Automatic Updates security concern



Hi,

Is there any way of setting the AU repository so it never uses https (tcp
443) and only uses http (tcp 80)?
Or, it uses only admin allowed update servers?

This might be a bit strange, but on a highly security strict LAN with
content filtering proxy (as in this case), this imposes a security risk
since https doesn't permit content parsing. Meaning that tcp 443 rules
*must* be set at the routers/firewalls and so, default configured http
clients (browsers on out-of-the box installs for instance) end up rendering
content that they weren't suposed to.

Thank you,
rusga


.



Relevant Pages

  • Fwd: Re: IPFW: Blocking me out. How to debug?
    ... allow tcp from any to any in established ... add allow udp from any 33434-34458 to any out ... add allow tcp from any to any https in setup ...
    (freebsd-questions)
  • Re: IPFW: Blocking me out. How to debug?
    ... add allow udp from any 33434-34458 to any out ... add allow tcp from any to any ssh in setup ... add allow tcp from any to any https in setup ...
    (FreeBSD-Security)
  • Re: IPFW: Blocking me out. How to debug?
    ... allow tcp from any to any in established ... add allow udp from any 33434-34458 to any out ... add allow tcp from any to any https in setup ...
    (FreeBSD-Security)
  • Re: IPFW: Blocking me out. How to debug?
    ... add allow udp from any 33434-34458 to any out ... add allow tcp from any to any ssh in setup ... add allow tcp from any to any https in setup ...
    (FreeBSD-Security)
  • Re: IPFW: Blocking me out. How to debug?
    ... allow tcp from any to any in established ... add allow udp from any 33434-34458 to any out ... add allow tcp from any to any https in setup ...
    (FreeBSD-Security)