Discussion:
(no subject)
Rez P
2009-03-02 18:03:32 UTC
Permalink
Hi all

Is there any way to set up CVS on a Redhat Linux server so users using wincvs on windows client machines could use the pserver method (or any method) to do regular CVS transactions (ci,co,add,etc) but don't actually have user id/pw on the linux server and no entries in /etc/passwd? For security reasons we just want them to have access to the repository and not anything else on the linux server.

Thanks

Rez
_________________________________________________________________
Express your personality in color! Preview and select themes for Hotmail®.
http://www.windowslive-hotmail.com/LearnMore/personalize.aspx?ocid=TXT_MSGTX_WL_HM_express_032009#colortheme
Rez P
2009-03-02 18:14:28 UTC
Permalink
Also is it possible to restrict access to or hide certain projects or modules from certain users?



From: ***@hotmail.com
To: info-***@nongnu.org
Date: Mon, 2 Mar 2009 10:03:32 -0800
Subject: (no subject)




Hi all

Is there any way to set up CVS on a Redhat Linux server so users using wincvs on windows client machines could use the pserver method (or any method) to do regular CVS transactions (ci,co,add,etc) but don't actually have user id/pw on the linux server and no entries in /etc/passwd? For security reasons we just want them to have access to the repository and not anything else on the linux server.

Thanks

Rez


Express your personality in color! Preview and select themes for Hotmail®. See how.
_________________________________________________________________
Windows Live™ Groups: Create an online spot for your favorite groups to meet.
http://windowslive.com/online/groups?ocid=TXT_TAGLM_WL_groups_032009
Todd Denniston
2009-03-02 18:15:54 UTC
Permalink
Post by Rez P
Hi all
Is there any way to set up CVS on a Redhat Linux server so users using wincvs on windows client machines could use the pserver method (or any method) to do regular CVS transactions (ci,co,add,etc) but don't actually have user id/pw on the linux server and no entries in /etc/passwd? For security reasons we just want them to have access to the repository and not anything else on the linux server.
Thanks
http://ximbiot.com/cvs/manual/cvs-1.11.23/cvs_2.html#IDX87

http://ximbiot.com/cvs/manual/cvs-1.11.23/cvs_2.html#SEC32
second paragraph:
"On the other hand, once a user has non-read-only access to the repository,
she can execute programs on the server system through a variety of means.
Thus, repository access implies fairly broad system access as well. It might
be possible to modify CVS to prevent that, but no one has done so as of this
writing."

i.e., you may be (probably are) buying yourself nothing. either you trust
your users or you don't.
Rez P
2009-03-02 18:34:14 UTC
Permalink
Loading...