Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1069321
| From | Russ Allbery <rra@debian.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.devel |
| Subject | Bug#992692: general: Use https for {deb,security}.debian.org by default |
| Date | 2021-09-01 17:00 +0200 |
| Message-ID | <CSzIS-2p5-5@gated-at.bofh.it> (permalink) |
| References | <COVoC-1JB-21@gated-at.bofh.it> <CSuSS-7Wr-15@gated-at.bofh.it> <CSvcd-83d-3@gated-at.bofh.it> <COVoC-1JB-21@gated-at.bofh.it> <CSvcd-83d-3@gated-at.bofh.it> |
| Organization | The Eyrie |
Cross-posted to 2 groups.
Ansgar <ansgar@43-1.org> writes: > On Wed, 2021-09-01 at 11:15 +0200, Helmut Grohne wrote: >> I believe that the discussion has later identified that doing so would >> break squid-deb-proxy-client and auto-apt-proxy. Given that the >> security benefits are not strong (beyond embracing good habits), I >> think the reasonable thing to do is keep preferring http. > That is an opt-in choice which likely only a small number of users use. > People wanting to use a caching proxy can just switch to http as part of > this choice; it doesn't seem a good reason to not use https by default > for all other users. Completely agreed. >> Caching packages and transport level encryption are fundamentally >> incompatible. > No. You can explicitly configure apt to use a local caching mirror or > use a trusted TLS certificate for the mirror the proxy impersonates. Yes. For example, the approach used by apt-cacher-ng works fine. Explicitly opting in to a local cache seems desirable. -- Russ Allbery (rra@debian.org) <https://www.eyrie.org/~eagle/>
Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@debian.org> - 2021-08-22 15:10 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-01 11:50 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-01 12:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Russ Allbery <rra@debian.org> - 2021-09-01 17:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@iijmio-mail.jp> - 2021-09-02 04:00 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Roberto C. Sánchez <roberto@debian.org> - 2021-09-02 18:30 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Jeremy Stanley <fungi@yuggoth.org> - 2021-09-02 19:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Jeremy Stanley <fungi@yuggoth.org> - 2021-09-02 19:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-02 21:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-02 23:10 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Paul Wise <pabs@debian.org> - 2021-09-03 04:50 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default David Kalnischkies <david@kalnischkies.de> - 2021-09-05 12:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-03 13:20 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-03 13:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Philipp Kern <pkern@debian.org> - 2021-09-03 13:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@iijmio-mail.jp> - 2021-09-04 22:20 +0200
csiph-web