Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Post-quantum key exchange and post-quantum signatures protect different parts of SSH. Key exchange helps protect session traffic from being recorded now and decrypted later; signatures authenticate users and servers against future impersonation. OpenSSH’s hybrid post-quantum key exchange is broadly enabled by default, while its documented composite post-quantum signature support remains experimental and opt-in.

What changes—and what does not

SSH uses key exchange when a client and server establish the cryptographic secrets for a connection. It uses signatures separately to prove identity during user or host authentication. Enabling post-quantum key exchange therefore does not replace your login key, change a server’s host key, or make either one a post-quantum signature key.

Change Purpose When it is used Quantum threat addressed OpenSSH status
Post-quantum key exchange (KEX) Establishes the shared secret used to protect the SSH session During transport setup Recorded traffic being decrypted later Hybrid KEX has been broadly enabled by default; the default method is ML-KEM/X25519 in OpenSSH 10.0 and later, according to the OpenSSH 10.0 release notes.
Post-quantum signature Authenticates a user or server identity by proving possession of a private key During user or host authentication Future forgery or impersonation using a quantum-capable computer The latest documented composite ML-DSA-44/Ed25519 support is experimental and opt-in, per the OpenSSH release notes.

How OpenSSH’s hybrid key exchange works

OpenSSH hybrid methods combine a post-quantum key-establishment method with a classical elliptic-curve Diffie–Hellman method. In the standardized ML-KEM hybrid, the parties derive one secret from ML-KEM and another from X25519, then combine them to produce the shared secret used by SSH. The method specified in RFC 10042 is named mlkem768x25519-sha256.

The hybrid construction is aimed at session confidentiality: it adds protection against an attacker who captures encrypted SSH traffic today and hopes to decrypt it later. It does not alter the authentication key used to log in.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How SSH signatures authenticate identities

Public-key user authentication works by having the client demonstrate possession of a private key corresponding to an accepted public key. Host authentication uses signatures to establish that the server is the expected host. These operations are separate from transport KEX, so a connection can use post-quantum KEX while still authenticating with conventional SSH keys.

OpenSSH’s release notes describe an experimental composite signature algorithm named mldsa44-ed25519, combining ML-DSA-44 with Ed25519. The notes document key generation with ssh-keygen -t mldsa44-ed25519 and say administrators must explicitly enable it in relevant settings, such as HostKeyAlgorithms and PubkeyAcceptedAlgorithms. This is not a default migration of existing keys.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

OpenSSH post-quantum timeline

  • OpenSSH 9.0 (2022): OpenSSH made post-quantum key agreement the default, initially using sntrup761x25519-sha512, as described in its post-quantum guidance.
  • OpenSSH 9.9: The project’s specifications index lists mlkem768x25519-sha256 from this version onward.
  • OpenSSH 10.0 (2025): The release notes say ML-KEM/X25519 became the default key agreement.
  • OpenSSH 10.1: The project guidance says this release began warning when a connection uses KEX without post-quantum protection.

The post-quantum guidance page still describes signature support as future work, while the newer release notes document experimental composite signatures. Read those statements together: signature support is now documented for that release, but it is experimental and not enabled by default.

Why SSH may warn that a connection lacks post-quantum KEX

A warning means the negotiated key exchange did not include post-quantum protection. The client and server must share a KEX method; the warning can appear if the server is too old or unsupported, or if a local KexAlgorithms setting has removed the hybrid methods.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Check the client version: run ssh -V.
  2. Check server support: consult the server administrator or deployment documentation. OpenSSH support for sntrup761x25519-sha512 begins with 9.0; support for mlkem768x25519-sha256 is listed from 9.9.
  3. Inspect local overrides: review SSH configuration for a KexAlgorithms override that excludes the available hybrid methods.
  4. Prefer updating the server: OpenSSH recommends upgrading when possible. Its guidance documents WarnWeakCrypto no-pq-kex as a selective way to silence the warning when accepting the risk—not as a cryptographic fix.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do you need a new SSH key?

Not because you see a warning about post-quantum key exchange. That warning concerns session setup, not the signature algorithm of your user key. Do not regenerate every SSH key as a response to a KEX warning.

Adopting experimental post-quantum signatures is a separate compatibility project. The documented composite algorithm requires explicit configuration, and the relevant clients and servers must support and accept it. OpenSSH’s guidance frames signature migration as preparation for future signature forgery, not an urgent response to recorded-traffic decryption: it says the urgency is ensuring classical signature keys are retired before cryptographically relevant computers become a reality.

Best Value
Yubico - YubiKey 5Ci - Multi-Factor authentication (MFA) Security Key and passkey for iPhone/Android/PC, Dual connectors for Lighting/USB-C, FIDO Certified
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.