I meant in the context of a Bastion ssh server, which is what the patent meant i think.
Or define the runtime options from the base-ssh-server in rc.conf (that's what i normally do):
sshd_enable="YES"
sshd_dsa_enable="NO"
sshd_ecdsa_enable="NO"
sshd_ed25519_enable="YES"
sshd_rsa_enable="NO"
If you want RSA=YES then you probably/maybe want to delete all moduli less then 4096.