On Thursday 12 May 2005 20:18, Marc Haber wrote:
[ ... ]
> "UsePam yes" is generally a _big_ surprise for the local admin since
> it allows passwords to be used even if "UsePasswordAuthentification
> no" is set in sshd_config.
[ ... ]

I have exactly those set on a few hosts:
foohost:/var/log# egrep "PasswordAuth|UsePAM" /etc/ssh/sshd_config
PasswordAuthentication no
UsePAM yes

But from client hosts with no proper pubkey, I get :
$ ssh foohost
Permission denied (publickey).

From what you mention above, I should actually be prompted for a 
password, right? I only remember setting "PasswordAuthentication no" in 
sshd_config and I haven't touched any PAM stuff (ie. default Sarge 

