RFC 8270: Increase the Secure Shell Minimum Recommended Diffie-Hellman Modulus Size to 2048 Bits
In plain English — editorial summary, not part of the RFC
The Diffie-Hellman (DH) Group Exchange for the Secure Shell (SSH) transport-layer protocol specifies that servers and clients should support groups with a minimum modulus group size of 1024 bits. Recent security research has shown that the minimum value of 1024 bits is insufficient to protect against state-sponsored actors and any organization with enough computing resources. This RFC updates RFC 4419, which allowed for DH moduli less than 2048 bits; now, 2048 bits is the minimum acceptable group size.
Document record
- Document ID
- RFC8270
- Published
- December 2017
- Authors
- L. Velvindron; M. Baushke
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 5
- Also known as
- —
- Updates:
- RFC 4419
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8732Generic Security Service Application Program Interface (GSS-API) Key Exchange with SHA-2Current
February 2020
- RFC 9142Key Exchange (KEX) Method Updates and Recommendations for Secure Shell (SSH)Current
January 2022
- RFC 9941Secure Shell (SSH) Key Exchange Method Using Hybrid Streamlined NTRU Prime sntrup761 and X25519 with SHA-512: sntrup761x25519-sha512Current
April 2026
- RFC 9987Secure Shell (SSH) Agent ProtocolCurrent
May 2026
- RFC 10015Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2Current
July 2026
- RFC 4819Secure Shell Public Key SubsystemUpdated
March 2007
- RFC 8160IUTF8 Terminal Mode in Secure Shell (SSH)Current
April 2017
- RFC 9519Update to the IANA SSH Protocol Parameters Registry RequirementsCurrent
January 2024
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?