Libmbedcrypto checksum

Tried to search forum for anything covering this but I don’t see anything which makes me think its a me problem. Getting this while running zypper dup, not really sure how to proceed. Any help greatly appreciated.


Warning: Digest verification failed for file 'libmbedcrypto16-3.6.6-1.1.x86_64.rpm'
[/var/tmp/zypp.tmp/AP_0xDfw1rl/x86_64/libmbedcrypto16-3.6.6-1.1.x86_64.rpm]

  expected 1f38d255dd5b5fc29242262a704a610be1df33b24c7630b561428a5e503fa8dbe15018bd9464c2dd63acd6c9c40205f2220881faf2b52a11e2459ce11e88593f
  but got  0b1c7738ad8db1d66aa0c42002ffb2fda23804b5ecea536d543a056e2eeb3154f4c02eb0ec8d9ebe6cb6ca0c14cd4955a7526e7b66e9bb89914a1df1c64a4414

Accepting packages with wrong checksums can lead to a corrupted system and in extreme cases even to a system compromise.

However if you made certain that the file with checksum '0b1c..' is secure, correct
and should be used within this operation, enter the first 4 characters of the checksum
to unblock using this file on your own risk. Empty input will discard the file.
1 Like
1 Like

Just ran into the same thing, with the same checksums. I can confirm that nine hours after the OP, the same problem persists.

With all the supply chain attacks these days, how confident are we that this is just a mirror that is nine hours slow to sync?

Please always show (in a code block → the “</>” button in the forums editor) the command you ran plus all the output the command produced.

Did you run

zypper clean && zypper -vv refresh && zypper dist-upgrade

Just plain old zypper dup. After over 2.5 GB of downloads, we end with the following.

Retrieving: libmbedcrypto16-3.6.6-1.1.x86_64 (Main Repository (OSS))                                                                    (128/857), 617.1 KiB
Retrieving: libmbedcrypto16-3.6.6-1.1.x86_64.rpm ...........................................................................................[done (544.0 KiB/s)]

Warning: Digest verification failed for file 'libmbedcrypto16-3.6.6-1.1.x86_64.rpm'
[/var/tmp/zypp.tmp/AP_0xT3Qpz3/x86_64/libmbedcrypto16-3.6.6-1.1.x86_64.rpm]

expected 1f38d255dd5b5fc29242262a704a610be1df33b24c7630b561428a5e503fa8dbe15018bd9464c2dd63acd6c9c40205f2220881faf2b52a11e2459ce11e88593f
but got  0b1c7738ad8db1d66aa0c42002ffb2fda23804b5ecea536d543a056e2eeb3154f4c02eb0ec8d9ebe6cb6ca0c14cd4955a7526e7b66e9bb89914a1df1c64a4414

Accepting packages with wrong checksums can lead to a corrupted system and in extreme cases even to a system compromise.

However if you made certain that the file with checksum '0b1c..' is secure, correct
and should be used within this operation, enter the first 4 characters of the checksum
to unblock using this file on your own risk. Empty input will discard the file.

Unblock or discard? [0b1c/...? shows all options] (discard):

I chose to discard. Retrying produced the same.

Because of the size of the download, I’d rather not zypper clean, but I did run zypper -vv refresh just now:

Verbosity: 3
Initializing Target
Specified repositories:
Checking whether to refresh metadata for Main Update Repository
Retrieving: https://download.opensuse.org/update/tumbleweed/repodata/repomd.xml ..............................................................[done (3.5 KiB/s)]
Repository 'Main Update Repository' is up to date.
Checking whether to refresh metadata for Main Repository (NON-OSS)
Retrieving: https://download.opensuse.org/tumbleweed/repo/non-oss/repodata/repomd.xml .......................................................[done (12.4 KiB/s)]
Repository 'Main Repository (NON-OSS)' is up to date.
Checking whether to refresh metadata for Main Repository (OSS)
Retrieving: https://download.opensuse.org/tumbleweed/repo/oss/repodata/repomd.xml ...........................................................[done (13.8 KiB/s)]
Repository 'Main Repository (OSS)' is up to date.
Skipping disabled repository 'Packman Repository'
Checking whether to refresh metadata for libdvdcss repository
Retrieving: https://opensuse-guide.org/repo/openSUSE_Tumbleweed/repodata/repomd.xml ..........................................................[done (3.0 KiB/s)]
Repository 'libdvdcss repository' is up to date.
Checking whether to refresh metadata for multimedia:apps
Retrieving: https://download.opensuse.org/repositories/multimedia:/apps/openSUSE_Tumbleweed/repodata/repomd.xml ..............................[done (2.9 KiB/s)]
Repository 'multimedia:apps' is up to date.
Checking whether to refresh metadata for multimedia:proaudio
Retrieving: https://download.opensuse.org/repositories/multimedia:/proaudio/openSUSE_Tumbleweed/repodata/repomd.xml ..........................[done (2.9 KiB/s)]
Repository 'multimedia:proaudio' is up to date.
Checking whether to refresh metadata for multimedia:apps
Retrieving: https://download.opensuse.org/repositories/multimedia:/apps/openSUSE_Tumbleweed/repodata/repomd.xml ..............................[done (2.9 KiB/s)]
Repository 'multimedia:apps' is up to date.
Checking whether to refresh metadata for openSUSE:Tumbleweed
Retrieving: https://download.opensuse.org/repositories/openSUSE:/Tumbleweed/standard/repodata/repomd.xml .....................................[done (2.6 KiB/s)]
Repository 'openSUSE:Tumbleweed' is up to date.
Checking whether to refresh metadata for network:im:signal
Retrieving: https://download.opensuse.org/repositories/network:/im:/signal/openSUSE_Tumbleweed/repodata/repomd.xml ...........................[done (2.6 KiB/s)]
Repository 'network:im:signal' is up to date.
Skipping disabled repository 'openSUSE:Tumbleweed'
Checking whether to refresh metadata for openSUSE:Tumbleweed
Retrieving: https://download.opensuse.org/tumbleweed/repo/oss/repodata/repomd.xml ...........................................................[done (13.8 KiB/s)]
Repository 'openSUSE:Tumbleweed' is up to date.
Checking whether to refresh metadata for openSUSE:Tumbleweed
Retrieving: https://download.opensuse.org/repositories/openSUSE:/Tumbleweed/standard/repodata/repomd.xml .....................................[done (2.6 KiB/s)]
Repository 'openSUSE:Tumbleweed' is up to date.
Checking whether to refresh metadata for multimedia:libs
Retrieving: https://download.opensuse.org/repositories/multimedia:/libs/openSUSE_Tumbleweed/repodata/repomd.xml ..............................[done (2.9 KiB/s)]
Repository 'multimedia:libs' is up to date.
Checking whether to refresh metadata for microsoft-edge
Retrieving: https://packages.microsoft.com/yumrepos/edge-stable/repodata/repomd.xml ..........................................................[done (1.5 KiB/s)]
Repository 'microsoft-edge' is up to date.
Skipping disabled repository 'openSUSE-20230714-0'
Checking whether to refresh metadata for packman-essentials
Retrieving: https://ftp.gwdg.de/pub/linux/misc/packman/suse/openSUSE_Tumbleweed/Essentials/repodata/repomd.xml ...............................[done (1.3 KiB/s)]
Repository 'packman-essentials' is up to date.
Skipping disabled repository 'openSUSE-Tumbleweed-Debug'
Checking whether to refresh metadata for Open H.264 Codec (openSUSE Tumbleweed)
Retrieving: http://codecs.opensuse.org/openh264/openSUSE_Tumbleweed/repodata/repomd.xml ......................................................[done (2.9 KiB/s)]
Repository 'Open H.264 Codec (openSUSE Tumbleweed)' is up to date.
Skipping disabled repository 'openSUSE-Tumbleweed-Source'
Checking whether to refresh metadata for spotify-easyrpm
Repository 'spotify-easyrpm' is up to date.
Checking whether to refresh metadata for vscode
Retrieving: https://packages.microsoft.com/yumrepos/vscode/repodata/repomd.xml ...........................................................................[done]
Repository 'vscode' is up to date.
Checking whether to refresh metadata for Windsurf Repository
Retrieving: https://windsurf-stable.codeiumdata.com/wVxQEIWkwPUEAGf3/yum/repo/repodata/repomd.xml ........................................................[done]
Repository 'Windsurf Repository' is up to date.
All repositories have been refreshed.

Running zypper dup after that reloads the cache as expected, tries to retrieve libmbedcrypto16-3.6.6-1.1.x86_64.rpm, and fails with the checksum error as before.

So how is the corrupted package supposed to be replaced ?

The presumably-corrupted package doesn’t get that far. If the digest verification fails, the file doesn’t make it into cache. It will be re-downloaded each attempt.

However, I’m now under the belief that the rpm file itself may be fine. I’ve downloaded it manually from two mirrors (mirror.sfo12.us.leaseweb.net and mirrors.edge.kernel.org) and they both return identical files. Running rpm --checksigon both reports “digests signatures OK”.

I also deleted everything in /var/cache/zypp/raw/download.opensuse.org-oss and /var/cache/zypp/solv/download.opensuse.org-oss to force metadata to be redownloaded, but it didn’t change the final outcome.

I’m currently in the process of dusting off my ancient, moth-eaten sysadmin hat to dig into this more.

