Subject: Re: CVS and security.
To: Laine Stump <lainestump@rcn.com>
From: Richard Rauch <rkr@rkr.kcnet.com>
List: netbsd-help
Date: 02/05/2000 21:56:14
> 2) Configure the ssh client so that it can login to their account on the
> server machine without requiring an interactive login (I've never done that
> for ssh, so I can't tell you how to do it.

...and the ``obvious things'' don't seem to work.  (From the
documentation, and examination of the (as-installed) configuration files,
I _should_ be able to just use {r,s}hosts{.equiv,} and it should ``just
work''.  Even if I use an account with the same name as with the remote
system, this doesn't seem to work.

My ssh[d] is as installed from our package system.  The remote site that
I've been using for testing using an ssh of unknown origin.

(Right now, I'm just trying to set up ssh so that I don't need to give a
password, which I take to be what you mean by ``without requiring an
interactive login''.)


> (An alternative to (2) if you're just providing anonymous read-only access
> to CVS would be to setup an account on the server that didn't require a
> password for ssh access. But then you get into the whole can of worms with
> protecting the rest of the system from that account.)

If this were all that I were shooting for, I gather from the cvs.info file
that I could simply create a read-only, CVS-only password and it wouldn't
really matter (so long as privacy of the project wasn't a major issue).

Unfortunately, in this case, all memebers will have to be able to
contribute, so read-only won't work.


  "I probably don't know what I'm talking about."  --rkr@rkr.kcnet.com