apt-revoker - Check for Revocation Certificates before running apt-get

Information

ID: 140
PHID: PHID-TASK-fmfckf46hede24dqp4hj
Author: Patrick
Status at Migration Time: open
Priority at Migration Time: Normal

Description

Migrated from:
https://github.com/Whonix/Whonix/issues/125


Debian has no good mechanism to revoke apt keys in case of compromise, neither a way to inform users in emergency situations:
https://lists.debian.org/debian-security/2013/10/msg00065.html

An apt key revoker should be written:
https://lists.debian.org/debian-security/2013/12/msg00031.html

And up-streamed to Debian.

  • Keyservers may not be used: [Sks-devel] How much load are keyservers willing to handle?
  • The code for downloading the revocation certificates should be configurable.
  • .d style configuration folder. Where distributions and PPA’s can drop configuration snippets. Using arrays.
  • Code should be re-usable for Whonix News key revocation as well (using configuration snippet).

Related:


Implementation:
One should discuss this with debian-security list / debian apt developers (sh vs #bash [arrays] vs #python vs ...) as more sophisticated implementation plans materialized.

Comments


HulaHoop

2016-12-16 02:55:57 UTC


HulaHoop

2016-12-16 23:27:54 UTC


HulaHoop

2016-12-16 23:50:40 UTC


Patrick

2016-12-17 01:02:41 UTC


HulaHoop

2016-12-18 00:37:08 UTC


Patrick

2016-12-18 12:53:32 UTC


Patrick

2016-12-18 13:38:24 UTC


HulaHoop

2016-12-18 15:13:50 UTC


Patrick

2016-12-18 15:38:48 UTC