[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: cvs and security

* Peter Jay Salzman <p@dirac.org> [2001.11.27 09:47:30-0800]:
> is there a way to use ssh for cvs without giving people shell access on my
> machine?   giving user cvs a shell of /bin/false seems to screw up cvs.

no, but look at stunnel and tunnel pserver traffic through SSL.
pserver is insecure because it sends the CVS data clear-text, works
with clear-text passwords, and because it runs as root.

martin;              (greetings from the heart of the sun.)
  \____ echo mailto: !#^."<*>"|tr "<*> mailto:"; net@madduck
your fly might be open (but don't check it just now).

Attachment: pgpA3EX7KrJLF.pgp
Description: PGP signature

Reply to: