SSD Nodes Learn Hosting plans →
How to do am Matt ConnorBy Matt Connor · Updated 2026-08-29

How to fix duplicate apt sources for good

Seeing "configured multiple times"? Find the matching .list and .sources files, keep one declaration, and make apt update run clean again.

Wetín duplicate apt sources error mean

Duplicate apt sources mean say one repository don dey declared twice, for two different files, and APT (advanced package tool) don find both copies. For Ubuntu 24.04 and newer, this one almost always happen because third party install script write old one line .list file, while deb822 .sources file for the same repository don already dey for disk. Nothing spoil and no package dey at risk. Delete one of the two declarations, and the message go disappear.

Na this line people dey paste for search box:

W: Target Packages (stable/binary-amd64/Packages) is configured multiple times in /etc/apt/sources.list.d/docker.list:1 and /etc/apt/sources.list.d/docker.sources:1

Read am from the end. Two files, each with line number, declare the same thing. Target Packages na the index apt downloads to learn which packages repository dey offer, and stable/binary-amd64/Packages name the component (stable) and architecture (amd64) wey that index cover. So apt dey tell you say amd64 index for stable component dey configured for docker.list at line 1, and again for docker.sources at line 1.

For apt 3.0 and newer, wey mean Ubuntu 25.04 onward and Debian 13, the same message dey start with Warning: instead of W:. The text after the prefix remain the same.

That warning na the mild case. apt merge the two declarations and update still run, because both describe the same archive with the same key. The hard case stop everything:

E: Conflicting values set for option Signed-By regarding source https://download.docker.com/linux/ubuntu/ noble: /usr/share/keyrings/docker-archive-keyring.gpg != /etc/apt/keyrings/docker.asc
E: The list of sources could not be read.

apt refuse for here because the two declarations name different signing keys for one archive. E go merge two identical declarations, but e no go choose between two Signed-By values, because choosing the wrong one mean checking package signatures against key wey archive owner never sign with. So apt no read any sources at all. apt update and apt install both fail with those same two lines until you edit the files by hand.

Duplicate file dey come from where

The two formats dey inside separate files wey get different extensions, so nothing for disk dey stop both from existing. apt dey notice the overlap late, when e expand every source file into the list of index targets wey e plan to fetch. Before that time, docker.list and docker.sources na two files wey no get connection.

Four normal events fit produce the pair:

  • Vendor install script, or command wey person copy from older post, write /etc/apt/sources.list.d/vendor.list with a tee line.
  • Later, vendor own package release /etc/apt/sources.list.d/vendor.sources and install am for you.
  • add-apt-repository for Ubuntu 24.04 and newer dey write deb822 .sources files, so PPA (personal package archive) wey you add by hand before as .list go come back as .sources.
  • Release upgrade rewrite distribution own sources into deb822 and leave your handwritten .list file untouched beside dem.

Each path dey reasonable by itself. Duplicate na wetin you get when two of dem happen for the same box, often months apart.

The two formats, side by side

Old format na one line for each repository, and every part of the line get fixed position.

deb [arch=amd64 signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu noble stable

The order no dey change: the type (deb for binary packages, deb-src for source packages), then options inside square brackets, then the archive URI (uniform resource identifier), then the suite, and then one or more components. Because position dey determine the meaning, one wrong space fit change wetin apt reads.

deb822 dey write the same information as a stanza of named fields. The name come from RFC 822, the mail header style wey Debian already dey use for package control files.

Types: deb
URIs: https://download.docker.com/linux/ubuntu
Suites: noble
Components: stable
Architectures: amd64
Signed-By: /etc/apt/keyrings/docker.asc

Na the same repository and the same key; nothing add. The mapping direct: deb become Types, the archive address become URIs, the suite become Suites, the components become Components, and each bracket option become its own field, so signed-by= become Signed-By: and arch= become Architectures:.

Every field name dey plural because every field dey accept a space separated list. Suites: noble noble-updates noble-backports for one stanza replace three separate deb lines. Blank line dey end a stanza, so one .sources file fit hold several repositories. deb822 also carry settings wey the one line format no handle well: Enabled: no to switch repository off, Trusted, Check-Valid-Until, and an inline key wey you paste straight inside Signed-By, with every line indented by one space and blank lines written as one dot.

