After upgrading default openssh on RH7.0 using openssh-clients-2.2.0p1-5.i386.rpm, I noticed /usr/bin/ssh has protection mode as "-rwsr-xr-x". Is this a feature or a bug? I don't think allow ing ssh start on privilaged port is a good idea.
I agree that the ssh client should NOT be setuid-root by default.
setuid bit is required for RSAAuthentication and RhostsRSAAuthentication.
Only for RhostsRSAAuthentication, not RSAAuthentication. Otherwise I must be doing something wrong, because RSA Auth works perfectly without suid bit set on the client. :-]
Oh. You're correct :-)
All of the above. Any kind of RHosts authentication is based on the client connecting from a "privileged" port, and ssh needs to be setuid in order to do this correctly.