1.2.1.15 Ensure Acquire::Check-Date is configured

Information

The APT configuration option Acquire::Check-Date controls whether APT verifies that the system clock is plausible relative to the Valid-Until field in a repository's Release file. When enabled (the default), APT will reject Release files dated significantly in the future or past, preventing the use of stale repository metadata. This option should be explicitly set to true to ensure this validation is always active and cannot be silently disabled by other configuration.

Repository Release files include a Valid-Until field specifying a date after which the metadata should be considered stale. A man-in-the-middle attacker who intercepts APT traffic could serve an older Release file to make the system appear up-to-date while pinning it to outdated, vulnerable package versions. Without clock validity checking, APT may accept stale metadata and report no available updates, leaving known vulnerabilities unpatched. Explicitly enabling Acquire::Check-Date prevents this class of replay attack against the APT update process.

Solution

Create or append to a configuration file to explicitly enable date checking:

# printf '%s\n' "" 'Acquire::Check-Date "true";' >> /etc/apt/apt.conf.d/99-no-insecure-repositories

Verify the setting has taken effect:

# apt-config dump | grep -Psi -- 'Acquire::Check-Date'

Note: All configuration files under /etc/apt/apt.conf.d/ are processed in lexicographic order. Where conflicting settings exist, the last one takes precedence.

Impact:

If the system clock is significantly incorrect (e.g., due to misconfigured NTP, hardware clock drift, or clock manipulation), enabling Check-Date will cause apt update to fail with a date-related error. Ensure NTP synchronization is correctly configured (see the Time Synchronization section of the benchmark) before applying this setting. This is a fail-safe behavior that prevents operating against potentially stale repository metadata.

See Also

https://workbench.cisecurity.org/benchmarks/27797

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-11, 800-53|SI-12, CSCv7|7.3

Plugin: Unix

Control ID: 4317b75cdfaae56db4bbf9f61b0c739ebf01d3d86bb24b02e2764ff2570e80a0