Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1069576

Bug#992692: general: Use https for {deb,security}.debian.org by default

From Simon Richter <sjr@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.devel
Subject Bug#992692: general: Use https for {deb,security}.debian.org by default
Date 2021-09-03 13:20 +0200
Message-ID <CTfoJ-4AS-1@gated-at.bofh.it> (permalink)
References (6 earlier) <CT0J4-336-9@gated-at.bofh.it> <COVoC-1JB-21@gated-at.bofh.it> <CT289-44W-3@gated-at.bofh.it> <COVoC-1JB-21@gated-at.bofh.it> <CT289-44W-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Hi,

On 02.09.21 23:02, Ansgar wrote:

>> As it is now, I can install a Debian system where no X.509
>> certificate authorities are trusted.

> That doesn't change with the proposal?

>>    - If I deselect all CAs in the configuration dialog of the
>> ca-certificates package, what mechanism will allow apt to work?

> If people intentionally detrust them, they have to deal with the
> fallout.

So this introduces a policy that users need to mark X.509 CAs as trusted?

> People can also detrust Debian's OpenPGP signing keys; it's
> not much different.

The Debian signing keys have separate trust setup, and are trusted for 
nothing but APT updates.

If we wanted the same for X.509, we'd need /etc/apt/ca-certificates or 
something such, and apt to configure the list of accepted CAs explicitly 
in the TLS layer rather than using the default settings.

> Accessing www.debian.org will also not work on such systems (and unlike
> deb.d.o that does not even offer non-https). It's not Debian's problem.

There are a lot of systems out there that have no need to access 
www.debian.org, but do need to access deb.debian.org.

>>    - Do we want to pin the certificate provider for Debian mirrors, in
>> the knowledge that we want to be bound to this provider for several
>> years, do we want any "root" CA to be able to provide a trust anchor?

> Probably not?

So what do we want then? A list of root CAs that users have to mark as 
trusted, possibly with an "are you sure?" dialog in ca-certificates?

This isn't a simple change of default, because this simple change pulls 
in a lot of dependencies. That users can override the default means 
adding another work step for users, either a manual step that needs to 
be performed after a manual installation, or an automated step that 
needs to be integrated into users' deployment processes.

>>    - Is there a revocation mechanism by which we can mark "root" CAs
>> as
>> untrustworthy?

> If we don't have one, shouldn't we worry more about that given the
> widespread use of TLS?

We have a big hammer, shipping a new ca-certificates package. If we want 
something that only affects apt, but not other packages, that mechanism 
doesn't exist yet.

> Do we have a revocation mechanism by which we can mark OpenPGP signing
> keys as untrustworthy (say for apt)?

Yes, by shipping an update.

>>    - do we have a contingency plan if deb.debian.org hosting on Fastly
>> is no longer feasible?

> As far as I know there is also at least https://cdn-aws.deb.debian.org/
> if you don't like Fastly.

It's not about what I like, but on what external services we want to depend.

    Simon

Back to linux.debian.bugs.dist | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@debian.org> - 2021-08-22 15:10 +0200
  Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-01 11:50 +0200
    Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-01 12:00 +0200
      Bug#992692: general: Use https for {deb,security}.debian.org by default Russ Allbery <rra@debian.org> - 2021-09-01 17:00 +0200
        Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@iijmio-mail.jp> - 2021-09-02 04:00 +0200
          Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Roberto C. Sánchez <roberto@debian.org> - 2021-09-02 18:30 +0200
            Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Jeremy Stanley <fungi@yuggoth.org> - 2021-09-02 19:00 +0200
          Bug#992692: general: Use https for {deb,security}.debian.org by default Jeremy Stanley <fungi@yuggoth.org> - 2021-09-02 19:00 +0200
          Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-02 21:40 +0200
            Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-02 23:10 +0200
              Bug#992692: general: Use https for {deb,security}.debian.org by default Paul Wise <pabs@debian.org> - 2021-09-03 04:50 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default David Kalnischkies <david@kalnischkies.de> - 2021-09-05 12:40 +0200
              Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-03 13:20 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-03 13:40 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Philipp Kern <pkern@debian.org> - 2021-09-03 13:40 +0200
            Bug#992692: general: Use https for {deb,security}.debian.org by default Hideki Yamane <henrich@iijmio-mail.jp> - 2021-09-04 22:20 +0200
              Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-09 20:10 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Paul Wise <pabs@debian.org> - 2021-09-10 02:00 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Simon Richter <sjr@debian.org> - 2021-09-10 17:10 +0200
          Bug#992692: general: Use https for {deb,security}.debian.org by default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 13:20 +0200
            Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 13:40 +0200
              Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 14:00 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 14:10 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Helmut Grohne <helmut@subdivi.de> - 2021-09-08 15:50 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 16:00 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Tim Woodall <debiandevel@woodall.me.uk> - 2021-09-08 14:20 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-08 14:30 +0200
            Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Michael Stone <mstone@debian.org> - 2021-09-09 01:30 +0200
              Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Timo Röhling <roehling@debian.org> - 2021-09-09 08:40 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Michael Stone <mstone@debian.org> - 2021-09-09 14:40 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Timo Röhling <roehling@debian.org> - 2021-09-09 15:00 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Michael Stone <mstone@debian.org> - 2021-09-09 15:10 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Timo Röhling <roehling@debian.org> - 2021-09-09 15:30 +0200
              Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Helmut Grohne <helmut@subdivi.de> - 2021-09-10 09:40 +0200
                Bug#992692: general: Use https for {deb,security}.debian.org by default Ansgar <ansgar@43-1.org> - 2021-09-10 10:20 +0200
                Re: Bug#992692: general: Use https for {deb,security}.debian.org by  default Michael Stone <mstone@debian.org> - 2021-09-10 14:10 +0200
                Bug#994409: task-laptop: please recommend automatic apt proxying Phil Morrell <debian@emorrp1.name> - 2021-09-15 19:20 +0200
                Re: task-laptop: please recommend automatic apt proxying Russ Allbery <rra@debian.org> - 2021-09-15 19:40 +0200
                Bug#994409: +1 (Re: task-laptop: please recommend automatic apt proxying) Holger Levsen <holger@layer-acht.org> - 2021-09-15 19:50 +0200

csiph-web