Re: Allowing CVS, RCP & SCP

Linux Advanced Routing and Traffic Control

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



bert hubert said:
> On Thu, Jul 04, 2002 at 02:01:07PM +0100, Alex Bennee wrote:
>> A. Peter Mee said:
>> > <snip>
>> > Could someone give me some pointers to achieving stable cvs and rcp
>> > access through a fairly restrictive firewall.
>> > <snip>
>>
>> CVS isn't a network protocol. You generally run it using remote shell
>> tools, in the CVS manual it allows you to specifify how with the
>> CVS_RSH evrionment variable.
>
> CVS 'pserver' lives on port 2401. Use netstat -an to see which ports
> have LISTENing sockets, and open up those ports.

Quite correct of course.

There are numerous ways of accessing remote CVS repositries (see
http://www.cvshome.org/docs/manual/cvs_2.html#SEC26). CVS over ssh seems to
be the preffered method of large development communities (sourceforge and
savanah at least). Once you've got ssh working you don't need to do any
additional (network level) work to get CVS running. I would generally be
wary of just opening up ports that are listening without being aware of the
security implications of using that protocol. The CVS documentation suggests
Kerboros over pserver for security. ssh works just as well (the documention
only refers to rsh which isecure but replaceable by ssh).

Alex
www.bennee.com/~alex/


_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

[Index of Archives]     [LARTC Home Page]     [Netfilter]     [Netfilter Development]     [Network Development]     [Bugtraq]     [GCC Help]     [Yosemite News]     [Linux Kernel]     [Fedora Users]
  Powered by Linux