* Client should refuse to connect to host¹ that only support SHA-1 for RSA host key exchange
* Client should refuse to authenticate to host that only support SHA-1 for RSA public key authentication
* A clear error message should be shown in the above cases
¹ Both master and agent, which complicates things as the agent host key handling is a bit special
|