Description
An http:// URL for an Ansible Galaxy server can send role or collection requests and responses without encryption.
Potential impact
An actor able to intercept the network can read or alter metadata or download responses, undermining trust in automation dependencies.
Remediation
Set server in [galaxy] to a supported https:// URL and keep ignore_certs=False. Configure a trusted certificate for an internal server.
Examples
The examples compare connection schemes for the same Galaxy server. HTTPS protects transport; the packages themselves still need appropriate trust checks.
Before
text
[galaxy]
cache_dir=~/.ansible/galaxy_cache
ignore_certs=False
server=http://galaxy.ansible.com
After
text
[galaxy]
cache_dir=~/.ansible/galaxy_cache
ignore_certs=False
server=https://galaxy.ansible.com