Secure Shell (SSH)
A protocol (RFC 4251 to RFC 4254) giving an encrypted, integrity-protected channel for remote command-line login, file transfer and tunnelling, replacing Telnet and rlogin.
Secure Shell (SSH) provides a protected channel over an untrusted network, mostly for command-line administration. The current version, SSH-2, is specified across RFC 4251 to RFC 4254, which split it into a transport layer, an authentication layer and a connection layer. The transport layer authenticates the server by its host key, agrees session keys and protects everything that follows. The client then authenticates, commonly with a password or with a key pair whose public half is stored on the server. SSH listens by default on TCP port 22, and the ISC2 exam outline names it as a secure protocol.
SSH replaced cleartext tools such as Telnet and rlogin, which exposed passwords to anyone capturing traffic. It also carries other traffic: SFTP is a file transfer protocol that runs inside SSH, which is different from FTPS, FTP protected by TLS. Port forwarding lets SSH tunnel other connections, which can also bypass egress controls. The weak point is first contact: if a user accepts an unknown host key without checking it, a man-in-the-middle can pose as the server.
Exam relevance: a scenario replacing Telnet for remote administration is likely to point to SSH. Candidates are expected to keep SFTP and FTPS apart, and to know that SSH secures the session but still depends on verifying the server’s host key.