linux4metoo
New Member
Locally, I've got OpenSSH v. 10.2 installed, and since v. 10.1, OpenSSH gives me the following warning when I SSH into my Shared server:
I checked the version currently in use on the KnownHost cPanel-based shared server hosting my account, and it showed:
According to the document referenced in the link above, OpenSSH has offered post-quantum key agreement to prevent "store now, decrypt later" attacks for several years and it has been the default since OpenSSH-9.0, released in 2022.** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See https://openssh.com/pq.html
I checked the version currently in use on the KnownHost cPanel-based shared server hosting my account, and it showed:
I understand that there is controversy about whether its worth protecting against quantum-computer-based attacks, but I'm wondering if there are plans and/or a way to upgrade the version of OpenSSH on the server to OpenSSH-9.x or later just for the added protection?$ ssh -V
OpenSSH_8.0p1, OpenSSL 1.1.1k FIPS 25 Mar 2021