I recently submitted a new individual draft for ssh x509 which backs down from what we specified in the latest WG draft, and just specifies how we use certificates in our implementations. It's available at http://tools.ietf.org/wg/secsh/draft-saarenmaa-ssh-x509-00.txt Any thoughts? / Oskari