Replace ssh package with something more robust
The current SSH package mostly copied internal things from Go's SSH package, then adding a few missing pieces in order to also be able to write SSH private keys to disk. Only Ed25519 keys are supported.
Since then, Sigsum has also added its own internal implementation of SSH private keys and related parsing. It would be nice to not maintain two separate internal implementations; and instead make a single cleaned-up and well tested implementation available as a package. The long-term plan is to make that package available in Sigsum's key-mgmt repository.
As long as we get Ed25519 keys from that package it should be good enough to pick up here (feature parity). It's worth thinking about if we should also support RSA and ECDSA, as now an OS package is only able to consistently unpack the same Ed25519 key from EFI NVRAM.
Not a high priority right now, but adding this here as a placeholder.