Wia each file dey

  • /etc/apt/sources.list: the original single file. For Ubuntu 24.04 and newer, e dey usually empty or e get only comment wey point to the new location.
  • /etc/apt/sources.list.d/*.list: entries wey get one line each, normally one file for each repository.
  • /etc/apt/sources.list.d/*.sources: deb822 stanzas. Ubuntu 24.04 and newer dey keep the distribution own repositories here, for ubuntu.sources.
  • /etc/apt/keyrings/: na here keys wey you add suppose dey. /usr/share/keyrings/ hold keys wey come from a package.

apt dey read only files wey end for .list or .sources, and filename fit contain letters, digits, underscore, hyphen and period. If file get any other extension, apt go skip am and show notice. This one matter for the fix wey come below.

Find the duplicate pair

Start with the directory listing:

ls -l /etc/apt/sources.list.d/
-rw-r--r-- 1 root root  195 Aug  3 09:12 docker.list
-rw-r--r-- 1 root root  254 Aug  9 14:40 docker.sources
-rw-r--r-- 1 root root 2683 Jun 11 08:02 ubuntu.sources

Two files wey get the same stem but different extensions na the common pair, but no trust the names. Read wetin dey inside dem, because duplicate fit dey hide inside file wey get any name:

grep -rn -E '^(deb |deb-src |Types:|URIs:|Suites:|Signed-By:)' /etc/apt/sources.list /etc/apt/sources.list.d/
/etc/apt/sources.list.d/docker.list:1:deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu noble stable
/etc/apt/sources.list.d/docker.sources:1:Types: deb
/etc/apt/sources.list.d/docker.sources:2:URIs: https://download.docker.com/linux/ubuntu
/etc/apt/sources.list.d/docker.sources:3:Suites: noble
/etc/apt/sources.list.d/docker.sources:6:Signed-By: /etc/apt/keyrings/docker.asc

The pair na the two entries wey get the same host and the same suite. Both point to https://download.docker.com/linux/ubuntu and suite noble, so na the same repository dem write two times. Their Signed-By paths too no agree, and na this one dey produce the Conflicting values error wey show earlier.

Use grep instead of an apt command for this step. When apt don already stop because of the conflict, e no fit list your sources too, so apt-cache policy go print the same error instead of the answer wey you want.

Fix am: keep the deb822 file, remove the old one

Keep the .sources file. Na the format apt tooling dey write now, and na the direction Debian and Ubuntu dey follow. Before you delete anything, check which of the two key paths dey exist for disk:

ls -l /etc/apt/keyrings/ /usr/share/keyrings/ | grep -i docker
-rw-r--r-- 1 root root 4813 Aug  9 14:40 docker.asc

Na only /etc/apt/keyrings/docker.asc dey present, so the deb822 file dey show the correct information, while the .list file dey point to key wey dem don remove. If the file wey you plan to keep name the missing key, first copy the working path enter am. After that, delete the other file.

Move the old file comot from the directory instead of deleting am directly:

sudo mkdir -p /root/apt-sources-backup
sudo mv /etc/apt/sources.list.d/docker.list /root/apt-sources-backup/
sudo apt update

Renaming am to docker.list.bak and leaving am there still dey work, because apt ignores extensions wey e no know. But every apt run go print this:

N: Ignoring file 'docker.list.bak' in directory '/etc/apt/sources.list.d/' as it has an invalid filename extension

Moving the file go another place keeps that notice off your screen and still preserves the backup. A healthy apt update afterwards go look like this, with no line wey name two files:

Hit:1 http://archive.ubuntu.com/ubuntu noble InRelease
Get:2 https://download.docker.com/linux/ubuntu noble InRelease [48.8 kB]
Get:3 http://security.ubuntu.com/ubuntu noble-security InRelease [126 kB]
Fetched 175 kB in 1s (146 kB/s)
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
All packages are up to date.

Now confirm say the repository survive the edit:

apt-cache policy | grep download.docker.com
 500 https://download.docker.com/linux/ubuntu noble/stable amd64 Packages
     origin download.docker.com

If vendor documentation still assume say na the one-line file dem dey use, you fit keep that one and delete the .sources file instead. One rule dey decide the matter either way: only one file fit declare a particular archive and suite.

