info-cvs archive search

Search String: Display: Description: Sort:

Results:

References: [ pserver: 4404 ] [ security: 1340 ]

Total 529 documents matching your query.

321. Re: questions on CVS, WinCVS (score: 9)
Author: HIDDEN
Date: Mon, 25 Feb 2002 17:31:22 -0500 (EST)
[ On Monday, February 25, 2002 at 21:06:40 (+0300), Leonid Krutyansky wrote: ] What, exactly, do you mean by "lock"? CVS controls commit permissions by who can write to the directory in the repositor
/archive/html/info-cvs/2002-02/msg01100.html (6,619 bytes)

322. questions on CVS, WinCVS (score: 9)
Author: HIDDEN
Date: Mon, 25 Feb 2002 21:06:40 +0300
Hi, I'm starting using CVS and would be highly appreciated if somebody could answer the following questions: 1. I need to lock some (not all) files from editing by other users. I have WinCVS 1.2 clie
/archive/html/info-cvs/2002-02/msg01073.html (5,476 bytes)

323. Re: ANN: cvssh - secure ext-to-pserver bridge (score: 177)
Author: HIDDEN
Date: Fri, 22 Feb 2002 16:48:57 -0500 (EST)
[ On Friday, February 22, 2002 at 05:46:34 (-0800), David A. Desrosiers wrote: ] What don't you understand about "read-only anonymous access"? Where in that phrase does it say anything about allowing
/archive/html/info-cvs/2002-02/msg00924.html (11,634 bytes)

324. Re: ANN: cvssh - secure ext-to-pserver bridge (score: 135)
Author: HIDDEN
Date: Fri, 22 Feb 2002 05:46:34 -0800 (PST)
Great, then once again, you make absolutely no sense. If I have a copy of the master, which allows anonymous read-only access, and that copy also accepts authenticated commits (via whatever solution
/archive/html/info-cvs/2002-02/msg00878.html (9,473 bytes)

325. Re: ANN: cvssh - secure ext-to-pserver bridge (score: 110)
Author: HIDDEN
Date: Fri, 22 Feb 2002 03:38:04 -0500 (EST)
[ On Thursday, February 21, 2002 at 18:44:19 (-0800), David A. Desrosiers wrote: ] I don't personally know if NetBSD's implementation of anonymous SSH access to their CVS repository is vulnerable or
/archive/html/info-cvs/2002-02/msg00870.html (11,555 bytes)

326. Re: ANN: cvssh - secure ext-to-pserver bridge (score: 148)
Author: HIDDEN
Date: Fri, 22 Feb 2002 01:25:15 -0500 (EST)
[ On Thursday, February 21, 2002 at 18:38:15 (-0800), David A. Desrosiers wrote: ] If you're blind and stupid enough to sync a read-only anonymously accessed repository back to the master then you're
/archive/html/info-cvs/2002-02/msg00869.html (8,783 bytes)

327. RE: ANN: cvssh - secure ext-to-pserver bridge (score: 147)
Author: HIDDEN
Date: Thu, 21 Feb 2002 22:16:59 -0500
Sorry, I've gotta jump in for a minute... Greg is right about SSH v pserver, however. Read up on rsync via an ssh tunnel to do this. Sudo, and noshell for a non-priviliged role account are also advis
/archive/html/info-cvs/2002-02/msg00863.html (9,365 bytes)

328. Re: ANN: cvssh - secure ext-to-pserver bridge (score: 133)
Author: HIDDEN
Date: Thu, 21 Feb 2002 18:38:15 -0800 (PST)
And if the copy needs to get sync'd back to the "real" repository (a definate requirement), there goes your security. Next idea? i.e. you give them no access. Hence, pserver. I don't want to give ou
/archive/html/info-cvs/2002-02/msg00860.html (8,161 bytes)

329. Re: Pserver Protocol (score: 120)
Author: HIDDEN
Date: Thu, 21 Feb 2002 19:31:50 -0500 (EST)
[ On Thursday, February 21, 2002 at 17:58:51 (-0500), Larry Jones wrote: ] Just to be pedantic...... Note cvsclient.texi documents not just the cvspserver protocol per se -- but rather the whole gene
/archive/html/info-cvs/2002-02/msg00848.html (5,430 bytes)

