It seems like you are reinventing the wheel here.
Did you look at RFC4255?
Did you look at RFC4255?
We could use RFC4255 instead, but we'd still have the same problems around issuing them, and we could set up sharkey to support it if we wanted to.
It also becomes more complicated when you are running multiple ssh services on a single host or using proxies/forwarders.
I use a similar method to secure my own ssh services before that I used a tool that converts the fingerprint into a phrase but it wasn't collision resistant enough.