Project

General

Profile

Actions

Feature #16423

open

Update the SSH server configuration to current standards and include post-quantum cryptography algorithms

Added by KStar Runner 5 months ago. Updated 2 days ago.

Status:
Feedback
Priority:
Normal
Assignee:
Category:
Operating System
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
26.03
Release Notes:
Default

Description

The SSH server in 25.07.1 uses OpenSSH_9.7p1 which natively supports one PQC (post quantum crypto) key exchange algorithm.

/etc/ssh/sshd_config has the following setting:
KexAlgorithms ,diffie-hellman-group-exchange-sha256

This should be updated to:
KexAlgorithms ,,diffie-hellman-group-exchange-sha256

This will maintain compatibility with existing clients, but offer PQC to newer clients.


Files

clipboard-202602121251-kufni.png (152 KB) clipboard-202602121251-kufni.png → luckman212, 02/12/2026 05:51 PM
Actions

Also available in: Atom PDF