For a noob wouldn't it just be easier to just bite the bullet, generate
new, more secure keys? Rather than debate how they should thwart the
will of OpenSSL and the complicit distro makers. :-)
But then perhaps a noob wouldn't have keys generated in 2014, although a
quick google suggests ssh-keygen only changed the default of RSA-SHA
from SHA1 to SHA2 in release OpenSSH 8.1/8.1p1 (2019-10-09), with the
warning introduced OpenSSH 7.7/7.7p1 (2018-04-02).
Anyway, thanks everyone for correcting me. I just hoped to save people
the trouble of doing the standard SSH key checks, before discovering the
software change.