[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

CVS and Security



I have been reading up on CVS Security and something has become quite
apparent.  CVS is a gaping security hole.  The pserver method is easily spied
upon and using rsh, ssh, etc. require all CVS users to have accounts on the
box, trusting the users to use a secure access method and not rsh.  It looks 
to me that to really secure CVS we will need to have it on a separate box 
so that compromises that happen on it don't risk the whole site.  This is more 
long-term, but something we should probably discuss at some point.  

At any rate, I don't see any really good way to secure CVS right now,
short of turning off the pserver method and requiring everyone to use ssh/fsh.

Do we want to do this?

-- 
-------------------
Daniel E. Markle
syntax@ashtech.net
-------------------