[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#499897: preventing replay attacks against the security archive



Joerg Jaspert wrote:
>>>> - have it expire in a period long enough so a new point release will
>>>> have happened in the meantime, say half a year.
>>> Probably still not acceptable for CD-Roms.
>> I don't think that should be a problem - I don't believe CD-Roms are the
>> target of this feature. APT already handles CD-Roms differently so it
>> could exclude them from this check.
> 
> Hello apt team, anyone working on supporting this? :)
> (It's used in both, the normal and the security archive).
> 
No one at present, IIRC.

Should this be incorporated into apt in Lenny? It's not hard to apply the patch from
Thomas, but it doesn't address feature that apt should not accept Release files without
'Valid-Until' entry after seeing it once earlier. Moreover, current apt architecture IIRC
doesn't allow seeing previous Release files while deciding accept or decline just
downloaded one -> apt ABI bump may be needed. And this is also another pain for Christian,
we just done last (we hope) translation changes for apt.

Michael, your opinion?

-- 
Eugene V. Lyubimkin aka JackYF, JID: jackyf.devel(maildog)gmail.com
Ukrainian C++ developer, Debian APT contributor

Attachment: signature.asc
Description: OpenPGP digital signature


Reply to: