[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
CVS and Security
I have been reading up on CVS Security and something has become quite
apparent. CVS is a gaping security hole. The pserver method is easily spied
upon and using rsh, ssh, etc. require all CVS users to have accounts on the
box, trusting the users to use a secure access method and not rsh. It looks
to me that to really secure CVS we will need to have it on a separate box
so that compromises that happen on it don't risk the whole site. This is more
long-term, but something we should probably discuss at some point.
At any rate, I don't see any really good way to secure CVS right now,
short of turning off the pserver method and requiring everyone to use ssh/fsh.
Do we want to do this?
--
-------------------
Daniel E. Markle
syntax@ashtech.net
-------------------