RFC 7076: P6R's Secure Shell Public Key Subsystem
In plain English — editorial summary, not part of the RFC
The Secure Shell (SSH) Public Key Subsystem protocol defines a key distribution protocol that is limited to provisioning an SSH server with a user's public keys. This document describes a new protocol that builds on the protocol defined in RFC 4819 to allow the provisioning of keys and certificates to a server using the SSH transport. The new protocol allows the calling client to organize keys and certificates in different namespaces on a server. These namespaces can be used by the server to allow a client to configure any application running on the server (e.g., SSH, Key Management Interoperability Protocol (KMIP), Simple Network Management Protocol (SNMP)). The new protocol provides a server-independent mechanism for clients to add public keys, remove public keys, add certificates, remove certificates, and list the current set of keys and certificates known by the server by namespace (e.g., list all public keys in the SSH namespace). Rights to manage keys and certificates in a particular namespace are specific and limited to the authorized user and are defined as part of the server's implementation. The described protocol is backward compatible to version 2 defined by RFC 4819.
Document record
- Document ID
- RFC7076
- Published
- November 2013
- Authors
- M. Joseph; J. Susoy
- Status
- INFORMATIONAL
- Stream
- INDEPENDENT
- Area
- —
- Pages
- 11
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 5749Distribution of EAP-Based Keys for Handover and Re-AuthenticationCurrent
March 2010
- RFC 4563The Key ID Information Type for the General Extension Payload in Multimedia Internet KEYing (MIKEY)Updated
June 2006
- RFC 3547The Group Domain of InterpretationObsoleted
July 2003
- RFC 7397Report from the Smart Object Security WorkshopCurrent
December 2014
- RFC 7489Domain-based Message Authentication, Reporting, and Conformance (DMARC)Obsoleted
March 2015
- RFC 6218Cisco Vendor-Specific RADIUS Attributes for the Delivery of Keying MaterialCurrent
April 2011
- RFC 7943A Method for Generating Semantically Opaque Interface Identifiers (IIDs) with the Dynamic Host Configuration Protocol for IPv6 (DHCPv6)Current
September 2016
- RFC 6139Routing and Addressing in Networks with Global Enterprise Recursion (RANGER) ScenariosCurrent
February 2011
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?