4XOOK1JdY+zcmJQcWprR/0dAek6ZmabKOmA4dYKWVkS4fT8twAR
AQABiQREBBgBAgAPBQJa1emhAhsCBQkFo5qAAikJEHr97rj7+KWQwV0gBBkBAgAG
BQJa1emhAAoJEDJozwOO7ARbmC8P/RQFOtqPRfeTJlNBnuOJkwBaSJipOUpmtMaY
YdeM/78cwsvzX9R8Sf+UgEJz8Mr5ED1Q4Noi5OsTcFaKB9tyZJ1/GrL3ifZ1hFuo
pcoXYi1A27bd2nYP6M8Oj8Ty6f7ragksQJ0YAHnf41pexLX0IDM8H11nAzDpOn1f
uhh39fbl2qmoCKgzWayyeMhWJU2+E10B8bc911A586yQ+1TGLf4DDCLAepeMEtub
ANoLSid5M5nJn5LhU6fcJG2MRMTZCLUYczVK+GUkcVVKz+8yIhKv6mPZ+Fg3t+RR
5JtRGuMWefdLfVeXMbpD3L4JyIM3oFTWf/g3SjcLRDwRTyvSvwDV0F0ifG1SZ++2
4hxSduflVTbbuhP7Z5At1sYgWaW1HXdbmrJDwOpQwLsnTZ1Olssb1aYcSTLh457o
FiJiNs82SyyBiNgg21E6MaGtpgM8vgj8ISRzgxLj0VzghBn0+W7epC0eCL9Ql+C+
/TFnzu/2BfVCucObr13h9uamLSGKzwOxB9vCGJ+inwM5AnLFAoOCJiWJrBWVyVHE
qI3OMF3rdnl76kkENDMAfE94u/1I1tAHJPM34rP8oSCOrpHNKBrJyrOxxbKbIi9y
tbCrLPDKZQ0g9lVx0lRFRx0MaUZPP52LMakPrr7obAGEM8ZQc/F/R3H+l8eyuyPB
6tWfrWiZ3C4QANQDlbxUv3jsN7gnn/+vHPgEWLtQvgKXx+j88DzJ1E4eqOwmPWj9
+9yGQbktPTwrxp8lt0OVDdvKD5GoAkZJv9p0Og15AOKCGyWO6PVpA7135oKMFsrO
NOrfQQiTai7t7kP+hTdeeIPFi8JsGam2RyRmhEaHX6YwbtuwMIy357LoZ3xf5OIk
ogZDUa4f9mwysQAlODWwOWcUuOHPi9TeSEQCnE9CPTGXvFYS01jiiQxzhh4SPz76
FQrz/4qiHSQmfPKwSThJcvkx2LsW1WiAk5zD8hiI0AaOqaZm85C3WxPpzIDWWLsl
sz8aWloJOoXoRj/AT6KunU51RVlJuu5eVHQGsVHu0tE3Uuy5q+C1k3ZbWRbVHjS1
3H8xWXdNHtta0OdDlkZDxysPBlcKc44UIUKCHd+bmM0BDdWXf4adMQVkiQJuiZG0
YLYjHrIlQWORN1F3RWxlH+JzBueiemXhjlnZGmRGsFoNaIOZS3OE/8F27hZBDYW5
m2nfdfZkRG3U4jPdJrEURSF2BUAOTvt0nqUCVp31IHtoUNCz+Hl3MbuItWg7tRZr
1buH6fNMNUyk1x22asrouW01LwCHYdOfclbZmFZ/NSZgBJEjhEeKNzy18yzCaHIo
iWxPkkHWxrwJinUU9xPTIzC2dREr53Pjx4ku9GiPC4ISgtylUYtxHD1aiQREBBgB
AgAPAhsCBQJl9GEOBQkO4N5tAinBXSAEGQECAAYFAlrV6aEACgkQMmjPA47sBFuY
Lw/9FAU62o9F95MmU0Ge44mTAFpImKk5Sma0xphh14z/vxzCy/Nf1HxJ/5SAQnPw
yvkQPVDg2iLk6xNwVooH23JknX8asveJ9nWEW6ilyhdiLUDbtt3adg/ozw6PxPLp
/utqCSxAnRgAed/jWl7EtfQgMzwfXWcDMOk6fV+6GHf19uXaqagIqDNZrLJ4yFYl
