Information
OpenSSH has integrated post-quantum cryptography (PQC) to secure SSH connections against potential attacks from future quantum computers. This includes the adoption of hybrid key agreement algorithms that combine classical cryptographic methods with quantum-resistant ones.
More information about the openSSH server configuration is available in the "Configure SSH Server" section overview.
PQC helps secure SSH connections against potential attacks from future quantum computers providing protection against both classical and quantum adversaries.
The combination of established classical algorithms with the forward-looking security of PQC algorithms, offers a robust solution during the transition phase to fully quantum-resistant cryptography.
Solution
Edit or create a drop-in file under /etc/ssh/sshd_config.d/ to enable the post-quantum cryptography key exchange algorithm(s) using the additive form. The drop-in file should be named so that lexical order places it before any other drop-in that sets KexAlgorithms (for example 10-cis-sshd.conf ), and the KexAlgorithms directive must appear above any Include or Match statements.
- IF - openSSH-server version is 9.9 or greater, enable both sntrup761x25519-sha512 and mlkem768x25519-sha256 :
# printf '%s\n' 'KexAlgorithms +sntrup761x25519-sha512,mlkem768x25519-sha256' > /etc/ssh/sshd_config.d/10-cis-sshd.conf
- IF - openSSH-server version is less than 9.9, enable only sntrup761x25519-sha512 :
# printf '%s\n' 'KexAlgorithms +sntrup761x25519-sha512' > /etc/ssh/sshd_config.d/10-cis-sshd.conf
Then reload (or restart) the sshd service to apply the change:
# systemctl reload-or-restart sshd.service
Verify the running configuration includes the required PQC key exchange algorithm(s):
# sshd -T | grep -i '^kexalgorithms'
Note: If local site policy has stricter requirements, add any additional KexAlgorithms that are required by local site policy to the additive list in the example.
Run the following command to apply the configuration change to the running sshd daemon without interrupting active sessions:
# systemctl reload sshd
Impact:
A restrictive list of key exchange algorithms available to the SSH server may prevent some clients from being able to connect.
Including a non-supported key exchange algorithm in the kexalgorithms option, may prevent the SSH server from starting.
Note: The list of supported key exchange algorithms may also be obtained using the ssh -Q KexAlgorithms command.