Algorithms & Limitations¶
SSHClient implements a deliberately small set of modern-enough algorithms, negotiated per RFC 4253 §7.1: for each slot the client proposes a short preference list and the first algorithm the server also offers is selected, independently for each direction. The server must support at least one algorithm per slot — OpenSSH does, in its default configuration.
Negotiated algorithms¶
Preference lists, most preferred first:
| Role | Algorithms |
|---|---|
| Key exchange | diffie-hellman-group14-sha256 (RFC 3526 2048-bit MODP) |
| Server host key | rsa-sha2-256 — the server must have an RSA host key |
| Cipher (per direction) | aes128-ctr, aes256-ctr |
| MAC (per direction) | hmac-sha2-256, hmac-sha2-512 |
| Compression | none |
Crypto primitives are provided by the nettle/GMP library inside Conga's
SSL plugin, called via ⎕NA; the SSH protocol logic is APL.
Authentication¶
| Supported | Not supported |
|---|---|
| password | keyboard-interactive |
RSA public key (rsa-sha2-256), unencrypted openssh-key-v1 files |
encrypted (passphrase) key files |
| ed25519 / ECDSA / DSA keys | |
| agent forwarding, certificates |
Unsupported key files are rejected with a specific message, e.g.
Unsupported key type: ssh-ed25519.
Features and limits¶
| Feature | Status |
|---|---|
Remote command execution (Exec) |
✓ stdout, stderr, exit status, exit signal |
| SFTP v3 upload / download / list / stat | ✓ binary-exact, UTF-8 names |
| Multiple sequential channels per connection | ✓ |
| Reconnect after close or failure | ✓ |
| Interactive shell / PTY | ✗ |
| Port forwarding / tunnels | ✗ |
| SCP | ✗ (use SFTP) |
| Concurrent channels / pipelined SFTP | ✗ (operations are sequential) |
| Rekeying | ✗ |
| Hashed known_hosts entries | ✓ matched (HMAC-SHA-1), written on accept-new when the file uses them |
Interoperability¶
Developed and continuously tested against OpenSSH (8.x–10.x,
internal-sftp), including a server restricted to Ciphers aes256-ctr
and MACs hmac-sha2-512 to prove the fallback path. The client selects
algorithms from the server's KEXINIT before proceeding, so a slot with
no mutual algorithm fails fast with a message naming the gap and
listing what the server offers, e.g.:
Algorithm negotiation failed: server does not offer
diffie-hellman-group14-sha256 (key exchange); server offers:
mlkem768x25519-sha256 sntrup761x25519-sha512 curve25519-sha256 ...
OpenSSH 10 disables modp Diffie-Hellman by default
From OpenSSH 10.0 (shipped in Debian 13 "trixie" and derivatives),
finite-field Diffie-Hellman key exchange is disabled by default. To
accept connections from this client, the server needs it re-enabled
in sshd_config (+ appends to the defaults):
The test suite's setup_sshd.sh does this for its throwaway servers,
along with Ciphers +aes128-ctr,aes256-ctr and
MACs +hmac-sha2-256,hmac-sha2-512 for servers whose defaults have
been narrowed.