07d1ba
diff --color -ru a/ssh_config.5 b/ssh_config.5
07d1ba
--- a/ssh_config.5	2022-07-12 15:05:22.550013071 +0200
07d1ba
+++ b/ssh_config.5	2022-07-12 15:17:20.016704545 +0200
07d1ba
@@ -373,17 +373,13 @@
9070b3
 .Qq *.c.example.com
9070b3
 domains.
9070b3
 .It Cm CASignatureAlgorithms
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 Specifies which algorithms are allowed for signing of certificates
9070b3
 by certificate authorities (CAs).
9070b3
-The default is:
9070b3
-.Bd -literal -offset indent
9070b3
-ssh-ed25519,ecdsa-sha2-nistp256,
9070b3
-ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,
9070b3
-sk-ssh-ed25519@openssh.com,
9070b3
-sk-ecdsa-sha2-nistp256@openssh.com,
9070b3
-rsa-sha2-512,rsa-sha2-256
9070b3
-.Ed
9070b3
-.Pp
9070b3
 If the specified list begins with a
9070b3
 .Sq +
9070b3
 character, then the specified algorithms will be appended to the default set
07d1ba
@@ -445,20 +441,25 @@
9070b3
 (the default),
9070b3
 the check will not be executed.
9070b3
 .It Cm Ciphers
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 Specifies the ciphers allowed and their order of preference.
9070b3
 Multiple ciphers must be comma-separated.
9070b3
 If the specified list begins with a
9070b3
 .Sq +
9070b3
-character, then the specified ciphers will be appended to the default set
9070b3
-instead of replacing them.
9070b3
+character, then the specified ciphers will be appended to the built-in
9070b3
+openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq -
9070b3
 character, then the specified ciphers (including wildcards) will be removed
9070b3
-from the default set instead of replacing them.
9070b3
+from the built-in openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq ^
9070b3
 character, then the specified ciphers will be placed at the head of the
9070b3
-default set.
9070b3
+built-in openssh default set.
9070b3
 .Pp
9070b3
 The supported ciphers are:
9070b3
 .Bd -literal -offset indent
07d1ba
@@ -474,13 +475,6 @@
9070b3
 chacha20-poly1305@openssh.com
9070b3
 .Ed
9070b3
 .Pp
9070b3
-The default is:
9070b3
-.Bd -literal -offset indent
9070b3
-chacha20-poly1305@openssh.com,
9070b3
-aes128-ctr,aes192-ctr,aes256-ctr,
9070b3
-aes128-gcm@openssh.com,aes256-gcm@openssh.com
9070b3
-.Ed
9070b3
-.Pp
9070b3
 The list of available ciphers may also be obtained using
9070b3
 .Qq ssh -Q cipher .
9070b3
 .It Cm ClearAllForwardings
07d1ba
@@ -874,6 +868,11 @@
9070b3
 The default is
9070b3
 .Dq no .
9070b3
 .It Cm GSSAPIKexAlgorithms
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 The list of key exchange algorithms that are offered for GSSAPI
9070b3
 key exchange. Possible values are
9070b3
 .Bd -literal -offset 3n
07d1ba
@@ -886,10 +885,8 @@
9070b3
 gss-curve25519-sha256-
9070b3
 .Ed
9070b3
 .Pp
9070b3
-The default is
9070b3
-.Dq gss-group14-sha256-,gss-group16-sha512-,gss-nistp256-sha256-,
9070b3
-gss-curve25519-sha256-,gss-group14-sha1-,gss-gex-sha1- .
9070b3
 This option only applies to connections using GSSAPI.
9070b3
+.Pp
9070b3
 .It Cm HashKnownHosts
9070b3
 Indicates that
9070b3
 .Xr ssh 1
07d1ba
@@ -1219,29 +1216,25 @@
9070b3
 and
9070b3
 .Cm pam .
9070b3
 .It Cm KexAlgorithms
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 Specifies the available KEX (Key Exchange) algorithms.
9070b3
 Multiple algorithms must be comma-separated.
9070b3
 If the specified list begins with a
9070b3
 .Sq +
9070b3
-character, then the specified methods will be appended to the default set
9070b3
-instead of replacing them.
