More Modular Exponentiation (MODP) Diffie-Hellman (DH) Key Exchange (KEX) Groups for Secure Shell (SSH)
RFC 8268

Technical Summary

This document defines added Modular Exponential (MODP) Groups for the
Secure Shell (SSH) protocol using SHA-2 hashes.

Working Group Summary

The document received few reviews on the mailing list. However, 
discussions occur on whether:
    - choosing IKE vs TLS primes
    - choosing fixed primes versus random.  
The consensus for this document was to restraint to the primes defined for IKE.

The draft describes the following key exchange algorithms:
* diffie-hellman-group14-sha256 
* diffie-hellman-group15-sha512 
* diffie-hellman-group16-sha512 
* diffie-hellman-group17-sha512 
* diffie-hellman-group18-sha512 

These suites have been at least partially implemented. [00],[2]
* OpenSSH has implemented and distributed at least diffie-hellman-group14-sha256 it already [0]
* Dropbear has preliminary support for  diffie-hellman-group14-sha256 by Matt Johnston [1] 
* RLogin supports dh-group{14,15,16}-sha256 since version 2.19.8 [3]. 
* Tera Term committed dh-group{14,15,16}-sha256  support committed to trunk, and it will be included in next release. [4] 
* Poderosa [5] committed to support dh-group{14,15,16}-sha256 support where a pull request has been sent  [6]. 

