github GitHub Changelog ·

GitHub Strengthens SSH Security with Algorithm Deprecations and Post-Quantum KEX

securitydeprecationengineer
security deprecation breaking feature

GitHub is rolling out significant security enhancements for SSH by deprecating several weak algorithms and requiring stronger key sizes. This includes removing support for RSA keys using SHA-1 and the `diffie-hellman-group-exchange-sha256` key exchange method. Simultaneously, GitHub will enforce a minimum 3072-bit size for new RSA SSH keys and introduce the `mlkem768x25519-sha256` post-quantum key exchange. Users connecting via Git clients over SSH are affected and should ensure their systems support stronger algorithms or switch to recommended key types like Ed25519 before changes take full effect in January 2026.

  • →Remove weak SSH algorithms
  • →Mandate larger RSA SSH keys
  • →Add post-quantum key exchange support
  • →Phased rollout schedule for SSH security changes
  • →Guidance for users affected by SSH changes
Breaking changes (1) ›
  • Mandate larger RSA SSH keys

    All new RSA SSH keys uploaded to GitHub after October 14, 2026, must be at least 3072 bits in size for both signing and authentication. This requirement aligns with modern 128-bit security standards.

Deprecations (1) ›
  • Remove weak SSH algorithms

    GitHub will remove support for RSA keys using SHA-1 (ssh-rsa signature type) and the `diffie-hellman-group-exchange-sha256` key exchange mechanism. These methods are being phased out due to known weaknesses or potential vulnerability to quantum computing.

Features (1) ›
  • Add post-quantum key exchange support

    GitHub is adding support for the `mlkem768x25519-sha256` post-quantum key exchange method for SSH sessions on github.com and GitHub Enterprise Cloud (excluding the U.S. region). This provides a newer, more performant method that is secure against quantum computers.

Notes (2) ›
  • Phased rollout schedule for SSH security changes

    The new RSA key size requirement and ML-KEM enablement take effect on October 14, 2026. Brownouts for the removal of SHA-1 RSA keys and Diffie-Hellman KEX are scheduled for November 4 and December 9, 2026, with final removal on January 13, 2026. GitHub Enterprise Server will adopt changes in versions 3.24 and 3.25.

  • Guidance for users affected by SSH changes

    Users connecting via Git clients over SSH are affected by these changes. It is recommended to ensure existing RSA keys use SHA-2 or upgrade SSH software (e.g., OpenSSH 7.2p1+). For new key generation, Ed25519 keys are recommended.

Read the original announcement →

https://github.blog/changelog/2026-09-22-security-improvements-for-ssh

Related releases