[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: RFC: New authn/authz policy for svn.collab.net

From: Alec Kloss <alec.kloss_at_oracle.com>
Date: 30 Jul 2009 12:14:58 -0500

On 2009-07-30 12:37, C. Michael Pilato wrote:
> Arfrever Frehtes Taifersar Arahesis wrote:
[chop]
> > IMHO anonymous repository access should be still available over SSL connections.
>
> I disagree. Doing this adds unnecessary complication to the configuration
> (some of which is exactly the kind of thing I'm trying to get rid of by
> applying the rules I suggested), unnecessary performance/load penalties to
> the server (why do we want to be doing SSL calculations for anonymous
> accessors?), and all while bringing no discernible benefit to the users.
>

SSL for anonymous access prevents MITM attacks on downloads from the
repository.

-- 
Alec.Kloss_at_oracle.com			Oracle Middleware
PGP key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x432B9956

  • application/pgp-signature attachment: stored
Received on 2009-07-30 19:15:22 CEST

This is an archived mail posted to the Subversion Dev mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.