- markus@cvs.openbsd.org 2003/12/14 12:37:21
     [ssh_config.5]
     we don't support GSS KEX; from Simon Wilkinson
diff --git a/ChangeLog b/ChangeLog
index b7a73ae..39e8042 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -20,6 +20,9 @@
    - dtucker@cvs.openbsd.org 2003/12/09 23:45:32
      [clientloop.c]
      Clear exit code when ssh -N is terminated with a SIGTERM.  ok markus@
+   - markus@cvs.openbsd.org 2003/12/14 12:37:21
+     [ssh_config.5]
+     we don't support GSS KEX; from Simon Wilkinson
 
 20031209
  - (dtucker) OpenBSD CVS Sync
@@ -1589,4 +1592,4 @@
  - Fix sshd BindAddress and -b options for systems using fake-getaddrinfo.
    Report from murple@murple.net, diagnosis from dtucker@zip.com.au
 
-$Id: ChangeLog,v 1.3144 2003/12/17 05:31:53 djm Exp $
+$Id: ChangeLog,v 1.3145 2003/12/17 05:32:23 djm Exp $
diff --git a/ssh_config.5 b/ssh_config.5
index 3aafa4e..cb26eab 100644
--- a/ssh_config.5
+++ b/ssh_config.5
@@ -34,7 +34,7 @@
 .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
 .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
 .\"
-.\" $OpenBSD: ssh_config.5,v 1.26 2003/12/09 21:53:37 markus Exp $
+.\" $OpenBSD: ssh_config.5,v 1.27 2003/12/14 12:37:21 markus Exp $
 .Dd September 25, 1999
 .Dt SSH_CONFIG 5
 .Os
@@ -350,9 +350,7 @@
 host key database instead of
 .Pa /etc/ssh/ssh_known_hosts .
 .It Cm GSSAPIAuthentication
-Specifies whether authentication based on GSSAPI may be used, either using
-the result of a successful key exchange, or using GSSAPI user
-authentication.
+Specifies whether user authentication based on GSSAPI is allowed.
 The default is
 .Dq no .
 Note that this option applies to protocol version 2 only.