Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.devel > #101497
| From | Simon Richter <sjr@debian.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.devel |
| Subject | Bug#992692: general: Use https for {deb,security}.debian.org by default |
| Date | 2021-09-02 21:40 +0200 |
| Message-ID | <CT0J4-336-9@gated-at.bofh.it> (permalink) |
| References | (2 earlier) <CSvcd-83d-3@gated-at.bofh.it> <CSzIS-2p5-5@gated-at.bofh.it> <CSJId-hl-1@gated-at.bofh.it> <COVoC-1JB-21@gated-at.bofh.it> <CSJId-hl-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
Hi,
On 02.09.21 03:22, Hideki Yamane wrote:
> Providing "default secure setting" is good message to users.
The TLS layer is not part of the security model, so we'd be teaching
users to look for the wrong thing, kind of like the "encrypted with SSL"
badges on web pages in the 90ies.
We have our own PKI that is decoupled from the X.509 certificate
infrastructure, and neither ascribes any trust in them nor depends on
the availability of an external service.
As it is now, I can install a Debian system where no X.509 certificate
authorities are trusted.
- If I deselect all CAs in the configuration dialog of the
ca-certificates package, what mechanism will allow apt to work?
- Do we want to pin the certificate provider for Debian mirrors, in
the knowledge that we want to be bound to this provider for several
years, do we want any "root" CA to be able to provide a trust anchor?
- Is there a revocation mechanism by which we can mark "root" CAs as
untrustworthy?
- What does the UI look like if OSCP verification fails?
- How do mirror operators get a signed certificate?
I think we're adding a lot of complexity and external dependencies to
the system here, which adds a lot of burden to mirror operators that
aren't large CDNs. That may be acceptable for an entity like Ubuntu, who
aren't dependent on donations, but we would be tied to the goodwill of
CDN operators here, so:
- do we wish to communicate that the existing mirrors outside
deb.debian.org are somehow less "secure"?
- do we have a contingency plan if deb.debian.org hosting on Fastly is
no longer feasible?
Simon
Back to linux.debian.devel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@debian.org> - 2021-08-22 15:10 +0200
Processed: Re: Bug#992692: general: Use https for {deb,security}.debian.org by default "Debian Bug Tracking System" <owner@bugs.debian.org> - 2021-09-01 11:50 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-01 11:50 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-01 12:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Russ Allbery <rra@debian.org> - 2021-09-01 17:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@iijmio-mail.jp> - 2021-09-02 04:00 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Roberto C. Sánchez <roberto@debian.org> - 2021-09-02 18:30 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Jeremy Stanley <fungi@yuggoth.org> - 2021-09-02 19:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Jeremy Stanley <fungi@yuggoth.org> - 2021-09-02 19:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-02 21:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-02 23:10 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Paul Wise <pabs@debian.org> - 2021-09-03 04:50 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default David Kalnischkies <david@kalnischkies.de> - 2021-09-05 12:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-03 13:20 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-03 13:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Philipp Kern <pkern@debian.org> - 2021-09-03 13:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@iijmio-mail.jp> - 2021-09-04 22:20 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-09 20:10 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Paul Wise <pabs@debian.org> - 2021-09-10 02:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-10 17:10 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 13:20 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 13:40 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 14:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 14:10 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 15:50 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 16:00 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-09 01:30 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2021-09-09 01:40 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Eduard Bloch <edi@gmx.de> - 2021-09-10 11:30 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Timo Röhling <roehling@debian.org> - 2021-09-10 12:10 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-10 14:00 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Tim Woodall <debiandevel@woodall.me.uk> - 2021-09-08 14:20 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 14:30 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-09 01:30 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Timo Röhling <roehling@debian.org> - 2021-09-09 08:40 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-09 14:40 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Timo Röhling <roehling@debian.org> - 2021-09-09 15:00 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-09 15:10 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Timo Röhling <roehling@debian.org> - 2021-09-09 15:30 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-09 15:00 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default David Kalnischkies <david@kalnischkies.de> - 2021-09-10 16:40 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-10 17:10 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default David Kalnischkies <david@kalnischkies.de> - 2021-09-10 20:10 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-10 21:20 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Paul Wise <pabs@debian.org> - 2021-09-12 05:20 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Holger Levsen <holger@layer-acht.org> - 2021-09-13 00:00 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default David Kalnischkies <david@kalnischkies.de> - 2021-09-13 15:10 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-10 09:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-10 10:20 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-10 14:10 +0200
Bug#994409: task-laptop: please recommend automatic apt proxying Phil Morrell <debian@emorrp1.name> - 2021-09-15 19:20 +0200
Re: task-laptop: please recommend automatic apt proxying Russ Allbery <rra@debian.org> - 2021-09-15 19:40 +0200
Re: task-laptop: please recommend automatic apt proxying Russ Allbery <rra@debian.org> - 2021-09-15 19:40 +0200
Bug#992692: next steps Hans-Christoph Steiner <hans@eds.org> - 2021-12-09 12:30 +0100
Bug#992692: more steps towards this goal Hans-Christoph Steiner <hans@eds.org> - 2022-03-30 10:00 +0200
Bug#992692: moar Hans-Christoph Steiner <hans@eds.org> - 2022-03-30 12:30 +0200
Bug#992692: link Geert Stappers <stappers@stappers.nl> - 2022-03-30 12:50 +0200
csiph-web