doc/en/admin-guide/security.txt and simple-setups.txt give overlapping (and different) advice

Bug #787337 reported by Andrew Bennetts
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Bazaar
Confirmed
Medium
Unassigned

Bug Description

doc/en/admin-guide/security.txt recommends bzr_ssh_path_limiter and bzr_access (from the contrib/ directory). doc/en/admin-guide/simple-setups.txt recommends hand-written authorized_keys command lines for the same or very similar purposes.

I think we should:
 * keep security.txt, but replace its SSH content with the corresponding parts of simple-setups.txt's
 * have simple-setups.txt refer to security.txt for the Further Configuration section.

The rationale is:
 * security.txt, and how it appears in the table of contents at <http://doc.bazaar.canonical.com/bzr.dev/en/admin-guide/index.html>, is a fairly clear and discoverable location
 * bzr_access isn't very useful compared to just writing the command= directive manually, because it can't actually do much access control.

I don't feel especially strongly about the exact solution, but it seems clear that current situation isn't optimal.

Jelmer Vernooij (jelmer)
tags: added: check-for-breezy
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.