Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1069580
| From | Ansgar <ansgar@43-1.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.devel |
| Subject | Bug#992692: general: Use https for {deb,security}.debian.org by default |
| Date | 2021-09-03 13:40 +0200 |
| Message-ID | <CTfI5-4Ib-11@gated-at.bofh.it> (permalink) |
| References | (8 earlier) <CT289-44W-3@gated-at.bofh.it> <COVoC-1JB-21@gated-at.bofh.it> <CTfoJ-4AS-1@gated-at.bofh.it> <COVoC-1JB-21@gated-at.bofh.it> <CTfoJ-4AS-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
On Fri, 2021-09-03 at 13:11 +0200, Simon Richter wrote: > > > - If I deselect all CAs in the configuration dialog of the > > > ca-certificates package, what mechanism will allow apt to work? > > > If people intentionally detrust them, they have to deal with the > > fallout. > > So this introduces a policy that users need to mark X.509 CAs as > trusted? No. > > People can also detrust Debian's OpenPGP signing keys; it's > > not much different. > > The Debian signing keys have separate trust setup, and are trusted > for nothing but APT updates. > > If we wanted the same for X.509, we'd need /etc/apt/ca-certificates > or > something such, and apt to configure the list of accepted CAs > explicitly > in the TLS layer rather than using the default settings. People who only want to trust specific CAs for APT can do that. APT has a CaPath setting. > > Accessing www.debian.org will also not work on such systems (and > > unlike > > deb.d.o that does not even offer non-https). It's not Debian's > > problem. > > There are a lot of systems out there that have no need to access > www.debian.org, but do need to access deb.debian.org. And nothing stops them from doing so. > > > - Do we want to pin the certificate provider for Debian > > > mirrors, in > > > the knowledge that we want to be bound to this provider for > > > several > > > years, do we want any "root" CA to be able to provide a trust > > > anchor? > > > Probably not? > > So what do we want then? A list of root CAs that users have to mark > as trusted, possibly with an "are you sure?" dialog in ca- > certificates? We already have that. > This isn't a simple change of default, because this simple change > pulls in a lot of dependencies. ca-certificates should already be installed by default (it is Priority: standard and recommended by apt). > That users can override the default means adding another work step > for users, either a manual step that needs to be performed after a > manual installation, or an automated step that needs to be integrated > into users' deployment processes. I don't see the problem? Currently we add another work step for users that want to use https. > > If we don't have one, shouldn't we worry more about that given the > > widespread use of TLS? > > We have a big hammer, shipping a new ca-certificates package. If we > want something that only affects apt, but not other packages, that > mechanism doesn't exist yet. If a CA is untrustworthy, I don't think we would only want to detrust it for apt's https method. So I see no problem. > > It's not about what I like, but on what external services we want to > depend. So your concern is about Debian providing the deb.debian.org service at all? That seems unrelated to the https or not question. Ansgar
Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@debian.org> - 2021-08-22 15:10 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-01 11:50 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-01 12:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Russ Allbery <rra@debian.org> - 2021-09-01 17:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@iijmio-mail.jp> - 2021-09-02 04:00 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Roberto C. Sánchez <roberto@debian.org> - 2021-09-02 18:30 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Jeremy Stanley <fungi@yuggoth.org> - 2021-09-02 19:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Jeremy Stanley <fungi@yuggoth.org> - 2021-09-02 19:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-02 21:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-02 23:10 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Paul Wise <pabs@debian.org> - 2021-09-03 04:50 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default David Kalnischkies <david@kalnischkies.de> - 2021-09-05 12:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-03 13:20 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-03 13:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Philipp Kern <pkern@debian.org> - 2021-09-03 13:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@iijmio-mail.jp> - 2021-09-04 22:20 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-09 20:10 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Paul Wise <pabs@debian.org> - 2021-09-10 02:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-10 17:10 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 13:20 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 13:40 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 14:00 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 14:10 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 15:50 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 16:00 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Tim Woodall <debiandevel@woodall.me.uk> - 2021-09-08 14:20 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 14:30 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-09 01:30 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Timo Röhling <roehling@debian.org> - 2021-09-09 08:40 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-09 14:40 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Timo Röhling <roehling@debian.org> - 2021-09-09 15:00 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-09 15:10 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Timo Röhling <roehling@debian.org> - 2021-09-09 15:30 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-10 09:40 +0200
Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-10 10:20 +0200
Re: Bug#992692: general: Use https for {deb,security}.debian.org by default Michael Stone <mstone@debian.org> - 2021-09-10 14:10 +0200
Bug#994409: task-laptop: please recommend automatic apt proxying Phil Morrell <debian@emorrp1.name> - 2021-09-15 19:20 +0200
Re: task-laptop: please recommend automatic apt proxying Russ Allbery <rra@debian.org> - 2021-09-15 19:40 +0200
Bug#994409: +1 (Re: task-laptop: please recommend automatic apt proxying) Holger Levsen <holger@layer-acht.org> - 2021-09-15 19:50 +0200
csiph-web