[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: RFC: New authn/authz policy for svn.collab.net

From: Jeremy Whitlock <jcscoobyrs_at_gmail.com>
Date: Thu, 30 Jul 2009 11:41:34 -0600

>
>> I disagree. Doing this adds unnecessary complication to the configuration
>> (some of which is exactly the kind of thing I'm trying to get rid of by
>> applying the rules I suggested), unnecessary performance/load penalties to
>> the server (why do we want to be doing SSL calculations for anonymous
>> accessors?), and all while bringing no discernible benefit to the users.
>>
>>
>
> SSL for anonymous access prevents MITM attacks on downloads from the
> repository.
>
Subversion's source code isn't something that is hidden so why is a MITM
scenario a concern? If a MITM scenario does occur, SSL or not, there is
a bigger problem that Subversion's server configuration can't help with.

-- 
Jeremy Whitlock
http://www.thoughtspark.org
------------------------------------------------------
http://subversion.tigris.org/ds/viewMessage.do?dsForumId=462&dsMessageId=2377068
Received on 2009-07-30 19:42:09 CEST

This is an archived mail posted to the Subversion Dev mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.