{"id":98964,"date":"2026-09-22T07:11:47","date_gmt":"2026-09-22T14:11:47","guid":{"rendered":"https:\/\/github.blog\/changelog\/2026-09-22-security-improvements-for-ssh"},"modified":"2026-09-22T12:12:35","modified_gmt":"2026-09-22T19:12:35","slug":"security-improvements-for-ssh","status":"publish","type":[3523],"link":"https:\/\/github.blog\/changelog\/2026-09-22-security-improvements-for-ssh","title":{"rendered":"Security improvements for SSH"},"content":{"rendered":"<!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><p>We&rsquo;re removing several SSH algorithms, adding a new algorithm, and requiring larger RSA SSH keys to improve security.<\/p>\n<p>The changes are as follows:<\/p>\n<ul>\n<li>We&rsquo;re removing the ability to use RSA keys using SHA-1 in SSH (i.e., the <code>ssh-rsa<\/code> signature type, including <code>ssh-rsa-cert-v01@openssh.com<\/code> certificates using SHA-1).<\/li>\n<li>We&rsquo;re removing the key exchange mechanism <code>diffie-hellman-group-exchange-sha256<\/code>.<\/li>\n<li>All new RSA SSH keys uploaded after October 14, 2026 must be at least 3072 bits in size, both for signing and authentication.<\/li>\n<li>We&rsquo;re additionally supporting the post-quantum key exchange method <code>mlkem768x25519-sha256<\/code> for SSH sessions on github.com and GitHub Enterprise Cloud with Data Residency, except for the U.S. region.<\/li>\n<\/ul>\n<p>Adding ML-KEM lets us offer a newer, more performant key exchange method that is secure against quantum computers.<\/p>\n<p>We&rsquo;re also removing the older Diffie-Hellman method, a slow, little-used algorithm that could be broken with advances in quantum computing. For RSA, we&rsquo;re removing the use of SHA-1 since it&rsquo;s known to be weak, as well as increasing key sizes to align with 128-bit security requirements.<\/p>\n<h2 id=\"schedule\" id=\"schedule\" ><a class=\"heading-link\" href=\"#schedule\">Schedule<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<ul>\n<li>October 14, 2026: The new RSA key size requirements take effect.  In addition, <code>mlkem768x25519-sha256<\/code> will be enabled on github.com and GitHub Enterprise Cloud with Data Residency (except for the U.S. region).<\/li>\n<li>November 4, 2026: We&rsquo;ll have a brownout of the removal of the <code>ssh-rsa<\/code> signature type (i.e., RSA keys using SHA-1) and the <code>diffie-hellman-group-exchange-sha256<\/code> key exchange algorithm.<\/li>\n<li>December 9, 2026: We&rsquo;ll have another brownout for the <code>ssh-rsa<\/code> signature type and the <code>diffie-hellman-group-exchange-sha256<\/code> key exchange algorithm.<\/li>\n<li>January 13, 2026: We&rsquo;ll remove the <code>ssh-rsa<\/code> signature type and <code>diffie-hellman-group-exchange-sha256<\/code> key exchange algorithm.<\/li>\n<\/ul>\n<p>These changes will all take effect in GitHub Enterprise Server in version 3.25, except for the addition of <code>mlkem768x25519-sha256<\/code>, which will take effect in version 3.24.<\/p>\n<h2 id=\"preparing-for-these-changes\" id=\"preparing-for-these-changes\" ><a class=\"heading-link\" href=\"#preparing-for-these-changes\">Preparing for these changes<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>The only affected users are those connecting with a Git client over SSH or those using the unauthenticated Git protocol on GitHub Enterprise Server. If your Git remotes start with <code>https:\/\/<\/code>, nothing here will affect you.<\/p>\n<h2 id=\"rsa-key-changes\" id=\"rsa-key-changes\" ><a class=\"heading-link\" href=\"#rsa-key-changes\">RSA key changes<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>If you&rsquo;re using an existing RSA key, make sure you&rsquo;re using RSA with SHA-2 (i.e., the <code>rsa-sha2-256<\/code> and <code>rsa-sha2-512<\/code> signature types). You do not need to generate a new key, since all RSA keys are capable of signing with all hash algorithms. As long as the SSH program or library you&rsquo;re using supports RSA with SHA-2, you can continue to use the same key without a problem and most SSH implementations supporting RSA with SHA-2 will choose it automatically.<\/p>\n<p>Note the distinction between the <strong>key type<\/strong> <code>ssh-rsa<\/code>, which applies generically to all RSA keys regardless of signature algorithm, and the confusingly named <strong>signature type<\/strong> <code>ssh-rsa<\/code>, which indicates an RSA key using SHA-1 (as opposed to <code>rsa-sha2-256<\/code> and <code>rsa-sha2-512<\/code>, which refer to RSA keys using SHA-256 and SHA-512, respectively).