EMZETT.
Login

SSH-USERAUTH

In short: The SSH sub-protocol that, on the encrypted connection established by SSH-TRANS, handles the actual authentication of the user — e.g. via password or public-key methods.

In more detail: After SSH-TRANS has established a secure, encrypted connection to the server, SSH-USERAUTH checks whether the client can identify itself to the server. With the most common method, public-key authentication, the client proves possession of a private key without ever transmitting it — for this the server only knows the matching public key. Only after successful authentication does SSH-CONNECT open the actual channels (shell, port forwarding etc.).

In Depth

SSH-USERAUTH supports several authentication methods, which the client can offer one after another until one succeeds: password (a classic password, transmitted over the connection already encrypted by SSH-TRANS — not in plain text as with Telnet), publickey (the most common and most secure method, see below) and keyboard-interactive (for two-factor prompts or similar interactive prompts).

With public-key authentication, a cryptographic proof takes place without the private key ever being transmitted: the client signs a random message specified by the server with its private key, and the server checks this signature with the previously stored public key — only someone who has the matching private key can create a valid signature. For security reasons, SSH servers should be configured so that password login is temporarily blocked after several failed attempts (protection against brute force), or password login is deactivated completely and only public-key login is allowed.

See also: SSH, SSH-TRANS, SSH-CONNECT, Public key, Private key