Re: How best to secure CVS?

From: yap_noel
Subject: Re: How best to secure CVS?
Date: Thu, 8 Nov 2001 09:24:13 -0500

I prefer using SSH.  pserver stores the password (mildly encrypted) on the
file system (eg root can figure it out).


I was wondering if there was information out there on how best to secure

How secure is the pserver mode?  Can a user who has a CVS account gain root
access on a system running pserver?

I am not concerned with the passwords being passed in the clear because I
using STUNNEL for the pserver protocol.

How useful is it to setup a chroot environment?

Thanks for any info, pointers, etc...


John Villalovos
Intel Corporation
BEAVERTON, OR  97006-5762
(503) 677-5777   Fax: (503) 677-6670

GPG 1.+/PGP 5.+/ DSS/Diffie Helman
1024D/1A25D86C 2F24 AD89 E5D5 C92B 7FE2  F878 7ED5 2D38 1A25 D86C

