[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#499897: preventing replay attacks against the security archive



reassign 499897 apt
severity 499897 important
thanks

On 11517 March 1977, Joerg Jaspert wrote:

>> One proposed solution is to optionally add a "Valid-Until" field to
>> Release files on at least the security archive, tho it might make sense
>> for unstable etc also.
> Should be easy for us (ftp.d.o) to do, I think i add something like this
> soon.

Done. We now generate Release files having "Valid-Until:" headers. Same
format as the Date: one, just currently (for the main archive) 7 days in
future.

Would be nice if apt could get this implemented soon[1] and then the
release team asked how we could get this into lenny.
(If its *only* this change, maybe lenny proper. If that doesnt work,
maybe r1? Or possibly really a DSA for it).

[1] Luckily, apt just ignores unknown fields in release files, so no
    harm done having it there already.

-- 
bye, Joerg
Five exclamation marks, the sure sign of an insane mind.
			-- Terry Pratchett, Reaper Man

Attachment: pgp3sPUDdmAwX.pgp
Description: PGP signature


Reply to: