Bug 55528 - deprecation warning when using username:password authentication in a sources.list file
Summary: deprecation warning when using username:password authentication in a sources....
Status: NEW
Alias: None
Product: UCS
Classification: Unclassified
Component: Update - Repository administration
Version: UCS 5.0
Hardware: Other Linux
: P5 normal
Target Milestone: ---
Assignee: UCS maintainers
QA Contact: UCS maintainers
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-01-04 11:41 CET by Dirk Ahrnke
Modified: 2026-01-05 11:17 CET (History)
5 users (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 3: Simply Wrong: The implementation doesn't match the docu
Who will be affected by this bug?: 3: Will affect average number of installed domains
How will those affected feel about the bug?: 2: A Pain – users won’t like this once they notice it
User Pain: 0.103
Enterprise Customer affected?: Yes
School Customer affected?: Yes
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number: 2024042621000057, 2025040821000179, 2025100721000043, 2026010421000028
Bug group (optional): Security
Customer ID:
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Dirk Ahrnke univentionstaff 2023-01-04 11:41:22 CET
When using a protected repository it is common atm to put username:password into a deb repo definition into a /etc/apt/sources.list.d/*list.
The line are generated by UCRVs documented in https://docs.software-univention.de/developer-reference/5.0/en/repositories.html#integrate-with-ucsucr

This attempt now generates a warning during "apt update":

N: Die Verwendung von apt_auth.conf(5) sollte gegenüber der Methode bevorzugt werden, Login-Informationen direkt in den sources.list(5)-Abschnitt für »https://service.software-univention.de/
univention-repository/apt/99999/5.0/maintained/component« einzutragen.
N: Die Verwendung von apt_auth.conf(5) sollte gegenüber der Methode bevorzugt werden, Login-Informationen direkt in den sources.list(5)-Abschnitt für »https://service.software-univention.de/
univention-repository/apt/99999/5.0/maintained/component« einzutragen.


this affects our own customer repositories as well as protected repos used by partners like OX or Kopano.
Comment 1 Christina Scheinig univentionstaff 2025-04-08 16:18:56 CEST
I do not think, this is only a feature request, it is a bug, because you need a workaround to enable protected repositories
Comment 2 Dirk Schnick 2025-04-08 16:42:59 CEST
Seen today in a customer environment. Searched for that bug with auth, apt and apt_auth.
Hope I would find the bug from now with that keywords :D