Package: openssh-server
Version: 1:4.7p1-12
Severity: important

openssh-server depends on openssh-blacklist. This enhances the size of an 
small debian system significantly. 

I think it es wrong to force the blacklist on every user of openssh.

openssh-server should:

* check at runtime if blacklists are installed. It may log a warning message 
if it does not find blacklists (by default, which must be switched off 
explicitely in the sshd_config file)
* and only recommend the openssh-blacklist package

Alternatively debian could provide a package which provides openssh-blacklist 
but actually do not contain any blacklists.

Regards
-- 
Wolfgang Walter
Studentenwerk München
Anstalt des öffentlichen Rechts



--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to