SSH Rekey Configuration Notes
SSH rekeying is the process of exchanging the session keys at a configured interval, either after a time limit or a data limit for an SSH session. Rekeying can be initiated by both SSH client and SSH server. While the key exchange renegotiation is taking place, data is not passed through the SSH connection. The algorithm that was used at connection startup is used during rekeying. SSH rekey exchange is supported on OpenSSH-based client version 7.5 or later.
Keep the following items in mind when configuring SSH rekey.
- SSH sessions established without the rekey configuration will not have the rekey functionality.
- When rekey is enabled, the existing SSH session will not have the rekey functionality until the rekey exchange occurs from the other side.
- Removing the rekey configuration disables the SSH rekey for existing SSH sessions.
- When the rekey configuration is changed, the behavior of the existing session will not be affected until the next rekey exchange for the corresponding session.
- When the next rekey exchange occurs, the related data and time parameters of the corresponding SSH session will reset to the configured rekey value.
- The encryption method must not be modified during rekey.