SSH and OpenSSH Algorithm History and Timeline - From SSH-1 to Post-Quantum Key Exchange, and How Algorithms Enter and Leave the Defaults

First Published:
Last Updated:

GitHub announced in its changelog dated 2026-09-22 that it plans to remove the ssh-rsa signature type (an RSA signature using SHA-1) and the key exchange algorithm diffie-hellman-group-exchange-sha256 on 2027-01-13. OpenSSH disabled the ssh-rsa signature by default in OpenSSH 8.8 (2021-09-26), more than five years before GitHub's planned removal date. RFC 8332 (March 2018) recommended that implementations should begin disabling ssh-rsa in default configurations once implementers believed the new RSA signature algorithms were widely adopted. Even for the same algorithms, the dates on which they leave can vary between implementations, standards, and major hosting services.

Algorithms do not leave all at once. In OpenSSH, leaving has several stages: announcement, default disabling, disabling at compile time, and finally, code removal. The DSA algorithm ssh-dss has gone through all four of these stages. The arrival of new algorithms can also follow a phased approach: experimental addition, being disabled by default, inclusion in the default list, and becoming the default. By OpenSSH 10.1, OpenSSH had gone as far as warning about key exchanges that are not post-quantum. Whether a connection succeeds or fails depends on the stage the other party is at, and whose default that stage is: the client's ssh(1) or the server's sshd(8).

This article presents a timeline, from the initial release of SSH 1.0 (1995-07-12) to the latest version, OpenSSH 10.5 (2026-08-11), detailing the entry and exit of algorithms. It is based on the release notes for each version of OpenSSH, RFCs, and GitHub announcements. It also includes RFC 10042 (August 2026) and GitHub's schedule through 2027-01-13. The latter half of the article summarizes the status of key algorithms in one table split into three parts. All information was verified as of 2026-10-04.

Background and Method of Creating the SSH and OpenSSH Algorithm Timeline

In an SSH connection, both the client and server present a list of algorithms, selecting those that are mutually supported. The OpenSSH Legacy Options page states, For a successful connection, there must be at least one mutually-supported choice for each parameter. This applies to key exchange algorithms (KexAlgorithms), host key algorithms (HostKeyAlgorithms), encryption methods (Ciphers), and MACs (MACs). If no common options are found, OpenSSH clients version 7.0 and later will produce errors such as no matching key exchange method found or no matching host key type found. If one side disables an algorithm from its default list, while the other side continues to use an older version, and no common options remain, the connection will fail at this point. The same page also states that if the settings used in user authentication do not match between the client and server, authentication fails even when it appears to be configured (A mismatch between the client and server during authentication will cause authentication to fail, despite it appearing to be configured.). The purpose of this article is to list when such changes to the default lists happened, in which source, and how far through the stages the algorithms went, based solely on what the primary sources say.

Sources Used in This Article

The timeline rows come mainly from the following sources:

  • Release notes for each version of OpenSSH — Text from www.openssh.org/txt/release-X.Y (www.openssh.com redirects to www.openssh.org). Except for the three rows from the Project History page, the dates and changes listed for OpenSSH entries were taken from this source. The dates are found in the line at the beginning of each release note, marked with was released on. For OpenSSH 2.9 and OpenSSH 6.2 through 6.5, this line was not present, so the dates from the headings on the Release Notes page were used instead.
  • OpenSSH's Project History, Legacy Options, and Post-Quantum Cryptography pages — These pages describe the origins of OpenSSH, handling connection failures and temporary workarounds, and the project's approach to post-quantum cryptography.
  • Manual pages for ssh_config(5) and sshd_config(5) — The current versions on man.openbsd.org were consulted to verify the list of default algorithms. ⚠ These are documentation for OpenBSD's development versions, and may advance beyond released versions.
  • RFCs and Internet-Drafts — The text of RFCs from rfc-editor.org, and records from the IETF Datatracker for drafts. RFC dates are given to the month.
  • GitHub changelogs and blogs — The dates and content for entries related to GitHub were taken from these sources.
  • NVD (National Vulnerability Database) CVE records — The dates for entries related to vulnerabilities are the publication dates from the NVD.
  • Usenet announcements — The SSH 1.0 announcement is on Google Groups in comp.security.unix. When checking, Google Groups returned an HTTP 429 error, preventing access to the full text, so this article read the text in an Internet Archive copy. ⚠ This is an archive, not a live primary source.

How Stages and Dates Are Written in This Timeline

This timeline includes a Stage column, which uses specific terminology to describe what occurred in each row. OpenSSH rows use the following terms:

  • Added — The release notes indicate that support has been added, but do not specify whether it is the default.
  • Experimental — The release notes say it is experimental. It is not used unless configured.
  • Disabled by default — The code exists and can be enabled through configuration, but is not included in the default list. OpenSSH uses this term for both incoming algorithms (e.g., sntrup761x25519-sha512@openssh.com in OpenSSH 8.5) and outgoing algorithms (e.g., ssh-dss in OpenSSH 7.0).
  • In the default list — It is offered and accepted without configuration, but it is not chosen first. This applies to entries such as to the default KEXAlgorithms list in OpenSSH 8.9 and available by default in OpenSSH 9.9.
  • Default — If both sides support it, it is chosen first. This applies to entries such as the default when both the client and server support it in OpenSSH 6.5 and used by default in OpenSSH 10.0.
  • Warned — The client issues a warning when a connection uses it.
  • Announced — The release notes announce a future stage.
  • Disabled at compile time — The code is not included unless explicitly enabled during the build process.
  • Removed — The code has been removed.
  • Released — This row refers to the release itself.
  • Project — This row describes events related to the project, such as incorporating source code.

OpenSSH release notes often use ssh(1) or sshd(8) before describing changes to indicate whether the change applies to the client or server. In this article, when the notes limit a change to one side (client or server), the row names that side. When the notes do not explicitly mention a side, the subject of the note is retained. For example, in the OpenSSH 8.8 release notes, the subject is This release.

GitHub entries use the following terms: Announced, Added, Restricted for new keys, Brownout, and Removed. The term Restricted for new keys indicates that restrictions apply only to keys registered subsequently. Brownout refers to a temporary period of deactivation prior to removal. For IETF entries, the document status is one of the following: Proposed Standard, Best Current Practice, Informational, or Internet-Draft. The strength of requirements, such as MUST or SHOULD, appears in the What Happened column and in the status table for the Current Overview. The row for the public release of SSH 1.0 uses Released, and the vulnerability rows use Disclosed.

Dates are as follows: for OpenSSH entries, the dates refer to the release notes (the Project History page for three rows); for RFCs, the dates are the months listed on rfc-editor.org; for GitHub, the dates are either the publication dates of the changelog or blog posts, or the implementation dates given in the announcements. When GitHub has announced a future date as scheduled, the row begins with Scheduled. As of the verification date of 2026-10-04, the four GitHub dates listed as 2026-10-14 and later have not yet occurred.

The Two Meanings of ssh-rsa

The term ssh-rsa refers to two distinct things. One is a type of RSA key. The other is an RSA signature algorithm that uses SHA-1. GitHub's changelog from September 22, 2026, states the following.

Note the distinction between the key type ssh-rsa, which applies generically to all RSA keys regardless of
signature algorithm, and the confusingly named signature type ssh-rsa, which indicates an RSA key using SHA-1
(as opposed to rsa-sha2-256 and rsa-sha2-512, which refer to RSA keys using SHA-256 and SHA-512,
respectively).

The OpenSSH 8.5 release notes also say that "ssh-rsa" keys are capable of signing using "rsa-sha2-256" (RSA/SHA256), "rsa-sha2-512" (RSA/SHA512) and "ssh-rsa" (RSA/SHA1). Only the last of these is being turned off by default. This article refers to the signature algorithm as ssh-rsa signatures (SHA-1), and the key itself as an RSA key (the key type is ssh-rsa). Even when ssh-rsa signatures are no longer supported, RSA keys can still be used with the rsa-sha2-256 and rsa-sha2-512 signature algorithms.

OpenSSH's configuration options have also been updated to reflect this distinction. The OpenSSH 7.8 (August 24, 2018) release notes say that the meanings of the server's sshd(8) options PubkeyAcceptedKeyTypes and HostbasedAcceptedKeyTypes have changed (These now specify signature algorithms that are accepted for their respective authentication mechanism, where previously they specified accepted key types.).

What This Article Leaves to Other Articles

NIST's standardization of post-quantum cryptography (including ML-KEM) and the history of AWS's support for post-quantum cryptography are covered in Post-Quantum Cryptography Standardization Timeline and Migration on AWS. The specific SSH algorithms accepted by AWS (including AWS Transfer Family security policies and Amazon EC2 key pairs) are covered in SSH Algorithms on AWS Endpoints. Details regarding the xz backdoor are found in Major Security Vulnerabilities History and Timeline, while the definitions of Ed25519 and Curve25519 are provided in Cryptography Glossary for Engineers. The phasing out of SHA-1 in TLS certificates is discussed in TLS Certificate Ecosystem History and Timeline.