Tb4TXQHxtz3XUDnzrJD7VMYt/gMMIsB6l4wS25sA2gtKJ3kzmcmfkuFTp9wkbYxE
xNkItRhzNUr4ZSRxVUrP7zIiEq/qY9n4WDe35FHkm1Ea4xZ590t9V5cxukPcvgnI
gzegVNZ/+DdKNwtEPBFPK9K/ANXQXSJ8bVJn77biHFJ25+VVNtu6E/tnkC3WxiBZ
pbUdd1uaskPA6lDAuydNnU6WyxvVphxJMuHjnugWImI2zzZLLIGI2CDbUToxoa2m
Azy+CPwhJHODEuPRXOCEGfT5bt6kLR4Iv1CX4L79MWfO7/YF9UK5w5uvXeH25qYt
IYrPA7EH28IYn6KfAzkCcsUCg4ImJYmsFZXJUcSojc4wXet2eXvqSQQ0MwB8T3i7
/UjW0Ack8zfis/yhII6ukc0oGsnKs7HFspsiL3K1sKss8MplDSD2VXHSVEVHHQxp
Rk8/nYsxqQ+uvuhsAYQzxlBz8X9Hcf6Xx7K7I8Hq1Z+taJkJEHr97rj7+KWQjDwP
/3RJkzFDTtjoQcge7MadZ3kFzNEZ9nO2qbxpBKk1OdJqa8bNMZ7zuYjwswDoE2Dt
MV5+vAHTY2a6uZgiiBpuRG8tD3TxuQVWz1xG9C3V+A4Vd8OH38lrR4+SnAT+IAlG
IU+Oqu3EUOrMj5RqfhrLJwSkyIwvFjPVsIiJovj1P+T6M3+/aloaFRSFzu49hpm6
5VYaeyMQdGGmmq3Vsrd0Lkut1RnC6IMVmNwNyIWLbhsPveEzlEnLdmAXG+1G1V7G
GnuIkrWX7YRhXN+lvojVnkj5qL7yy9X1ZSfYwg2i0+VLFf3uljhUWqADg1fgqb/U
jwqqHXTToWIA4HY+AThetbLUilM4i7qk+mpcEAhRpVF9lX8k0FRq8JldDp18oeCX
lKtf51YuDZ+fwoz54gH2Z9r9B8XIDLgEpsK165hRwXcPCzVmrO+4I3Kex1m3d8RY
tqV8k2Z4sMx02iSKVAFsYIFWTp82H+bIHCVH/BwAiH0bkKjGHBPbzV6El56H+oob
VAwrWXgwVO2cQ+n5ea91MX+jkWZbBeOrb3GrFg5Ecb5jcZ+dNQwk/ZWKP2PupV42
SXvGGqTTd+mF6akTHEiFtf7BvbwwKFA6eexf/g7x8yLKjVqC5Km15hJIfZ0V/hzR
vlkNlIOF3x+FFM1NI3aZkDKYJEKS8vmIv+3TfBc1tgTuuQINBFcsg+oBEADLvY11
Boo+RJ4068hv5WNSUKEFb07NCusU4o+WK1QJifAQPQlVIthS0Z9pX6D9nXNCaJN4
jrm6xgNv4eH0Pdy7IWfsSzLMIWJq7pdvo0hSgfzAcNWIqUbaAUpdz3EgBarptwpF
reBuP6guWIeDYaP/dxnUlKcaLIndarwPSj8V/UlrjjozjaEe9fQ+QwUnHDXXGO1c
IwkMagsuB+BBlYN3Oah0pxcVxSO4xaYfJ7K14zgUEbl0/cizZJrMYssgQ6kFfRiJ
yDKWnZrAQ1biqz/Gxd8QGIEB20KPb8+S6zRC/nhPTNfYUdh06G5iUV1k/8ah5YRD
Gn7G+sIFOmbXHGthWRtxxHL0zX2RILILo8S9FfRHLlplP4AP71KzH6uvFOvHpUFm
tRmhD7ALiuFj3YpfiAyhb9K7VfDi2ufvEF/D9Hl4BpAm7hw9nhNmToHJLYl9PxDg
W/myob5bxlkzyG9keU915AB7y3sEEL8kZISOBJn/w4YDutc87ck5481MmJ/snQMa
