The IETF Secure Shell Maintenance working group held an interim meeting to discuss progress on composite signature drafts and potential post-quantum algorithm implementations. The group also evaluated the security risks of transport-level compression in SSH, debating whether to deprecate the feature due to side-channel vulnerabilities.
The transition to composite signatures represents a critical step in securing the streaming industry's underlying management infrastructure against future quantum threats. By combining classical and post-quantum algorithms, the IETF ensures that even if one cryptographic layer fails, the transport layer remains protected. The debate over deprecating compression highlights a shift toward prioritizing security over bandwidth efficiency, as modern side-channel attacks exploit legacy features from the 1990s. Strategists should monitor the final decision on transport-level compression, as its removal may necessitate application-level adjustments for high-latency management environments. Watch for the next draft release to confirm if MLDDSA 65 is added to the supported algorithm list.
The IETF's composite signature work for SSH builds on a broader effort within the LAMPS working group, which defines the underlying composite constructions that SSH-specific drafts map into the protocol. At IETF 123 in July 2025, the LAMPS working group presented updates to composite ML-DSA and composite KEM drafts, including a complete Python reference implementation hosted on GitHub that generates test vectors and tables for the specifications. The same session noted that ML-DSA and ML-DSA component secret keys were reduced to seeds, simplifying encoding because the ML-DSA and ML-KEM components became fixed-length. Additional algorithm combinations were requested, including ML-DSA87 with RSA3072 and ML-KEM-1024 with P521, reflecting pressure from products that currently use P521 and face auditor resistance to downgrading to P384.
Damien Miller of OpenSSH has driven the SSH-specific mapping. His initial individual draft, draft-miller-sshm-mldsa44-ed25519-composite-sigs, published in June 2026, specified the COMPSIG-MLDSA44-Ed25519-SHA512 scheme using the identifier ssh-mldsa44-ed25519@openssh.com, explicitly promising that the composite would be no worse than the classical algorithm alone if a vulnerability were found in the post-quantum component. That draft was subsequently replaced by draft-miller-sshm-composite-sigs-00, last updated July 23, 2026, which expanded coverage to include COMPSIG-MLDSA87-ECDSA-P384-SHA512 mapped as ssh-mldsa87-p384, and was itself superseded by the working-group draft draft-ietf-sshm-composite-sigs, signaling formal adoption by the SSHM working group.
A parallel individual draft from Huawei, draft-sun-ssh-composite-sigs-01 published July 4, 2025, proposed a broader set of composite combinations including ML-DSA-65 with Ed25519 and ML-DSA-87 with Ed448, using pre-hash variants of ML-DSA rather than the pure mode selected by Miller's draft. The existence of two competing approaches within the IETF SSHM working group mirrors the debate visible on the mailing list, where Simon Josefsson argued in July 2026 that at least two post-quantum signature schemes based on different primitives should be standardized in hybrid form to mitigate threats including potential weaknesses in lattice-based constructions, while Scott Fluhrer of Cisco countered that SLH-DSA's performance cost makes it prohibitive in some environments and ML-DSA remains necessary as an alternative. Organizations are also evaluating post-quantum cryptography migration strategy to address long-term data security.
The IETF SSH Maintenance working group is advancing composite signatures to integrate post-quantum algorithms, ensuring transport layer protection against future quantum threats. Simultaneously, members are debating the deprecation of transport-level compression to mitigate side-channel vulnerabilities. These efforts are critical for securing management infrastructure as the industry transitions toward quantum-resistant cryptographic standards.
The goal is to integrate post-quantum algorithms with classical ones to ensure that the transport layer remains protected even if one cryptographic layer is compromised.
The group is evaluating deprecation because transport-level compression is susceptible to persistent side-channel attacks that exploit shared compression contexts across multiple channels.
Working group members have reached preliminary consensus on supporting MLDDSA 44 with ED25519 and MLDDSA 87 with P384 combinations.
It represents a critical step in securing the industry's management infrastructure against future quantum threats by combining classical and post-quantum algorithms.
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source