After upgrading default openssh on RH7.0
I noticed /usr/bin/ssh has protection mode as
"-rwsr-xr-x". Is this a feature or a bug?
I don't think allow ing ssh start on privilaged port
is a good idea.
I agree that the ssh client should NOT be setuid-root by default.
setuid bit is required for RSAAuthentication and RhostsRSAAuthentication.
Only for RhostsRSAAuthentication, not RSAAuthentication. Otherwise I must be
doing something wrong, because RSA Auth works perfectly without suid bit set on
the client. :-]
Oh. You're correct :-)
All of the above. Any kind of RHosts authentication is based on the client
connecting from a "privileged" port, and ssh needs to be setuid in order to do