This article does not cover how to use SSH, nor how to write configuration files. It also does not address timelines for hosting services other than GitHub, such as GitLab or Bitbucket. Nor does it cover the version histories of SSH implementations other than OpenSSH, such as PuTTY. However, it does document the versions that GitHub lists as a minimum requirement. For vulnerabilities, it gives mainly the dates, the range of affected versions, and the versions that addressed them. It does not describe attack procedures.

SSH and OpenSSH Algorithm Historical Timeline (Updates from July 12, 1995)

The following six tables constitute the main timeline. Each table has the following columns. All references were obtained on 2026-10-04.

  • Date — The date, as described in the previous section. RFC dates are given to the month.
  • Track — The category of event. This will indicate one of the following: Origin (the beginning of SSH), OpenSSH, IETF, GitHub, or Vulnerability.
  • Stage — A term as defined in the previous section.
  • What Happened — A description of the event. In some cases, this will include verbatim excerpts from release notes and announcements.
  • Source — The documentation used as the basis for this entry.

Index:

  • 1995–2005 - The period when SSH 1.0 was released, OpenSSH was initiated, and SSH protocol 2 became the default.
  • 2006–2013 - The period when the SSH-2 RFCs were published, OpenSSH disabled SSH-1 by default, and support for elliptic curves was introduced.
  • 2014–2019 - The period when Curve25519 and Ed25519 were introduced in OpenSSH, SSH-1 was removed, and DSA and older ciphers began to be phased out.
  • 2020–2023 - The period when ssh-rsa signatures (SHA-1) left the defaults, and post-quantum key exchange became the default.
  • 2024–2025 - The period when OpenSSH removed DSA, and ML-KEM key exchange became the client default.
  • 2026–2027 - The period when the RFCs for post-quantum key exchange were published, and GitHub planned to remove ssh-rsa signatures and diffie-hellman-group-exchange-sha256.

* You can sort the table by clicking on the column name.

1995–2005 — SSH 1.0, the Start of OpenSSH, and Protocol 2 as the Default

During this period, SSH was released to the public, and OpenSSH started. OpenSSH supported SSH protocol version 2, and OpenSSH 2.9 made it the default protocol.

DateTrackStageWhat HappenedSource
1995-07-12OriginReleasedTatu Ylönen released SSH 1.0. The announcement to comp.security.unix says Introducing SSH (Secure Shell) Version 1.0. On server authentication, it says Client RSA-authenticates the server machine in the beginning of every connection.ANNOUNCEMENT: Ssh (Secure Shell) Remote Login Program / Internet Archive copy (2024-06-16)
1995-11-15IETFInternet-DraftAn Internet-Draft outlining the SSH protocol was published. It was designated draft-ylonen-ssh-protocol-00 (The SSH (Secure Shell) Remote Login Protocol). The date in the text of the draft is 15 November 1995, while the Datatracker record shows 1995-11-16.draft-ylonen-ssh-protocol-00
1999-09-26OpenSSHProjectOpenBSD developers incorporated code that would form the basis of OpenSSH. The Project History page notes that it branched from OSSH and states, The initial import was done on Sep 26, 1999. OSSH was a version by Björn Grönvall, based on Tatu Ylönen's ssh 1.2.12.OpenSSH: Project History
1999-12-01OpenSSHReleasedOpenSSH 1.2.2 was released alongside OpenBSD 2.6. The Project History page states, That marked the OpenSSH 1.2.2 release, which was shipped with OpenBSD 2.6 in December 1, 1999. At this point, OpenSSH was an implementation of SSH protocol version 1.OpenSSH: Project History
2000-06-15OpenSSHReleasedOpenSSH 2.0 was released alongside OpenBSD 2.7. The Project History page describes the version that handled both the SSH 1 and SSH 2 protocols as This version, called OpenSSH 2.0, shipped with OpenBSD 2.7 on June 15, 2000.OpenSSH: Project History
2001-04-29OpenSSHDefaultOpenSSH 2.9 made SSH protocol version 2 the default protocol. The release notes state, SSH protocol v2 is now the default protocol version, and indicate that users could change this by using the Protocol option in ssh(1) and sshd(8). OpenSSH 3.0 (2001-11-06) also included the same statement.OpenSSH 2.9 release notes / OpenSSH 3.0 release notes

2006–2013 — The SSH-2 RFCs, SSH-1 Disabled by Default, and Elliptic Curves

During this period (2006–2013), SSH protocol version 2 became RFCs. OpenSSH disabled SSH protocol version 1 by default and incorporated support for key exchange and signatures using elliptic curves.

DateTrackStageWhat HappenedSource
2006-01IETFProposed StandardRFC 4250 to 4254, which define SSH protocol version 2, were published. The transport layer specification (RFC 4253) designated diffie-hellman-group1-sha1 and diffie-hellman-group14-sha1 as REQUIRED for key exchange, ssh-dss as REQUIRED for host keys, and ssh-rsa as RECOMMENDED. For ciphers, 3des-cbc is REQUIRED, and for MACs, hmac-sha1 is REQUIRED.RFC 4253: The Secure Shell (SSH) Transport Layer Protocol
2006-03IETFProposed StandardRFC 4419 defined Diffie-Hellman group exchange. The methods are named diffie-hellman-group-exchange-sha1 and diffie-hellman-group-exchange-sha256.RFC 4419: Diffie-Hellman Group Exchange for the Secure Shell (SSH) Transport Layer Protocol
2006-09-27OpenSSHAddedOpenSSH 4.4 added support for Diffie-Hellman group exchange using SHA-256. The release notes state, Add support for Diffie-Hellman group exchange key agreement with a final hash of SHA256. The name for this method is diffie-hellman-group-exchange-sha256 as defined in RFC 4419.OpenSSH 4.4 release notes
2009-12IETFProposed StandardRFC 5656 introduced elliptic curve key exchange (ECDH) and digital signatures (ECDSA) to SSH. Three curves, nistp256, nistp384, and nistp521, are designated as REQUIRED.RFC 5656: Elliptic Curve Algorithm Integration in the Secure Shell Transport Layer
2010-03-08OpenSSHDisabled by defaultOpenSSH 5.4 disabled SSH protocol version 1 by default. The release notes state, After a transition period of about 10 years, this release disables SSH protocol 1 by default. Clients and servers requiring the older protocol can explicitly enable it in ssh_config, sshd_config, or via the command line.OpenSSH 5.4 release notes
2011-01-24OpenSSHDefaultOpenSSH 5.7 added support for ECDH and ECDSA as defined in RFC 5656. The release notes state, ECDH in a 256 bit curve field is the preferred key agreement algorithm when both the client and server support it.OpenSSH 5.7 release notes
2012-07IETFProposed StandardRFC 6668 defined the MAC algorithms hmac-sha2-256 and hmac-sha2-512.RFC 6668: SHA-2 Data Integrity Verification for the Secure Shell (SSH) Transport Layer Protocol
2013-03-22OpenSSHAddedOpenSSH 6.2 added support for AES-GCM encryption. The encryption algorithms are named aes128-gcm@openssh.com and aes256-gcm@openssh.com.OpenSSH 6.2 release notes
2013-03-22OpenSSHDefaultOpenSSH 6.2 added support for encrypt-then-mac (EtM) MAC mode and used it by default when available. Changes to ssh(1) and sshd(8) include the note, These modes are considered more secure and are used by default when available.OpenSSH 6.2 release notes

2014–2019 — Curve25519 and Ed25519 Arrive, SSH-1 Is Removed, and DSA and Old Ciphers Start to Leave

During this period, Curve25519 key exchange and Ed25519 keys were introduced in OpenSSH. OpenSSH removed SSH protocol version 1 and began the gradual deprecation of DSA and older ciphers.

