Technical Summary
This document specifies additions and amendments to SSH GSS-API
Methods [RFC4462]. It defines a new key exchange method that uses
SHA-2 for integrity and deprecates weak DH groups. The purpose of
this specification is to modernize the cryptographic primitives used
by GSS Key Exchanges.
Working Group Summary
No serious issues were raised with this document, but it received little
feedback overall.
Document Quality
The only currently know implementation are patches for OpenSSH in Fedora:
https://src.fedoraproject.org/rpms/openssh/blob/master/f/openssh-7.5p1-gssapi-kex-with-ec.patch
Personnel
Daniel Migault is the document shepherd.
Benjamin Kaduk is the responsible Area Director.
RFC Editor Note
RFC Editor Note
In Section 5.1, sixth paragraph, please remove "according
to Section 4 of [RFC5656]" from the first sentence; that reference
is incorrect and RFC 7546 is (correctly) cited three paragraphs earlier.