| Re: svnserve-only + ViewCVS HOWTO
From: Eric Gillespie <epg_at_pretzelnet.org>
 Date: 2004-07-21 04:56:53 CEST 
I don't normally do this sort of thing but i'm terribly bored and
 Keith Smith <keith@pharos.co.nz> writes:
 > * I don't access the repository via SSH, so the configuration
 You have no host verification at all, leaving you vulnerable to
 > * Permissions are less restrictive than they could be in some
 In my experience, people follow instructions as blindly as they
 > 5. Add a user 'svn' and convert everything below the directory
 Binaries should always be owned by root.  They should certainly
 > * Ensure that httpd runs as user 'apache', and add apache to
 As described above, this lets a compromised httpd write to your
 Other than that :), it's a nice document.  Document these issues
 --  
 ---------------------------------------------------------------------
 | 
This is an archived mail posted to the Subversion Users mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.