DateTrackStageWhat HappenedSource
2014-01-30OpenSSHDefaultOpenSSH 6.5 made Curve25519 key exchange the default. In ssh(1) and sshd(8), the notes state, This key exchange method is the default when both the client and server support it. The name of the method is curve25519-sha256@libssh.org (as noted in the OpenSSH 6.7 release notes and RFC 8731).OpenSSH 6.5 release notes / OpenSSH 6.7 release notes
2014-01-30OpenSSHAddedOpenSSH 6.5 added support for Ed25519 keys and the chacha20-poly1305@openssh.com cipher. Regarding Ed25519, the notes state, It may be used for both user and host keys.OpenSSH 6.5 release notes
2014-10-06OpenSSHDisabled by defaultIn OpenSSH 6.7, the sshd(8) server disabled CBC ciphers and arcfour by default. The notes state, sshd(8): The default set of ciphers and MACs has been altered to remove unsafe algorithms. In particular, CBC ciphers and arcfour* are disabled by default.OpenSSH 6.7 release notes
2015-07-01OpenSSHAnnouncedOpenSSH 6.9 announced changes planned for the upcoming OpenSSH 7.0. The announcement included plans to disable SSH protocol 1 by default at compile time, and to disable diffie-hellman-group1-sha1 and ssh-dss by default at run time.OpenSSH 6.9 release notes
2015-07-01OpenSSHDefaultOpenSSH 6.9 made chacha20-poly1305@openssh.com the default cipher. The notes state, ssh(1), sshd(8): promote chacha20-poly1305@openssh.com to be the default cipher.OpenSSH 6.9 release notes
2015-08-11OpenSSHDisabled at compile timeOpenSSH 7.0 disabled support for SSH protocol version 1 by default at compile time. The notes state, Support for the legacy SSH version 1 protocol is disabled by default at compile time.OpenSSH 7.0 release notes
2015-08-11OpenSSHDisabled by defaultOpenSSH 7.0 disabled 1024-bit diffie-hellman-group1-sha1 and ssh-dss host keys and user keys by default at run time. The notes indicate that both are disabled by default at run-time and can be re-enabled using the steps outlined in the Legacy Options page.OpenSSH 7.0 release notes / OpenSSH: Legacy Options
2016-02-29OpenSSHAddedOpenSSH 7.2 added support for RSA signatures using SHA-256 and SHA-512 hash algorithms. The notes state, all: add support for RSA signatures using SHA-256/512 hash algorithms. The OpenSSH 8.2 release notes indicate that rsa-sha2-256 and rsa-sha2-512 were available from OpenSSH 7.2. In the same release, the minimum modulus size for diffie-hellman-group-exchange was increased to 2048 bits.OpenSSH 7.2 release notes / OpenSSH 8.2 release notes
2016-02-29OpenSSHDisabled by defaultOpenSSH 7.2, by default, disabled older ciphers and MAC algorithms in the client ssh(1). This included blowfish-cbc, cast128-cbc, all arcfour variants, the rijndael-cbc aliases for AES, and MD5-based and truncated HMACs. The notes state, These algorithms are already disabled by default in sshd.OpenSSH 7.2 release notes
2016-08-01OpenSSHAddedOpenSSH 7.3 added fixed Diffie-Hellman groups for 2K, 4K, and 8K. The notes list these groups without specifying their names, referring to them as those defined in draft-ietf-curdle-ssh-kex-sha2-03. This draft lists diffie-hellman-group14-sha256, diffie-hellman-group16-sha512, and diffie-hellman-group18-sha512.OpenSSH 7.3 release notes / draft-ietf-curdle-ssh-kex-sha2-03
2016-12-19OpenSSHRemovedOpenSSH 7.4 removed support for SSH protocol version 1 on the server side. The notes state: This release removes server support for the SSH v.1 protocol.OpenSSH 7.4 release notes
2016-12-19OpenSSHDisabled by defaultIn OpenSSH 7.4, the ssh(1) client no longer includes 3des-cbc as a default proposal. The notes say that this may cause problems connecting to older devices (As 3des-cbc was the only mandatory cipher in the SSH RFCs, this may cause problems connecting to older devices using the default configuration).OpenSSH 7.4 release notes
2016-12-19OpenSSHAddedOpenSSH 7.4 added the key exchange name curve25519-sha256. The notes state, This is identical to the currently-supported method named "curve25519-sha256@libssh.org".OpenSSH 7.4 release notes
2017-10-03OpenSSHRemovedOpenSSH 7.6 removed SSH protocol version 1 from the ssh(1) client. In the same release, the hmac-ripemd160 MAC and the arcfour, blowfish, and CAST ciphers were removed from ssh(1) and sshd(8). It also began rejecting RSA keys smaller than 1024 bits.OpenSSH 7.6 release notes
2017-10-03OpenSSHDisabled by defaultIn OpenSSH 7.6, the ssh(1) client no longer offers CBC ciphers by default. The notes state: ssh(1): do not offer CBC ciphers by default.OpenSSH 7.6 release notes
2017-12IETFProposed StandardRFC 8268 added more MODP groups, and RFC 8270 raised the recommended minimum modulus size for group exchange to 2048 bits. RFC 8268 includes methods such as diffie-hellman-group14-sha256, diffie-hellman-group16-sha512, and diffie-hellman-group18-sha512.RFC 8268 / RFC 8270
2018-03IETFProposed StandardRFC 8332 defined rsa-sha2-256 and rsa-sha2-512. It also stated that implementations should start to disable ssh-rsa in their default configurations once implementers judge that the new RSA signatures are widely used (implementations SHOULD start to disable "ssh-rsa" in their default configurations as soon as the implementers believe that new RSA signature algorithms have been widely adopted). RFC 8308, also from the same month, defined the extension server-sig-algs for servers to indicate the signatures they accept.RFC 8332 / RFC 8308
2019-04-17OpenSSHExperimentalOpenSSH 8.0 added a post-quantum key exchange as an experiment. The notes state: Add experimental quantum-computing resistant key exchange method, based on a combination of Streamlined NTRU Prime 4591^761 and X25519. The name of this method is sntrup4591761x25519-sha512@tinyssh.org according to the OpenSSH 8.5 release notes.OpenSSH 8.0 release notes
2019-08-28GitHubRestricted for new keysGitHub stopped accepting new registrations for DSA keys (ssh-dss). The changelog states: You can no longer add new DSA keys (ssh-dss) to your GitHub account. Existing DSA keys are not affected and will continue to function.New SSH-DSS keys are no longer supported

2020–2023 — The ssh-rsa Signature Leaves the Defaults, and Post-Quantum Key Exchange Becomes the Default

During this period, OpenSSH disabled the ssh-rsa signature by default as planned, and GitHub also began requiring SHA-2 signatures for newly registered RSA keys. Post-quantum key exchange became the default in OpenSSH 9.0.

DateTrackStageWhat HappenedSource
2020-02IETFProposed StandardRFC 8709 defines the public key algorithms for Ed25519 and Ed448, while RFC 8731 defines key exchange for Curve25519 and Curve448. RFC 8731 says that curve25519-sha256@libssh.org was widely deployed in libssh and OpenSSH, and defines curve25519-sha256.RFC 8709 / RFC 8731
2020-02-14OpenSSHAnnouncedOpenSSH 8.2 announced that it will disable ssh-rsa signatures (SHA-1) by default in a future release, noting that chosen-prefix attacks against SHA-1 had become possible. It lists rsa-sha2-256 and rsa-sha2-512 (available since OpenSSH 7.2), ssh-ed25519 (available since OpenSSH 6.5), and ecdsa-sha2-nistp256/384/521 (available since OpenSSH 5.7) as alternatives. Release notes for OpenSSH 8.3 through 8.6 also contain the same announcement.OpenSSH 8.2 release notes
2020-02-14OpenSSHDisabled by defaultOpenSSH 8.2 removed diffie-hellman-group14-sha1 from the default key exchange proposals for both the client and server. The release notes state, this release removes diffie-hellman-group14-sha1 from the default key exchange proposal for both the client and server. In the same release, it also removed ssh-rsa from the list of algorithms accepted for certificate signatures (CASignatureAlgorithms).OpenSSH 8.2 release notes
2020-04IETFBest Current PracticeRFC 8758 deprecated RC4 (arcfour) in SSH. It moved arcfour in RFC 4253 from OPTIONAL to MUST NOT (by moving it from OPTIONAL to MUST NOT). OpenSSH had already removed support for arcfour in OpenSSH 7.6.RFC 8758: Deprecating RC4 in Secure Shell (SSH)
2021-03-03OpenSSHDisabled by defaultOpenSSH 8.5 replaced the experimental post-quantum key exchange with sntrup761x25519-sha512@openssh.com. The release notes state, The previous sntrup4591761x25519-sha512@tinyssh.org method is replaced with sntrup761x25519-sha512@openssh.com. It adds (note this both the updated method and the one that it replaced are disabled by default).OpenSSH 8.5 release notes
2021-03-03OpenSSHDefaultOpenSSH 8.5 changed the first-preference signature algorithm from ECDSA to Ed25519. The notes state, ssh(1), sshd(8): this release changes the first-preference signature algorithm from ECDSA to ED25519. The client ssh(1) also enabled the UpdateHostKeys option by default, subject to preconditions.OpenSSH 8.5 release notes
2021-08-20OpenSSHAnnouncedOpenSSH 8.7 announced that the next version will disable ssh-rsa signatures by default. The announcement header reads Imminent deprecation notice, and the text states: OpenSSH will disable the ssh-rsa signature scheme by default in the next release.OpenSSH 8.7 release notes
2021-09-01GitHubAnnouncedGitHub announced a schedule for changes to SSH keys and algorithms. The announcement details the removal of support for all DSA keys, the requirement for SHA-2 signatures for RSA keys added after November 2, 2021, the removal of hmac-sha1 and the CBC ciphers, the addition of ECDSA and Ed25519 host keys, and the shutdown of the unencrypted Git protocol. The announcement included a table designating November 2, 2021, and January 11, 2022, as brownout dates, and March 15, 2022, as the date the changes became permanent. The table cited here is from the text of the post as updated on November 17, 2021.Improving Git protocol security on GitHub
2021-09-26OpenSSHDisabled by defaultOpenSSH 8.8 disabled ssh-rsa signatures (signatures using RSA with the SHA-1 hash algorithm) by default. The subject in the notes is This release: This release disables RSA signatures using the SHA-1 hash algorithm by default. Regarding RSA keys, the notes state: there is no need to replace ssh-rsa keys. As a temporary workaround for connecting to older implementations, the notes show an example that adds +ssh-rsa to the HostkeyAlgorithms and PubkeyAcceptedAlgorithms options.OpenSSH 8.8 release notes
2021-11-02GitHubRestricted for new keysThis date became GitHub's cutoff for RSA keys that may continue to use SHA-1 signatures. This date was also the first brownout. The 2021-09-01 announcement stated that RSA keys with a valid_after date after November 2, 2021, would need SHA-2 signatures during the brownouts and after the change became permanent. The 2022-03-15 changelog describes what was made permanent: Required SHA-2 signatures on all RSA keys uploaded after November 2, 2021 (RSA keys uploaded prior to the cutoff may still use SHA-1 signatures).Improving Git protocol security on GitHub / Removed unencrypted Git protocol and certain SSH keys
2022-01IETFProposed StandardRFC 9142 revised recommendations for key exchange. The specification changed diffie-hellman-group1-sha1 from MUST to SHOULD NOT, and diffie-hellman-group14-sha1 from MUST to MAY. diffie-hellman-group14-sha256 is MUST, curve25519-sha256 is SHOULD, and diffie-hellman-group-exchange-sha256 is MAY.RFC 9142: Key Exchange (KEX) Method Updates and Recommendations for Secure Shell (SSH)
2022-02-23OpenSSHIn the default listOpenSSH 8.9 added sntrup761x25519-sha512@openssh.com to the default list of key exchanges. The changes to ssh(1) and sshd(8) noted that it is placed (after the ECDH methods but before the prime-group DH ones), and added, The next release of OpenSSH is likely to make this key exchange the default method.OpenSSH 8.9 release notes
2022-03-15GitHubRemovedGitHub made the announced changes permanent. The changelog details the removal of support for DSA keys, the requirement for SHA-2 signatures on RSA keys registered after 2021-11-02, the removal of HMAC-SHA-1 and CBC ciphers, and the discontinuation of the unencrypted Git protocol.Removed unencrypted Git protocol and certain SSH keys
2022-04-08OpenSSHDefaultOpenSSH 9.0 made sntrup761x25519-sha512@openssh.com the default key exchange. The notes state, ssh(1), sshd(8): use the hybrid Streamlined NTRU Prime + x25519 key exchange method by default. It also says that pairing it with X25519 ECDH is a backstop in case weaknesses are found in NTRU Prime.OpenSSH 9.0 release notes
2023-12-18VulnerabilityDisclosedThe Terrapin attack (CVE-2023-48795) was disclosed. The NVD lists affected systems as OpenSSH before 9.6 and other products. The researchers' site says that connections protected by ChaCha20-Poly1305, or by CBC combined with Encrypt-then-MAC, are affected. OpenSSH 9.6 (2023-12-18) addressed it with the strict KEX extension, which is enabled automatically when both sides support it.CVE-2023-48795 (NVD) / Terrapin Attack / OpenSSH 9.6 release notes