Why one broken third-party source dey block apt update

The neighbouring failure dey look different but root na the same: na third-party source wey apt no fit use. The first version na missing key:

Err:5 https://download.docker.com/linux/ubuntu noble InRelease
  The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 7EA0A9C3F273FCD8
E: The repository 'https://download.docker.com/linux/ubuntu noble InRelease' is not signed.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.

The Signed-By field dey missing, or e dey point to file wey no be usable key, so apt no fit verify the signature for the archive InRelease file. E then discard the whole repository instead of trusting package lists wey e no fit check. Check the key file itself:

ls -l /etc/apt/keyrings/docker.asc
gpg --show-keys /etc/apt/keyrings/docker.asc

A working key go print a pub line with key id and a uid line wey name the vendor. gpg: no valid OpenPGP data found. mean say the file no be key at all. Usually, na because the download save error page after the key URL don move. Fetch the key again, check the file, then run apt update.

The second version fit happen after release upgrade:

Err:6 https://ppa.launchpadcontent.net/ondrej/php/ubuntu plucky InRelease
  404  Not Found [IP: 10.0.0.80 443]
E: The repository 'https://ppa.launchpadcontent.net/ondrej/php/ubuntu plucky Release' does not have a Release file.

The PPA never publish anything for that suite, so the path no dey exist for the server and the request return 404. Your other repositories still update, and the packages wey you already get no change. But the run still exit with non-zero status, so any script wey check the exit status of apt update go report failure every time e run. Na why you suppose clear one dead source for box wey get unattended security upgrades configured: na for the daily noise real failure fit hide. Vendor install scripts fit hit both versions of this problem. Na why most Tailscale install errors on Ubuntu turn out to be keyring wey the script never write, or release codename wey the archive no carry.

Disable one source without breaking the rest

For a deb822 file, add one field to the stanza and save am:

Types: deb
URIs: https://ppa.launchpadcontent.net/ondrej/php/ubuntu
Suites: plucky
Components: main
Signed-By: /etc/apt/keyrings/ondrej-php.asc
Enabled: no

The apt manual recommend this instead of commenting out every line for the stanza, and e easier to undo. For one line file, put a # for the beginning of the line. For either format, you fit move the file comot /etc/apt/sources.list.d/ too. Na this option you suppose use when the repository don disappear permanently.

Run sudo apt update again. The Err: block for that repository go disappear, and the exit status go return to 0. You fit check am with echo $? for the next line.

No ever use sudo rm /etc/apt/sources.list.d/* to fix broken source. For Ubuntu 24.04 and newer, e dey delete ubuntu.sources. This file hold the distribution own repositories. So apt go remain without any package lists and report E: Unable to locate package curl for software wey clearly dey exist. If you don already run am, write the file back:

Types: deb
URIs: http://archive.ubuntu.com/ubuntu/
Suites: noble noble-updates noble-backports
Components: main restricted universe multiverse
Signed-By: /usr/share/keyrings/ubuntu-archive-keyring.gpg

Types: deb
URIs: http://security.ubuntu.com/ubuntu/
Suites: noble-security
Components: main restricted universe multiverse
Signed-By: /usr/share/keyrings/ubuntu-archive-keyring.gpg

Save am as /etc/apt/sources.list.d/ubuntu.sources. Replace noble with your own release name from lsb_release -cs, then run sudo apt update.

Convert legacy .list files go deb822

As of August 2026, apt 3.0 and newer get converter for this work. Debian 13 get am, and Ubuntu 25.04 plus every release after am, including 26.04, get am too. Check the version, then run am:

apt --version
sudo apt modernize-sources

E go rewrite the one-line files wey dey under /etc/apt/sources.list.d/ into deb822 .sources files. Read wetin e print, then list the directory by yourself and run apt update before you trust the result. Ubuntu 24.04 get older apt wey no get this subcommand, and for there the command go answer E: Invalid operation modernize-sources. For that release, convert am by hand with the field mapping above.

Conversion no compulsory for now, because apt still dey read both formats. E make sense to do am for server wey you plan keep, because every tool wey dey write sources now dey write deb822, and a box wey get only .sources files no fit develop this kind duplicate.

