Skip to content

File downloads performed by Salt in a TemplateVM fail #4231

@DemiMarie

Description

@DemiMarie

Qubes OS version:

R4.0

Affected component(s):

qubes-core-admin, though this mostly causes problems when using Salt.


Steps to reproduce the behavior:

Run gpg --recv-keys with any keyserver in a TemplateVM.

Expected behavior:

The updates proxy should allow traffic to the keyserver

Actual behavior:

Access to the keyserver is denied.

General notes:

This was originally discovered when using SaltStack to add apt repositories to a template. Using a keyserver and key ID (the most secure way of adding the key, without requiring the key to be copied into dom0) does not work. Copying the key into dom0 might work (and, since the key would never be parsed by anything whatsoever in dom0, only passed as a stream of bytes, might even be safe), but I did not try.


Related issues:

Possibly #1955?

Metadata

Metadata

Assignees

No one assigned

    Labels

    C: SaltThis issue pertains to the use of Salt (aka SaltStack) in Qubes OS.C: templatesThis issue pertains to templates in general (as opposed to specific templates).P: defaultPriority: default. Default priority for new issues, to be replaced given sufficient information.R: upstream issueResolution: This issue pertains to software that the Qubes OS Project does not develop or control.

    Type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions