I'd like to ask that you not enable gssapi support for the ssh package. The problem is that there is a key exchange method that has not yet been accepted upstream that you probably want if you want Kerberos support. Having the ssh package do some but not all of the desired Kerberos support would be confusing to users.
I'm not sure I know of anyone working on getting this patch accepted upstream. All the involved parties are just too busy. The other option is to maintain the key exchange patch as a Debian local patch. I think that's something to consider for the sarge+1 time frame, but I'd rather see how bad the openssh 3.9 port is before deciding it will be easy to do and actually trying to convince you that you want to maintain a patch that large.;) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]