Skip to main content

SSH Keys

Applies to:
ssh-agent~/.ssh/etc/sshRSA / DSA / ECDSA / Ed25519

Overview​

The SSH Keys source discovers SSH keys from the local ssh-agent, the user's ~/.ssh directory, and the system-wide /etc/ssh directory. It then assesses each key's algorithm to determine its quantum vulnerability.

What It Scans​

LocationDetails
ssh-agentKeys currently loaded into the running SSH agent
~/.sshUser SSH keys and identities in the home directory
/etc/sshSystem-wide host keys and SSH configuration

Each discovered key is assessed by algorithm:

  • RSA - quantum-vulnerable
  • DSA - quantum-vulnerable
  • ECDSA - quantum-vulnerable
  • Ed25519 - quantum-vulnerable

When to Use​

🔑

Host Key Inventory

Catalog SSH host and user keys on a server and grade their algorithms

📊

PQC Readiness

Understand the quantum exposure of your SSH key material

How to Run​

Run an SSH Keys scan from the Cockpit scan wizard:

1

Open Run a Scan

In the Cockpit, go to Run a Scan.

2

Select the source

In Step 1 (Source), choose SSH Keys.

3

Start the scan

Start the scan and review the discovered keys and their assessments.