CISSP-ISSAP · Question #125
Which of the following user authentications are supported by the SSH-1 protocol but not by the SSH-2 protocol? Each correct answer represents a complete solution. Choose all that apply.
The correct answer is A. TIS authentication B. Rhosts (rsh-style) authentication C. Kerberos authentication. SSH-1 included several legacy authentication methods that SSH-2 deliberately removed or replaced for security and design reasons. TIS (Terminal Information Security) authentication was a challenge-response method exclusive to SSH-1 that SSH-2 replaced with the more flexible…
Question
Which of the following user authentications are supported by the SSH-1 protocol but not by the SSH-2 protocol? Each correct answer represents a complete solution. Choose all that apply.
Options
- ATIS authentication
- BRhosts (rsh-style) authentication
- CKerberos authentication
- DPassword-based authentication
How the community answered
(23 responses)- A57% (13)
- D43% (10)
Explanation
SSH-1 included several legacy authentication methods that SSH-2 deliberately removed or replaced for security and design reasons. TIS (Terminal Information Security) authentication was a challenge-response method exclusive to SSH-1 that SSH-2 replaced with the more flexible keyboard-interactive mechanism. Rhosts (rsh-style) authentication was inherited from the older rsh protocol and dropped in SSH-2 due to well-known security weaknesses (it trusts hostname/IP-based identity). Kerberos authentication was natively built into SSH-1, but SSH-2 does not include it directly - SSH-2 can support Kerberos only indirectly via GSSAPI, which is a different mechanism.
Password-based authentication (D) is wrong because it is supported by both SSH-1 and SSH-2 - it's one of the core methods that carried over, making it a distractor here.
Memory tip: Think of SSH-2 as a "security cleanup" - it stripped out anything tied to legacy Unix trust models (Rhosts), proprietary challenge-response (TIS), and tightly-coupled Kerberos, keeping only the portable, well-defined methods like passwords and public keys. If it smells like 1990s Unix trust, SSH-2 probably dropped it.
Topics
Community Discussion
No community discussion yet for this question.