>Except that, according to the Metasploit project, on Debian/Ubuntu boxes
>with broken OpenSSL
That is an implementation problem, limited to Debian and derivated systems. Certificates are
the only way to be sure that your server is not password-guessed.