Networks, devices, and sensors · GraphQL type

SSH type

Secure Shell (SSH) service. SSH is a cryptographic network protocol for operating network services securely over an unsecured network. Its most notable applications are remote login and command-line execution.

RFC4253 document describes the SSH transport layer protocol, which typically runs on top of TCP/IP. The protocol can be used as a basis for a number of secure network services. It provides strong encryption, server authentication, and integrity protection. It may also provide compression.

Key exchange method, public key algorithm, symmetric encryption algorithm, message authentication algorithm, and hash algorithm are all negotiated.

RFC4253 document also describes the Diffie-Hellman key exchange method and the minimal set of algorithms that are needed to implement the SSH transport layer protocol.

Fields

Field Name Description
version - String! Version of the SSH service running
vendor - String! Vendor of the SSH service running
serverKex - [String!] Server Key Exchange The key exchange method specifies how one-time session keys are generated for encryption and for authentication, and how the server authentication is done.
hostKeyAlgo - [String!] Host Key Algorithms The key exchange method specifies how one-time session keys are generated for encryption and for authentication, and how the server authentication is done.
serverToClientCiphers - [String!] Server To Client Ciphers An encryption algorithm and a key will be negotiated during the key exchange. When encryption is in effect, the packet length, padding length, payload, and padding fields of each packet MUST be encrypted with the given algorithm.
serverToClientMACs - [String!] Server To Client MACs Data integrity is protected by including with each packet a MAC that is computed from a shared secret, packet sequence number, and the contents of the packet.
compression - [String!]

Compression A name-list of acceptable compression algorithms in order of preference. The chosen compression algorithm MUST be the first algorithm on the client's name-list that is also on the server's name-list. If there is no such algorithm, both sides MUST disconnect.

Note that "none" must be explicitly listed if it is to be acceptable.

fingerprint - SshFingerprint!

Fingerprint The security of the SSH protocols relies on the verification of public host keys. Since public keys tend to be very large, it is difficult for a human to verify an entire host key. Even with a Public Key Infrastructure (PKI) in place, it is useful to have a standard for exchanging short fingerprints of public keys.

The fingerprint of a public key consists of the output of the MD5 message-digest algorithm [RFC1321]. The input to the algorithm is the public key data as specified by [RFC4253]. (This is the same data that is base64 encoded to form the body of the public key file.)

The output of the algorithm is presented to the user as a sequence of 16 octets printed as hexadecimal with lowercase letters and separated by colons.

Used by

  • ServiceReport union: The service specific data structure describing details of the specific type of service.

Example

Example

{
  "version": "abc123",
  "vendor": "xyz789",
  "serverKex": ["abc123"],
  "hostKeyAlgo": ["abc123"],
  "serverToClientCiphers": ["abc123"],
  "serverToClientMACs": ["abc123"],
  "compression": ["xyz789"],
  "fingerprint": SshFingerprint
}