Hosted Apt Repository not working with 3.84.0 - Sonatype Nexus Repository - Sonatype Community

Hosted Apt Repository not working with 3.84.0

post by Linus on Sep 16, 2025

While testing Nexus 3.84.0-03 Community Edition on our test server, we noticed that our hosted apt repository is no longer working as expected. While we can still upload packages as expected, the download from such a repo fails due to a bad signature:

$ dpkg-deb --build corp-apt-test
dpkg-deb: building package 'corp-apt-test' in 'corp-apt-test.deb'.
$ curl -fsSL -u "$NEXUS_USERNAME:$NEXUS_PASSWORD" -H "Content-Type: multipart/form-data" --data-binary "@./corp-apt-test.deb" "$NEXUS_BASE_URL/repository/integration-test-apt-hosted-jammy/"
$ gpg --dearmor <apt-integration-test.asc | tee /etc/apt/keyrings/integration-test-hosted.gpg > /dev/null
$ echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/integration-test-hosted.gpg] $NEXUS_BASE_URL/repository/integration-test-apt-hosted-jammy jammy main" > /etc/apt/sources.list.d/nexus-hosted.list
$ apt-get update -o APT::Update::Error-Mode=any
Hit:1 http://apt.corp.com/daily/ubuntu jammy InRelease
Hit:2 http://apt.corp.com/daily/ubuntu jammy-updates InRelease
Hit:3 http://apt.corp.com/daily/ubuntu jammy-security InRelease
Ign:4 https://nexus-test.corp.com/repository/integration-test-apt-hosted-jammy jammy InRelease
Hit:5 https://nexus-test.corp.com/repository/integration-test-apt-proxy-adoptium-jammy jammy InRelease
Get:6 https://nexus-test.corp.com/repository/integration-test-apt-hosted-jammy jammy Release [622 B]
Get:7 https://nexus-test.corp.com/repository/integration-test-apt-hosted-jammy jammy Release.gpg [217 B]
Ign:7 https://nexus-test.corp.com/repository/integration-test-apt-hosted-jammy jammy Release.gpg
Reading package lists...
W: GPG error: https://nexus-test.corp.com/repository/integration-test-apt-hosted-jammy jammy Release: The following signatures were invalid: BADSIG 2B2657DE310832FF Nexus Integration Test <infra@corp.com>
E: The repository 'https://nexus-test.corp.com/repository/integration-test-apt-hosted-jammy jammy Release' is not signed.

After this, I reverted the instance back to 3.83.2-01 (also restoring the H2 db in the process), and it worked as expected again:

After upgrading again, the same error happens. I compared the key in the admin interface with our production instance, and even copied it to our test instance again, but to no avail.

I found the following log line in nexus.log of the test instance, our prod instance does not log this line, so hopefully it’s a good starting point:

2025-09-16 06:13:50,091+0200 WARN  [qtp2142209372-373]  *UNKNOWN org.sonatype.nexus.repository.view.handlers.ExceptionHandler - Invalid content: GET /dists/jammy/InRelease: org.sonatype.nexus.repository.InvalidContentException: Detected content type [text/plain], but expected [application/pgp-encrypted, application/pgp]: /dists/jammy/Release.gpg

The key can still be accessed via http (https://nexus-test.corp.com/repository/integration-test-apt-hosted-jammy/dists/jammy/Release.gpg and https://nexus.corp.com/repository/integration-test-apt-hosted-jammy/dists/jammy/Release.gpg, respectively), but they both report a Content-Type of text/plain.

Additional environment information, if necessary: Both instances are behind an nginx reverse proxy, and use a forward proxy (with an exception for *.corp.com) for accessing the internet.

Any help would be appreciated.


post by mpiggott on Sep 16, 2025

Thanks for the report. I believe we should have a point release this week which includes the fix for this issue.

post by Linus on Sep 22, 2025

Indeed 3.84.1 fixed it. Thanks!