4 ms·
Dunno why you got downvoted, you are exactly correct. Another thing that rots when it's "years" is the trusted CA bundle, so you cannot even talk to remote pee
by outsomnia 5y ago
Dunno why you got downvoted, you are exactly correct.
Another thing that rots when it's "years" is the trusted CA bundle, so you cannot even talk to remote peers until you update it.
- xyzzy123 5y agoThe usual trick is to mount /etc/ssl/certs from the host. This also means stuff like "extra" CAs can be configured at host level. The packaging issues... 99% of all CVEs are junk, in context - not reachable except in exotic configurations, component not used in container, kernel bugs reported against kernel headers package in the container because of course no docker scanner filters those out, cve is actually misreported, tons of "locally" (aka not) exploitable issues esp privesc... but yeah, ok, it's the 1/100 that gets you.