Tune apt-transport-http Without Losing Security

apt-transport-http is the plumbing behind every http:// repository URL, and bolting on a proxy or a bandwidth cap can quietly weaken it. This covers a proxy, a host exception, a timeout, bandwidth limiting and redirect handling, using the installed behaviour from APT 2.8.3 on Ubuntu 24.04.

Allow about fifteen minutes. You need an administrator account, a working APT configuration and, for the download test, network access to the repositories in /etc/apt/sources.list or /etc/apt/sources.list.d/. You never run this transport yourself; APT selects it whenever a configured repository uses an http:// URI.

Security boundary: HTTP is unencrypted. Anyone able to observe the connection can see the traffic to the repository or proxy. APT's package authentication is a separate layer and stays intact regardless, but it does not make HTTP private. Prefer HTTPS repositories where they exist, and never put proxy passwords directly into a world-readable configuration file.

1. Confirm the installed transport

Start with read-only checks. These are ordinary commands and need no sudo:

$ apt-get --version | sed -n '1,2p'
apt 2.8.3 (amd64)
Supported modules:
$ dpkg-query -W -f='${Package} ${Version}\n' apt
apt 2.8.3

The exact second line can vary with the build. The checkpoint that matters is that the package and the transport come from the same APT installation. You can also read the transport's local manual:

$ man apt-transport-http

Do not try to invoke a transport helper directly like it is curl. APT owns connection setup, repository metadata, package verification and retry decisions, all of it.

2. Choose the smallest proxy change

APT accepts a general proxy in Acquire::http::Proxy, plus a host-specific override such as Acquire::http::Proxy::packages.example.org. The special value DIRECT bypasses a proxy for that one host. Supported proxy URI schemes are http, https and socks5h, the last of which resolves host names through the SOCKS proxy itself.

For a persistent setting, create a dedicated file rather than editing a distribution-managed one. This example assumes an HTTP proxy on a local port, with one repository host left outside it:

$ sudoedit /etc/apt/apt.conf.d/80http-transport

Put this in the editor, swapping the example host and port for values your network administrator actually gave you:

Acquire::http {
  Proxy "http://127.0.0.1:3128/";
  Proxy::packages.example.org "DIRECT";
};

Save, exit, then check what APT actually reads back:

$ apt-config dump | grep -E '^Acquire::http::(Proxy|Proxy::)'
Acquire::http::Proxy "http://127.0.0.1:3128/";
Acquire::http::Proxy::packages.example.org "DIRECT";

Checkpoint: if that output contains a password, stop and move the credential to apt_auth.conf(5) or your site's approved secret mechanism instead. Treat any proxy URL containing user:pass@ as a secret, even inside a root-owned file.

3. Add connection limits deliberately

Put only the limits you actually need in the same file. This example gives connections a ten-second timeout and caps the transport at 512 kilobytes per second:

Acquire::http {
  Proxy "http://127.0.0.1:3128/";
  Proxy::packages.example.org "DIRECT";
  Timeout "10";
  Dl-Limit "512";
};

Timeout covers both connection and data activity. Dl-Limit takes an integer number of kilobytes per second, and defaults to 0, meaning no transport-level limit at all. Here is the surprising part: a non-zero download limit also disables downloading from multiple servers at once, so it can make a busy machine slower even when the number itself looks generous.

Verify the parsed values before you attempt a download:

$ apt-config dump | grep -E '^Acquire::http::(Timeout|Dl-Limit)'
Acquire::http::Timeout "10";
Acquire::http::Dl-Limit "512";

Missing a value? Check braces, semicolons and the filename first. APT configuration is case-sensitive in option names, and it is easy to assume a setting from a shell profile or another tool is being picked up by APT when it is not.

4. Decide how redirects should work

HTTP redirects are followed by default. For a repository environment where an unexpected redirect should fail loudly instead, add this:

Acquire::http {
  Proxy "http://127.0.0.1:3128/";
  Proxy::packages.example.org "DIRECT";
  Timeout "10";
  Dl-Limit "512";
  AllowRedirect "false";
};

This is a policy choice, not a general hardening switch. Some repository mirrors deliberately redirect clients, so test it against every configured source before you rely on it. The transport's default HTTP pipelining depth is 10. If a known broken server or proxy cannot handle HTTP/1.1 pipelining, set Pipeline-Depth to 0 as a targeted fix instead of touching unrelated settings.

5. Test through APT

Warning: apt-get update downloads repository metadata and changes the local package-list cache. It does not install or remove packages, but still run it during a sensible maintenance window on a production host, since it needs elevated privileges to write under /var/lib/apt/lists:

$ sudo apt-get update
Hit:1 http://packages.example.org/ubuntu noble InRelease
Reading package lists... Done

Your lines will differ. A successful run shows APT could resolve the source, connect using the selected route, and retrieve metadata that passed its own repository checks. A failure mentioning a proxy usually points at the URI, listener, authentication or host exception. A failure mentioning a redirect lines up with AllowRedirect "false".

For a quick experiment, skip editing the file and override one value on the command line instead:

$ sudo apt-get -o Acquire::http::Proxy="DIRECT" update

This does not remove the persistent setting; it only affects that one invocation, which is useful for separating a proxy fault from a repository or DNS fault.

6. Recover cleanly

If the new policy breaks updates, restore service first with a one-command bypass:

$ sudo apt-get -o Acquire::http::Proxy="DIRECT" \
    -o Acquire::http::AllowRedirect="true" update

Then remove or edit only the file you created. This is an administrator action that changes persistent behaviour:

$ sudoedit /etc/apt/apt.conf.d/80http-transport
$ apt-config dump | grep '^Acquire::http::' || true

Delete the file to fall back to the distribution and environment defaults. If you used the http_proxy environment variable instead, unset it in whatever shell or service environment launched APT. Check both places when results seem inconsistent: a command-line override wins for that invocation, while a host-specific proxy rule beats automatic proxy detection for that host.

Done means