-
-
Notifications
You must be signed in to change notification settings - Fork 53
Closed
Labels
C: SaltThis issue pertains to the use of Salt (aka SaltStack) in Qubes OS.This issue pertains to the use of Salt (aka SaltStack) in Qubes OS.C: templatesThis issue pertains to templates in general (as opposed to specific templates).This issue pertains to templates in general (as opposed to specific templates).P: defaultPriority: default. Default priority for new issues, to be replaced given sufficient information.Priority: default. Default priority for new issues, to be replaced given sufficient information.R: upstream issueResolution: This issue pertains to software that the Qubes OS Project does not develop or control.Resolution: This issue pertains to software that the Qubes OS Project does not develop or control.
Milestone
Description
Qubes OS version:
R4.0
Affected component(s):
qubes-core-admin, though this mostly causes problems when using Salt.
Steps to reproduce the behavior:
Run gpg --recv-keys with any keyserver in a TemplateVM.
Expected behavior:
The updates proxy should allow traffic to the keyserver
Actual behavior:
Access to the keyserver is denied.
General notes:
This was originally discovered when using SaltStack to add apt repositories to a template. Using a keyserver and key ID (the most secure way of adding the key, without requiring the key to be copied into dom0) does not work. Copying the key into dom0 might work (and, since the key would never be parsed by anything whatsoever in dom0, only passed as a stream of bytes, might even be safe), but I did not try.
Related issues:
Possibly #1955?
Metadata
Metadata
Assignees
Labels
C: SaltThis issue pertains to the use of Salt (aka SaltStack) in Qubes OS.This issue pertains to the use of Salt (aka SaltStack) in Qubes OS.C: templatesThis issue pertains to templates in general (as opposed to specific templates).This issue pertains to templates in general (as opposed to specific templates).P: defaultPriority: default. Default priority for new issues, to be replaced given sufficient information.Priority: default. Default priority for new issues, to be replaced given sufficient information.R: upstream issueResolution: This issue pertains to software that the Qubes OS Project does not develop or control.Resolution: This issue pertains to software that the Qubes OS Project does not develop or control.