2024–2025 — DSA Is Removed, and ML-KEM Becomes the Client's Default Key Exchange

During this period, OpenSSH removed DSA as previously announced. A key exchange method utilizing ML-KEM was introduced, becoming the default for clients in OpenSSH 10.0.

DateTrackStageWhat HappenedSource
2024-03-11OpenSSHAnnouncedOpenSSH 9.7 announced a timeline for removing DSA support. This version makes DSA support optional at compile time (defaulting to enabled), the next version will disable it by default at compile time, and it will be removed in the first release of 2025. The release notes state: This release makes DSA support in OpenSSH compile-time optional, defaulting to on.OpenSSH 9.7 release notes
2024-03-29VulnerabilityDisclosedA backdoor in xz and liblzma (CVE-2024-3094) was reported. The NVD states that upstream xz tarballs, starting with version 5.6.0, contained malicious code. The report to oss-security was titled backdoor in upstream xz/liblzma leading to ssh server compromise. The report noted that openssh does not directly use liblzma, and names, as the path of the impact, that Debian and other distributions patch OpenSSH for systemd notification and that libsystemd depends on lzma.backdoor in upstream xz/liblzma leading to ssh server compromise (oss-security) / CVE-2024-3094 (NVD)
2024-07-01OpenSSHDisabled at compile timeOpenSSH 9.8 disabled DSA support by default at compile time. The release notes state: all: as mentioned above, the DSA signature algorithm is now disabled at compile time. To use DSA with portable OpenSSH, --enable-dsa-keys must be passed to configure.OpenSSH 9.8 release notes
2024-07-01VulnerabilityDisclosedregreSSHion (CVE-2024-6387) was disclosed and fixed in OpenSSH 9.8. The OpenSSH 9.8 release notes state that a race condition existed in the server's sshd(8) in Portable OpenSSH versions between 8.5p1 and 9.7p1 (inclusive). It also states that OpenBSD is not vulnerable. Qualys, which discovered it, says that versions earlier than 4.4p1 are also affected unless they are patched for CVE-2006-5051 and CVE-2008-4109. The name regreSSHion comes from the Qualys disclosure.OpenSSH 9.8 release notes / CVE-2024-6387 (NVD) / regreSSHion (Qualys)
2024-09-19OpenSSHIn the default listOpenSSH 9.9 added mlkem768x25519-sha256, a combination of ML-KEM and X25519, to the default list. In changes to ssh(1) and sshd(8), the release notes state: This algorithm "mlkem768x25519-sha256" is available by default. In the same release, sntrup761x25519-sha512@openssh.com is now also accessible using the IANA-assigned name sntrup761x25519-sha512.OpenSSH 9.9 release notes
2025-04-09OpenSSHRemovedOpenSSH 10.0 removed support for the DSA signature algorithm. The notes state completing the deprecation process that began in 2015 (when DSA was disabled by default).OpenSSH 10.0 release notes
2025-04-09OpenSSHDefaultIn OpenSSH 10.0, the client ssh(1) now defaults to mlkem768x25519-sha256 for key exchange. The notes state: ssh(1): the hybrid post-quantum algorithm mlkem768x25519-sha256 is now used by default for key agreement.OpenSSH 10.0 release notes
2025-04-09OpenSSHDisabled by defaultOpenSSH 10.0 now disables finite field Diffie-Hellman by default on the server sshd(8). diffie-hellman-group* and diffie-hellman-group-exchange-* have been removed from the default KEXAlgorithms list. The notes state: The client is unchanged and continues to support these methods by default.OpenSSH 10.0 release notes
2025-09-15GitHubAnnouncedGitHub announced the addition of sntrup761x25519-sha512 to SSH key exchange. The effective date is 2025-09-17, and this applies to GitHub.com and GitHub Enterprise Cloud with data residency, excluding the US region. The post explains the US region exception by saying that only FIPS-approved cryptography may be used there. The post said it would be included in GitHub Enterprise Server 3.19.Post-quantum security for SSH access on GitHub
2025-10-06OpenSSHWarnedOpenSSH 10.1 now issues a warning when the client ssh(1) connects using a non-post-quantum key exchange algorithm. The notes state: ssh(1): add a warning when the connection negotiates a non-post quantum key agreement algorithm. The warning is controlled by the new ssh_config option WarnWeakCrypto, which is enabled by default.OpenSSH 10.1 release notes
2025-10-06OpenSSHRemovedOpenSSH 10.1 removed experimental support for XMSS keys. The notes state This was never enabled by default. and indicate plans to implement a new post-quantum signature scheme in the near future.OpenSSH 10.1 release notes
2025-10-06OpenSSHAnnouncedOpenSSH 10.1 announced the deprecation of SHA-1 SSHFP records. Future versions will ignore SHA-1 SSHFP records, and ssh-keygen -r will only generate SSHFP records using SHA-256. The date for supporting SSHFP records in Amazon Route 53 is documented in AWS History and Timeline regarding Amazon Route 53.OpenSSH 10.1 release notes

2026–2027 — Post-Quantum RFCs, OpenSSH 10.5, and GitHub's Schedule

During this period, the two post-quantum key exchanges that OpenSSH had made defaults became RFCs. GitHub announced its schedule for removing ssh-rsa signatures and diffie-hellman-group-exchange-sha256.

