Hmm, what I've always wondered: why can't I have the SSH public key of the server signed/certified the same way as a SSL public key?
That could e.g. allow me to specify "mark all SSH keys certified by company-internal CA as trusted" or putting the expected certificate into DNS...