<?xml version="1.0" encoding="UTF-8"?>
<b:Sources SelectedStyle="" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography"  xmlns="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" >
<b:Source>
<b:Tag>brucker.ea:cvs-server:2002-b</b:Tag>
<b:SourceType>Report</b:SourceType>
<b:Publisher>Albert-Ludwigs-Universit&#228;t Freiburg</b:Publisher>
<b:Year>2002</b:Year>
<b:Issue>182</b:Issue>
<b:Author>
<b:Author><b:NameList>
<b:Person><b:Last>Brucker</b:Last><b:First>Achim</b:First><b:Middle>D</b:Middle></b:Person>
<b:Person><b:Last>Rittinger</b:Last><b:First>Frank</b:First></b:Person>
<b:Person><b:Last>Wolff</b:Last><b:First>Burkhart</b:First></b:Person>
</b:NameList></b:Author>
</b:Author>
<b:Title>A CVS-Server Security Architecture &#8212; Concepts and Formal Analysis</b:Title>
<b:Comments>We present a secure architecture of a CVS-server, its implementation (i.e. mainly its configuration) and its formal analysis. Our CVS-server is uses cvsauth, that provides protection of passwords and protection of some internal data of the CVS repository. In contrast to other (security oriented) CVS-architectures, our approach allows the CVS-server run on an open filesystem, i.e. a filesystem where users can have direct access both by CVS-commands and by standard UNIX/POSIX commands such as mv. For our secure architecture of the CVS-server, we provide a formal specification and security analysys. The latter is based on a refinement mapping high-level security requirements on the architecture on low-level security mechanisms on the UNIX/POSIX filesystem level. The purpose of the formal analysis of the secure CVS-server architecture is twofold: First, it is the bases for the specification of mutual security properties such as non-repudiation, authentication and access control for this architecture. Second, the mapping of the architecture on standard security implementation technology is described. Thus, our approach can be seen as a method to give a formal underpinning for the usually tricky business of system administrators.</b:Comments>
</b:Source>
</b:Sources>

