x/crypto/ssh clients will accept a host certificate that is otherwise rejected by OpenSSH for a given trusted host CA. These options should only apply to user certificates; this is a behavior divergence that should be fixed. This was originally reported as http://b/523056263 and deemed to be security hardening. cc @drakkan