Re: PAM Patch (was Re: authenticating cvs against ldap)

From: Derek Robert Price
Subject: Re: PAM Patch (was Re: authenticating cvs against ldap)
Date: Sun, 20 Jul 2003 12:42:52 -0400
Brian Murphy wrote:

Derek Robert Price wrote:

1.  Your patch needs a ChangeLog entry.

Has been sent.

Okay, I committed the PAM stuff. Your ChangeLog was a bit terse. I rewrote one instead of sending it back this time since I felt bad about putting this off for so long, so you can look at what I did for pointer on your next one. I'll probably send the next one back for revisions.

3. I think I would also like future clients to accept a "-p" option to always request the password from the command line rather than looking in ~/.cvspass so that users have the option to use a password not either stored in ~/.cvspass or passed in on the command line. I will write this soon.

This should not be too bad to impliment. I'm not sure how many will be willing to use it though.
It's hard to get used to inconvenience.

Security and convenience are almost always a trade-off, but I'd like to let individual users and sysadmins have the choice on this one.



Email: derek@ximbiot.com

Get CVS support at <http://ximbiot.com>!
There is not a truth on earth which I fear or would disguise.  But secret 
slanders cannot be disarmed, because they are secret.

                        - Thomas Jefferson to William Duane, 1806

