I'm migrating our SSH to use Signed SSH keys generated by Vault and there's been a lot of resistance.

As the only security guy all I have to say is

