OpenSSH 10.6 Introduces Post‑Quantum Signature Algorithm and Deprecates Experimental Keys
OpenSSH 10.6 ships a hybrid post‑quantum signature algorithm and disables several legacy behaviours. Organizations must upgrade, regenerate keys, and document the change to maintain cryptographic governance and audit readiness.
ADTP Breach Watch· October 7, 2026· Help Net Security
SeverityMedium
Type🤖 Advisory
ConfidenceHigh
ReportedOct 7, 2026
Cloud & Infrastructure ProvidersCloud infrastructure providersSaaS platformsEnterprise IT and security teamsVulnerability Exploit
What happened
The OpenSSH team released version 10.6, enabling the hybrid post‑quantum signature algorithm ssh‑mldsa44‑ed25519 and disabling unsafe compression, username handling, and credential storage behaviours. Experimental keys created with earlier post‑quantum support must be regenerated or removed.
Why it matters for trust and compliance
The update underscores the need for continuous cryptographic‑algorithm governance and documented change‑management, both core control objectives that map to many compliance frameworks.
Provides a concrete example of a control‑area (cryptographic algorithm governance) that must be continuously monitored and evidenced.
Creates audit‑ready evidence of patch management, key regeneration, and policy updates across frameworks.
Who is affected
Cloud infrastructure providersSaaS platformsEnterprise IT and security teams
Recommended actions
Upgrade all OpenSSH instances to version 10.6.
Identify and replace any keys generated with the experimental post‑quantum algorithm.
Update cryptographic policies to reflect the newly supported algorithm and deprecate the experimental one.
Record the upgrade, key regeneration, and policy change in your control‑evidence repository.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.