Comment It would be nice if OpenSSH could query LDAP (Score 1) 212
It would be nice if OpenSSH could query an LDAP server for the sshPublicKey field directly. There's a patch that does it, but as far as I know it's not integrated into the main ssh code base that ships with general Linux distributions. Supporting that and then having people use the SSHFP record with secure DNS would be nice additions to SSH best practices.