Page MenuHomeVyOS Platform

Support sshd HostCertificate configuration
Open, NormalPublicFEATURE REQUEST

Description

Summary

Add support for configuration of HostCertificate files in the sshd service. This allows the use of pre-signed SSH host keys to be deployed to VyOS hosts.

Use case

This allows users to skip the "trust-on-first-use" by having pre-signed and validated SSH host keys.

No more prompts like this:

The authenticity of host 'vyos.example.com (2001:db8::1)' can't be established.
ED25519 key fingerprint is SHA256:zJ+clLpAPHB+KLlj0A3mAvNQkaoUyu8qOTx6tc+k1McEI.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])?

Additional information

See: https://goteleport.com/blog/how-to-configure-ssh-certificate-based-authentication/#how-to-configure-ssh-to-use-host-certificates

Details

Version
-
Is it a breaking change?
Perfectly compatible
Issue type
Feature (new functionality)

Event Timeline

superq created this object in space S1 VyOS Public.
superq created this object with edit policy "All Users".
Viacheslav triaged this task as Normal priority.May 11 2026, 3:06 PM