DateTrackStageWhat HappenedSource
2026-04IETFInformationalRFC 9941 defined sntrup761x25519-sha512. The status is Informational, and the OK to Implement designation in the IANA table is marked as SHOULD. For negotiation with older implementations, it makes it RECOMMENDED to announce and accept sntrup761x25519-sha512@openssh.com as an alias.RFC 9941
2026-07-06OpenSSHExperimentalOpenSSH 10.4 added a post-quantum signature that combines ML-DSA 44 and Ed25519 as an experiment. The notes state This scheme is not enabled by default. The note references a draft (draft-miller-sshm-mldsa44-ed25519-composite-sigs) which defines the signature name as ssh-mldsa44-ed25519@openssh.com. Datatracker shows this draft as replaced, and its line of successors leads to the working group draft in the 2026-08-21 row.OpenSSH 10.4 release notes / draft-miller-sshm-mldsa44-ed25519-composite-sigs
2026-08IETFInformationalRFC 10042 defined post-quantum/traditional hybrid key exchange using ML-KEM. The status is Informational. The methods defined include mlkem768nistp256-sha256, mlkem1024nistp384-sha384, and mlkem768x25519-sha256. In the IANA table, OK to Implement is SHOULD for all three.RFC 10042
2026-08-11OpenSSHReleasedOpenSSH 10.5 was released. It is the latest version as of the verification date. The release notes indicate that this version includes several security fixes and minor bug fixes. A compatibility-related change requires the portable version of OpenSSH to support elliptic curve cryptography (including NISTP521 curves) in libcrypto.OpenSSH 10.5 release notes
2026-08-21IETFInternet-DraftA draft for post-quantum composite signatures (draft-ietf-sshm-composite-sigs-00) was published as a draft of the SSH working group. The draft indicates that the intended status is Standards Track. It defines two methods: ssh-mldsa44-ed25519 and ssh-mldsa87-p384.draft-ietf-sshm-composite-sigs
2026-09-22GitHubAnnouncedGitHub announced the removal and addition of SSH algorithms, as well as requirements for RSA key sizes. The changes are the removal of the ssh-rsa signature type (including ssh-rsa-cert-v01@openssh.com certificates using SHA-1) and diffie-hellman-group-exchange-sha256, a requirement that newly registered RSA keys be at least 3072 bits, and the addition of mlkem768x25519-sha256. For GitHub Enterprise Server, mlkem768x25519-sha256 will be available in version 3.24, while the remaining changes will be in version 3.25. The text at publication gave the final date as January 13, 2026, and it was corrected to January 13, 2027 on 2026-09-28.Security improvements for SSH
2026-10-14GitHubRestricted for new keysScheduled. RSA SSH keys registered after this date must be at least 3072 bits in size for both signing and authentication. The changelog states: All new RSA SSH keys uploaded after October 14, 2026 must be at least 3072 bits in size, both for signing and authentication.Security improvements for SSH
2026-10-14GitHubAddedScheduled. For GitHub.com and GitHub Enterprise Cloud with data residency (excluding the US region), mlkem768x25519-sha256 will be enabled.Security improvements for SSH
2026-11-04GitHubBrownoutScheduled. A brownout of the removal of the ssh-rsa signature type and diffie-hellman-group-exchange-sha256 takes place.Security improvements for SSH
2026-12-09GitHubBrownoutScheduled. A second brownout for the ssh-rsa signature type and diffie-hellman-group-exchange-sha256 takes place.Security improvements for SSH
2027-01-13GitHubRemovedScheduled. The ssh-rsa signature type and the diffie-hellman-group-exchange-sha256 key exchange are removed.Security improvements for SSH

Current Overview of SSH and OpenSSH Algorithms

As of October 4, 2026, the latest version of OpenSSH is OpenSSH 10.5 (released August 11, 2026). This section reorganizes the timeline entries by lineage. Furthermore, it summarizes the status of the major algorithms in one table split into three parts, and looks at how the dates in OpenSSH, the IETF, and GitHub differ.

How an Algorithm Leaves: Announced, Disabled by Default, Disabled at Compile Time, Removed

In OpenSSH, algorithms do not leave all at once. The following table lists the stages of leaving for each lineage. Not reached indicates that that stage had not been reached as of the verification date. Skipped indicates that the stage was bypassed and the algorithm proceeded to the next stage. — indicates that no statement corresponding to that stage was found in the release notes this article read (OpenSSH 2.9, 3.0, 3.7, 4.4, and OpenSSH 5.4 through 10.5).

AlgorithmAnnouncedDisabled by defaultDisabled at compile timeRemoved
SSH protocol 1OpenSSH 6.9 (2015-07-01) announced changes for version 7.0. OpenSSH 7.3 (2016-08-01) to 7.5 (2017-03-20) announced its removal.OpenSSH 5.4 (2010-03-08). Client and server.OpenSSH 7.0 (2015-08-11)sshd(8): OpenSSH 7.4 (2016-12-19). ssh(1): OpenSSH 7.6 (2017-10-03)
ssh-dss (DSA)OpenSSH 6.9 (2015-07-01) announced changes for version 7.0. OpenSSH 9.7 (2024-03-11) to 9.9 (2024-09-19) announced the timeline for removal.OpenSSH 7.0 (2015-08-11). At run timeOpenSSH 9.8 (2024-07-01)OpenSSH 10.0 (2025-04-09)
ssh-rsa signatures (SHA-1)Every release from OpenSSH 8.2 (2020-02-14) to OpenSSH 8.7 (2021-08-20) announced it.OpenSSH 8.8 (2021-09-26)Not reachedNot reached
diffie-hellman-group1-sha1OpenSSH 6.9 (2015-07-01)OpenSSH 7.0 (2015-08-11). At run timeNot reachedNot reached
diffie-hellman-group14-sha1—OpenSSH 8.2 (2020-02-14). Client and serverNot reachedNot reached
Finite field Diffie-Hellman (diffie-hellman-group*, diffie-hellman-group-exchange-*)—sshd(8): OpenSSH 10.0 (2025-04-09). ssh(1) remains unchanged.Not reachedNot reached
CBC ciphersOpenSSH 6.9 (2015-07-01), 7.0, and 7.1 (2015-08-21) announced that blowfish-cbc, cast128-cbc, and the rijndael-cbc (AES) aliases would be disabled by default. OpenSSH 7.5 (2017-03-20) announced that the client would no longer offer the remaining CBC ciphers by default.sshd(8): OpenSSH 6.7 (2014-10-06). ssh(1): OpenSSH 7.2 (2016-02-29) disabled blowfish-cbc, cast128-cbc, and the rijndael-cbc aliases; OpenSSH 7.4 (2016-12-19) removed 3des-cbc from its default proposal; and OpenSSH 7.6 (2017-10-03) stopped offering CBC ciphers by default.Not reached (blowfish-cbc and cast128-cbc: next row)Not reached (blowfish-cbc and cast128-cbc: next row)
arcfour, blowfish, and CAST ciphersFrom OpenSSH 6.9 (2015-07-01) to 7.1, disabling by default was announced. OpenSSH 7.4 (2016-12-19) and OpenSSH 7.5 (2017-03-20) announced the removal of Blowfish and RC4.sshd(8): OpenSSH 6.7 (2014-10-06) for CBC ciphers and arcfour. ssh(1): OpenSSH 7.2 (2016-02-29)SkippedOpenSSH 7.6 (2017-10-03)

The table shows three things:

  1. Among the stages that change the code, every lineage starts with being disabled by default. Algorithms that are disabled by default can be re-enabled through configuration settings. For ssh-dss and diffie-hellman-group1-sha1 in OpenSSH 7.0, the Legacy Options page shows how to add them to the default list with a +, as in HostKeyAlgorithms +ssh-dss and KexAlgorithms +diffie-hellman-group1-sha1. If an algorithm is disabled at compile time, it cannot be re-enabled through configuration; a rebuild is required. If an algorithm is removed entirely, it will no longer be usable in that version.
  2. The time from being disabled by default to being removed differs from lineage to lineage. For SSH protocol 1, it took about seven and a half years, from OpenSSH 5.4 (2010-03-08) to the client's removal in OpenSSH 7.6 (2017-10-03). For ssh-dss, it took nearly ten years, from OpenSSH 7.0 (2015-08-11) to OpenSSH 10.0 (2025-04-09). The ssh-rsa signature was disabled by default in OpenSSH 8.8. No notice of its removal was found in the notes this article read, up to OpenSSH 10.5.
  3. The client and the server diverge. SSH protocol 1 was removed first from the server's sshd(8). CBC ciphers were disabled by default in sshd(8) first. Finite field Diffie-Hellman is currently only removed from the default settings in sshd(8). The default list in the current ssh_config(5) still includes diffie-hellman-group-exchange-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, and diffie-hellman-group14-sha256.

Changes were also made to the default settings for key generation. ssh-keygen increased the default key size for RSA to 3072 bits in OpenSSH 8.0 (2019-04-17), prevented ssh-keygen -A from creating DSA keys in OpenSSH 9.1 (2022-10-04), and set Ed25519 as the default key type in OpenSSH 9.5 (2023-10-04).

How an Algorithm Arrives: Experimental, Disabled by Default, In the Default List, Default, Warned

Arrival can also go in stages. The Streamlined NTRU Prime key exchange in particular went through every stage, from the experimental addition to becoming the default. The following table lists the stages of arrival for each lineage. The meanings of Skipped and Not reached are the same as in the previous table.

AlgorithmExperimentalDisabled by defaultIn the default listDefault
Streamlined NTRU Prime and X25519 (sntrup4591761x25519-sha512@tinyssh.org → sntrup761x25519-sha512@openssh.com → sntrup761x25519-sha512)OpenSSH 8.0 (2019-04-17)OpenSSH 8.5 (2021-03-03). The experimental method was replaced with sntrup761, as sntrup761x25519-sha512@openssh.com.OpenSSH 8.9 (2022-02-23)OpenSSH 9.0 (2022-04-08). ssh(1) and sshd(8)
mlkem768x25519-sha256SkippedSkippedOpenSSH 9.9 (2024-09-19)ssh(1): OpenSSH 10.0 (2025-04-09)
Curve25519 (curve25519-sha256@libssh.org, curve25519-sha256)SkippedSkippedSkippedOpenSSH 6.5 (2014-01-30)
ECDH (ecdh-sha2-nistp256 and others)SkippedSkippedSkippedOpenSSH 5.7 (2011-01-24). 256-bit curve.
Composite signature of ML-DSA 44 and Ed25519 (ssh-mldsa44-ed25519@openssh.com)OpenSSH 10.4 (2026-07-06)OpenSSH 10.4 (2026-07-06). not enabled by defaultNot reachedNot reached

The Streamlined NTRU Prime lineage took nearly three years, from OpenSSH 8.0 to OpenSSH 9.0, to become the default. mlkem768x25519-sha256 was initially included in the default list in OpenSSH 9.9, skipping the experimental and disabled-by-default stages, and about seven months later became the client default in OpenSSH 10.0.

