It seems to me (no security expert by any means) that port knocking and similar schemes are useful because they're orthogonal to SSH infrastructure and thus can provide a certain amount of defense against sshd 0-days and the like.
Consider the Debian PRNG flaw from a couple years ago. As I understand it, most SSH/SSL keys generated on Debian and Debian-derived boxes over a period of about two years were (rather) easily guessable. Even if you were able to redact any compromised keys as soon as this was publicly revealed, who knows how long malicious attackers may have known about it before it was made public. If your server had port knocking enabled you would have had a bit of insulation from this attack.
Comments
It seems to me (no security expert by any means) that port knocking and similar schemes are useful because they're orthogonal to SSH infrastructure and thus can provide a certain amount of defense against sshd 0-days and the like.
Consider the Debian PRNG flaw from a couple years ago. As I understand it, most SSH/SSL keys generated on Debian and Debian-derived boxes over a period of about two years were (rather) easily guessable. Even if you were able to redact any compromised keys as soon as this was publicly revealed, who knows how long malicious attackers may have known about it before it was made public. If your server had port knocking enabled you would have had a bit of insulation from this attack.