1.2.1.11 Ensure repositories are set to https in /etc/apt/sources.list.d directory

Information

APT supports both HTTP and HTTPS transport for repository access. While official repositories for the target distributions use HTTPS by default, custom or third-party repositories added by administrators may be configured with HTTP. Repositories served over plain HTTP are susceptible to network interception - an attacker positioned between the system and a mirror could suppress specific security updates, withholding patches to keep the system vulnerable to known exploits, or intercept repository metadata to profile installed software versions.

APT verifies package integrity via GPG signatures, but plain HTTP transport leaves repository metadata and package lists exposed to network interception. An attacker positioned between the system and a repository mirror could suppress specific security updates, preventing patches from being applied and keeping the system vulnerable to known exploits. Enforcing HTTPS transport ensures the integrity and confidentiality of the repository communication channel, complementing GPG signature verification.

Solution

Edit each file in /etc/apt/sources.list.d/ that contains HTTP repository URIs and replace http:// with https://.

Example - legacy .list format:

deb https://deb.debian.org/debian bookworm main

Example - deb822 .sources format:

URIs: https://deb.debian.org/debian

Impact:

Changing a repository from HTTP to HTTPS requires that the repository server supports HTTPS. For local mirrors that serve only HTTP, switching the client to HTTPS without a corresponding server-side change will cause apt update to fail for that repository.

See Also

https://workbench.cisecurity.org/benchmarks/27797

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: d9811b54a650a5ddafa5f681064b11c42a799293258d507e49ec794680718d3a