hierynomus / hierynomus/sshj

Feature request: adding mlkem768x25519-sha256 post-quantum key exchange

Open
#1,017 0 comments 3 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
2.7k
Forks
620
Avg merge
3d 23h
Merged PRs (30d)
11

Description

Hello,

Are there any plans for SSHJ to support the new `mlkem768x25519-sha256` key exchange algorithm?

[OpenSSH 9.9](https://www.openssh.com/txt/release-9.9) (2024-09-19) introduced support for the new FIPS 203 Module-Lattice Key Encapsulation Mechanism (ML-KEM) post-quantum key exchange algorithm. ML-KEM (formally known as CRYSTALS Kyber) has been [formally standardized by NIST](https://csrc.nist.gov/pubs/fips/203/final) earlier last year, and is designed to be secure against quantum attacks. OpenSSH has chosen to support ML-KEM by using a PQ/T hybrid implementation: `mlkem768x25519-sha256`. Efforts are already underway standardising this via [an IETF Draft](https://datatracker.ietf.org/doc/draft-ietf-sshm-mlkem-hybrid-kex/).

[OpenSSH 10.0](https://www.openssh.com/txt/release-10.0) (2025-04-09) is now using this new quantum-resistant key exchange algorithm by default.

And, as recently announced, [OpenSSH 10.1](https://www.openssh.com/pq.html) will start warning if no post-quantum key exchange algorithm is supported by the server. This in an effort to speed-up adoption and help thwart "store now, decrypt later" attacks.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.