xb/8wweu0mxKqn5A/ZUmN8F/kIs797rU9aHDomvXUOoPKzbUwDSFSpSVV1jg7rzr
5S8Wn6gnXlmCfEbHCoQDdHmpjBDLcM/5QiGEIGCxQUYZHi6CHHkhu6Nte4r0hXmI
wm7NeNPFnbRVNZENAgNGzZghCqXIDYG1BVdxwwARAQABiQREBBgBCgAPAhsCBQJl
9GEXBQkSikQtAinBXSAEGQEKAAYFAlcsg+oACgkQVHBtfFo4L81Xhg/+O/mDSVRi
OeACMPz1pzwe3F1R4ycNOkWk5PK4MlxSqtSup5Y5s6A56EwjHY4wZo9S1J1l+FRw
KYPjQfCeCG+f1LCD3stAv6Z1zh4pQwhJlpZ+M4WWzl6IdxcR4pXVYxKdS8YaxxOS
V9Y1WHmeOrE/dE4NJPSzLAhplueokstAcUyrqRrogStlZ0TfV9nyWIby5OAeS3vf
+qZt1WLzb8hbPteNT0YdLr8Egrgtzhqo7v+4EFOXQDMwp1+4u+IGHqCKRlwDE5f4
5r/0kJ5Indv3KCEH9h5WRIiQQC9nxcZYJDBYqXpoDT2cTjs6QbnN73nPtR3wz1G6
uWdqJUk97dZSJPOo4cDTsmDVu469rSp/wWv/D86udV9BMpeC0LmqVED1gdH7rrqv
uLmLqmRjqU2obx2Y38PZ62fMneXR6viG02GgfS6S3bbVa2bhIqB0cmvw5A6q6UfS
VBrbXCe62EBACJwBPu/SkobgZO/3A+RABVARGChJuhjbETroPXq5fsHBYGhozipO
xIXhb4VV9NncNoY3C2q4Xn2T0ocLRim/nb33ozg7iSmauMSxr7csY7/BFyg12S3O
f9pPsCsFdi/LKx0XzCbs5bzKnFPak7G1Q+6WIUkCJ2zJX7nO1linfZuLittZx/wT
RtVUu1cbpdQwNIxb0dVupmF8xvb3FWrmoa0JEHr97rj7+KWQR0MP/jlBI7erhbZ/
X3D0a+x8QLuCoppUH4DQZb6VPPOEO5PAhM52DTD9vgm1Se0YsNkrwDyV228iOS23
YkwCfsY4GONwHxq/T6iZ8NzsWnzwlM/UwmS2Lhw+z41MQxpI07Ie0ADOcce2rvUa
XteqTeE0XUldmoGSdmSiuhIqF+8gqNvvlvOhHLq/K9UIya+QNcEHIGxgmrBzJF7w
aHlKkNAgQTYiSzMaD2BtknroI7ERNtMqy3CD3gp3USxrFAbLdhKFoUl7X3bH1eJJ
ptDfe5s6kYCSvwP3SPOGqd++o8qTJDzT5eEnEikloI9xnX/FQQdig8jjPi7+6xqR
UyWAWNtVXOb3aUMmXtk1K/Ob/z8r7OBk8xWaBhu909lzWsnMSRCiOBB57nErBiWw
4z6MLl9l0sFPCvo1VTAF099u1Is+atDTiPICSwNRQPaX1dQcY1DyJVxoBp5aN+BY
SIelgSKWl4O2ubHLtBZp7066IQEP6Goqb4FxBT0y5iiH0cSg9xWb5WTHmFRlXzW8
RwA+FAngAxYjZPW1iieM8lURV6SH8uxqFZv02T91SXW57Y0LbrBFHv2nmF+sFlWP
oC6iYVx9OI1Zhg2fQaMXIrDSsV18bVF6WELqESR7gaNXcSN1tIgydMGgHisspf/n
dUIoyfq2JAH/h3VJtcs9+73uTaJOSqsi
-----END PGP PUBLIC KEY BLOCK-----
E: The list of sources could not be read.dy been reported and resolved.