9070b3
+character, then the specified methods will be appended to the built-in
9070b3
+openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq -
9070b3
 character, then the specified methods (including wildcards) will be removed
9070b3
-from the default set instead of replacing them.
9070b3
+from the built-in openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq ^
9070b3
 character, then the specified methods will be placed at the head of the
9070b3
-default set.
9070b3
-The default is:
9070b3
-.Bd -literal -offset indent
9070b3
-curve25519-sha256,curve25519-sha256@libssh.org,
9070b3
-ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,
9070b3
-diffie-hellman-group-exchange-sha256,
9070b3
-diffie-hellman-group16-sha512,
9070b3
-diffie-hellman-group18-sha512,
9070b3
-diffie-hellman-group14-sha256
9070b3
-.Ed
9070b3
+built-in openssh default set.
9070b3
 .Pp
9070b3
 The list of available key exchange algorithms may also be obtained using
9070b3
 .Qq ssh -Q kex .
07d1ba
@@ -1351,37 +1344,33 @@
9070b3
 file.
9070b3
 This option is intended for debugging and no overrides are enabled by default.
9070b3
 .It Cm MACs
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 Specifies the MAC (message authentication code) algorithms
9070b3
 in order of preference.
9070b3
 The MAC algorithm is used for data integrity protection.
9070b3
 Multiple algorithms must be comma-separated.
9070b3
 If the specified list begins with a
9070b3
 .Sq +
9070b3
-character, then the specified algorithms will be appended to the default set
9070b3
-instead of replacing them.
9070b3
+character, then the specified algorithms will be appended to the built-in
9070b3
+openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq -
9070b3
 character, then the specified algorithms (including wildcards) will be removed
9070b3
-from the default set instead of replacing them.
9070b3
+from the built-in openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq ^
9070b3
 character, then the specified algorithms will be placed at the head of the
9070b3
-default set.
9070b3
+built-in openssh default set.
9070b3
 .Pp
9070b3
 The algorithms that contain
9070b3
 .Qq -etm
9070b3
 calculate the MAC after encryption (encrypt-then-mac).
9070b3
 These are considered safer and their use recommended.
9070b3
 .Pp
9070b3
-The default is:
9070b3
-.Bd -literal -offset indent
9070b3
-umac-64-etm@openssh.com,umac-128-etm@openssh.com,
9070b3
-hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,
9070b3
-hmac-sha1-etm@openssh.com,
9070b3
-umac-64@openssh.com,umac-128@openssh.com,
9070b3
-hmac-sha2-256,hmac-sha2-512,hmac-sha1
9070b3
-.Ed
9070b3
-.Pp
9070b3
 The list of available MAC algorithms may also be obtained using
9070b3
 .Qq ssh -Q mac .
9070b3
 .It Cm NoHostAuthenticationForLocalhost
07d1ba
@@ -1553,37 +1542,25 @@
9070b3
 The default is
9070b3
 .Cm no .
9070b3
 .It Cm PubkeyAcceptedAlgorithms
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 Specifies the signature algorithms that will be used for public key
9070b3
 authentication as a comma-separated list of patterns.
9070b3
 If the specified list begins with a
9070b3
 .Sq +
9070b3
-character, then the algorithms after it will be appended to the default
9070b3
-instead of replacing it.
9070b3
+character, then the algorithms after it will be appended to the built-in
9070b3
+openssh default instead of replacing it.
9070b3
 If the specified list begins with a
9070b3
 .Sq -
9070b3
 character, then the specified algorithms (including wildcards) will be removed
9070b3
-from the default set instead of replacing them.
9070b3
+from the built-in openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq ^
9070b3
 character, then the specified algorithms will be placed at the head of the
9070b3
-default set.
