ssh – Why OpenSSH deprecated DSA keys – Information Security Stack Exchange
Posted by jpluimers on 2020/03/10
In a lot of ssh-keygen related posts, you still see DSA being mentioned, though that has been deprecated and later removed from OpenSSH.
I wondered why, so I did some digging.
TL;DR: it’s complicated:
- different standards mandating eventually conflicting parameters,
- extending the parameters would require protocol extension,
- a logjam vulnerability for certain combinations of parameters and finally
- better algorithms having become available.
Some of the related topics cannot be archived in the WayBack machine or refuse being archived at Archive.is, so here is a list of partially archived relevant links:
- [WayBack] ssh – Why OpenSSH deprecated DSA keys – Information Security Stack Exchange
- [WayBack refused/Archive.is refused] 1647 – Implement FIPS 186-3 for DSA keys
–jeroen






Leave a comment