# sudo -i
# get cert in base64 encoded format
wget http://.../proxycert.crt
cp proxycert.crt /usr/share/ca-certificates/
dpkg-reconfigure ca-certificates
# mark certificates to add
update-ca-certificates
ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 -oHostKeyAlgorithms=+ssh-dss user@host
# .zshrc
alias sshl="ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 -oHostKeyAlgorithms=+ssh-dss"