LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 04-15-2019, 04:47 PM   #1
Mi82
Member
 
Registered: Nov 2015
Posts: 53

Rep: Reputation: Disabled
apt-get via httpS


I'm trying to modify my repository sources list to get everything via httpS after reading about replay attacks. I installed apt-get-https and modified to list to "https". The main repo is working, but security.debian.org isn't working:

Code:
Err:8 https://security.debian.org/debian-security stretch/updates Release
  server certificate verification failed. CAfile: /etc/ssl/certs/ca-certificates.crt CRLfile: none
Reading package lists... Done
E: The repository 'https://security.debian.org/debian-security stretch/updates Release' does no longer have a Release file.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
I'm assuming I just don't understand something about how repos work or specifically how the security repo works.






Footnote: The reasons I am trying to use apt via httpS:

"numerous research papers have shown both APT and YUM repositories to be vulnerable to replay attacks when the repository is accessed via HTTP, even with GPG signatures. Repositories should only be accessed via TLS, 100% of the time." – Joe Damato Oct 21 '16 at 10:00
https://isis.poly.edu/~jcappos/paper...ror_ccs_08.pdf

and

"There has in fact been multiple exploits of apt (1, 2) that allows arbitrary code execution as root that would have been prevented if https was used instead of http. So https do provide real security benefit because sometimes bugs happen and the more layers of security you have the better." – Niklas Holm
1. https://www.debian.org/security/2016/dsa-3733
2. https://www.debian.org/security/2019/dsa-4371

Last edited by Mi82; 04-15-2019 at 04:54 PM.
 
Old 04-15-2019, 05:29 PM   #2
hydrurga
LQ Guru
 
Registered: Nov 2008
Location: Pictland
Distribution: Linux Mint 21 MATE
Posts: 8,048
Blog Entries: 5

Rep: Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925
Putting https://security.debian.org/debian-security into Firefox indicates that the subdomain isn't set up (or set up correctly) for https.

Try using:

Code:
http://deb.debian.org/debian-security/

Last edited by hydrurga; 04-16-2019 at 06:47 AM.
 
1 members found this post helpful.
Old 04-15-2019, 05:45 PM   #3
scasey
LQ Veteran
 
Registered: Feb 2013
Location: Tucson, AZ, USA
Distribution: CentOS 7.9.2009
Posts: 5,725

Rep: Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211
Yes. Whether or not a url is using https is controlled by the remote site. It’s not something you can force to happen from your end.
I’m curious if you actually needed to change anything. For example, http://linuxquestions.org will be connected to the https url because the site has been configured to redirect all web requests to https
That may also be the case for at least some of your repository sources.
 
1 members found this post helpful.
Old 04-16-2019, 06:40 AM   #4
Mi82
Member
 
Registered: Nov 2015
Posts: 53

Original Poster
Rep: Reputation: Disabled
That worked!
http://deb.debian.org/debian-security/
gets forwarded to an https site:
https://cdn-aws.deb.debian.org/debian-security/

Thanks!!
 
1 members found this post helpful.
  


Reply

Tags
apt, apt-get, https, ssl



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Need suggestion:->>Failed HTTPS transfer to https://supportfiles.sun.com/curl manalisharmabe Solaris / OpenSolaris 11 01-10-2014 12:58 AM
https certication error , the page can not be loaded via https ust Linux - Server 2 11-21-2013 08:49 PM
redirect https://www.domain.com to https://domain.com decenter Linux - Server 4 09-13-2011 10:05 AM
apache 2.0 https to https redirect struct Linux - Software 1 04-22-2011 05:43 PM
How to allow login via specific port via https rickylim Linux - Security 2 04-17-2006 09:32 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 10:01 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration