Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #237673

Re: Debian Security

Path csiph.com!newsfeed.xs4all.nl!newsfeed9.news.xs4all.nl!bofh.it!news.nic.it!robomod
From "Andrew M.A. Cater" <amacater@einval.com>
Newsgroups linux.debian.user
Subject Re: Debian Security
Date Sat, 24 Jul 2021 11:40:01 +0200
Message-ID <CEmit-3fd-3@gated-at.bofh.it> (permalink)
References <CEi5b-Um-1@gated-at.bofh.it>
X-Original-To debian-user@lists.debian.org
X-Mailbox-Line From debian-user-request@lists.debian.org Sat Jul 24 09:33:59 2021
Old-Return-Path <amacater@einval.com>
X-Amavis-Spam-Status No, score=-8.3 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, CAPINIT=0.5, LDO_WHITELIST=-5, MURPHY_DRUGS_REL5=0.5, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham autolearn_force=no
X-Policyd-Weight using cached result; rate: -4.6
MIME-Version 1.0
Content-Type text/plain; charset=us-ascii
Content-Disposition inline
X-Mailing-List <debian-user@lists.debian.org> archive/latest/778310
List-ID <debian-user.lists.debian.org>
List-URL <https://lists.debian.org/debian-user/>
List-Archive https://lists.debian.org/msgid-search/YPvedv4AOknIPg3o@einval.com
Approved robomod@news.nic.it
Lines 43
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Sat, 24 Jul 2021 09:33:42 +0000
X-Original-Message-ID <YPvedv4AOknIPg3o@einval.com>
X-Original-References <ad8b972c-a295-df45-77c0-80ab8f485cae@polynamaude.com>
Xref csiph.com linux.debian.user:237673

Show key headers only | View raw


On Sat, Jul 24, 2021 at 01:07:24AM -0400, Polyna-Maude Racicot-Summerside wrote:
> Hi !
> How would you copy the debian security update repository ?
> I know it's not recommended.
> But I'd like to do so.
> -- 
> Polyna-Maude R.-Summerside
> -Be smart, Be wise, Support opensource development
> 

In general, this is a very bad idea because - and only because - you don't want
the possibility of machines getting incorrect / out of date fixes.
Security-critical things are security-critical - trying to maintain one
canonical source of truth where uploads are moderated and from a known source
is hard. Forcing people to go to the one source solves that problem in one
sense (and may also lessen the risk of some Evil Hacker maintaining a 
security repository stuffed with malware and spoofing).
[Having said all that: I've a feeling that security.d.o is actually a set
of servers to serve Europe/Asia/N. America behind the content delivery
network.]

If you really, really, really want to do it properly: I'd suggest approaching
the people in charge of security.d.o, having a conversation about exactly
what you want to do, why and for how many people. You'd probably need to 
assure tham that your mirror will be relatively secure from attack - so their
machines are not at risk - and then arrange for some form of push mirroring, 
so that they push updates to you at their convenience. This means that they
will need the ability to have an account on your machine sufficiently to
use ssh and forced commands to push the updates.

Debian mirrors in general are updated about four times a day and it's 
asynchronous. Pushed updates mean that everyone gets a drip feed of updates
whenever they're published. This is how several of us currently run private
mirrors for the main Debian distribution.

Unless you are a bank / government agency / pharmaceutical company that 
keeps all critical systems airgapped and entirely isolated from the Internet, 
maintaining a separate security mirror may be more trouble than it's worth
in my opinion.

All the very best, as ever,

Andy Cater

Back to linux.debian.user | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Debian Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-24 07:10 +0200
  Re: Debian Security <tomas@tuxteam.de> - 2021-07-24 10:50 +0200
    Re: Debian Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-24 17:50 +0200
      Re: Debian Security Georgi Naplatanov <gosho@oles.biz> - 2021-07-24 18:20 +0200
        Re: Debian Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-24 19:50 +0200
          Re: Debian Security The Wanderer <wanderer@fastmail.fm> - 2021-07-24 20:00 +0200
      Re: Debian Security tomas@tuxteam.de - 2021-07-24 19:20 +0200
  Re: Debian Security basti <basti@unix-solution.de> - 2021-07-24 11:20 +0200
  Re: Debian Security "Andrew M.A. Cater" <amacater@einval.com> - 2021-07-24 11:40 +0200
    Re: Debian Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-24 20:30 +0200
    Re: Debian Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-08-11 10:30 +0200
    Re: Debian Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-08-11 10:30 +0200

csiph-web