Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you use an experimental hybrid ML-DSA 44/Ed25519 SSH authentication key, replace it with a newly generated key after upgrading to OpenSSH 10.6. The new enabled signature algorithm is named ssh-mldsa44-ed25519; earlier experimental keys used a name with an @openssh.com suffix. OpenSSH says keys made with that earlier support must be regenerated and/or removed. Generate the replacement under a different filename, install its public key where needed, and verify access before retiring your fallback.

What changed in OpenSSH 10.6

Released on October 6, 2026, OpenSSH 10.6 enables the hybrid post-quantum signature algorithm ssh-mldsa44-ed25519. The experimental implementation used the vendor-suffixed name ssh-mldsa44-ed25519@openssh.com. The OpenSSH 10.6 release notes state that keys generated with the previous experimental support must be regenerated and/or removed.

This is a key replacement, not a key conversion or configuration rename. Create a new key pair; do not expect a setting change to turn the old private key into a key of the new type. The OpenSSH specifications index lists the earlier composite signature draft under its experimental name.

Generate a replacement key without overwriting the old one

Use the generation syntax shown in the OpenSSH release notes, and specify a new output path so the existing key remains available while you migrate:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
ssh-keygen -t mldsa44-ed25519 -f ~/.ssh/id_mldsa44_ed25519

When prompted, set a passphrase appropriate to your use case and follow your organization’s key-management policy. The command creates a private key at ~/.ssh/id_mldsa44_ed25519 and its public counterpart at ~/.ssh/id_mldsa44_ed25519.pub. The algorithm option comes from the 10.6 release notes; choosing a separate filename is a practical precaution to avoid overwriting the old key.

Install and test the new public key

  1. Keep your current access path available. Do not remove the experimental key or another working login method while setting up the replacement.
  2. Install the new public key. Add the contents of ~/.ssh/id_mldsa44_ed25519.pub to the relevant account’s ~/.ssh/authorized_keys, or add it through the central SSH key-management system used by that account. Repeat this for each account or service that relies on the key.
  3. Make a fresh connection using the replacement. For example, specify the private key explicitly with ssh -i ~/.ssh/id_mldsa44_ed25519 user@host. Test the actual server or service, rather than relying on the fact that key generation succeeded.
  4. Retire the old key only after verification. Once the replacement works for every required account, automation job, and endpoint, remove the experimental public key from the corresponding authorized-key locations or key-management system. Keep any necessary fallback until you have confirmed it is safe to remove.

The staged rollout is prudent migration practice; the OpenSSH release note requires regeneration and/or removal but does not prescribe a deployment procedure.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Check compatibility across your endpoints

Do not assume every SSH client, server, embedded device, hosted Git service, or third-party SSH implementation supports the newly enabled signature algorithm just because your local OpenSSH is version 10.6. OpenSSH’s published material does not provide a complete compatibility matrix. Check the versions and algorithm support for the clients and services you actually use, and consult hosted-service documentation where applicable. Maintain a tested fallback during migration if an endpoint cannot yet use the replacement.

  • Inventory accounts and services that currently rely on the experimental key.
  • Confirm that the client used for each connection and the receiving server or service support the new signature algorithm.
  • Test interactive logins and relevant automation separately; successful access to one endpoint does not verify the others.
  • Remove the previous key only from locations where the replacement has been tested.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Authentication keys are not post-quantum key exchange

An SSH authentication key signs a request to prove who the user is. Key exchange negotiates shared secrets for the SSH session’s transport. Replacing the experimental authentication key addresses the former; it does not change the key-exchange algorithm selected for a connection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

OpenSSH’s post-quantum cryptography overview discusses hybrid key agreement separately and notes that mlkem768x25519-sha256 became the default key-agreement scheme in OpenSSH 10.0. A key-exchange warning about a connection selecting a non-post-quantum-safe scheme is about that negotiation, not proof that the user’s authentication key needs a different setting. Treat authentication-key migration and transport key-exchange configuration as separate tasks.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.