> CAs are ignored, the only thing that matters is that the cert does not change. With today's rogue CAs and governments, this policy is better suited for detecting man-in-the-middle attacks than a browser blindly trusting a CA.
I'm not sure this is a good idea. SSH best practice is that you acquire the server's key fingerprints via a previous secure channel. E.g., Hetzner will email them to you when they set up your server.