One thing I've never understood is the point behind denying root login if you're enforcing key-based auth
The administrator then has to do one of a) remember/manage a root password for su b) remember/manage a user password for sudo c) use passwordless sudo
What is the advantage?
Or is it just a hang-over from the telnet days where capturing the connection header was simple and thus preventing root login stopped the capturer from getting the root password at the start of the session?