This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · #001 · Week 39 · Sep 21 – 27, 2026

x/crypto/ssh: one signer interface, SignerV2

Nice to knowecosystem

What changed
Accepted: a SignerV2 interface that folds today's Signer, AlgorithmSigner and MultiAlgorithmSigner into one, with SignContext taking a context and the signature algorithm, and Algorithms listing the algorithms a key offers. New constructors come with it: NewSignerV2, NewSignerV2WithAlgorithms and NewCertificateSignerV2.
Production impact
SignerV2 drops DSA keys and the legacy PEM encryption of RFC 1423, and the proposal describes it as the API meant to replace the current one when x/crypto/ssh moves into the standard library.
Try it
Check whether your code still uses DSA keys or RFC 1423 encrypted PEM keys; neither will be accepted by SignerV2.
Source
github.com/golang/go/issues/74424

Understand it, then run it

When an SSH client or server proves who it is, it signs data with its private key. In Go's x/crypto/ssh package, the thing that signs is a Signer. Over the years two more interfaces were added beside it, so that RSA keys could choose between signature algorithms, and code had to check which one a key implemented.

The accepted proposal replaces the three with one interface, SignerV2. You ask it which algorithms it supports, and you pass the algorithm you want when you sign.

After the change ships

go · the proposal's code; it does not compile until the change ships

// From the accepted proposal; it does not compile until the change ships.
type SignerV2 interface {
	PublicKey() PublicKey
	Sign(rand io.Reader, data []byte) (*Signature, error)
	SignContext(ctx context.Context, rand io.Reader, data []byte, algorithm string) (*Signature, error)
	Algorithms() []string
	Signer() (crypto.Signer, error)
}

func NewSignerV2(signer crypto.Signer) (SignerV2, error)
func NewSignerV2WithAlgorithms(signer SignerV2, algorithms []string) (SignerV2, error)
func NewCertificateSignerV2(cert *Certificate, signer SignerV2) (SignerV2, error)

Written by gpt-oss-120b from the linked source · claims checked against the sources · human-reviewed