If you only want certificate logins (via TrustedUserCAKeys CAs), set the following in sshd_config:


AuthorizedKeysFile none
PasswordAuthentication no