ubuntu-cloud template: use simplestreams to add integrity verification

Bug #1182458 reported by Serge Hallyn
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
lxc (Ubuntu)
Fix Released
Medium
Scott Moser

Bug Description

Currently we wget the ubuntu-cloud template without any integrity verification. We then proceed to execute binaries like /bin/passwd while still in the ubuntu-cloud template (in a chroot, but without any effective containment). We should be verifying that the image we download has not been tampered with.

Changed in lxc (Ubuntu):
status: New → Triaged
importance: Undecided → Medium
assignee: nobody → Scott Moser (smoser)
Revision history for this message
Stéphane Graber (stgraber) wrote :

The current donwload template model to download those images does do both https and gpg validation.

Changed in lxc (Ubuntu):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.