9070b3
-The default for this option is:
9070b3
-.Bd -literal -offset 3n
9070b3
-ssh-ed25519-cert-v01@openssh.com,
9070b3
-ecdsa-sha2-nistp256-cert-v01@openssh.com,
9070b3
-ecdsa-sha2-nistp384-cert-v01@openssh.com,
9070b3
-ecdsa-sha2-nistp521-cert-v01@openssh.com,
9070b3
-sk-ssh-ed25519-cert-v01@openssh.com,
9070b3
-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,
9070b3
-rsa-sha2-512-cert-v01@openssh.com,
9070b3
-rsa-sha2-256-cert-v01@openssh.com,
9070b3
-ssh-rsa-cert-v01@openssh.com,
9070b3
-ssh-ed25519,
9070b3
-ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,
9070b3
-sk-ssh-ed25519@openssh.com,
9070b3
-sk-ecdsa-sha2-nistp256@openssh.com,
9070b3
-rsa-sha2-512,rsa-sha2-256,ssh-rsa
9070b3
-.Ed
9070b3
+built-in openssh default set.
9070b3
 .Pp
9070b3
 The list of available signature algorithms may also be obtained using
9070b3
 .Qq ssh -Q PubkeyAcceptedAlgorithms .
07d1ba
diff --color -ru a/sshd_config.5 b/sshd_config.5
07d1ba
--- a/sshd_config.5	2022-07-12 15:05:22.535012771 +0200
07d1ba
+++ b/sshd_config.5	2022-07-12 15:15:33.394809258 +0200
07d1ba
@@ -373,17 +373,13 @@
9070b3
 then no banner is displayed.
9070b3
 By default, no banner is displayed.
9070b3
 .It Cm CASignatureAlgorithms
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 Specifies which algorithms are allowed for signing of certificates
9070b3
 by certificate authorities (CAs).
9070b3
-The default is:
9070b3
-.Bd -literal -offset indent
9070b3
-ssh-ed25519,ecdsa-sha2-nistp256,
9070b3
-ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,
9070b3
-sk-ssh-ed25519@openssh.com,
9070b3
-sk-ecdsa-sha2-nistp256@openssh.com,
9070b3
-rsa-sha2-512,rsa-sha2-256
9070b3
-.Ed
9070b3
-.Pp
9070b3
 If the specified list begins with a
9070b3
 .Sq +
9070b3
 character, then the specified algorithms will be appended to the default set
07d1ba
@@ -450,20 +446,25 @@
9070b3
 indicating not to
9070b3
 .Xr chroot 2 .
9070b3
 .It Cm Ciphers
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 Specifies the ciphers allowed.
9070b3
 Multiple ciphers must be comma-separated.
9070b3
 If the specified list begins with a
9070b3
 .Sq +
9070b3
-character, then the specified ciphers will be appended to the default set
9070b3
-instead of replacing them.
9070b3
+character, then the specified ciphers will be appended to the built-in
9070b3
+openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq -
9070b3
 character, then the specified ciphers (including wildcards) will be removed
9070b3
-from the default set instead of replacing them.
9070b3
+from the built-in openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq ^
9070b3
 character, then the specified ciphers will be placed at the head of the
9070b3
-default set.
9070b3
+built-in openssh default set.
9070b3
 .Pp
9070b3
 The supported ciphers are:
9070b3
 .Pp
07d1ba
@@ -490,13 +491,6 @@
9070b3
 chacha20-poly1305@openssh.com
9070b3
 .El
9070b3
 .Pp
9070b3
-The default is:
9070b3
-.Bd -literal -offset indent
9070b3
-chacha20-poly1305@openssh.com,
9070b3
-aes128-ctr,aes192-ctr,aes256-ctr,
9070b3
-aes128-gcm@openssh.com,aes256-gcm@openssh.com
9070b3
-.Ed
9070b3
-.Pp
9070b3
 The list of available ciphers may also be obtained using
9070b3
 .Qq ssh -Q cipher .
9070b3
 .It Cm ClientAliveCountMax
07d1ba
@@ -685,21 +679,22 @@
9070b3
 .Cm GSSAPIKeyExchange
9070b3
 needs to be enabled in the server and also used by the client.
