RFC 4462: Generic Security Service Application Program Interface (GSS-API) Authentication and Key Exchange for the Secure Shell (SSH) Protocol
In plain English — editorial summary, not part of the RFC
The Secure Shell protocol (SSH) is a protocol for secure remote login and other secure network services over an insecure network. The Generic Security Service Application Program Interface (GSS-API) provides security services to callers in a mechanism-independent fashion. This memo describes methods for using the GSS-API for authentication and key exchange in SSH. It defines an SSH user authentication method that uses a specified GSS-API mechanism to authenticate a user, and a family of SSH key exchange methods that use GSS-API to authenticate a Diffie-Hellman key exchange. This memo also defines a new host public key algorithm that can be used when no operations are needed using a host's public key, and a new user authentication method that allows an authorization name to be used in conjunction with any authentication that has already occurred as a side-effect of GSS-API-based key exchange. [STANDARDS-TRACK]
Document record
- Document ID
- RFC4462
- Published
- May 2006
- Authors
- J. Hutzelman; J. Salowey; J. Galbraith; V. Welch
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 29
- Also known as
- —
Referenced by
2 later RFCs formally update or obsolete part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4476Attribute Certificate (AC) Policies ExtensionCurrent
May 2006
- RFC 4442Bootstrapping Timed Efficient Stream Loss-Tolerant Authentication (TESLA)Current
March 2006
- RFC 4490Using the GOST 28147-89, GOST R 34.11-94, GOST R 34.10-94, and GOST R 34.10-2001 Algorithms with Cryptographic Message Syntax (CMS)Current
May 2006
- RFC 4491Using the GOST R 34.10-94, GOST R 34.10-2001, and GOST R 34.11-94 Algorithms with the Internet X.509 Public Key Infrastructure Certificate and CRL ProfileCurrent
May 2006
- RFC 4492Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS)Obsoleted
May 2006
- RFC 4430Kerberized Internet Negotiation of Keys (KINK)Current
March 2006
- RFC 4422Simple Authentication and Security Layer (SASL)Current
June 2006
- RFC 4419Diffie-Hellman Group Exchange for the Secure Shell (SSH) Transport Layer ProtocolUpdated
March 2006
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?