UpdatedPROPOSED STANDARDIETF stream

RFC 4819: Secure Shell Public Key Subsystem

Still current, but amended. Parts of this document are changed or extended by RFC 9519. Read both.

In plain English — editorial summary, not part of the RFC

Secure Shell defines a user authentication mechanism that is based on public keys, but does not define any mechanism for key distribution. No common key management solution exists in current implementations. This document describes a protocol that can be used to configure public keys in an implementation-independent fashion, allowing client software to take on the burden of this configuration. The Public Key Subsystem provides a server-independent mechanism for clients to add public keys, remove public keys, and list the current public keys known by the server. Rights to manage public keys are specific and limited to the authenticated user. A public key may also be associated with various restrictions, including a mandatory command or subsystem. [STANDARDS-TRACK]

Document record

Document ID
RFC4819
Published
March 2007
Authors
J. Galbraith; J. Van Dyke; J. Bright
Status
PROPOSED STANDARD
Stream
IETF
Area
sec
Pages
17
Also known as
Updated by:
RFC 9519

Topics

Referenced by

One later RFC formally updates or obsoletes part of this document.

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/4819-secure-shell-public-key-subsystem