[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: CVS



On Sun, 31 Oct 1999, Jason Pincin wrote:

[snip]

> Aaron answerd one of my questions.  I just don't want it to be a
> requirment in the future for a developer to have a shell account.  I think
> thats ludicrous to state as a requirment.  More shells = less security.
> But, Aaron points out the possibility of making it a web-based cgi script,
> so they could force the update through a browser, thus removing the shell
> requimenr, which is fine.  
> 
> You also answered why bother doing ssh cvs.  Thats fine too, but can we
> tunnel cvs over ssh without a shell account?  If so great, otherwise
> tunneling cvs over ssh should not ever be a requirment either.

Well to use ssh you have to have a vaild shell on the "server".   I was
looking into using a restricted shell or even a bogus shell to reduce the
security risk.  I was able to run some sucessful CVS tests, but then got
distracted... you know the rest.

BTW, I'm on IRC...

--
Aaron Turner, Core Developer       http://vodka.linuxkb.org/~aturner/
Linux Knowledge Base Organization  http://linuxkb.org/
Because world domination requires quality open documentation.