<\/p>\n<p>Here&rsquo;s a list of some common software that uses SSH to connect to GitHub and the version necessary to support RSA with SHA-2 robustly with the default configuration:<\/p>\n<div data-target=\"content-table-wrap.container\" class=\"content-table-wrap\"><content-table-wrap><table>\n<thead>\n<tr>\n<th>Software<\/th>\n<th>Minimum Version<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>OpenSSH<\/td>\n<td>7.2p1<\/td>\n<\/tr>\n<tr>\n<td>JSch<\/td>\n<td>0.1.66 from <a href=\"https:\/\/github.com\/mwiede\/jsch\">this fork<\/a><\/td>\n<\/tr>\n<tr>\n<td>TeamCity<\/td>\n<td>2021.2.3<\/td>\n<\/tr>\n<tr>\n<td>Go SSH<\/td>\n<td>0.16.0<\/td>\n<\/tr>\n<tr>\n<td>libssh2<\/td>\n<td>1.11.0<\/td>\n<\/tr>\n<tr>\n<td>PuTTY<\/td>\n<td>0.82<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/content-table-wrap><\/div>\n<p>Alternatively, if you&rsquo;re using older software and can&rsquo;t upgrade, you may be able to use an Ed25519 or ECDSA key instead. All Ed25519 and ECDSA keys we support are strong, secure, and will continue to work for the indefinite future.<\/p>\n<p>For generating new keys, we recommend using an Ed25519 key whenever possible. However, if you still need an RSA key for compatibility with other services, you can generate one as long as it as at least 3072 bits in size.<\/p>\n<h2 id=\"removal-of-diffie-hellman-group-exchange-sha256\" id=\"removal-of-diffie-hellman-group-exchange-sha256\" ><a class=\"heading-link\" href=\"#removal-of-diffie-hellman-group-exchange-sha256\">Removal of <code>diffie-hellman-group-exchange-sha256<\/code><span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>If you&rsquo;re using one of the SSH implementations above that supports RSA with SHA-2, it should also support a strong key exchange mechanism.<\/p>\n<h2 id=\"new-post-quantum-algorithms\" id=\"new-post-quantum-algorithms\" ><a class=\"heading-link\" href=\"#new-post-quantum-algorithms\">New post-quantum algorithms<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>The addition of the <code>mlkem768x25519-sha256<\/code> shouldn&rsquo;t require any changes from users. SSH clients will automatically use the new algorithm by default if configured to prefer it. Users who use an older SSH client should automatically fall back to an older key exchange algorithm.<\/p>\n<\/body><\/html>\n","protected":false},"excerpt":{"rendered":"<p>We&rsquo;re removing several SSH algorithms, adding a new algorithm, and requiring larger RSA SSH keys to improve security. The changes are as follows: We&rsquo;re removing the ability to use RSA&hellip;<\/p>\n","protected":false},"author":2106,"featured_media":0,"template":"","meta":{"_gh_post_show_toc":"","_gh_post_is_no_robots":"","_gh_post_is_featured":"","_gh_post_is_excluded":"","_gh_post_is_unlisted":"","_gh_post_related_link_1":"","_gh_post_related_link_2":"","_gh_post_related_link_3":"","_gh_post_sq_img":"","_gh_post_sq_img_id":"","_gh_post_cta_title":"","_gh_post_cta_text":"","_gh_post_cta_link":"","_gh_post_cta_button":"","_gh_post_recirc_hide":"","_gh_post_recirc_col_1":"","_gh_post_recirc_col_2":"","_gh_post_recirc_col_3":"","_gh_post_recirc_col_4":"","_featured_video":"","_gh_post_additional_query_params":"","footnotes":"","_links_to":"","_links_to_target":"","primary_cta":"","primary_cta_url":"","secondary_cta":"","secondary_cta_url":""},"label":[3633,3627],"group":[3918],"coauthors":[3100],"class_list":["post-98964","changelog","type-changelog","status-publish","hentry","changelog-type-deprecations","changelog-label-account-management","changelog-label-application-security","changelog-group-09-2026"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Security improvements for SSH - GitHub Changelog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/github.blog\/changelog\/2026-09-22-security-improvements-for-ssh\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security improvements for SSH \u00b7 GitHub Changelog\" \/>\n<meta property=\"og:description\" content=\"We&rsquo;re removing several SSH algorithms, adding a new algorithm, and requiring larger RSA SSH keys to improve security. The changes are as follows: We&rsquo;re removing the ability to use RSA&hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/github.blog\/changelog\/2026-09-22-security-improvements-for-ssh\/\" \/>\n<meta property=\"og:site_name\" content=\"The GitHub Blog\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-22T19:12:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2024\/08\/d34e9c19123898a8a886147f37a1d167130d1c15be6d399a9c4b30ee6f2a7395-1200x630-1.png?fit=1200%2C630\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data2\" content=\"Allison\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/github.blog\\\/changelog\\\/2026-09-22-security-improvements-for-ssh\\\/\",\"url\":\"https:\\\/\\\/github.blog\\\/changelog\\\/2026-09-22-security-improvements-for-ssh\\\/\",\"name\":\"Security