service ssh trusted-user-ca lets you set a CA public key to trust to issue SSH certificates. T6013 added support for this, reusing the certificate definition that T6034 added, but T6034 only accepts RSA key types - ECDSA and ed25519 are valid public key types for an SSH CA, and the version of OpenSSH in use would accept these without issue. Not being able to configure these key types prevents me from using the trusted-user-ca feature as intended.
I'm not familiar enough with RPKI to know if ECDSA or ed25519 keys are reasonable in that context - that choice would impact how this bug is resolved