9070b3
 .It Cm GSSAPIKexAlgorithms
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 The list of key exchange algorithms that are accepted by GSSAPI
9070b3
 key exchange. Possible values are
9070b3
 .Bd -literal -offset 3n
9070b3
-gss-gex-sha1-,
9070b3
-gss-group1-sha1-,
9070b3
-gss-group14-sha1-,
9070b3
-gss-group14-sha256-,
9070b3
-gss-group16-sha512-,
9070b3
-gss-nistp256-sha256-,
9070b3
+gss-gex-sha1-
9070b3
+gss-group1-sha1-
9070b3
+gss-group14-sha1-
9070b3
+gss-group14-sha256-
9070b3
+gss-group16-sha512-
9070b3
+gss-nistp256-sha256-
9070b3
 gss-curve25519-sha256-
9070b3
 .Ed
9070b3
-.Pp
9070b3
-The default is
9070b3
-.Dq gss-group14-sha256-,gss-group16-sha512-,gss-nistp256-sha256-,
9070b3
-gss-curve25519-sha256-,gss-group14-sha1-,gss-gex-sha1- .
9070b3
 This option only applies to connections using GSSAPI.
9070b3
 .It Cm HostbasedAcceptedAlgorithms
9070b3
 Specifies the signature algorithms that will be accepted for hostbased
07d1ba
@@ -799,26 +794,13 @@
9070b3
 .Ev SSH_AUTH_SOCK
9070b3
 environment variable.
9070b3
 .It Cm HostKeyAlgorithms
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 Specifies the host key signature algorithms
9070b3
 that the server offers.
9070b3
-The default for this option is:
9070b3
-.Bd -literal -offset 3n
9070b3
-ssh-ed25519-cert-v01@openssh.com,
9070b3
-ecdsa-sha2-nistp256-cert-v01@openssh.com,
9070b3
-ecdsa-sha2-nistp384-cert-v01@openssh.com,
9070b3
-ecdsa-sha2-nistp521-cert-v01@openssh.com,
9070b3
-sk-ssh-ed25519-cert-v01@openssh.com,
9070b3
-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,
9070b3
-rsa-sha2-512-cert-v01@openssh.com,
9070b3
-rsa-sha2-256-cert-v01@openssh.com,
9070b3
-ssh-rsa-cert-v01@openssh.com,
9070b3
-ssh-ed25519,
9070b3
-ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,
9070b3
-sk-ssh-ed25519@openssh.com,
9070b3
-sk-ecdsa-sha2-nistp256@openssh.com,
9070b3
-rsa-sha2-512,rsa-sha2-256,ssh-rsa
9070b3
-.Ed
9070b3
-.Pp
9070b3
 The list of available signature algorithms may also be obtained using
9070b3
 .Qq ssh -Q HostKeyAlgorithms .
9070b3
 .It Cm IgnoreRhosts
07d1ba
@@ -965,20 +947,25 @@
9070b3
 The default is
9070b3
 .Cm yes .
9070b3
 .It Cm KexAlgorithms
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 Specifies the available KEX (Key Exchange) algorithms.
9070b3
 Multiple algorithms must be comma-separated.
9070b3
 Alternately if the specified list begins with a
9070b3
 .Sq +
9070b3
-character, then the specified methods will be appended to the default set
9070b3
-instead of replacing them.
9070b3
+character, then the specified methods will be appended to the built-in
9070b3
+openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq -
9070b3
 character, then the specified methods (including wildcards) will be removed
9070b3
-from the default set instead of replacing them.
9070b3
+from the built-in openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq ^
9070b3
 character, then the specified methods will be placed at the head of the
9070b3
-default set.
9070b3
+built-in openssh default set.
9070b3
 The supported algorithms are:
9070b3
 .Pp
9070b3
 .Bl -item -compact -offset indent
07d1ba
@@ -1010,15 +997,6 @@
9070b3
 sntrup761x25519-sha512@openssh.com
9070b3
 .El
9070b3
 .Pp
9070b3
-The default is:
9070b3
-.Bd -literal -offset indent
9070b3
-curve25519-sha256,curve25519-sha256@libssh.org,
9070b3
-ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,
9070b3
-diffie-hellman-group-exchange-sha256,
9070b3
-diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,
9070b3
-diffie-hellman-group14-sha256
9070b3
-.Ed
9070b3
-.Pp
9070b3
 The list of available key exchange algorithms may also be obtained using
9070b3
 .Qq ssh -Q KexAlgorithms .
9070b3
 .It Cm ListenAddress
07d1ba
@@ -1104,21 +1082,26 @@
9070b3
 file.
