On Wed, 3 Oct 2012 19:49:27 +0100, cl@isbd.net said:
At present I don't allow passwordless (i.e. public key with no passphrase) logins
You can't stop them. There is no way, from the server, to ascertain whether or not the key being used to authenticate has been protected by a passphrase because that is decrypted on the sending system, not the receiving one.