[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

RE: RE: Repository Passwords are in clear text?

From: Gale, David <David.Gale_at_Hypertherm.com>
Date: 2005-11-11 17:37:01 CET

Leon Zandman wrote:
>> This is an FAQ, addressed here:
>> http://subversion.tigris.org/faq.html#plaintext-passwords
>
> I think he's talking about the repository passwords that are used when
> accessing the repository using svnserve (in repo/conf/passwd), not the
> SVN client password cache that the FAQ talks about.
>
>> I agree with you that the CVS-like lightweight password
>> hiding would be nice, but I haven't got around to submitting
>> a patch...
>
> I think it would be better to not store passwords, but only their
> hashes, just like Apache does. Maybe a htpasswd-like tool should be
> added to svnserve?

And a command to the svn client to allow the user to change their
password, since currently there's no way to change a user's password
without having the admin do it, which isn't a friendly thing...

-David

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@subversion.tigris.org
For additional commands, e-mail: users-help@subversion.tigris.org
Received on Fri Nov 11 17:40:37 2005

This is an archived mail posted to the Subversion Users mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.