Insecure lxc templates download

Oct 10, 2022
46
1
11
Currently, the lxc templates are downloaded from http://download.proxmox.com, which is also used as the domain for the Proxmox Debian repository.
It was already reported that the domain has an invalid SSL certificate, which the Proxmox Staff pointed to not be a big concern as the Debian packages are signed.

However, the templates don't seem to be signed, yet their checksum is validated. Moreover, nowadays Debian allows HTTPS connections to the https://deb.debian.org/ repositories.

In any case, this represents data that is leaked to potential MITM attackers that could be easily avoided with a free Let's Encrypt certificate. Please review the decision of not fixing the certificate issue, as nowadays there are cost-effective automation options to handle it.
 
  • Like
Reactions: Johannes S

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!