{"id":160,"date":"2008-08-20T12:04:22","date_gmt":"2008-08-20T20:04:22","guid":{"rendered":"http:\/\/www.outflux.net\/blog\/?p=160"},"modified":"2008-09-16T12:43:20","modified_gmt":"2008-09-16T20:43:20","slug":"ubuntu-security-repository-structure","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2008\/08\/20\/ubuntu-security-repository-structure\/","title":{"rendered":"Ubuntu security repository structure"},"content":{"rendered":"<p><a href=\"http:\/\/mruiz.openminds.cl\/blog\/index.php\/2008\/08\/20\/security-packages-in-ubuntu\/\">Miguel Ruiz<\/a> asked about Ubuntu security repositories.  Here&#8217;s how things are done:<\/p>\n<p>The &#8220;security.ubuntu.com&#8221; archive contains explicitly only the &#8220;$RELEASE-security&#8221; pockets.  It is included in all Ubuntu <code>sources.list<\/code> files so that the package manager knows what the most recent security release of a package will be.<\/p>\n<p>The central &#8220;archive.ubuntu.com&#8221; server (and all the Ubuntu mirrors) also contain the &#8220;$RELEASE-security&#8221; pockets, in addition to the rest of the archive (and will continue to have all pockets &#8212; which answers the core of Miguel&#8217;s question).  While mirrors are not required to mirror the -security pocket, it certainly helps with the load on the primary Ubuntu archive servers.<\/p>\n<p>The &#8220;security.ubuntu.com&#8221; entry is last in <code>sources.list<\/code>, giving the option of pulling an updated package from an earlier mentioned mirror (resulting in a faster download for the user, and less bandwidth used by the central Ubuntu archive servers).  In the case that the mirror is behind, the package is available directly from &#8220;security.ubuntu.com&#8221;.  In this way, mirrors cannot (accidentally or intentionally) &#8220;go rogue&#8221; &#8212; the latest security updates are always visible on the security archive server.<\/p>\n<p style='text-align:left'>&copy; 2008, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Miguel Ruiz asked about Ubuntu security repositories. Here&#8217;s how things are done: The &#8220;security.ubuntu.com&#8221; archive contains explicitly only the &#8220;$RELEASE-security&#8221; pockets. It is included in all Ubuntu sources.list files so that the package manager knows what the most recent security release of a package will be. The central &#8220;archive.ubuntu.com&#8221; server (and all the Ubuntu mirrors) [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,6,14,19],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/160"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=160"}],"version-history":[{"count":0,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/160\/revisions"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=160"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=160"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=160"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}