improvements for SSH - The GitHub Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#website\"},\"datePublished\":\"2026-09-22T14:11:47+00:00\",\"dateModified\":\"2026-09-22T19:12:35+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/github.blog\\\/changelog\\\/2026-09-22-security-improvements-for-ssh\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/github.blog\\\/changelog\\\/2026-09-22-security-improvements-for-ssh\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/github.blog\\\/changelog\\\/2026-09-22-security-improvements-for-ssh\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/github.blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Changelogs\",\"item\":\"https:\\\/\\\/github.blog\\\/changelog\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Security improvements for SSH\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/github.blog\\\/#website\",\"url\":\"https:\\\/\\\/github.blog\\\/\",\"name\":\"The GitHub Blog\",\"description\":\"Updates, ideas, and inspiration from GitHub to help developers build and design software.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/github.blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Security improvements for SSH - GitHub Changelog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/github.blog\/changelog\/2026-09-22-security-improvements-for-ssh\/","og_locale":"en_US","og_type":"article","og_title":"Security improvements for SSH \u00b7 GitHub Changelog","og_description":"We&rsquo;re removing several SSH algorithms, adding a new algorithm, and requiring larger RSA SSH keys to improve security. The changes are as follows: We&rsquo;re removing the ability to use RSA&hellip;","og_url":"https:\/\/github.blog\/changelog\/2026-09-22-security-improvements-for-ssh\/","og_site_name":"The GitHub Blog","article_modified_time":"2026-09-22T19:12:35+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/github.blog\/wp-content\/uploads\/2024\/08\/d34e9c19123898a8a886147f37a1d167130d1c15be6d399a9c4b30ee6f2a7395-1200x630-1.png?fit=1200%2C630","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"3 minutes","Written by":"Allison"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/github.blog\/changelog\/2026-09-22-security-improvements-for-ssh\/","url":"https:\/\/github.blog\/changelog\/2026-09-22-security-improvements-for-ssh\/","name":"Security improvements for SSH - The GitHub Blog","isPartOf":{"@id":"https:\/\/github.blog\/#website"},"datePublished":"2026-09-22T14:11:47+00:00","dateModified":"2026-09-22T19:12:35+00:00","breadcrumb":{"@id":"https:\/\/github.blog\/changelog\/2026-09-22-security-improvements-for-ssh\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/github.blog\/changelog\/2026-09-22-security-improvements-for-ssh\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/github.blog\/changelog\/2026-09-22-security-improvements-for-ssh\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/github.blog\/"},{"@type":"ListItem","position":2,"name":"Changelogs","item":"https:\/\/github.blog\/changelog\/"},{"@type":"ListItem","position":3,"name":"Security improvements for SSH"}]},{"@type":"WebSite","@id":"https:\/\/github.blog\/#website","url":"https:\/\/github.blog\/","name":"The GitHub Blog","description":"Updates, ideas, and inspiration from GitHub to help developers build and design software.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/github.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/changelogs\/98964","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/changelogs"}],"about":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/types\/changelog"}],"author":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/users\/2106"}],"version-history":[{"count":3,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/changelogs\/98964\/revisions"}],"predecessor-version":[{"id":98977,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/changelogs\/98964\/revisions\/98977"}],"wp:attachment":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media?parent=98964"}],"wp:term":[{"taxonomy":"changelog-type","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/type?post=98964"},{"taxonomy":"changelog-label","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/label?post=98964"},{"taxonomy":"changelog-group","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/group?post=98964"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/coauthors?post=98964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}