SSH support for Suite B

Suite B contains a set of encryption and authentication algorithms that meet high security requirements. Table 21 lists all algorithms in Suite B.

The SSH server and client support using the X.509v3 certificate for identity authentication in compliance with the algorithm, negotiation, and authentication specifications defined in RFC 6239.

Table 21: Suite B algorithms

Security level

Key exchange algorithm

Encryption algorithm and HMAC algorithm

Public key algorithm

128-bit

ecdh-sha2-nistp256

aes128-gcm

x509v3-ecdsa-sha2-nistp256

x509v3-ecdsa-sha2-nistp384

192-bit

ecdh-sha2-nistp384

aes256-gcm

x509v3-ecdsa-sha2-nistp384

Both

ecdh-sha2-nistp256

ecdh-sha2-nistp384

aes128-gcm

aes256-gcm

x509v3-ecdsa-sha2-nistp256

x509v3-ecdsa-sha2-nistp384