Re: PAM authentication patch - v2

Derek Robert Price <[email protected]>
Newsgroups gmane.comp.version-control.cvs.bugs
Organization Ximbiot <http://ximbiot.com>
Message-ID <[email protected]>
Brian Murphy wrote:

> Mark D. Baushke wrote:
>
>> I guess that I really do not understand why :pserver: needs to use PAM
>> authentication. I am not saying there is not a reason, I just have not
>> understood it.
>
>
> One good reason is that you want to use LDAP or NIS authentication but 
> you
> dont want local shell users. Local shell users can do very stupid 
> stuff like
> remove parts of the repository which is not possible via pserver.


This is the kind of thing I am supporting this for.  We're already 
allowing system passwords to be sent across the wire in the clear if 
that is what the adminstrator wants.  We might as well go with one of 
the generic APIs which allows an administrator to configure where the 
password comes from.  PAM seems to fall pretty well into the generic and 
well-accepted/supported category.

A note on the clear-text complaint, an SSH tunnel for the :pserver: 
connection isn't an uncommon configuration, which removes some of the 
problems Mark has been citing.

That does still leave room for improvement in the handling of the 
.cvspass file, but I think we should leave that for later and accept the 
PAM functionality.  My only concern is future support of the code, but 
then, isn't that one of the things the experimental branch is there to 
test for?

Brian, your patch looked good, though I haven't attempted to install it 
yet, but it will still need manual (doc/cvs.texinfo) additions before it 
can be committed.

Derek

-- 
                *8^)

Email: [email protected]

Get CVS support at <http://ximbiot.com>!
-- 
Boy:  A noise with dirt on it
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.