> I have a question about Sun SSH vs OpenSSH.  When vulnerabilities are
> discovered and an alert is sent by CERT, IW, FSISAC, SAGE, etc, it indicates
> the vendor and version of software that is vulnerable.  Whenever the alert
> has to do with ssh, it indicates several vendors, but never Sun.  My
> understanding is that Sun SSH is based upon a version of OpenSSH.  The fact
> that Sun SSH is never mentioned in these alerts gives me the impression that
> the Sun SSH is not kept up to date.  So if one wants to keep abreast of
> security issues with the ssh protocol, use OpenSSH and not Sun SSH?

Pretty much half and half.  There are strong arguements for and against
both the SunSSH and OpenSSH.  Some of the arguements:

* Any vulnerability in OpenSSH is evaluated by Sun, and if it is pertinent
  a patch is issued for SunSSH.
* The versioning/revision control for Sun SSH is horrid.  With OpenSSH
  one can look at the version number and instantly know if it is current.
* SunSSH has the appropriate hooks for their auditing/quota/logging
* OpenSSH can be updated much much faster, since new code is released
  within hours of the announcement of a vulnerability.  Sun patches can take
  up to a month.