By the way, in case it’s helpful, the sha256sum of the libmbedcrypto16-3.6.6-1.1.x86_64.rpm file I’m receiving is e56a6b8c74d074fd4ec76ff5decb488d7214614ae39cd6a0fb014f45a0f78b1c.

I do not see any problem installing this file

# zypper in libmbedcrypto16
Loading repository data...
Reading installed packages...
Resolving package dependencies...

The following NEW package is going to be installed:
  libmbedcrypto16

1 new package to install.

Package download size:   617.1 KiB

Package install size change:
              |     651.6 KiB  required by packages that will be installed
   651.6 KiB  |  -      0 B    released by packages that will be removed

Backend:  classic_rpmtrans
Continue? [y/n/v/...? shows all options] (y): 
Preloading: libmbedcrypto16-3.6.6-1.1.x86_64.rpm [done]
Preload finished. [success (7.8 KiB/s) ] ....................................................................................[done]
Retrieving: libmbedcrypto16-3.6.6-1.1.x86_64 (openSUSE Tumbleweed OSS)                                         (1/1), 617.1 KiB    

Checking for file conflicts: ................................................................................................[done]
(1/1) Installing: libmbedcrypto16-3.6.6-1.1.x86_64 ..........................................................................[done]
Running post-transaction scripts ............................................................................................[done]
#

Would you mind sharing the sha256 of the rpm it just downloaded? Presumably the command would be find /var/cache/zypp/packages/ -name libmbedcrypto16-3.6.6-1.1.x86_64.rpm | xargs sha256sum.

Do you know if there’s a way to discover which mirror your system used?

@Roys Three different Tumbleweed systems…

find /var/cache/zypp/packages/ -name libmbedcrypto16-3.6.6-1.1.x86_64.rpm | xargs sha256sum
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855  -

find /var/cache/zypp/packages/ -name libmbedcrypto16-3.6.6-1.1.x86_64.rpm | xargs sha256sum
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855  -

find /var/cache/zypp/packages/ -name libmbedcrypto16-3.6.6-1.1.x86_64.rpm | xargs sha256sum
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855  -
1 Like

i just wanted to add something, it happened to me too, but it’s a different package: libmbedx509-7-3.6.6-1.1.x86_64.rpm:

Warning: Digest verification failed for file 'libmbedx509-7-3.6.6-1.1.x86_64.rpm'
[/var/tmp/zypp.tmp/AP_0xh2AiqN/x86_64/libmbedx509-7-3.6.6-1.1.x86_64.rpm]

  expected a0b4b9680a01dd1c3a145c0907531dd354261f9b459bf20bdb893fc6865bcaa1d59c3ea26f1b008bb103dac5df75a2eb1e833d05a8ece008948656a410fdc791
  but got  b253435e6f81c1eeb3de994e12202b4a2cce37d719eb95651165f3666f7516e0a42e38d9e1afb78d28af1262f1e653927c00de781d154d36bfdd59054366a161

Accepting packages with wrong checksums can lead to a corrupted system and in extreme cases even to a system compromise.

However if you made certain that the file with checksum 'b253..' is secure, correct
and should be used within this operation, enter the first 4 characters of the checksum
to unblock using this file on your own risk. Empty input will discard the file.

Unblock or discard? [b253/...? shows all options] (discard): ?

Sorry, I do not keep a permanent package cache.

I don’t. I use download.opensuse.org which is a redirector and /var/log/zypp/history does only show

...
2026-06-28 18:52:16|command|root@HOST01|'zypper' 'in' 'libmbedcrypto16'|
2026-06-28 18:52:17|install|libmbedcrypto16|3.6.6-1.1|x86_64|root@HOST01|02_oss|1f38d255dd5b5fc29242262a704a610be1df33b24c7630b561428a5e503fa8dbe15018bd9464c2dd63acd6c9c40205f2220881faf2b52a11e2459ce11e88593f|

I temporarily swapped the “Main Repository (OSS)” repo URL from https://download.opensuse.org/tumbleweed/repo/oss/ to https://mirrors.edge.kernel.org/opensuse/tumbleweed/repo/oss/ and everything downloaded and installed fine.

Specifically, I used YaST’s Software Repositories to do this and then just ran zypper dup again.

One of the mirrors to which download.opensuse.org is redirecting seems to have some serious sync problems. Repo software that has the potential to offer a file of one checksum but to declare a manifest for a different checksum, just because of sync delays, is a very bad design. I can imagine something like that being abused for a supply chain attack, especially if users get used to accepting these checksum errors.

Anyway, things are okay now. I’m going to switch my repo back to download.opensuse.org and hope I don’t have to look up this topic again in the near future.

Thanks everyone for pitching in help!

2 Likes

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.