SSH-TRANS
In short: The SSH transport sub-protocol — the lowest layer of SSH, which establishes the encrypted, integrity-protected connection between client and server before any user is authenticated at all.
In more detail: When the connection is established, SSH-TRANS negotiates the encryption algorithm, carries out the key exchange and checks the server host key, so that the client can be sure it’s talking to the right server (protection against man-in-the-middle attacks). Only on this secured connection does SSH-USERAUTH build to authenticate the user.
In Depth
The connection setup roughly follows this pattern:
1. Establish a TCP connection to the server (port 22)
2. Exchange protocol versions ("SSH-2.0-OpenSSH_9.0" or similar)
3. Negotiate algorithms (which encryption, which key exchange)
4. Carry out the key exchange -> a shared session key is created
5. Check the server host key (does the client already know this server? "known_hosts")
6. From here on: the entire connection is encrypted
The server host key check in step 5 is crucial for security: on the very first connection to a new server, SSH shows a fingerprint (“Are you sure you want to continue connecting?”) — if the user confirms it, the key is stored locally in ~/.ssh/known_hosts. On every further connection, the client compares the key presented by the server with the stored one — if it suddenly differs, SSH warns loudly, because this can either mean a legitimate reinstallation of the server or a man-in-the-middle attack attempt.
See also: SSH, SSH-USERAUTH, SSH-CONNECT, Handshake