The new behavior of denying locked users has caught many of us by surprise, so I've made a patch to 3.7.1p2 that adds a "DenyLockedAccounts" keyword in the sshd_config file. The default behavior is "yes" (the current behavior), and the patch also updates the sshd_config man page and the template config file.
Created attachment 477 [details] Patch to add DenyLockedAccounts option to sshd_config
I'd rather see OpenSSH with *LESS* knobs and buttons to push for configuration then more. And this is really not a useful one in the long run. - Ben
It should not have been a surprise as it was listed in the release notes. It's also in ChangeLog and the man page. As Ben says, the patch serves no long-term purpose.
Mass change of RESOLVED bugs to CLOSED