@stefano Ah, we forever have problems with PCI DSS compliance scanner companies. e.g. failure to accept that a "user enumeration bug" in SSH is not really a security problem when:
1. OpenSSH refuse to accept that it is a security problem;
2. RedHat refuse to accept that it is a security problem (and therefore won't release a fix); and
3. The only user with a shell account is root, so even if enumeration is a problem, all you can do is tell that a Linux box has a root account (well, duhh).
@steve "Paper" tech world and real tech world are so distant...