"Any user can create any number of user authentication RSA keys for his/her own use. Each user has a file which lists the RSA public keys for which proof of possession of the corresponding private key is accepted as authentication. User authentication keys are typically 1024 bits."
ECDSA key authentication was added in OpenSSH 5.7, released in January 2011:
https://www.openssh.com/txt/release-5.7
Ed25519 key authentication was added in OpenSSH 6.5, released in January 2014:
https://www.openssh.com/txt/release-6.5
And RSA support has been around since the beginning.
I think the overlap between "must use DSA keys" and "uses modern OpenSSH" is practically zero, and the level of pushback in this thread doesn't correspond to reality.
Of course a reasonable solutions would be to run it in some sandbox/VM.
Additionally, the old client will be difficult to use in a current OS because of library and general system incompatibility (Debian with openssh-client-ssh1 is a rare exception, and it's just a command-line ssh, not the library mentioned in https://news.ycombinator.com/item?id=38963372).
If there's a wide need for it, hopefully everybody won't maintain their own fork; all that's necessary is people band together and maintain a single fork.
https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/ss...
You can see that the team did a big refactor of key handling about 14 months ago that required multiple rounds changes to the DSA code.
That's the sort of cost that legacy code brings - it's not about make changing to the DSA feature, it's about the cost of maintaining the DSA code when you make changes across the codebase.
In the original mail, DJM mentions that they'd like to explore a post-quantum signature algorithm. Adding that to the codebase is likely to require some broad changes to key management, and that will be less work if there are fewer supported key types.
"Instead of of us maintaining DSA for a smaller and smaller population, that small/shrinking population should take some responsibility on themselves."
$ rpm -qi putty | tail -1
Putty is a SSH, Telnet & Rlogin client - this time for Linux.
$ rpm -qi dropbear | tail -2
Dropbear is a relatively small SSH server and client. It's particularly useful
for "embedded"-type Linux (or other Unix) systems, such as wireless routers.
The focus for SSH is safety. These others shift more to broad compatibility; I do wish they would throw warnings for weak ciphers.I’m going to assume that the hardware that supports DSA only has long been abandoned by its manufacturer.
Again, air-gapping and limiting the physical extent of the network to the room or building would provide significant protection against attacks here.