user key passphrase change:
ssh-keygen -p -f <user private key file>
+viewing a user certificate:
+ ssh-keygen -L -f <user certificate file>
+
adding keys automatically to ssh-agent (on ssh clients):
add "AddKeysToAgent yes" to ~/.ssh/config
--- /dev/null
+-----BEGIN OPENSSH PRIVATE KEY-----
+b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW
+QyNTUxOQAAACCov7UxRarXY9DYCnXN3p9V9dIA+cdgE01zDt2Ib7skaAAAAJDhnXcI4Z13
+CAAAAAtzc2gtZWQyNTUxOQAAACCov7UxRarXY9DYCnXN3p9V9dIA+cdgE01zDt2Ib7skaA
+AAAEDur/ftds6sV1ODzHgaE9Zopp9q81/cpZ28oeJx0kBqs6i/tTFFqtdj0NgKdc3en1X1
+0gD5x2ATTXMO3YhvuyRoAAAAB3NjcmlwdHMBAgMEBQY=
+-----END OPENSSH PRIVATE KEY-----
--- /dev/null
+ssh-ed25519-cert-v01@openssh.com AAAAIHNzaC1lZDI1NTE5LWNlcnQtdjAxQG9wZW5zc2guY29tAAAAIMaRMK9mahwip3DwXLugYw5QbhNWptJ6dbsacxP/v3aaAAAAIKi/tTFFqtdj0NgKdc3en1X10gD5x2ATTXMO3YhvuyRoAAAAAAAAAAAAAAABAAAAB3NjcmlwdHMAAAAIAAAABHJvb3QAAAAAX+5X8AAAAABgjIvwAAAAAAAAAIIAAAAVcGVybWl0LVgxMS1mb3J3YXJkaW5nAAAAAAAAABdwZXJtaXQtYWdlbnQtZm9yd2FyZGluZwAAAAAAAAAWcGVybWl0LXBvcnQtZm9yd2FyZGluZwAAAAAAAAAKcGVybWl0LXB0eQAAAAAAAAAOcGVybWl0LXVzZXItcmMAAAAAAAAAAAAAADMAAAALc3NoLWVkMjU1MTkAAAAgJx/9ddTx01W1u94abBt2dEl9ggi3PEqaBGTOWnSTqvkAAABTAAAAC3NzaC1lZDI1NTE5AAAAQB9cdusB0DL33bTFbKKM1RlDc/VF8kte/fksqWOtkxDamWc08jSMsYWCXZSWcp+h61XBzCdhdyUUzwcWN9cpGw0= scripts
--- /dev/null
+ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKi/tTFFqtdj0NgKdc3en1X10gD5x2ATTXMO3YhvuyRo scripts