Internet Engineering Task Force (IETF) D. Bider Request for Comments: 6668 Bitvise Limited Updates: 4253 M. Baushke Category: Standards Track Juniper Networks, Inc. ISSN: 2070-1721 July 2012SHA-2 Data Integrity Verification for the Secure Shell (SSH) Transport Layer Protocol
Bider & Baushke Standards Track [Page 1]
RFC 6668 Sha2-Transport Layer Protocol July 2012 1. Overview and RationaleThe Secure Shell (SSH) [RFC4251] is a very common protocol for secure remote login on the Internet. Currently, SSH defines data integrity verification using SHA-1 and MD5 algorithms [RFC4253]. Due to recent security concerns with these two algorithms ([RFC6194] and [RFC6151], respectively), implementors and users request support for data integrity verification using some of the SHA-2 family of secure hash algorithms.
1.1. Requirements Terminology
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].
2. Data Integrity Algorithms
This memo adopts the style and conventions of [RFC4253] in specifying how the use of new data integrity algorithms are indicated in SSH.
Bider & Baushke Standards Track [Page 2]
RFC 6668 Sha2-Transport Layer Protocol July 2012 3. IANA ConsiderationsThis document augments the MAC Algorithm Names in [RFC4253] and [RFC4250].
4. Security Considerations
The security considerations of RFC 4253 [RFC4253] apply to this document.5. References 5.1. Normative References[FIPS-180-3]
Bider & Baushke Standards Track [Page 3]
RFC 6668 Sha2-Transport Layer Protocol July 2012
[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
5.2. Informative References
[800-107] National Institute of Standards and Technology (NIST),
Bider & Baushke Standards Track [Page 4]
RFC 6668 Sha2-Transport Layer Protocol July 2012
Authors' Addresses