Simon Wilkinson simon at
Sat Oct 4 09:22:54 EDT 2008

On 4 Oct 2008, at 01:40, Ken Hornstein wrote:
>  Perhaps it is better in
>   other SSH implementations, but I have no experience with them.

This is an implementation, rather than a protocol, deficiency. There  
is support in the protocol for returning the text of Kerberos errors  
to the client. OpenSSH doesn't do so, because it was felt to add  
unnecessary complexity at the point the code was being integrated. No- 
one has had the energy to revist this since (I have the code, it's  
just not in their tree).



