Posted Aug 24, 2010 9:02 UTC (Tue) by tialaramex (subscriber, #21167)
Parent article: OpenSSH 5.6 released
“sshd(8) will now queue debug messages for bad ownership or
permissions on the user's keyfiles encountered during authentication”
I suspect this will save substantial administrative overhead around the world. Certainly I've wasted cumulative hours debugging incorrect permissions for SSH, having to turn up log verbosity, track down the problem and put the settings back...
Slightly interesting that we got so many CA-based PKI changes, and nothing from the DNS backed PKI world, given that the root got signed and several big .org registrars including DynDns announced DNSSEC support. Maybe the DNS PKI stuff for OpenSSH just works and nobody found any new bugs or limitations?