About this question
With the 8.2 release of OpenSSH, they have declared that ssh-rsa for SHA-1 will soon be removed. If I have (and might use, but not sure where) an ssh-rsa key, what are the next steps for me?
A Future deprecation notice was published recently -
It is now possible[1] to perform chosen-prefix attacks against the SHA-1 hash algorithm for less than USD$50K. For this reason, we will be disabling the ssh-rsa public key signature algorithm that depends on SHA-1 by default in a near-future release.
This algorithm is unfortunately still used widely despite the existence of better alternatives, being the only remaining public key signature algorithm specified by the original SSH RFCs.