1.2.1.14 Ensure AllowDowngradeToInsecureRepositories is configured

Information

The APT configuration option Acquire::AllowDowngradeToInsecureRepositories controls whether APT will silently fall back to an insecure (unsigned or weakly signed) repository when a secure version of the same repository is unavailable. When set to 1, APT permits this downgrade without user confirmation. This option should be explicitly set to 0 to prevent silent downgrade attacks.

Allowing silent downgrade to insecure repositories creates a downgrade attack vector. An attacker who can block access to the HTTPS or signed version of a repository (through network interference, DNS poisoning, or mirror compromise) could force APT to fall back to an insecure alternative under their control. This would allow serving malicious packages that APT accepts without warning. Explicitly setting AllowDowngradeToInsecureRepositories "0" ensures APT fails loudly rather than silently accepting an insecure fallback.

Solution

Create or append to a configuration file to explicitly disable insecure repository downgrade:

# echo 'Acquire::AllowDowngradeToInsecureRepositories "0";' >> /etc/apt/apt.conf.d/99-no-insecure-repositories

Verify the setting has taken effect:

# apt-config dump | grep AllowDowngradeToInsecureRepositories

Note: All configuration files under /etc/apt/apt.conf.d/ are processed in lexicographic order. Where conflicting settings exist, the last one takes precedence.

Impact:

Setting AllowDowngradeToInsecureRepositories "0" means that if a secure repository becomes temporarily unavailable and an insecure fallback is configured, apt update will fail rather than falling back silently. This is the safer failure mode - administrators will be alerted to the unavailability of the secure repository rather than unknowingly operating against an insecure one.

See Also

https://workbench.cisecurity.org/benchmarks/27797

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Unix

Control ID: a22ac65ab01023c8944f873a74049b154510fe211110eba272ce9f81a999dd10