Added certificate support, but why not X.509 and PKI? How to revoke certificate? OpenSSH is reinventing wheel again.Some nice addition and upgrades. SSH version 1 protocol disabled by default is good.
http://undeadly.org/cgi?action=article&sid=20100309072751