1.2.1.12 Ensure AllowInsecureRepositories is configured

Information

The APT configuration option Acquire::AllowInsecureRepositories controls whether APT is permitted to access repositories that do not have a valid cryptographic signature on their InRelease or Release.gpg metadata files. When set to 1, APT bypasses repository authentication and will download package lists and packages from unsigned or improperly signed repositories without warning. This option should be explicitly set to 0 to enforce repository signature verification.

Allowing insecure repositories removes a critical layer of the APT trust chain. An attacker who can perform a man-in-the-middle attack, compromise a mirror, or redirect DNS could serve unsigned repository metadata and packages that APT would accept without verification. This could result in the installation of malicious or backdoored packages indistinguishable from legitimate ones. Explicitly setting AllowInsecureRepositories "0" ensures APT refuses to proceed when repository signatures are absent or invalid.

Solution

Create a configuration file to explicitly disable insecure repository access:

# printf '%s\n' "" 'Acquire::AllowInsecureRepositories "0";' >> /etc/apt/apt.conf.d/99-no-insecure-repositories

Verify the setting has taken effect:

# apt-config dump | grep AllowInsecureRepositories

Note: All configuration files under /etc/apt/apt.conf.d/ are processed in lexicographic order. Where conflicting settings exist, the last one takes precedence. The 99- prefix ensures this setting overrides any earlier configuration.

Impact:

Setting AllowInsecureRepositories "0" will cause apt update to fail for any repository that does not provide a valid signed InRelease or Release.gpg file. If a legitimate repository in use does not support signing, it must be removed or replaced with a signed alternative before applying this setting. Internal or private repositories must be configured to sign their metadata.

See Also

https://workbench.cisecurity.org/benchmarks/27797

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Unix

Control ID: 123ccd07d86b794c34cc5bfa40f3a53eb8714757e6171393f0de8164056100a2