info-cvs
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: CVS, RSH and direct access to repository


From: Greg A. Woods
Subject: Re: CVS, RSH and direct access to repository
Date: Fri, 16 Jan 2004 16:46:40 -0500 (EST)

[ On Friday, January 16, 2004 at 12:36:14 (+0100), Claus Henriksen wrote: ]
> Subject: Re: CVS, RSH and direct access to repository
>
> Well, what then if you tunnel pserver like explained in 
> http://wwwhome.cs.utwente.nl/~klaren/index.html?left.html&cvs-stunnel.html ?

Network tunnels in no way change the fact that :pserver: provides
absolutely no security whatsoever, and indeed presents many risks over
and above those that are present with something like RSH (i.e. also
through a tunnel if the RSH connection must pass over an untrusted
network).

DO NOT USE pserver for anything but _anonymous_ (and presumably
read-only) access!

-- 
                                                Greg A. Woods

+1 416 218-0098                  VE3TCP            RoboHack <address@hidden>
Planix, Inc. <address@hidden>          Secrets of the Weird <address@hidden>




reply via email to

[Prev in Thread] Current Thread [Next in Thread]