Package: openssh-server Version: 4.3p2-8 It seems that GSSAPI credentials are not cleaned up unless PrivilegeSeparation is enabled. I prefer to keep that off so that I can use pam_krb5 keyboard-interactive authentication when I don't already have keys. Unfortunately if I do, /tmp quickly fills with old credential caches.