Project

Profile

Help

Issue #3411

closed

Document Implications that Pulp2 does not support metalink for rpm syncing

Added by bmbouter over 4 years ago. Updated over 3 years ago.

Status:
CLOSED - CURRENTRELEASE
Priority:
Normal
Assignee:
Sprint/Milestone:
-
Start date:
Due date:
Estimated time:
Severity:
2. Medium
Version:
Platform Release:
2.15.3
OS:
Triaged:
Yes
Groomed:
No
Sprint Candidate:
No
Tags:
Documentation, Easy Fix, Pulp 2
Sprint:
Sprint 33
Quarter:

Description

Pulp2 does not support metalink which means that it is vulnerable to a malicious mirror replay attack whereby old packages are delivered even though there are newer packages available in the mirror network.

The recommended fix is to:
1. Clearly state that pulp_rpm does not support metalink.
2. Add a warning that states the part about that talks about a malicious mirror replay attack and links to https://patrick.uiterwijk.org/blog/2018/2/23/fedora-package-delivery-security for more details.

I am reporting on behalf of a user who reported this to me privately.

Actions #1

Updated by bmbouter over 4 years ago

  • Tags Easy Fix added

+1 to adding this to the sprint. It's an easyfix for the docs change.

Actions #2

Updated by dalley over 4 years ago

  • Sprint/Milestone set to 56
  • Triaged changed from No to Yes
Actions #3

Updated by bmbouter over 4 years ago

  • Status changed from NEW to ASSIGNED
  • Assignee set to bmbouter

Added by bmbouter over 4 years ago

Revision ef87f564

Adds metalink clarification

https://pulp.plan.io/issues/3411 closes #3411

Actions #4

Updated by bmbouter over 4 years ago

  • Status changed from ASSIGNED to POST
Actions #5

Updated by bmbouter over 4 years ago

  • Status changed from POST to MODIFIED
Actions #6

Updated by bmbouter over 4 years ago

  • Platform Release set to 2.15.3
Actions #7

Updated by bmbouter over 4 years ago

  • Sprint set to Sprint 33
Actions #8

Updated by bmbouter over 4 years ago

  • Sprint/Milestone deleted (56)

Added by bmbouter over 4 years ago

Revision 8bffe902

Adds metalink clarification

https://pulp.plan.io/issues/3411 closes #3411

(cherry picked from commit ef87f564c48ca7bcf18e7510373a3b528775f016)

Added by bmbouter over 4 years ago

Revision 725b0a53

Metalink clarification

https://pulp.plan.io/issues/3411 re #3411

(cherry picked from commit a91f71df89a83aa4b80334b27b1410e59dc1b97f)

Actions #9

Updated by bmbouter over 4 years ago

Actions #10

Updated by bmbouter over 4 years ago

  • Status changed from MODIFIED to 5
Actions #11

Updated by bmbouter over 4 years ago

  • Status changed from 5 to CLOSED - CURRENTRELEASE
Actions #12

Updated by bmbouter over 3 years ago

  • Tags Pulp 2 added

Also available in: Atom PDF