From: Mike Ayers
Subject: Re: Security setup
Date: Tue, 17 Dec 2002 22:17:06 -0800
Larry Jones wrote:

Rewrite CVS?  Seriously, as I've said many times before, CVS was
designed to facilitate cooperative work, it was *not* designed to
enforce security in any way, shape, or form.  Any attempt to make it do
so is doomed to fail.

I'm not quite sure if this changes anything, but I don't need CVS to be a security application, just a securable one. Specifically, I want integrity and accountability. I don't care what happens in the repository, so long as we can be sure of who did what. I am aware that this requires security, I was just expecting the security to be handled external to CVS (chroot, ssh, etc.). Does this improve the picture for me?