330. Re: ANN: cvssh - secure ext-to-pserver bridge (score: 160)
Author: HIDDEN
Date: Thu, 21 Feb 2002 16:05:46 -0500 (EST)
[ On Thursday, February 21, 2002 at 18:59:36 (GMT), David A. Desrosiers wrote: ] There's only _EXACTLY_ one case where cvspserver is in any way more secure than giving out real accounts, and that's w
/archive/html/info-cvs/2002-02/msg00821.html (11,053 bytes)

331. Re: ANN: cvssh - secure ext-to-pserver bridge (score: 110)
Author: HIDDEN
Date: Thu, 21 Feb 2002 19:06:19 GMT
I'm intrigued. If you feel so strongly about eradicating pserver, then help those who wish to understand why. Have you written a HOWTO that explains how to set up read-only anonymous ssh access as w
/archive/html/info-cvs/2002-02/msg00812.html (7,500 bytes)

332. Re: ANN: cvssh - secure ext-to-pserver bridge (score: 136)
Author: HIDDEN
Date: Thu, 21 Feb 2002 18:59:36 GMT
Except in the cases where using pserver is actually _MORE_ secure than giving users a valid unix account on your server. I could very well trust my developers, and give them shell accounts, but I ca
/archive/html/info-cvs/2002-02/msg00811.html (7,805 bytes)

333. Re: cvsclient (score: 12)
Author: HIDDEN
Date: Thu, 14 Feb 2002 18:12:09 +0100
since company) ssh type would not the client have to support it then? this way the client does not have to support ssh and we can then have more clients to choose from, atleast that is what I think
/archive/html/info-cvs/2002-02/msg00497.html (4,950 bytes)

334. RE: SECURITY BUG in CVS 1.11.1 (score: 164)
Author: HIDDEN
Date: Tue, 12 Feb 2002 15:06:30 -0500
Sorry, but can you provide a reference url, or ftp path for this update? I checked out on http://ccvs.cvshome.org/servlets/ProjectDownloadList and the last version posted was v1.11p1 on 2001-10-16.
/archive/html/info-cvs/2002-02/msg00398.html (5,379 bytes)

335. Re: SECURITY BUG in CVS 1.11.1 (score: 164)
Author: HIDDEN
Date: Tue, 12 Feb 2002 08:45:28 -0800 (PST)
posted last september to address@hidden, no response from CVS community so I thought it was as designed. Anyhow, I wrote a taginfo trigger to validate user is in writers file to compensate. http://ww
/archive/html/info-cvs/2002-02/msg00380.html (6,140 bytes)

336. SECURITY BUG in CVS 1.11.1 (score: 164)
Author: HIDDEN
Date: Mon, 11 Feb 2002 17:04:47 -0500 (EST)
It has been brought to my attention that CVS 1.11.1 and 1.11.1p1 have a bug in pserver mode that allows read-only users to run the "tag" command. This allows read-only users to add and, more importan
/archive/html/info-cvs/2002-02/msg00338.html (4,993 bytes)

337. Re: Creating Per-User repositories (score: 38)
Author: HIDDEN
Date: Thu, 31 Jan 2002 12:47:22 -0800 (PST)
Greg has responded with most of what I wanted to say. I do have something to add, though. If your intent is to have students be able to grant access to other students, SSH is sufficient and is way mo
/archive/html/info-cvs/2002-01/msg01117.html (11,053 bytes)

338. Re: cvs security (score: 175)
Author: HIDDEN
Date: Thu, 31 Jan 2002 08:35:32 -0800 (PST)
If you want security (as the subject of your email suggests), use SSH instead of pserver. pserver has many insecurities. __________________________________________________ Do You Yahoo!? Great stuff
/archive/html/info-cvs/2002-01/msg01105.html (4,985 bytes)

339. cvs security (score: 164)
Author: HIDDEN
Date: Thu, 31 Jan 2002 14:39:00 +0100
Hello, I'm using cvs with mandrake 8.1 I wonder if pserver is the best way to proceed, but it seems to be easier to implement. These are the opérations i've done to implement pserver : -modify the c
/archive/html/info-cvs/2002-01/msg01099.html (4,715 bytes)

340. Re: security concept - set permissions for each directory - how to? (score: 177)
Author: HIDDEN
Date: Tue, 29 Jan 2002 16:51:11 -0600
I have a patch at http://home.attbi.com/~minyard that does what you want, and it has an SSL-based pserver. It does not support these functions over SSH, though. If you are willing to set up ACLs on y
/archive/html/info-cvs/2002-01/msg01029.html (6,181 bytes)


This search system is powered by Namazu