Ed25519 signatures were introduced in OpenSSH 6.5 (January 30, 2014) and became the first-preference signature algorithm in OpenSSH 8.5 (March 3, 2021). Before that, ECDSA was chosen first.

In released versions, the composite signature of ML-DSA 44 and Ed25519 is at the experimental stage of OpenSSH 10.4. However, the current ssh_config(5) and sshd_config(5) documentation on man.openbsd.org (documentation for the OpenBSD development version; the versions read on the verification date are dated 2026-09-20 and 2026-09-17) lists ssh-mldsa44-ed25519 in the default lists for HostKeyAlgorithms, PubkeyAcceptedAlgorithms, and others, and includes /etc/ssh/ssh_host_mldsa44_ed25519_key in the default HostKey settings for sshd(8). The names do not include @openssh.com. No statement of this change was found in the release notes up to OpenSSH 10.5. What a released version will do has to be checked in the next release notes.

OpenSSH 10.1 (October 6, 2025) added a warning stage after the default stage. The client ssh(1) issues a warning when it connects with a key exchange that is not post-quantum. The warning message is as follows (from the Post-Quantum Cryptography page):

** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See https://openssh.com/pq.html

The Post-Quantum Cryptography page says the warning is there to encourage migration to stronger algorithms (To encourage migration to these stronger algorithms). The Post-Quantum Cryptography page suggests updating the server to an implementation that supports mlkem768x25519-sha256 or sntrup761x25519-sha512 as a solution when the warning is received. If an update is not possible, the WarnWeakCrypto option in ssh_config(5) can be used to disable the warning for specific hosts.

How SSH Algorithms Enter and Leave OpenSSH Defaults - Stages by OpenSSH Version
How SSH Algorithms Enter and Leave OpenSSH Defaults - Stages by OpenSSH Version

The Algorithm Status Table

The following three tables list the status of key algorithms across the three tracks: OpenSSH, the IETF, and GitHub. The columns are as follows:

  • Algorithm — The name used in negotiations.
  • Kind — One of the following: Key exchange, Host key and signature, Protocol version, Cipher, or MAC.
  • Added to OpenSSH — The version and date the algorithm was added to OpenSSH. Cells whose content this article did not trace are marked Not traced. This applies to many algorithms available prior to OpenSSH 5.4.
  • Default in OpenSSH — The stage related to the default (Disabled by default for an arriving algorithm, In the default list, Default) and the version.
  • Disabled or Removed in OpenSSH — The stage and version when the algorithm was disabled or removed from OpenSSH. Stages not reached as of the verification date are marked Not reached.
  • IETF Status — The RFC that defines the algorithm and the month, along with the strength of the requirement. The strength of the requirement is given in the RFC's own words.
  • GitHub.com — The stage and date given in GitHub's announcements. Algorithms that the GitHub announcements cited in this article do not name are marked Not mentioned.

Table Part 1 covers key exchange algorithms.

AlgorithmKindAdded to OpenSSHDefault in OpenSSHDisabled or Removed in OpenSSHIETF StatusGitHub.com
diffie-hellman-group1-sha1Key exchangeNot tracedNot tracedDisabled by default: OpenSSH 7.0 (2015-08-11)RFC 4253 (January 2006): REQUIRED. RFC 9142 (January 2022): SHOULD NOTNot mentioned
diffie-hellman-group14-sha1Key exchangeNot tracedNot tracedDisabled by default: OpenSSH 8.2 (2020-02-14), for both client and server.RFC 4253: REQUIRED. RFC 9142: MAYNot mentioned
diffie-hellman-group-exchange-sha256Key exchangeAdded: OpenSSH 4.4 (2006-09-27). The notes do not give the method nameIn the default list: for ssh(1) in the current ssh_config(5)Disabled by default: For sshd(8) only, OpenSSH 10.0 (2025-04-09).RFC 4419 (March 2006). RFC 9142: MAYBrownout: 2026-11-04 and 2026-12-09. Removed: 2027-01-13. All are scheduled
diffie-hellman-group14-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512Key exchangeAdded: OpenSSH 7.3 (2016-08-01). The notes describe them as the groups from a draftIn the default list: for ssh(1) in the current ssh_config(5)Disabled by default: For sshd(8) only, OpenSSH 10.0 (2025-04-09).RFC 8268 (December 2017): group14-sha256 is SHOULD. RFC 9142: group14-sha256 is MUST, group16-sha512 is SHOULD, group18-sha512 is MAY.Not mentioned
ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521Key exchangeAdded: OpenSSH 5.7 (2011-01-24)Default: OpenSSH 5.7 (256-bit curve). In the default list in the current ssh_config(5) and sshd_config(5)Not reachedRFC 5656 (December 2009): The three curves are REQUIRED. RFC 9142: SHOULDNot mentioned
curve25519-sha256, curve25519-sha256@libssh.orgKey exchangeOpenSSH 6.5 (2014-01-30): curve25519-sha256@libssh.org. OpenSSH 7.4 (2016-12-19): curve25519-sha256.Default: OpenSSH 6.5. In the current ssh_config(5) and sshd_config(5), In the default list, after the post-quantum methodsNot reachedRFC 8731 (February 2020). RFC 9142: curve25519-sha256 is SHOULD.Not mentioned
sntrup4591761x25519-sha512@tinyssh.orgKey exchangeExperimental: OpenSSH 8.0 (2019-04-17)Disabled by default (OpenSSH 8.5 notes)Replaced with sntrup761x25519-sha512@openssh.com in OpenSSH 8.5 (2021-03-03).No RFC. The acknowledgments of RFC 9941 mention its historyNot mentioned
sntrup761x25519-sha512, sntrup761x25519-sha512@openssh.comKey exchangeOpenSSH 8.5 (2021-03-03). IANA name added in OpenSSH 9.9 (2024-09-19).Disabled by default: OpenSSH 8.5 (2021-03-03). In the default list: OpenSSH 8.9 (2022-02-23). Default: OpenSSH 9.0 (2022-04-08). In the current ssh_config(5) and sshd_config(5), In the default list, after mlkem768x25519-sha256Not reachedRFC 9941 (April 2026): Informational. IANA table OK to Implement is SHOULD.Added: the 2025-09-15 announcement said it would be enabled on 2025-09-17 (on GitHub.com, and on GitHub Enterprise Cloud with data residency except its US region)
mlkem768x25519-sha256Key exchangeOpenSSH 9.9 (2024-09-19)In the default list: OpenSSH 9.9. Default: ssh(1), OpenSSH 10.0 (2025-04-09)Not reachedRFC 10042 (August 2026): Informational. IANA table OK to Implement is SHOULD.Added: 2026-10-14. Scheduled. On GitHub.com, and on GitHub Enterprise Cloud with data residency except its US region

Table Part 2 covers host keys and signatures.

AlgorithmKindAdded to OpenSSHDefault in OpenSSHDisabled or Removed in OpenSSHIETF StatusGitHub.com
ssh-dssHost key and signatureNot tracedNot tracedDisabled by default: OpenSSH 7.0 (2015-08-11). Disabled at compile time: OpenSSH 9.8 (2024-07-01). Removed: OpenSSH 10.0 (2025-04-09)RFC 4253 (January 2006): REQUIREDRestricted for new keys: 2019-08-28. Removed: 2022-03-15
ssh-rsa (signature; RSA with SHA-1)Host key and signatureNot tracedNot tracedDisabled by default: OpenSSH 8.8 (2021-09-26); for certificate signatures (CASignatureAlgorithms), OpenSSH 8.2 (2020-02-14). Not reached for removalRFC 4253: RECOMMENDED. RFC 8332 (March 2018): SHOULD start to disableRestricted for new keys: RSA keys registered after 2021-11-02 (made permanent on 2022-03-15). Brownout: 2026-11-04 and 2026-12-09. Removed: 2027-01-13. The dates from 2026 on are scheduled
rsa-sha2-256, rsa-sha2-512Host key and signatureAdded: OpenSSH 7.2 (2016-02-29)The OpenSSH 8.2 notes say they are used by default if both sides support them (already used by default if the client and server support them).Not reachedRFC 8332 (March 2018): rsa-sha2-256 is RECOMMENDED, rsa-sha2-512 is OPTIONALRequired for RSA keys registered after 2021-11-02. The 2026-09-22 changelog asks that existing RSA keys use them too.
ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521Host key and signatureAdded: OpenSSH 5.7 (2011-01-24)Before OpenSSH 8.5 (2021-03-03), the first-preference signature algorithmNot reachedRFC 5656 (December 2009): All three curves are REQUIREDThe 2021-09-01 announcement said that ECDSA host keys would be added. The 2026-09-22 changelog says that ECDSA keys continue to work.
ssh-ed25519Host key and signatureAdded: OpenSSH 6.5 (2014-01-30)Default (first-preference signature algorithm): OpenSSH 8.5 (2021-03-03)Not reachedRFC 8709 (February 2020): SHOULDThe 2021-09-01 announcement said that Ed25519 host keys would be added. The 2026-09-22 changelog recommends Ed25519 for new keys.
ssh-mldsa44-ed25519@openssh.comHost key and signatureExperimental: OpenSSH 10.4 (2026-07-06)Disabled by default: OpenSSH 10.4 (not enabled by default). For the current man pages, see the note in the section on arrivalNot reachedInternet-Draft. The working group's draft-ietf-sshm-composite-sigs-00 (2026-08-21) defines it under the name ssh-mldsa44-ed25519Not mentioned

Table Part 3 covers the protocol version, ciphers, and MACs.

AlgorithmKindAdded to OpenSSHDefault in OpenSSHDisabled or Removed in OpenSSHIETF StatusGitHub.com
SSH protocol 1Protocol versionOpenSSH 1.2.2 (1999-12-01)In OpenSSH 2.9 (2001-04-29), the default protocol became SSH protocol 2Disabled by default: OpenSSH 5.4 (2010-03-08). Disabled at compile time: OpenSSH 7.0 (2015-08-11). Removed: sshd(8) in OpenSSH 7.4 (2016-12-19), ssh(1) in OpenSSH 7.6 (2017-10-03)No RFC. draft-ylonen-ssh-protocol-00 (November 1995) is an Internet-DraftNot mentioned
CBC ciphers (e.g., 3des-cbc, aes128-cbc)CipherNot tracedNot tracedDisabled by default: sshd(8) in OpenSSH 6.7 (2014-10-06), ssh(1) in OpenSSH 7.2 (2016-02-29) for the rijndael-cbc aliases, in OpenSSH 7.4 (2016-12-19) for 3des-cbc, and in OpenSSH 7.6 (2017-10-03) for CBC ciphers in generalRFC 4253: 3des-cbc is REQUIRED, aes128-cbc is RECOMMENDEDRemoved: 2022-03-15
The arcfour variants, blowfish-cbc, and cast128-cbcCipherNot tracedNot tracedDisabled by default: sshd(8) in OpenSSH 6.7 for CBC ciphers and arcfour, ssh(1) in OpenSSH 7.2 (2016-02-29). Removed: OpenSSH 7.6 (2017-10-03)RFC 4253: arcfour, blowfish-cbc, cast128-cbc are OPTIONAL. RFC 8758 (April 2020) moved RC4 from OPTIONAL to MUST NOT.Not mentioned
hmac-sha1MACNot tracedIn the default list: current ssh_config(5) and sshd_config(5)Not reachedRFC 4253: REQUIREDRemoved: 2022-03-15
chacha20-poly1305@openssh.comCipherAdded: OpenSSH 6.5 (2014-01-30)Default: OpenSSH 6.9 (2015-07-01). Also first in the default cipher list in the current ssh_config(5) and sshd_config(5)Not reachedInternet-Draft. The working group's draft-ietf-sshm-chacha20-poly1305-04 (2026-05-26) defines it under the name chacha20-poly1305Not mentioned

Where the tables say the current ssh_config(5) or the current sshd_config(5), they mean the default lists read on man.openbsd.org on the verification date. These may differ from the manuals for released versions.

The ssh-rsa row is the row for the signature algorithm. RSA keys (key type ssh-rsa) can continue to be used under the rsa-sha2-256 and rsa-sha2-512 row of Table Part 2. Combinations vulnerable to the Terrapin attack (CVE-2023-48795) include chacha20-poly1305@openssh.com. OpenSSH addressed it with the strict KEX extension in OpenSSH 9.6. The current default list of ciphers in ssh_config(5) and sshd_config(5) still includes chacha20-poly1305@openssh.com.

Three Clocks: OpenSSH, the IETF, and GitHub

Even for the same algorithm, the dates in OpenSSH, the IETF, and GitHub do not always line up. The following figure lines up the dates from the three tracks for the ssh-rsa signature.

The Same Algorithm, Three Clocks - The ssh-rsa Signature in OpenSSH, the IETF, and GitHub
The Same Algorithm, Three Clocks - The ssh-rsa Signature in OpenSSH, the IETF, and GitHub
The ssh-rsa signature was designated as RECOMMENDED in RFC 4253 (January 2006). OpenSSH introduced alternative signatures, rsa-sha2-256 and rsa-sha2-512, in OpenSSH 7.2 (February 29, 2016). RFC 8332 (March 2018) formalized this, stating that implementations should begin disabling ssh-rsa by default once implementers believed the new RSA signature algorithms were widely adopted. OpenSSH announced the change in OpenSSH 8.2 (February 14, 2020), and disabled it by default in OpenSSH 8.8 (September 26, 2021). GitHub began requiring SHA-2 signatures only for RSA keys registered after November 2, 2021 (a change that was made permanent on March 15, 2022), while allowing RSA keys registered before that date to continue using SHA-1 signatures. GitHub plans to remove the ssh-rsa signature entirely on January 13, 2027.

For other algorithms as well, the order is not consistent.

  • ssh-dss — RFC 4253 designated ssh-dss as REQUIRED. OpenSSH 9.7's release notes state that DSA was the only mandatory-to-implement signature algorithm in the SSHv2 RFCs (DSA was the only mandatory-to-implement algorithm in the SSHv2 RFCs). OpenSSH disabled it by default on 2015-08-11 and removed it on 2025-04-09. GitHub stopped new registrations on 2019-08-28 and removed support on 2022-03-15. GitHub's removal occurred three years before OpenSSH's.
  • hmac-sha1 — RFC 4253 designated hmac-sha1 as REQUIRED. GitHub removed it on 2022-03-15. In OpenSSH, it is still on the default lists in the current ssh_config(5) and sshd_config(5) as of the verification date.
  • diffie-hellman-group-exchange-sha256 — RFC 9142 (January 2022) designated it as MAY. OpenSSH 10.0 (2025-04-09) removed it from the default list for the server's sshd(8) but did not change it for the client's ssh(1). GitHub plans to remove it on 2027-01-13.
  • Post-quantum key exchange — OpenSSH made sntrup761x25519-sha512@openssh.com the default on 2022-04-08. GitHub announced 2025-09-17 as the date it would enable sntrup761x25519-sha512, and RFC 9941 was released in April 2026. For mlkem768x25519-sha256 as well, making it the default of the client ssh(1) in OpenSSH 10.0 (2025-04-09) preceded RFC 10042 (August 2026) and GitHub's planned enablement (2026-10-14).

No single date can definitively tell you when your connection might fail. The client version, the implementation and configuration of the server you are connecting to, and the default lists on each side, all operate according to different schedules.

What GitHub Changes Between October 2026 and January 2027

GitHub's changelog from 2026-09-22 lists four dates. All of them are scheduled as of the verification date of 2026-10-04.

  • 2026-10-14 — Newly registered RSA SSH keys must be at least 3072 bits. mlkem768x25519-sha256 is enabled on GitHub.com and on GitHub Enterprise Cloud with data residency, excluding the US region.
  • 2026-11-04 — A brownout of the removal of the ssh-rsa signature type and diffie-hellman-group-exchange-sha256.
  • 2026-12-09 — A second brownout.
  • 2027-01-13 — Removal of the ssh-rsa signature type and diffie-hellman-group-exchange-sha256.

These changes affect only users connecting to Git via SSH and users utilizing the unauthenticated Git protocol on GitHub Enterprise Server. The changelog states If your Git remotes start with https://, nothing here will affect you. On GitHub Enterprise Server, the addition of mlkem768x25519-sha256 will be included in version 3.24, while the other changes will be included in version 3.25.

Regarding users who are currently using RSA keys, the changelog notes, You do not need to generate a new key, since all RSA keys are capable of signing with all hash algorithms. What is required is that your SSH programs and libraries support RSA with SHA-2 signatures (rsa-sha2-256 and rsa-sha2-512). The changelog lists, for some common software, the minimum versions needed to support RSA with SHA-2 robustly with the default configuration:

SoftwareMinimum Version
OpenSSH7.2p1
JSch0.1.66 from this fork
TeamCity2021.2.3
Go SSH0.16.0
libssh21.11.0
PuTTY0.82

Regarding situations where older software cannot be updated, the changelog says you may be able to use an Ed25519 or ECDSA key instead. It recommends using Ed25519 for new keys, and if RSA keys are necessary, advises creating them with a size of 3072 bits or greater. OpenSSH's ssh-keygen has, since OpenSSH 8.0 (released on April 17, 2019), created RSA keys with a default size of 3072 bits. This 3072-bit requirement applies to keys registered after October 14, 2026.

Concerning diffie-hellman-group-exchange-sha256, the changelog states that implementations listed in the table that support RSA with SHA-2 signatures should also support strong key exchange. Regarding mlkem768x25519-sha256, the changelog indicates that no user changes should be required, and older clients should automatically fall back to an older key exchange.

Where the Sources Disagree

The sources disagree in the following places. This article does not round them to one side.

