Now that Salt is gone, the Cumin masters should be reimaged to stretch.
When that has happened, we can also deploy a backport of OpenSSH 7.6, which now provides CA support in ssh-keygen:
ssh-keygen(1): allow ssh-keygen to use a key held in ssh-agent as a CA when signing certificates. bz#2377