RFC 4819: Secure Shell Public Key Subsystem
In plain English — editorial summary, not part of the RFC
Secure Shell defines a user authentication mechanism that is based on public keys, but does not define any mechanism for key distribution. No common key management solution exists in current implementations. This document describes a protocol that can be used to configure public keys in an implementation-independent fashion, allowing client software to take on the burden of this configuration. The Public Key Subsystem provides a server-independent mechanism for clients to add public keys, remove public keys, and list the current public keys known by the server. Rights to manage public keys are specific and limited to the authenticated user. A public key may also be associated with various restrictions, including a mandatory command or subsystem. [STANDARDS-TRACK]
Document record
- Document ID
- RFC4819
- Published
- March 2007
- Authors
- J. Galbraith; J. Van Dyke; J. Bright
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 17
- Also known as
- —
- Updated by:
- RFC 9519
Topics
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8270Increase the Secure Shell Minimum Recommended Diffie-Hellman Modulus Size to 2048 BitsCurrent
December 2017
- RFC 8732Generic Security Service Application Program Interface (GSS-API) Key Exchange with SHA-2Current
February 2020
- RFC 9941Secure Shell (SSH) Key Exchange Method Using Hybrid Streamlined NTRU Prime sntrup761 and X25519 with SHA-512: sntrup761x25519-sha512Current
April 2026
- RFC 9987Secure Shell (SSH) Agent ProtocolCurrent
May 2026
- RFC 5114Additional Diffie-Hellman Groups for Use with IETF StandardsCurrent
January 2008
- RFC 5592Secure Shell Transport Model for the Simple Network Management Protocol (SNMP)Current
June 2009
- RFC 5647AES Galois Counter Mode for the Secure Shell Transport Layer ProtocolCurrent
August 2009
- RFC 8160IUTF8 Terminal Mode in Secure Shell (SSH)Current
April 2017
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?