RFC 4253: The Secure Shell (SSH) Transport Layer Protocol
In plain English — editorial summary, not part of the RFC
The Secure Shell (SSH) is a protocol for secure remote login and other secure network services over an insecure network. This document describes the SSH transport layer protocol, which typically runs on top of TCP/IP. The protocol can be used as a basis for a number of secure network services. It provides strong encryption, server authentication, and integrity protection. It may also provide compression. Key exchange method, public key algorithm, symmetric encryption algorithm, message authentication algorithm, and hash algorithm are all negotiated. This document also describes the Diffie-Hellman key exchange method and the minimal set of algorithms that are needed to implement the SSH transport layer protocol. [STANDARDS-TRACK]
Document record
- Document ID
- RFC4253
- Published
- January 2006
- Authors
- T. Ylonen; C. Lonvick
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 32
- Also known as
- —
Topics
Referenced by
7 later RFCs formally update or obsolete part of this document.
- RFC 6668SHA-2 Data Integrity Verification for the Secure Shell (SSH) Transport Layer ProtocolCurrent
July 2012
- RFC 8268More Modular Exponentiation (MODP) Diffie-Hellman (DH) Key Exchange (KEX) Groups for Secure Shell (SSH)Current
December 2017
- RFC 8308Extension Negotiation in the Secure Shell (SSH) ProtocolUpdated
March 2018
- RFC 8332Use of RSA Keys with SHA-256 and SHA-512 in the Secure Shell (SSH) ProtocolCurrent
March 2018
- RFC 8709Ed25519 and Ed448 Public Key Algorithms for the Secure Shell (SSH) ProtocolCurrent
February 2020
- RFC 8758Deprecating RC4 in Secure Shell (SSH)Current
April 2020
- RFC 9142Key Exchange (KEX) Method Updates and Recommendations for Secure Shell (SSH)Current
January 2022
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4254The Secure Shell (SSH) Connection ProtocolUpdated
January 2006
- RFC 4252The Secure Shell (SSH) Authentication ProtocolUpdated
January 2006
- RFC 4251The Secure Shell (SSH) Protocol ArchitectureUpdated
January 2006
- RFC 4256Generic Message Exchange Authentication for the Secure Shell Protocol (SSH)Current
January 2006
- RFC 4250The Secure Shell (SSH) Protocol Assigned NumbersUpdated
January 2006
- RFC 4211Internet X.509 Public Key Infrastructure Certificate Request Message Format (CRMF)Updated
September 2005
- RFC 4422Simple Authentication and Security Layer (SASL)Current
June 2006
- RFC 4490Using the GOST 28147-89, GOST R 34.11-94, GOST R 34.10-94, and GOST R 34.10-2001 Algorithms with Cryptographic Message Syntax (CMS)Current
May 2006
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?