Anyone know how to fix this?

What is the output of
lsb_release -a; uname -a
Thanks

@unbuntunewbie02 Which version of Ubuntu are you using?

Please enter the correct information in the support template so we can help you.

Additionally, large blocks of terminal output are almost impossible to read and understand in plain text.

Use the preformatted text option in the composer.

Highlight the text and click on the </> icon to add code blocks.

Thanks

1 Like

I find it easier to click </> (or enter ```) on an empty line first; then CtrlV to paste — no extra step for highlighting, which can get difficult with longer output. It’s important to do this on an empty line, because otherwise one gets inline monospace (can’t really call that “pre-formatted”) text, which isn’t much better because of line wrapping.

Open Software & Updates>Other Software and disable that veeam.com repository. Now try to update.

Then work out what is wrong with that repository’s gpg key.

Regards

1 Like

There seems to be a newer sources.list entry, containing a Signed-By field with the above public key block, which conflicts with an older key in /etc/apt/trusted.gpg.d/DEB-9BB5AC67.gpg. I think, this should do it:

sudo mv /etc/apt/trusted.gpg.d/DEB-9BB5AC67.gpg{,.disabled}

That only disables the old key, in case you need to restore it. There may still be an older entry in sources.list, which references it, though. You can find that one by running this:

grep -irF DEB-9BB5AC67 /etc/apt/sources.list*

Or, it could be the other way around; you’d have to examine which is the current signing key of that repository.


Please put all log and other console/terminal output in pre-formatted code blocks (click the </> icon in the editor first and paste into the new element), ideally wrapped in a “Hide Details” element, if it’s more than just a few lines. See items 4 and 5 in the Posting Guide.

Optional helper script

If you are so inclined, I took it upon myself to provide a little helper script for that. :sweat_droplets:

using the disabled did not work. and the output of grep cmd

$ sudo grep -irF DEB-9BB5AC67 /etc/apt/sources.list*
/etc/apt/sources.list.d/veeam.list:deb [arch=amd64 signed-by=/etc/apt/trusted.gpg.d/DEB-9BB5AC67.gpg] https://repository.veeam.com/backup/linux/agent/dpkg/debian/public stable veeam

As I said, there may still be a file referencing it, which you have found:

(BTW, should avoid using sudo when not required, like here. See this discussion if you’re interested in the details.)

See what happens when you disable that sources file:

sudo mv /etc/apt/sources.list.d/veeam.list{,.disabled}

Then run sudo apt update; see if there is still a line for the veeam repository. If there isn’t, we need to take a closer look at all the sources.list files:

grep -r '' /etc/apt/sources.list*

On a more OpSec related note, while searching for installation instructions, to take a look at the sources.list creation procedure, I found this:

It’s probably not a good idea to do so blindly, because that undermines the very idea of Secure APT, and the PGP/GPG Web of Trust idea at its core, for that matter. One should always authenticate such keys first. That can be as easy as comparing the fingerprint against a public record of it, i.e. on the vendor’s TLS-signed and encrypted website, to be sure no Man-in-the-Middle attacker can do a switcheroo of said key, or the .deb package it is delivered in. Ideally such keys should be signed by some trusted 3rd party; IIRC, the signing keys of the Tor Project’s repository are signed by some Debian developers in debian-keyring. Explaining all that is out of scope here; feel free to open a new topic if you’re interested. Or just have a look at this:
https://wiki.debian.org/SecureApt#How_to_tell_if_the_key_is_safe

Disabling the Veeam sources file let me run a apt update and i am going to update the system while i can before proceed.

Output of the file below:

deb [arch=amd64 signed-by=/etc/apt/trusted.gpg.d/DEB-9BB5AC67.gpg] https://repository.veeam.com/backup/linux/agent/dpkg/debian/public stable veeam
1 Like