Comment by djmdjm

3 years ago

We (OpenSSH) haven't "disregarded" the winning variants, we added NTRU before the standardisation process was finished and we'll almost certainly add the NIST finalists fairly soon.

I will eagerly await the new kex and keytypes, and will be sure to sysupgrade.

I will be very curious if the default kex shifts away from NTRU-Prime.

I might also point out that crystals-kyber was coequal to NTRU-Prime at the time that you set your new default kex.

I trust that the changelog will have a detailed explanation of all the changes that you will make, and why.

I will "ssh-rotate" whatever you decide.

https://www.linuxjournal.com/content/ssh-key-rotation-posix-...