LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Reply
  Search this Thread
Old 12-13-2009, 04:00 AM   #1
AleLinuxBSD
Member
 
Registered: May 2006
Location: Italy
Distribution: Ubuntu, ArchLinux, Debian, SL, OpenBSD
Posts: 274

Rep: Reputation: 42
Question preferences and security level


/etc/apt/apt.conf
Code:
APT::Default-Release "stable";
/etc/apt/preferences
Quote:
Package: *
Pin: release o=Debian,a=stable
Pin-Priority: 900

Package: *
Pin: origin download.virtualbox.org
Pin-Priority: 650

Package: *
Pin: origin www.debian-multimedia.org
Pin-Priority: 550

Package: *
Pin: origin www.backports.org
Pin-Priority: 500
I would like known if this configuration is sufficiently secure or if is better change the priority on some repository.
 
Old 12-13-2009, 05:50 AM   #2
the trooper
Senior Member
 
Registered: Jun 2006
Location: England
Distribution: Debian Bullseye
Posts: 1,508

Rep: Reputation: Disabled
Ok,i'm confused.
You are running Stable,and i assume your sources.list reflects this,why are you pinning individual repositories that should be pointing to Lenny/Stable already?.
Often people use apt pinning when they have mixed repositories in their sources.list.
For example a mixed Testing/Sid system.
The following guide shows the method i use for running a mixed system:

http://forums.debian.net/viewtopic.p...ing+sid+system

It might be worth posting your sources.list as well,so we know what exactly you are trying to pin.
 
Old 12-14-2009, 12:35 AM   #3
AleLinuxBSD
Member
 
Registered: May 2006
Location: Italy
Distribution: Ubuntu, ArchLinux, Debian, SL, OpenBSD
Posts: 274

Original Poster
Rep: Reputation: 42
Because i use even "external" repository, my idea will be to install program from other repository only when they aren't present on the main repository.

$ cat /etc/apt/sources.list
Quote:
deb http://mi.mirror.garr.it/mirrors/debian/ lenny main
deb-src http://mi.mirror.garr.it/mirrors/debian/ lenny main

deb http://security.debian.org/ lenny/updates main
deb-src http://security.debian.org/ lenny/updates main

deb http://volatile.debian.org/debian-volatile lenny/volatile main
deb-src http://volatile.debian.org/debian-volatile lenny/volatile main

# Multimedia
deb http://www.debian-multimedia.org lenny main
#deb-src http://www.debian-multimedia.org lenny main

# Utile ad es. per installare una vers. recente di pidgin.
deb http://www.backports.org/debian lenny-backports main

# Repository virtualbox
deb http://download.virtualbox.org/virtualbox/debian lenny non-free
 
Old 12-14-2009, 08:33 AM   #4
the trooper
Senior Member
 
Registered: Jun 2006
Location: England
Distribution: Debian Bullseye
Posts: 1,508

Rep: Reputation: Disabled
Quote:
Because i use even "external" repository, my idea will be to install program from other repository only when they aren't present on the main repository.
Looking at your sources.list i can sort of see where you are coming from.
If the package you require is not in the main repository,apt will install from an added repository such as Debian Multimedia automatically.
No need to use pinning for that.

Last edited by the trooper; 12-14-2009 at 09:52 AM.
 
Old 12-15-2009, 12:41 AM   #5
AleLinuxBSD
Member
 
Registered: May 2006
Location: Italy
Distribution: Ubuntu, ArchLinux, Debian, SL, OpenBSD
Posts: 274

Original Poster
Rep: Reputation: 42
Yes but i haven't checked if on the other repository there are some identical package but more update.
What i would like have, if avoid the installation package recent if exist version old on the main target, so i can avoid stability problem on the system because remain untouched.
 
Old 12-15-2009, 05:38 AM   #6
craigevil
Senior Member
 
Registered: Apr 2005
Location: OZ
Distribution: Debian Sid/RPIOS
Posts: 4,887
Blog Entries: 28

Rep: Reputation: 534Reputation: 534Reputation: 534Reputation: 534Reputation: 534Reputation: 534
If you want to get your packages from backports upgraded automatically the following entry in /etc/apt/preferences should be sufficient:

Package: *
Pin: release a=lenny-backports
Pin-Priority: 200


All backports are deactivated by default (i.e. the packages are pinned to 1 by using NotAutomatic: yes in the Release files, just as in experimental).

As for the other repos, I know debian-multimedia.org doesn't require pinning, the package versions are higher so aptitude/apt-get automatically installs from there rather than from lenny.
 
Old 12-16-2009, 02:02 AM   #7
AleLinuxBSD
Member
 
Registered: May 2006
Location: Italy
Distribution: Ubuntu, ArchLinux, Debian, SL, OpenBSD
Posts: 274

Original Poster
Rep: Reputation: 42
man apt_preferences
Quote:
100 < P <=500
causes a version to be installed unless there is a version
available belonging to some other distribution or the installed
version is more recent
Ok, I lower futher the priority on the last repository.

In summary using apt-pinning isn't possible doing what i would like, patience.

Last edited by AleLinuxBSD; 12-16-2009 at 02:05 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
security level legodude Mandriva 0 10-30-2004 05:00 PM
'security level' stuck nocelery Linux - Newbie 1 04-07-2004 11:53 PM
security level fawkes Linux - Newbie 0 02-29-2004 05:40 PM
Security Level question alextai Linux - Networking 0 01-30-2004 05:15 PM
Redhat 8.0 security level israel Linux - Software 1 03-22-2003 05:46 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 02:04 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration