Plan two separate SSH migrations: deploy and verify post-quantum (PQ) key exchange to protect session confidentiality, then transition host and user authentication keys when your SSH software and surrounding tools support suitable PQ signatures. Hybrid PQ key exchange does not replace the host key that authenticates the server or the user key used to log in.
Why SSH needs two post-quantum migration plans
SSH uses cryptography for distinct jobs. Key exchange establishes the secrets used to protect a session. The server’s host-key signature authenticates its identity during that exchange. User public-key authentication is a separate step used to authenticate a person or service account. Upgrading one job does not automatically upgrade the others.
The urgent PQ concern is key exchange: an attacker could record encrypted sessions now and try to decrypt them later if the negotiated key agreement becomes breakable. A hybrid exchange combines classical and PQ contributions to the session secret. RFC 10042 specifies hybrid SSH methods using ML-KEM with classical ECDH; the host key still participates in the exchange hash and authenticates the server. It is therefore inaccurate to call hybrid PQ KEX a PQ host key or PQ login key.
OpenSSH’s post-quantum guidance distinguishes this retrospective confidentiality risk from the future risk that a sufficiently capable quantum computer could forge classical signatures. NIST has standardized ML-DSA in FIPS 204, but that standard does not by itself mean an SSH implementation can use ML-DSA for host or user authentication. OpenSSH’s PQ guidance says PQ signature support will be added in the future; do not assume ordinary OpenSSH host or user keys can already be ML-DSA keys.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Which OpenSSH versions support PQ key exchange?
OpenSSH’s PQ page describes this release progression. These milestones do not prove what a particular connection negotiated: both peers must have a compatible method enabled, and configuration can change defaults.
| OpenSSH release | Milestone | What to check |
|---|---|---|
| 9.0, April 2022 | First release with default post-quantum key agreement, according to OpenSSH. | Confirm the actual client and server versions and the negotiated method; a default can be overridden. |
| 9.9, 2024 | Added mlkem768x25519-sha256. |
Check that both peers support a common hybrid method and that policy has not disabled it. |
| 10.0, April 2025 | Made mlkem768x25519-sha256 the default. |
Do not infer the effective setting solely from a package or operating-system label. |
| 10.1, 2025 | Added a warning when a connection does not use PQ KEX. | Use the warning as a prompt to inspect the connection and configuration, not as evidence that authentication keys are PQ. |
RFC 10042 defines three standardized hybrid method names: mlkem768nistp256-sha256, mlkem1024nistp384-sha384, and mlkem768x25519-sha256. Interoperability requires a method supported by both ends. Avoid copying an old broad algorithm override without checking whether it removes the hybrid methods you intend to use.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How to inventory your SSH estate
Build separate inventories for key exchange and authentication. Record the observed state for representative client-server pairs, not just what a configuration appears to request.
Record implementation and negotiation
- List SSH clients, servers, operating systems, appliances, managed SSH services, and their versions.
- Capture effective key-exchange policy, including
KexAlgorithmsoverrides, and record which method representative connections actually negotiate. - Record host-key algorithms, user-authentication methods, certificate use, trust stores, compliance profiles, and any policy that restricts algorithms.
- Identify automation and older endpoints that may not share a hybrid method with upgraded systems.
OpenSSH 10.1’s PQ warning means the server did not offer either mlkem768x25519-sha256 or sntrup761x25519-sha512. If the server release should support one of them, inspect effective configuration for an override that disabled it. The warning concerns key exchange; it does not report whether the host or user authentication signature is post-quantum.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Inventory host and user identities separately
- Host identities: map each server identity to its private-key custodian, authorized public key or certificate, client trust data, rotation process, and recovery route.
- User identities: map keys to people or service accounts, authorized-key records or certificate principals, agents, automation, onboarding and offboarding, and account recovery.
- Dependencies: note hardware security modules, agents, libraries, key formats, certificate authorities, backups, and any system that distributes or validates keys.
How to prioritize the migration
1. Upgrade and verify hybrid key exchange
Where supported, upgrade both ends to implementations that can negotiate a hybrid PQ method, then confirm the negotiated method for representative connections. OpenSSH recommends PQ key agreement and identifies mlkem768x25519-sha256 as its default from version 10.0. A client supporting that method is not enough if the server lacks it or policy disables it.
2. Keep authentication keys on a separate timeline
Continue to protect and manage the existing host and user authentication keys under your current security policy while tracking actual SSH support for PQ signatures. NIST published FIPS 204, which specifies ML-DSA, on August 13, 2024. NIST IR 8547, published as an initial public draft on November 12, 2024, describes a broader transition approach; it is not a finalized SSH deployment schedule. Neither publication establishes when a particular SSH stack will support PQ authentication.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Before setting a retirement date for classical authentication keys, verify support across the whole path: key generation and formats, SSH wire protocol, host certificates and user certificates, agents, hardware, libraries, managed services, and mixed-version clients and servers. A capability in one component does not establish end-to-end interoperability.
3. Preserve authenticated trust during rollover
When a replacement signature algorithm is supported by your deployed SSH stack, use an overlap period rather than asking users or automation to accept an unknown key. Distribute the new public identity through an authenticated channel, validate it on clients, test automated connections, and remove the old key only when coverage and recovery are confirmed. For certificate deployments, include issuer keys, principals, validity periods, renewal, revocation, and trust-anchor changes in the rollout plan.
Recommended Free Tools
Best Value
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
Do not solve a new-key mismatch by disabling host-key checks or blindly accepting a changed host key. RFC 9212’s CNSA profile calls for host-key validation through certificates where possible or another secure mechanism, and prohibits trust on first use (TOFU) within that profile. That prohibition is profile-specific; other environments still need strong authenticated host-key verification.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to test before broad deployment
Stage changes across representative systems before rolling them through a fleet. Include the combinations and workflows that could fail for reasons beyond basic algorithm negotiation.
- Old and new client-server combinations, including the actual negotiated KEX method and any policy overrides.
- Host-key verification, certificate validation, user authentication, and the expected behavior when a peer lacks a common algorithm.
- Agents, agent forwarding, hardware-backed keys, automation, scheduled jobs, and managed SSH services where used.
- Key backup and restore, emergency access, rollback, revocation, and removal of retired identities.
- Cryptographically secure randomness and fresh ephemeral exchange material, which RFC 10042 requires for its methods.
- Operational effects of larger keys or signatures when PQ authentication support becomes available, including any system limits or tooling assumptions that need validation.
How to choose a rollout path
The right sequence depends on different constraints at each layer; avoid treating “post-quantum SSH” as one switch.
| Decision | What determines the choice |
|---|---|
| KEX compatibility | Client and server versions, the hybrid methods they share, and effective algorithm policy. |
| Host and user trust | Pinned public keys versus certificates or another authenticated distribution method; certificate lifecycle and trust-anchor operations. |
| Signature readiness | Standardized algorithms such as ML-DSA versus implemented SSH support and compatibility across dependent tools. |
| Operational constraints | Compliance profile, fleet diversity, automation, key custody, recovery, and rollout capacity. |
RFC 9212 sets requirements for its CNSA profile, not a universal configuration for every SSH deployment. Likewise, a standardized algorithm is a necessary reference point, not proof that every vendor, appliance, or client supports it.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

