Open-source dependencies

OpenSSH

OpenSSH defaults to hybrid ML-KEM key exchange, protecting session establishment while host and user authentication keys remain classical.

ShippingVerified through 2026-09-06
Products

Verified capability

1 records
Open-source dependencies

OpenSSH 9.x / 10.0

Shipping
Hybrid key exchange
mlkem768x25519-sha256 default since 10.0
PQC host and user keys
Not available
COpenSSH release notesChecked 2026-09-06
Open first-party evidence

Do not infer: That SSH identities are quantum-resistant — only the session key exchange is.

Roadmap explorer

Published milestones

1 dated steps
  1. 2025-04-09
    shippedC

    OpenSSH 10.0 released

    mlkem768x25519-sha256 became the default key agreement method.

    OpenSSH release notes
Compare OpenSSLCompare GoogleCompare SignalCompare ThalesCompare Amazon Web ServicesCompare Infineon