As detailed on http://marc.info/?l=openbsd-cvs&m=135163261632479&w=2, OpenSSH now supports a setting that calls out to a defined program to generate the authorized_keys list for a login. Perhaps this could make key management for the ring easier?
If we feel this has merit, I would be happy to look into building openssh packages with this feature.