hostkey-agent.sh assumes there is SK provider all the time and doesn't filter the SK certtypes. SSH_CERTTYPES=`ssh -Q key-sig | grep 'cert-v01@openssh.com' should be modified to SSH_CERTTYPES=`ssh -Q key-sig | grep 'cert-v01@openssh.com' | maybe_filter_sk`