On Mon, Jun 16, 2003 at 03:06:56AM -0400, Abdul Latip wrote:

ehem .. :-)

> 1. Is it considered a security risk to put the root into the
>    /var/www/cvs/ (web) directory while protecting the CVSROOT/ 
>    directory?

mungkin tidak, selama httpd user tidak punya akses tulis ke
dir ybs. (read only).

> 2. Is it considered a problem to share one CVS server account with
>    several cvs (external) users?

kalau read-only, no problemo. setidaknya kalau ada problem, tanpa ini
juga sudah bisa timbul problem. bahkan dengan modus pserver, kalau
tidak run as root, kita men-share 1 uid untuk banyak user.

> 3. I have set "PasswordAuthentication no" on the CVS server
>    /etc/ssh/sshd_config file.

justru lebih safe?

kenapa tidak di-chroot saja sekalian?

Salam,

P.Y. Adi Prasaja


--
Right or wrong my list. Unsubscribe option is currently unavailable.
Indeed, it's available upon request .. but: cepek dulu donk!

Kirim email ke