RFC 9142: Key Exchange (KEX) Method Updates and Recommendations for Secure Shell (SSH)
In plain English — editorial summary, not part of the RFC
This document updates the recommended set of key exchange methods for use in the Secure Shell (SSH) protocol to meet evolving needs for stronger security. It updates RFCs 4250, 4253, 4432, and 4462.
Document record
- Document ID
- RFC9142
- Published
- January 2022
- Authors
- M. Baushke
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 19
- Also known as
- —
Topics
- 3DES
- AES
- Advanced Encryption Standard
- Curve25519
- Curve448
- DH
- Diffie-Hellman
- Digital Encryption Standard
- ECC
- ECDH
- Elliptic Curve Cryptography
- Elliptic Curve Diffie-Hellman
- FFC
- Finite Field Cryptography
- IFC
- Integer Factorization Cryptography
- MODP
- MTI
- Mandatory to Implement
- Modular Exponential
- Public Key Exchange
- RSA
- SHA-2
- Secure Shell Key Exchange
- Secure Shell
- Security Strength
- Triple-DES
- sha1
- sha256
- sha384
- sha512
- SHA-1
- Modular Exponentiation
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 10015Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2Current
July 2026
- RFC 9053CBOR Object Signing and Encryption (COSE): Initial AlgorithmsUpdated
August 2022
- RFC 8410Algorithm Identifiers for Ed25519, Ed448, X25519, and X448 for Use in the Internet X.509 Public Key InfrastructureUpdated
August 2018
- RFC 5903Elliptic Curve Groups modulo a Prime (ECP Groups) for IKE and IKEv2Current
June 2010
- RFC 9496The ristretto255 and decaf448 GroupsCurrent
December 2023
- RFC 8031Curve25519 and Curve448 for the Internet Key Exchange Protocol Version 2 (IKEv2) Key AgreementCurrent
December 2016
- RFC 6030Portable Symmetric Key Container (PSKC)Current
October 2010
- RFC 5489ECDHE_PSK Cipher Suites for Transport Layer Security (TLS)Current
March 2009
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?