Making SSH host certificates more usable
The author has implemented SSH protocol extensions to improve host certificate usability, allowing certificate-based trust instead of individual host keys. The system includes key revocation lists signed by certificate authorities to handle compromised keys. This enables seamless key rotation without user intervention when hosts need to replace compromised keys.