OpenSSH has announced its plans to remove support for DSA keys in the near future. The decision is based on the inherent weaknesses of the DSA algorithm, including the limited key size and use of the SHA1 digest. OpenSSH disabled DSA keys by default in 2015 but has maintained optional support. However, with alternatives like RSA, ECDSA, and EdDSA offering better security and performance, the need for DSA is considered obsolete, except for legacy devices. OpenSSH aims to accelerate the deprecation of DSA by removing it entirely in the next release after January 1, 2025. Users with DSA-only endpoints may need to maintain a legacy release of OpenSSH.
https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html