É assim que funciona. Verifique a manpage. Observe que public key authentication
vem antes de challenge-response authentication
.
Da seção AUTHENTICATION
do gerenciamento:
The methods available for authentication are: GSSAPI-based authentication, host-based authentication, public key authentication,
challenge-response authentication, and password authentication. Authentication methods are tried in the order specified above,
though protocol 2 has a configuration option to change the default order: PreferredAuthentications.