Skip to content

Algorithms & Limitations

SSHClient implements a deliberately small set of modern-enough algorithms, negotiated per RFC 4253 §7.1: for each slot the client proposes a short preference list and the first algorithm the server also offers is selected, independently for each direction. The server must support at least one algorithm per slot — OpenSSH does, in its default configuration.

Negotiated algorithms

Preference lists, most preferred first:

Role Algorithms
Key exchange diffie-hellman-group14-sha256 (RFC 3526 2048-bit MODP)
Server host key rsa-sha2-256 — the server must have an RSA host key
Cipher (per direction) aes128-ctr, aes256-ctr
MAC (per direction) hmac-sha2-256, hmac-sha2-512
Compression none

Crypto primitives are provided by the nettle/GMP library inside Conga's SSL plugin, called via ⎕NA; the SSH protocol logic is APL.

Authentication

Supported Not supported
password keyboard-interactive
RSA public key (rsa-sha2-256), unencrypted openssh-key-v1 files encrypted (passphrase) key files
ed25519 / ECDSA / DSA keys
agent forwarding, certificates

Unsupported key files are rejected with a specific message, e.g. Unsupported key type: ssh-ed25519.

Features and limits

Feature Status
Remote command execution (Exec) ✓ stdout, stderr, exit status, exit signal
SFTP v3 upload / download / list / stat ✓ binary-exact, UTF-8 names
Multiple sequential channels per connection ✓
Reconnect after close or failure ✓
Interactive shell / PTY ✗
Port forwarding / tunnels ✗
SCP ✗ (use SFTP)
Concurrent channels / pipelined SFTP ✗ (operations are sequential)
Rekeying ✗
Hashed known_hosts entries ✓ matched (HMAC-SHA-1), written on accept-new when the file uses them

Interoperability

Developed and continuously tested against OpenSSH (8.x–10.x, internal-sftp), including a server restricted to Ciphers aes256-ctr and MACs hmac-sha2-512 to prove the fallback path. The client selects algorithms from the server's KEXINIT before proceeding, so a slot with no mutual algorithm fails fast with a message naming the gap and listing what the server offers, e.g.:

Algorithm negotiation failed: server does not offer
diffie-hellman-group14-sha256 (key exchange); server offers:
mlkem768x25519-sha256 sntrup761x25519-sha512 curve25519-sha256 ...

OpenSSH 10 disables modp Diffie-Hellman by default

From OpenSSH 10.0 (shipped in Debian 13 "trixie" and derivatives), finite-field Diffie-Hellman key exchange is disabled by default. To accept connections from this client, the server needs it re-enabled in sshd_config (+ appends to the defaults):

KexAlgorithms +diffie-hellman-group14-sha256

The test suite's setup_sshd.sh does this for its throwaway servers, along with Ciphers +aes128-ctr,aes256-ctr and MACs +hmac-sha2-256,hmac-sha2-512 for servers whose defaults have been narrowed.