9070b3
 This option is intended for debugging and no overrides are enabled by default.
9070b3
 .It Cm MACs
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 Specifies the available MAC (message authentication code) algorithms.
9070b3
 The MAC algorithm is used for data integrity protection.
9070b3
 Multiple algorithms must be comma-separated.
9070b3
 If the specified list begins with a
9070b3
 .Sq +
9070b3
-character, then the specified algorithms will be appended to the default set
9070b3
-instead of replacing them.
9070b3
+character, then the specified algorithms will be appended to the built-in
9070b3
+openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq -
9070b3
 character, then the specified algorithms (including wildcards) will be removed
9070b3
-from the default set instead of replacing them.
9070b3
+from the built-in openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq ^
9070b3
 character, then the specified algorithms will be placed at the head of the
9070b3
-default set.
9070b3
+built-in openssh default set.
9070b3
 .Pp
9070b3
 The algorithms that contain
9070b3
 .Qq -etm
07d1ba
@@ -1161,15 +1144,6 @@
9070b3
 umac-128-etm@openssh.com
9070b3
 .El
9070b3
 .Pp
9070b3
-The default is:
9070b3
-.Bd -literal -offset indent
9070b3
-umac-64-etm@openssh.com,umac-128-etm@openssh.com,
9070b3
-hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,
9070b3
-hmac-sha1-etm@openssh.com,
9070b3
-umac-64@openssh.com,umac-128@openssh.com,
9070b3
-hmac-sha2-256,hmac-sha2-512,hmac-sha1
9070b3
-.Ed
9070b3
-.Pp
9070b3
 The list of available MAC algorithms may also be obtained using
9070b3
 .Qq ssh -Q mac .
9070b3
 .It Cm Match
07d1ba
@@ -1548,37 +1522,25 @@
9070b3
 The default is
9070b3
 .Cm yes .
9070b3
 .It Cm PubkeyAcceptedAlgorithms
9070b3
+The default is handled system-wide by
9070b3
+.Xr crypto-policies 7 .
07d1ba
+Information about defaults, how to modify the defaults and how to customize existing policies with sub-policies are present in manual page
9070b3
+.Xr update-crypto-policies 8 .
9070b3
+.Pp
9070b3
 Specifies the signature algorithms that will be accepted for public key
9070b3
 authentication as a list of comma-separated patterns.
9070b3
 Alternately if the specified list begins with a
9070b3
 .Sq +
9070b3
-character, then the specified algorithms will be appended to the default set
9070b3
-instead of replacing them.
9070b3
+character, then the specified algorithms will be appended to the built-in
9070b3
+openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq -
9070b3
 character, then the specified algorithms (including wildcards) will be removed
9070b3
-from the default set instead of replacing them.
9070b3
+from the built-in openssh default set instead of replacing them.
9070b3
 If the specified list begins with a
9070b3
 .Sq ^
9070b3
 character, then the specified algorithms will be placed at the head of the
9070b3
-default set.
9070b3
-The default for this option is:
9070b3
-.Bd -literal -offset 3n
9070b3
-ssh-ed25519-cert-v01@openssh.com,
9070b3
-ecdsa-sha2-nistp256-cert-v01@openssh.com,
9070b3
-ecdsa-sha2-nistp384-cert-v01@openssh.com,
9070b3
-ecdsa-sha2-nistp521-cert-v01@openssh.com,
9070b3
-sk-ssh-ed25519-cert-v01@openssh.com,
9070b3
-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,
9070b3
-rsa-sha2-512-cert-v01@openssh.com,
9070b3
-rsa-sha2-256-cert-v01@openssh.com,
9070b3
-ssh-rsa-cert-v01@openssh.com,
9070b3
-ssh-ed25519,
9070b3
-ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,
9070b3
-sk-ssh-ed25519@openssh.com,
9070b3
-sk-ecdsa-sha2-nistp256@openssh.com,
9070b3
-rsa-sha2-512,rsa-sha2-256,ssh-rsa
9070b3
-.Ed
9070b3
+built-in openssh default set.
9070b3
 .Pp
9070b3
 The list of available signature algorithms may also be obtained using
9070b3
 .Qq ssh -Q PubkeyAcceptedAlgorithms .