Project

General

Profile

Actions

tickets #113327

closed

Should we allow mirrors on dynamic IPs?

Added by emendonca almost 2 years ago. Updated almost 2 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
Mirrors
Target version:
-
Start date:
2022-07-06
Due date:
% Done:

100%

Estimated time:

Description

I maintain a RMT server for a (rather large) SUSE corporate customer in Brazil, and yesterday I got a call from their network security team regarding some suspect activity while downloading packages from download.opensuse.org.

The case is, while downloading the SLE-15-SP4-Updates (5591) repository provided by SCC, it hit a mirror that is running on a high port (18555) and on a dynamic IP DNS hostname (mrfeps.myftp.org). This triggered a lot of alarms and concerns on whether this is a reputable source. They are very strict about network access and supply-chain security, being a financial institution, so this puts us in a very tight spot.

Please consider NOT allowing dynamic IPs for mirrors.

Actions

Also available in: Atom PDF