Cryptography in SSH does not necessarily require Public Key Infrastructure (PKI) for authentication. GSSAPI also works. Password also works. Certificates (*not* public/private key) also work. This is just another plugin...

That the comms channel is encrypted is separate to the authentication mechanism that does it *over* the comms channel. GSSAPI is, bizarrely, doubly encrypted in SSH (SSH's own comms channel, along with the encrypted tokens being passed along).