Server fọ́ọ̀m ẹni kẹta tidy

Third party repositories na part of server wey dey age worst. Each one na promise from another person say dem go continue publish for your Ubuntu release. Release upgrade go test every one of those promises for the same afternoon.

  • Add third party repository only when distribution package no fit do the work. Plain LAMP stack for Ubuntu 24.04 no need any: Ubuntu archive get every package wey e use, with security updates for the whole life of the release.
  • Keep keys for /etc/apt/keyrings/, one file for each vendor, with mode 644. Unprivileged _apt user dey download and e must read the key. So, key file wey only root fit read go cause permission error every time dem fetch from that repository.
  • Point Signed-By to that exact file for every stanza. Key wey dey inside /etc/apt/trusted.gpg or /etc/apt/trusted.gpg.d/ dey trusted for every repository for the machine. That one mean say vendor key wey person add years ago fit validate packages from anywhere.
  • Before release upgrade, read your sources and check say each vendor don already publish for the suite wey you dey move go.

Key wey dey the old global keyring go show itself for every update:

W: https://download.docker.com/linux/ubuntu/dists/noble/InRelease: Key is stored in legacy trusted.gpg keyring (/etc/apt/trusted.gpg), see the DEPRECATION section in apt-key(8) for details.

Export that single key into its own file, then point the stanza to am:

gpg --no-default-keyring --keyring /etc/apt/trusted.gpg --export 7EA0A9C3F273FCD8 | sudo tee /etc/apt/keyrings/docker.gpg > /dev/null
sudo chmod 644 /etc/apt/keyrings/docker.gpg

Add Signed-By: /etc/apt/keyrings/docker.gpg to the repository stanza and run sudo apt update. The warning go stop once no repository depend on the old keyring. After that, you fit remove the entry with sudo gpg --no-default-keyring --keyring /etc/apt/trusted.gpg --delete-key 7EA0A9C3F273FCD8.

One more habit fit save you the biggest wahala. do-release-upgrade disables third party sources for the upgrade and leaves dem switched off afterwards. If you turn dem back on by hand, one at a time, na there duplicate declarations fit enter. Read Ubuntu 24.04 to 26.04 upgrade guide before you start, and write down the repositories wey you still need. For machine wey you just build, the cheapest time to set sources correctly na during the first ten minutes for new VPS, while the only entries for the machine still be the ones Ubuntu shipped.

FAQ

Why apt dey talk say one target dey configured multiple times?

Na because two files for inside /etc/apt/sources.list.d/ declare the same repository, suite, and component. The message dey name both files with line numbers, like docker.list:1 and docker.sources:1. apt dey merge dem and continue, so the update itself still dey work. E still make sense to clear the duplicate: once the two files name different signing keys, apt go stop with E: Conflicting values set for option Signed-By and refuse to read any source at all, wey go block apt install too.

Make I keep the .list file or the .sources file?

Keep the .sources file. deb822 na wetin add-apt-repository dey write for Ubuntu 24.04 and newer. E get one named field for each setting instead of positional text inside square brackets, and na the format distributions dey move toward. Before you delete the .list file, confirm say the Signed-By path inside the .sources file point to a key wey exist, with ls -l /etc/apt/keyrings/. Move the old file out of /etc/apt/sources.list.d/ instead of renaming am inside the directory, because leftover .bak name go make apt print ignored-file notice every time e run.

How I fit turn off one apt repository without removing am?

For deb822 .sources file, add Enabled: no to the stanza. For one-line .list file, put # for the beginning of the line. Either way, run sudo apt update afterwards, and the Err: block for that repository go disappear. This na the correct step when third-party repository never get packages for your Ubuntu release yet, and its 404 dey make apt update exit non-zero.

The one-line sources.list format dey go away?

E don deprecate am, but dem never remove am. apt still dey read .list files and e go continue for long time, so nothing for your server go break tomorrow. New tooling dey write deb822: Ubuntu 24.04 and newer dey keep distribution repositories for /etc/apt/sources.list.d/ubuntu.sources, and add-apt-repository dey write .sources files. For apt 3.0 and newer, sudo apt modernize-sources go convert the files wey you still get.

#apt#ubuntu#deb822#package-management#troubleshooting