
OpenSSH 9.9 released with DSA disabled and hybrid ML-KEM post-quantum key exchange
The OpenSSH project has announced the release of version 9.9. This update brings significant changes, including the disabling of the DSA signature algorithm by default at compile time, with plans to remove support for DSA entirely by early 2025.
OpenSSH 9.9 introduces a new hybrid post-quantum key exchange mechanism, combining the FIPS 203 Module-Lattice Key Encapsulation Mechanism (ML-KEM) with X25519 ECDH. Additionally, the release features enhanced controls to drop and penalize unwanted connections, as well as faster NTRUPrime key exchange code. Users will also benefit from the usual array of bug fixes and minor usability improvements.
du
No comments so far, maybe you want to be first?
Gu