ClusterHQ / flocker

Container data volume manager for your Dockerized application
https://clusterhq.com
Apache License 2.0
3.39k stars 290 forks source link

Debian apt repo is not signed #2374

Open sgnn7 opened 8 years ago

sgnn7 commented 8 years ago

Without a signed apt repo, it's impossible to know if the deb packages from https://clusterhq-archive.s3.amazonaws.com/ubuntu/ came from ClusterHQ or someone maliciously intercepted and/or modified them.

wallnerryan commented 8 years ago

Thank you, we appreciate your feedback @sgnn7 will bring this feedback to our release team.

wallnerryan commented 8 years ago

double checking, this issue is in our backlog already. You can track https://clusterhq.atlassian.net/browse/IDEA-5 for updates in the future.

magcius commented 8 years ago

Uh, well, since it's over TLS / HTTPS, traffic can't be intercepted. But yeah, preventing the scary apt warnings is a good idea.

sgnn7 commented 8 years ago

@magcius Without signing:

Edited with some links

andrewrothstein commented 8 years ago

this is problematic indeed. I tried signing into your Atlassian thingy and the issue IDEA-5 is not accessible. Are you committed to publishing signed packages?

twang2218 commented 8 years ago

The packages are still not signed, I tried to install flocker on Ubuntu 16.04, and got:

# apt-get update
...
W: The repository 'https://clusterhq-archive.s3.amazonaws.com/ubuntu/16.04/amd64  Release' is not signed.
N: Data from such a repository can't be authenticated and is therefore potentially dangerous to use.
N: See apt-secure(8) manpage for repository creation and user configuration details.
# apt-get install clusterhq-flocker-cli
Reading package lists... Done
Building dependency tree
Reading state information... Done
The following additional packages will be installed:
  clusterhq-python-flocker libpython2.7-minimal libpython2.7-stdlib python2.7
  python2.7-minimal
Suggested packages:
  python2.7-doc binutils binfmt-support
The following NEW packages will be installed:
  clusterhq-flocker-cli clusterhq-python-flocker libpython2.7-minimal
  libpython2.7-stdlib python2.7 python2.7-minimal
0 upgraded, 6 newly installed, 0 to remove and 0 not upgraded.
Need to get 49.0 MB of archives.
After this operation, 188 MB of additional disk space will be used.
Do you want to continue? [Y/n] y
WARNING: The following packages cannot be authenticated!
  clusterhq-python-flocker clusterhq-flocker-cli
Install these packages without verification? [y/N]
...
andreycizov commented 7 years ago

Still not fixed.

Reading package lists... Done
W: The repository 'https://clusterhq-archive.s3.amazonaws.com/ubuntu/16.04/amd64  Release' is not signed.
N: Data from such a repository can't be authenticated and is therefore potentially dangerous to use.
N: See apt-secure(8) manpage for repository creation and user configuration details.
adamtheturtle commented 7 years ago

@andreycizov ClusterHQ, the maintainer of this repository, has shut down. However, a group of the original developers is available for paid support and feature development. Check out https://www.scatterhq.com.