Skip to content

How to Check OpenSSH Supported Algorithms Using ssh -Q

The ssh -Q command displays the algorithms supported by the OpenSSH client. It is useful for verifying available encryption ciphers, MACs, key exchange methods, public key types, and signature algorithms when configuring or troubleshooting SSH connections.

The syntax for use is as follows:

$ ssh -Q query-option

Common query option values include:

  • cipher: Lists supported encryption ciphers.
  • mac: Lists supported message authentication code (MAC) algorithms.
  • kex: Lists supported key exchange algorithms.
  • key: Lists supported public key types.
  • sig: Lists supported signature algorithms.
  • help: Lists all available query options.

This example uses the kex query option to list the supported key exchange algorithms.

$ ssh -Q kex

diffie-hellman-group14-sha256
diffie-hellman-group16-sha512
ecdh-sha2-nistp256
ecdh-sha2-nistp384
curve25519-sha256
curve25519-sha256@libssh.org