Re: svnserve-only + ViewCVS HOWTO
From: Eric Gillespie <epg_at_pretzelnet.org>
Date: 2004-07-21 04:56:53 CEST
I don't normally do this sort of thing but i'm terribly bored and
Keith Smith <keith@pharos.co.nz> writes:
> * I don't access the repository via SSH, so the configuration
You have no host verification at all, leaving you vulnerable to
> * Permissions are less restrictive than they could be in some
In my experience, people follow instructions as blindly as they
> 5. Add a user 'svn' and convert everything below the directory
Binaries should always be owned by root. They should certainly
> * Ensure that httpd runs as user 'apache', and add apache to
As described above, this lets a compromised httpd write to your
Other than that :), it's a nice document. Document these issues
--
---------------------------------------------------------------------
|
This is an archived mail posted to the Subversion Users mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.