Re: Versioning system

From: Nomak (no.email_at_invalid.domain.fr)
Date: 06/04/04


Date: Fri, 4 Jun 2004 16:16:40 +0200

Le 04/06/2004 à 05:03:55, Nomak <no.email@invalid.domain.fr> a écrit:

> Hello,
>
> i need to choose a versioning system on the linux platform. The thing
> is that i need to host the tools on my personnal computer and i'm
> worried about security. I already now some way to do that but i don't
> find them apropriate (about security):
>
> * CVS pserver => traffic is in "plain text"
> * CVS/SSH => OpenSSL is too present in bugtrack
> * Subversion => the same because of apache, and also i'm not familiar
> with SSL management.
>
> does anybody knows other working solutions?

Thx for your answers

* i've looked the arch tutorial, and beside the really not standard
filenames ("=README" ??) it seems to have some ideas. But the
ftp/http/... traffic is also in plain text and the cryptic traffic is
handled by sftp.

Matt, your method is not applicable. I can't spend my time applying
patches send by email. And i need a http repository somewhere.

* I know CVS and subversion are used in production system, but these
production system genrallyhave automated backup systems, and the
apache is configured by someone who know security, read bugtrack and
patch whenever necessary.

I won't do that.

I don't think would-be "attackers" do not exists.

* I don't really know the difference between OpenSSL and OpenSSH. All
i know is that i don't want a ssh server listenin to the internet.

Still searching... (bitkeeper is the next)

-- 
Nomak


Relevant Pages

  • [NEWS] OpenSSL ASN.1 Parsing Vulnerabilities
    ... Get your security news from a reliable source. ... OpenSSL ASN.1 Parsing Vulnerabilities ... SSLv2 Client Crash ... SHA1 checksum: 4136fba00303a3d319d2052bfa8e1f09a2e12fc2 ...
    (Securiteam)
  • Re: The OpenSSL API
    ... if I have an application and want for it communicate ... between the black box approach and the gory-detail OpenSSL ... There is also no one best kind of security for all applications and users. ... OpenSSL is not the most secure facility, ...
    (comp.os.linux.networking)
  • Re: Windows Is Now More Secure Than Linux
    ... >OpenSSL is compiled into just about every 'secure' application in the Unix ... You know, a lot of people see me as a "Windows defender", mainly because I pop ... The solution, if there is one, to security problems, is to choose a supplier ...
    (comp.security.misc)
  • Security Vulnerability in Apache OpenSSL
    ... SSRT 2310 OpenSSL Vulnerabilities ... The information in the following Security Bulletin should be acted ...
    (comp.security.misc)
  • Security Vulnerability in Apache OpenSSL
    ... SSRT 2310 OpenSSL Vulnerabilities ... The information in the following Security Bulletin should be acted ...
    (comp.security.unix)