  • The final date in the GitHub changelog — The final date in the 2026-09-22 changelog on GitHub, as of its initial publication, was January 13, 2026. Internet Archive snapshots from 2026-09-22 and from earlier on 2026-09-28 show 2026, and a later 2026-09-28 snapshot and the current text show January 13, 2027. Older copies reposted on other sites may still show 2026. This article uses 2027-01-13 from the current text.
  • The date of draft-ylonen-ssh-protocol-00 — The draft's text indicates a date of 15 November 1995, while the Datatracker record shows 1995-11-16. This article uses the date from the draft's text.
  • The year Streamlined NTRU Prime was replaced — The acknowledgments of RFC 9941 give the year sntrup4591761 was replaced with sntrup761 as In 2020. OpenSSH 8.5, which included this change, was released on 2021-03-03. This article uses the release date.
  • What the Post-Quantum Cryptography page says — This page states that OpenSSH 9.0 and later versions support sntrup761x25519-sha512. In contrast, the notes for OpenSSH 9.9 indicate that OpenSSH 9.9 made the IANA name sntrup761x25519-sha512 available. OpenSSH versions 9.0 through 9.8 used the name sntrup761x25519-sha512@openssh.com. RFC 9941 recommends announcing and accepting both names, on the grounds that some earlier implementations may implement the method only under sntrup761x25519-sha512@openssh.com (Some earlier implementations may implement this protocol only through the name sntrup761x25519-sha512@openssh.com). The page also says that post-quantum signature algorithms will be added in the future, but OpenSSH 10.4 (2026-07-06) already added the composite signature of ML-DSA 44 and Ed25519 as an experiment.
  • How GitHub words the cutoff — The 2021-09-01 announcement words the cutoff by the valid_after date in its 2021-11-02 row and by upload (uploaded) in its 2022-03-15 row. The 2022-03-15 changelog uses uploaded. All of them use 2021-11-02 as the boundary.
  • The date and intended status of draft-ietf-sshm-composite-sigs-00 — The draft's text indicates a date of 21 August 2026, while the Datatracker record shows 2026-08-22. This article uses the date from the draft's text. The intended status, Standards Track, comes from the Intended status: line in the text of the draft. The intended-status field of the Datatracker record is empty.

SSH on AWS

This article does not fully cover which algorithms AWS's SSH endpoints accept. SSH Algorithms on AWS Endpoints covers AWS Transfer Family security policies, Amazon EC2 key pairs, and other endpoints, and uses the stage vocabulary of this article for GitHub's schedule.

On post-quantum key exchange, AWS Transfer Family announced hybrid post-quantum key exchange for SFTP on June 12, 2023. On May 21, 2025, it announced support for ML-KEM key exchange. The announcement on May 21, 2025, states that older methods, including a pre-standardized version of ML-KEM (Kyber) that was introduced in 2023, will be removed from existing policies. The post-quantum page of the Transfer Family user guide lists the SSH policies that support post-quantum key exchange as TransferSecurityPolicy-2025-03 and TransferSecurityPolicy-FIPS-2025-03, and lists the following methods: mlkem768nistp256-sha256, mlkem1024nistp384-sha384, and mlkem768x25519-sha256. These three methods share the same names as those defined in RFC 10042. The full picture of AWS's support for post-quantum cryptography is in Post-Quantum Cryptography Standardization Timeline and Migration on AWS.

Frequently Asked Questions about SSH and OpenSSH Algorithm History

This section answers common questions about SSH and OpenSSH algorithms, drawing on the information presented in this article. The information provided is current as of October 4, 2026.

Why does an OpenSSH client report no matching host key type found?

Because the two sides of the connection have no host key algorithm in common. One cause is when the server only offers ssh-dss or ssh-rsa signatures (SHA-1). OpenSSH disabled ssh-dss by default in OpenSSH 7.0 (2015-08-11) and removed it in OpenSSH 10.0 (2025-04-09). The ssh-rsa signature was also disabled by default in OpenSSH 8.8 (2021-09-26). The Legacy Options page suggests updating the software on the remote side or replacing weaker key types with more secure ones as the best solutions. You can temporarily re-enable the ssh-rsa signature by adding +ssh-rsa to the HostKeyAlgorithms setting. However, because DSA is disabled at compile time from OpenSSH 9.8 and its code is no longer present in OpenSSH 10.0 and later, ssh-dss cannot be re-enabled through configuration in those versions (the Legacy Options page still shows +ssh-dss). If a similar issue occurs during key exchange, the error message will be no matching key exchange method found.

Does disabling the ssh-rsa signature mean that RSA keys must be replaced?

No. What is being disabled is the ssh-rsa signature algorithm that uses SHA-1, not the ssh-rsa key type itself. The OpenSSH 8.8 release notes state that there is no need to replace ssh-rsa keys, and a GitHub changelog from September 22, 2026, states You do not need to generate a new key. The same RSA key can be used with rsa-sha2-256 or rsa-sha2-512 signatures. In many cases, these will be automatically selected if both the client and server support them. However, GitHub plans to require RSA keys registered after October 14, 2026, to be 3072 bits or greater.

What will change on GitHub on January 13, 2027?

On January 13, 2027, GitHub will remove support for the ssh-rsa signature type (an RSA signature that uses SHA-1) and the diffie-hellman-group-exchange-sha256 key exchange algorithm. This is scheduled as of the verification date. Prior to this, there will be brownouts on November 4, 2026, and December 9, 2026. GitHub Enterprise Server will receive this change in version 3.25. The text of the changelog at publication gave the final date as January 13, 2026, and it was corrected to 2027 on September 28, 2026.

Which OpenSSH version first used post-quantum key exchange by default?

OpenSSH 9.0 (released April 8, 2022) was the first to do so. OpenSSH 9.0 set sntrup761x25519-sha512@openssh.com as the default key exchange method for both ssh(1) and sshd(8). OpenSSH 10.0 (released April 9, 2025) then changed the default for the client's ssh(1) to mlkem768x25519-sha256. Both methods are hybrid approaches, combining post-quantum algorithms with X25519.

Why does OpenSSH 10.1 or later warn about a key exchange that is not post-quantum?

The Post-Quantum Cryptography page says the warning means that the server did not offer a post-quantum key exchange. Starting with OpenSSH 10.1 (released October 6, 2025), the client's ssh(1) command will issue a warning when connecting using a non-post-quantum key exchange. As the reason, the Post-Quantum Cryptography page gives the store now, decrypt later attack, in which a future quantum computer decrypts traffic recorded now. To resolve this, update the server so that it supports mlkem768x25519-sha256 or sntrup761x25519-sha512. If the server already runs a version that supports either of them, the page says to check whether its KexAlgorithms option has disabled them. If the server cannot be updated, you can disable the warning for specific hosts by using the WarnWeakCrypto option in the ssh_config(5) file.

Are RFC 9941 and RFC 10042 standards-track documents?

No. Both RFC 9941 (April 2026) and RFC 10042 (August 2026) are designated as Informational. Both came from drafts of the IETF SSH working group. OpenSSH made their methods defaults before the RFCs: the RFC 9941 method in ssh(1) and sshd(8) of OpenSSH 9.0, and mlkem768x25519-sha256 from RFC 10042 in ssh(1) of OpenSSH 10.0. By contrast, the working group draft that defines post-quantum composite signatures (draft-ietf-sshm-composite-sigs-00, August 21, 2026) states that it aims to be a Standards Track document.

Summary

This article lists how algorithms arrived and left, from the initial release of SSH 1.0 (1995-07-12) to OpenSSH 10.5 (2026-08-11). It lines them up by the dates in the OpenSSH release notes, the RFCs, and the GitHub announcements.

Algorithms leave in stages. In OpenSSH, the stages are announcement, default disabling, disabling at compile time, and removal. SSH protocol 1 and ssh-dss have both gone through every one of these stages. The ssh-rsa signature (using SHA-1) is currently at the stage of being disabled by default, as of OpenSSH 8.8 (2021-09-26).

Arrival can also go in stages. The Streamlined NTRU Prime and X25519 key exchange took nearly three years, from the experimental addition to becoming the default, spanning OpenSSH 8.0 to OpenSSH 9.0. mlkem768x25519-sha256 was added to the default list in OpenSSH 9.9 and became the client default in OpenSSH 10.0. OpenSSH 10.1 added a warning stage for key exchanges that are not post-quantum.

A default belongs to a side. OpenSSH 10.0 removed finite field Diffie-Hellman only from the default settings for the sshd(8) server, but it remains in the default list for the ssh(1) client. The sides also diverge on code removal: SSH protocol 1 was removed from the server first.

Dates across different sources don't always align. RFC 8332 (March 2018) said implementations should start to disable ssh-rsa by default once implementers believed new RSA signatures were widely adopted, OpenSSH 8.8 disabled it by default, and GitHub plans to remove it on 2027-01-13. For post-quantum key exchange, OpenSSH made it the default first, and the RFCs came later.

ssh-rsa refers to two things. The algorithm being phased out is the SHA-1-based signature algorithm. RSA keys (of the ssh-rsa key type) continue to be used with rsa-sha2-256 and rsa-sha2-512 signatures.

⚠ Things may change after the verification date. The four GitHub dates are all scheduled as of the verification date. The final date in the changelog was corrected once after publication. All information is current as of 2026-10-04.

This timeline will be updated as SSH and OpenSSH algorithms continue to evolve.

In addition, there are related history-and-timeline articles on this site, so please have a look if you are interested.


References:



References:
Tech Blog with curated related content

Written by Hidekazu Konishi