The ssh-keygen allows to use the -t switch not only for key generation, but also to sign the certificates, where the SHA2 extension can be used. This is omitted from the manual page.
fixed in HEAD
closing resolved bugs as of 8.6p1 release