Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1069581

Bug#992692: general: Use https for {deb,security}.debian.org by default

From Philipp Kern <pkern@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.devel
Subject Bug#992692: general: Use https for {deb,security}.debian.org by default
Date 2021-09-03 13:40 +0200
Message-ID <CTfI5-4Ib-5@gated-at.bofh.it> (permalink)
References (8 earlier) <CT289-44W-3@gated-at.bofh.it> <COVoC-1JB-21@gated-at.bofh.it> <CTfoJ-4AS-1@gated-at.bofh.it> <COVoC-1JB-21@gated-at.bofh.it> <CTfoJ-4AS-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


Hi,

On 03.09.21 13:11, Simon Richter wrote:
[Revocation mechanism]
>> If we don't have one, shouldn't we worry more about that given the
>> widespread use of TLS?
> We have a big hammer, shipping a new ca-certificates package. If we want 
> something that only affects apt, but not other packages, that mechanism 
> doesn't exist yet.

I think that's an interesting point, not just for revocation. There are 
forces pushing for more agility, switching out roots of trust more 
frequently. So for very old releases, you usually had the signing key of 
the next release on disk, so you could move to the next release. In this 
case you sort of risk not having the TLS authority on disk to make that 
happen. And of course we need to track what the authorities are doing 
that our frontends are using (e.g. [1] around how to deal with old 
Android devices).

But then I'm not sure how much we need to care about ancient releases 
that are out of security support. We would need to commit to regularly 
update the certificate bundle, though.

To your other point: I don't think managing trust into individual CAs 
will scale. We cannot really anticipate which CAs we are going to use in 
the future.

Kind regards
Philipp Kern

[1] https://letsencrypt.org/2020/12/21/extending-android-compatibility.html

Back to linux.debian.bugs.dist | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@debian.org> - 2021-08-22 15:10 +0200
  Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-01 11:50 +0200
    Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-01 12:00 +0200
      Bug#992692: general: Use https for {deb,security}.debian.org by default Russ Allbery <rra@debian.org> - 2021-09-01 17:00 +0200
        Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@iijmio-mail.jp> - 2021-09-02 04:00 +0200
          Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Roberto C. Sánchez <roberto@debian.org> - 2021-09-02 18:30 +0200
            Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Jeremy Stanley <fungi@yuggoth.org> - 2021-09-02 19:00 +0200
          Bug#992692: general: Use https for {deb,security}.debian.org by default Jeremy Stanley <fungi@yuggoth.org> - 2021-09-02 19:00 +0200
          Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-02 21:40 +0200
            Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-02 23:10 +0200
              Bug#992692: general: Use https for {deb,security}.debian.org by default Paul Wise <pabs@debian.org> - 2021-09-03 04:50 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default David Kalnischkies <david@kalnischkies.de> - 2021-09-05 12:40 +0200
              Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-03 13:20 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-03 13:40 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Philipp Kern <pkern@debian.org> - 2021-09-03 13:40 +0200
            Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@iijmio-mail.jp> - 2021-09-04 22:20 +0200
              Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-09 20:10 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Paul Wise <pabs@debian.org> - 2021-09-10 02:00 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-10 17:10 +0200
          Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 13:20 +0200
            Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 13:40 +0200
              Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 14:00 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 14:10 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 15:50 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 16:00 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Tim Woodall <debiandevel@woodall.me.uk> - 2021-09-08 14:20 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 14:30 +0200
            Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Michael Stone <mstone@debian.org> - 2021-09-09 01:30 +0200
              Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Timo Röhling <roehling@debian.org> - 2021-09-09 08:40 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Michael Stone <mstone@debian.org> - 2021-09-09 14:40 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Timo Röhling <roehling@debian.org> - 2021-09-09 15:00 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Michael Stone <mstone@debian.org> - 2021-09-09 15:10 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Timo Röhling <roehling@debian.org> - 2021-09-09 15:30 +0200
              Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Helmut Grohne <helmut@subdivi.de> - 2021-09-10 09:40 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-10 10:20 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Michael Stone <mstone@debian.org> - 2021-09-10 14:10 +0200
                Bug#994409: task-laptop: please recommend automatic apt proxying Phil Morrell <debian@emorrp1.name> - 2021-09-15 19:20 +0200
                Re: task-laptop: please recommend automatic apt proxying Russ Allbery <rra@debian.org> - 2021-09-15 19:40 +0200
                Bug#994409: +1 (Re: task-laptop: please recommend automatic apt proxying) Holger Levsen <holger@layer-acht.org> - 2021-09-15 19:50 +0200

csiph-web