[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#499897: preventing replay attacks against the security archive



On 11517 March 1977, Peter Palfrader wrote:

> One proposed solution is to optionally add a "Valid-Until" field to
> Release files on at least the security archive, tho it might make sense
> for unstable etc also.

Should be easy for us (ftp.d.o) to do, I think i add something like this
soon.

also, such a "fixed" apt, might be a candidate for the security archive
itself. Ie. a patch to apt only enabling this in the stable
version. Might want to ask security team when we have this
functionality. (Assuming the apt maintainers want to backport this
function into the then-lenny-release).


-- 
bye, Joerg
A BSP means that many DDs and other mere mortals get together to play
xroach. Sadly, that package was removed from Debian some time ago, so
they have to squash other bugs (preferably RC) instead.

Attachment: pgpLCh3EPC0eF.pgp
Description: PGP signature


Reply to: