From owner-freebsd-security@FreeBSD.ORG Tue Jan 31 05:37:52 2006 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6757916A420 for ; Tue, 31 Jan 2006 05:37:52 +0000 (GMT) (envelope-from darren.pilgrim@bitfreak.org) Received: from mail.bitfreak.org (mail.bitfreak.org [65.75.198.146]) by mx1.FreeBSD.org (Postfix) with ESMTP id 18F7743D49 for ; Tue, 31 Jan 2006 05:37:51 +0000 (GMT) (envelope-from darren.pilgrim@bitfreak.org) Received: from smiley (mail.bitfreak.org [65.75.198.146]) by mail.bitfreak.org (Postfix) with ESMTP id 96DE319F40; Mon, 30 Jan 2006 21:37:48 -0800 (PST) From: "Darren Pilgrim" To: Date: Mon, 30 Jan 2006 21:37:45 -0800 Message-ID: <003101c62628$79daaf40$672a15ac@smiley> MIME-Version: 1.0 Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: 7bit X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook, Build 10.0.6626 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180 In-Reply-To: <43DE799B.40103@greenmeadow.ca> Importance: Normal Cc: freebsd-security@freebsd.org Subject: RE: Is CVS security on topic for this list? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 31 Jan 2006 05:37:52 -0000 From: Duane Whitty > > I'm wondering about the security implications of running a CVS server > with group write permission on the repository and various other > configuration details. Is this an appropriate discussion for this > list? If it is I have a setup I'd like some feedback on. If this is > not the appropriate list please accept my apologies for the > distraction. If you're running on FreeBSD and want to discuss the security implications of your configuration, I would say yes. If it were, me, however, I'd probably try my luck on the GNU CVS mailing lists[1] first. Specifically, the info-cvs list. [1] http://savannah.nongnu.org/mail/?group=cvs