Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You cannot enable post-quantum signature authentication in standard upstream OpenSSH just by changing sshd_config. OpenSSH’s official guidance says signature support is future work; its documented post-quantum feature today is key exchange, a different part of the SSH connection. Before changing a server, check what its installed implementation actually supports.

Why a configuration setting cannot enable post-quantum signatures

SSH uses signatures to authenticate a server or a user. Key exchange is separate: it establishes the session’s shared secret and protects the confidentiality of the connection. A post-quantum key-exchange algorithm therefore does not mean that the server can authenticate users or itself with post-quantum signature keys.

OpenSSH documents post-quantum key agreement, but says, “OpenSSH will add support for post-quantum signature algorithms in the future.” The project describes post-quantum key agreement as available since OpenSSH 9.0, initially using sntrup761x25519-sha512. It says OpenSSH 9.9 added mlkem768x25519-sha256 and OpenSSH 10.0 made that algorithm the new default. These are key-exchange algorithms, not signature algorithms. OpenSSH’s post-quantum guidance

Directives such as HostKeyAlgorithms and PubkeyAcceptedAlgorithms govern which supported signature algorithms are permitted for host keys and public-key authentication. They cannot add an algorithm that the running daemon does not implement. Do not paste a speculative post-quantum signature name into either setting and assume the server can use it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Check what your installed server supports

OpenSSH versions, distribution packages, and separately built implementations can differ. Check the exact server binary and its matching manual before editing configuration; do not infer support from a specification entry or from a different machine’s version.

  1. Identify the daemon version and binary used by your service. For OpenSSH, run sshd -V where supported by your build, or consult the package manager and service definition if the command is not available.

    Rank #2
    Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
    • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
    • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
    • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
    • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
    • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  2. Read the matching sshd_config(5) manual and the release notes for that package. For example, the Debian testing manual describes HostKeyAlgorithms as the server’s host-key signature algorithm policy and PubkeyAcceptedAlgorithms as the public-key authentication algorithm policy. The manual is specific to Debian testing; use the documentation for your own distribution and installed version.

  3. Query the supported algorithms reported by the installed tools. ssh -Q key can show key types known to the client binary; ssh -Q PubkeyAcceptedAlgorithms and ssh -Q HostKeyAlgorithms can show the corresponding client-side algorithm lists. These queries do not prove that a particular sshd package accepts a key for authentication. Confirm server behavior against that daemon’s documentation and configuration-test output.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    Rank #3
    Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
    • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
    • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
    • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
    • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
    • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  4. Validate any intended configuration with the matching daemon’s test mode before reloading it. On OpenSSH, sshd -t checks configuration syntax and host keys; it does not create support for an algorithm missing from the build.

OpenSSH’s release notes are the appropriate place to recheck for upstream support announcements. An entry in the OpenSSH specifications listing—including the composite signature identifier ssh-mldsa44-ed25519@openssh.com, marked there for version 10.4 onward—is not, by itself, a deployment recipe or proof that a particular release or distribution package provides the feature. Confirm the release, package, and server manual before relying on it.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What you can do today

If your goal is post-quantum key exchange

Use a maintained OpenSSH release that supports the project-documented key-exchange algorithms, and check the effective configuration and client/server compatibility for your environment. The post-quantum exchange helps address “store now, decrypt later” risk: captured encrypted traffic could be decrypted in the future if the classical key agreement used to protect it is broken. This is a confidentiality measure, not post-quantum authentication.

If your goal is post-quantum signature authentication

There is no supported upstream sshd_config switch established by OpenSSH’s guidance for enabling it. Keep using algorithms supported by your deployed implementation, and monitor upstream release notes and your distribution’s package documentation for an explicit implementation and migration path. Do not weaken or replace production authentication based on an unverified algorithm name.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

If you are evaluating an experimental implementation

Open Quantum Safe documents a separate OQS-OpenSSH fork and fork-specific key-generation and test-server commands. Treat that workflow as a distinct, separately built implementation—not as configuration for ordinary distribution OpenSSH. Verify client and server compatibility, key formats, algorithm sizes, operational support, and production suitability independently; the fork’s instructions do not establish upstream support or general production endorsement. OQS-OpenSSH OQS-v10 instructions

Why signatures and key exchange have different urgency

A future quantum computer capable of breaking current public-key cryptography could threaten authentication by enabling signature forgery. Unlike the “store now, decrypt later” concern for key exchange, that would not retrospectively decrypt SSH sessions recorded today; it would threaten authentication going forward. OpenSSH’s guidance frames the signature concern as retiring classical signature keys before cryptographically relevant quantum computers become practical. The page gives a 5–20 year forecast range and says many observers expect the mid-2030s, but does not identify those observers in the cited passage, so treat that as the project page’s unsourced forecast rather than a precise deadline. OpenSSH: Post-Quantum Cryptography

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.