What has been planned for a long time now, prior to the infamous heartbleed fiasco of OpenSSL (which does not affect SSH at all), is now officially a reality - with the help of some recently adopted crypto from DJ Bernstein. OpenSSH now finally has a compile-time option to no longer depend on OpenSSL, the option `make OPENSSL=no` has now been introduced for a reduced-configuration OpenSSH to be built without OpenSSL.
The result would leave you with no legacy SSH-1 baggage at all, and on the SSH-2 front with only AES-CTR and chacha20+poly1305 ciphers, ECDH/curve25519 key exchange and Ed25519 public keys.
[Editor's Note: This appears to be very much a Work-in-Progress, so might not be available for your distro or via standard repositories.]
(Score: -1, Offtopic) by Anonymous Coward on Thursday May 01 2014, @01:34PM
Well we're movin on up,
To the east side.
To a deluxe apartment in the sky.
Movin on up,
To the east side.
We finally got a piece of the pie.
Fish don't fry in the kitchen;
Beans don't burn on the grill.
Took a whole lotta tryin',
Just to get up that hill.
Now we're up in the big leagues,
Gettin' our turn at bat.
As long as we live, it's you and me baby,
There ain't nothin wrong with that.
Well we're movin on up,
To the east side.
To a deluxe apartment in the sky.
Movin on up,
To the east side.
We finally got a piece of the pie.