Can we make some penalty for insane sshd defaults? I don't want to fix basic settings almost everywhere I go.

@zem Like having to turn off ecdsa and rsa host keys? I feel you!

more like having to turn off password authentication for the root user. or turning off trusted x11. both features that you have to turn on deliberately during packaging!

