Re: Problems with anonymous CVS on ddp?
On Fri, Sep 05, 2003 at 01:38:05AM +0200, Josip Rodin wrote:
> On Thu, Sep 04, 2003 at 10:19:41PM +0200, Denis Barbier wrote:
> > barbier@klecker:~$ cat /org/www.debian.org/ddp/cvs.log
> > Fatal error, aborting.
> > anonymous: no such user
> >
> > Same here from my own box, CVS operations work when being authenticated
> > but not with :pserver:anonymous. And everything works well for /cvs/webwml,
>
> Someone had removed anonymous from the passwd file. It could have been
> Osamu, I remember him complaining about some security aspect. I've restored
> it until further discussion.
What ??? Me ??? You must be kidding.
We certainly discussed security issues related to anonymous CVS.
First of all, the issue I raised will not be fixed by disabling
anonymous CVS for DDP. Issue was on anonymous CVS access to webwml.
Thus, I have no reason to do so.
Secondly, I did not recall acting on it either.
Thirdly, I am sometimes spaced and also sometimes stupid. Thus I can not
prove my innocence.
Fourthly, the solution Josip proposed for webwml was not much fun for me
so I kept quiet.
Anyway, I think keeping anonymous for DDP is GOOD thing and see no
issues.
Regards,
Osamu
Reply to: