On Mon, 16 Jun 2003, adi wrote:

> ehem .. :-)
he... he... ;)

>> 1. Is it considered a security risk to put the root into the
>>    /var/www/cvs/ (web) directory while protecting the CVSROOT/ 
>>    directory?

> mungkin tidak, selama httpd user tidak punya akses tulis ke
> dir ybs. (read only).

Siip... saya masih agak gelap mengenai peranan CVSROOT.
Kalau subversion, ada yang pernah coba?

>> 2. Is it considered a problem to share one CVS server account with
>>    several cvs (external) users?

> kalau read-only, no problemo. setidaknya kalau ada problem, tanpa ini
> juga sudah bisa timbul problem. bahkan dengan modus pserver, kalau
> tidak run as root, kita men-share 1 uid untuk banyak user.

Modenya R/W, sebab tujuannya agar pokja bisa berkolaborasi via CVS.

> kenapa tidak di-chroot saja sekalian?

Caranya? melalui ~/.ssh/authorized_keys
Bisa kasih contoh?

BTW, ada yang kasih komentar:)

> Thank you for the nice list of links.  You pushed the envelope 
> further than I did.  I realize I may want to follow in your 
> footsteps later on, so your references will be useful to me.  

--
Abdul Latip -- Angkasa Internet Junior Staff -- ANGIN.com
http://people.WebIndonesia.com/dullatip/ ----------------



--
Right or wrong my list. Unsubscribe option is currently unavailable.
Indeed, it's available upon request .. but: cepek dulu donk!

Kirim email ke