ImportError: cannot import name 'DSSKey' from 'paramiko'
Explains why `from paramiko import DSSKey` throws ImportError: cannot import name 'DSSKey' from 'paramiko' on paramiko 3+ and how to fix it by switching to RSAKey or Ed25519Key, or pinning paramiko below 3. Use when old SSH code or pysftp breaks after a paramiko upgrade. Not for other paramiko import errors.
ImportError: cannot import name 'DSSKey' from 'paramiko'
TL;DR: paramiko 3.0 deleted DSSKey because DSA keys are insecure. Switch your code to RSAKey or Ed25519Key and generate new keys. Pinning paramiko<3 only buys time.
ImportError: cannot import name 'DSSKey' from 'paramiko'The fix
- Replace the import:
from paramiko import RSAKeyor for new keys, Ed25519Key.
- Generate a replacement key (do not keep using DSA):
ssh-keygen -t ed25519 -f new_key- If a third-party library (like the archived pysftp) imports DSSKey internally, that library is unmaintained: replace it or pin
paramiko<3as a temporary bridge while you migrate.
- Verify:
python -c "from paramiko import RSAKey, Ed25519Key; print('ok')"Expected output: ok.
Agent? Search Vectle for more: curl -s 'https://vectle.com/api/v1/search?q=paramiko+DSSKey+ImportError'
When this applies
- The import worked before a paramiko upgrade to 3.x.
pip show paramikoreports 3.0 or newer.- A dependency like pysftp fails importing paramiko's DSSKey.
When it does NOT apply
- The error is
No module named 'paramiko', which means it is not installed. - You are on paramiko 2.x and still get it, which points at a broken install.
Why this happens
OpenSSH deprecated DSA and paramiko followed by removing DSSKey in the 3.0 major release. Anything still referencing DSA keys, including vendored or archived helpers, breaks loudly instead of silently using weak keys. Treat the ImportError as a push to retire DSA everywhere.
Compatibility
paramiko 3.0+ removed DSSKey. RSAKey and Ed25519Key exist in all modern paramiko versions.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.