[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-bugs] #9810 [Tor Sysadmin Team]: use Valid-Until field to prevent downgrade attacks for deb.torproject.org



#9810: use Valid-Until field to prevent downgrade attacks for deb.torproject.org
-------------------------------+------------------------
 Reporter:  proper             |          Owner:  weasel
     Type:  defect             |         Status:  new
 Priority:  normal             |      Milestone:
Component:  Tor Sysadmin Team  |        Version:
 Keywords:                     |  Actual Points:
Parent ID:                     |         Points:
-------------------------------+------------------------
 To prevent downgrade and stale mirror attacks against deb.torproject.org,
 please use the [http://blog.ganneff.de/blog/2008/09/23/valid-until-field-
 in-release-f.html Valid-Until] field.

 Since you are using reprepro, you can add in your conf/distributions file

 {{{
 ValidFor: 2w
 }}}

 (Or ValidFor: 4w or 1m.) under every instance of "Label:" or so.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9810>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs