Dear Wiki user,

You have subscribed to a wiki page or wiki category on "Subversion Wiki" for 
change notification.

The "MasterPassphrase" page has been changed by CMichaelPilato:
http://wiki.apache.org/subversion/MasterPassphrase?action=diff&rev1=35&rev2=36

Comment:
My concern about U.S. export controls has been alleviated.

   * Portability:  {{{~/.subversion/auth/}}} is portable across computers, 
allowing users to transfer what could be hundreds of different sets of stored 
repository credentials to other machines with ease.  So long as they employed 
the same master passphrase on those other machines, or did a one-time 
passphrase change, they would be able to make use of previously cached 
credentials.
  
  == Concerns ==
-  * Implementation of built-in encryption mechanisms tied to a "master 
passphrase" secret key might possibly complicate Subversion's distribution per 
the export control restrictions placed on such technologies. We need to 
understand and carefully consider the scope of that complication.
   * Is the Subversion codebase -- and the authn subsystem specifically -- 
capable of handling this sort of approach?  (Research continues.)
  
  The following IRC conversation occurred in irc.freenode.net ##crypto, and 
carries some concerns/questions about the planned approach raised by a user 
therein:

Reply via email to