Crypto-View

hyperledger/fabric-sdk-java

Readiness score
21 of 100
How this is calculated · previous scan 21
Cryptographic posture
Quantum-vulnerable 479 Reduced margin 15 Could not be determined 32 Quantum-safe 5
To address467
Key establishment6
Inventory only1
Total findings532
What was analysed
Branch main
Commit a61508e5bf7c8f7197926f28db51cdab0a6b9f1e Archive repo (#306)
Committed 2025-04-22 16:17 UTC
Scanned 2026-09-10 07:56 UTC 19 hours ago
Coverage 772 files, 6 go, 254 java, 2 javascript

Earlier scans of this repository

11 scans · score 27 → 25 · compare any two
11 scans · 27 → 25 (down 2). The filled point is the scan you are reading.
Scanned Commit Score To address
4 hours ago a61508e5bf7c main 25 467 Compare
5 hours ago a61508e5bf7c main 25 467 Compare
19 hours ago this scan a61508e5bf7c main 21 467
21 hours ago a61508e5bf7c main 21 467 Compare
1 day ago a61508e5bf7c main 21 467 Compare
1 day ago a61508e5bf7c main 21 467 Compare
1 day ago a61508e5bf7c main 21 467 Compare
1 day ago a61508e5bf7c main 27 466 Compare
3 days ago a61508e5bf7c main 27 466 Compare
3 days ago a61508e5bf7c main 27 466 Compare
11 days ago a61508e5bf7c main 27 466 Compare

Every repository in this history is re-scanned weekly.

List of cryptographic assets

ECDSA256-bitsecg/secp256r1 Quantum-vulnerable 389 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/ca/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  2. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/msp/admincerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  3. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/msp/cacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  4. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/msp/tlscacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  5. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/admincerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  6. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/cacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  7. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/signcerts/orderer.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  8. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/tlscacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  9. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  10. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  11. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/tlsca/tlsca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  12. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/admincerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  13. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/cacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  14. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/signcerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  15. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/tlscacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  16. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  17. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  18. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/ca/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  19. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  20. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  21. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/msp/tlscacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  22. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  23. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  24. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/signcerts/peer0.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  25. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/tlscacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  26. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  27. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  28. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  29. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  30. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/signcerts/peer1.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  31. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/tlscacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  32. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  33. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  34. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/tlsca/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  35. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  36. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  37. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/signcerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  38. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/tlscacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  39. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  40. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  41. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/admincerts/User1@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  42. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  43. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/signcerts/User1@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  44. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/tlscacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  45. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  46. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  47. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/ca/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  48. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/msp/admincerts/Admin@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  49. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/msp/cacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  50. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/msp/tlscacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  51. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/msp/admincerts/Admin@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  52. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/msp/cacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  53. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/msp/signcerts/peer0.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  54. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/msp/tlscacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  55. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  56. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  57. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/msp/admincerts/Admin@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  58. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/msp/cacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  59. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/msp/signcerts/peer1.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  60. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/msp/tlscacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  61. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  62. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  63. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/tlsca/tlsca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  64. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp/admincerts/Admin@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  65. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp/cacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  66. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp/signcerts/Admin@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  67. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp/tlscacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  68. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  69. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  70. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/msp/admincerts/User1@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  71. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/msp/cacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  72. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/msp/signcerts/User1@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  73. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/msp/tlscacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  74. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  75. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  76. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/ca/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  77. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/msp/admincerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  78. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/msp/cacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  79. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/msp/tlscacerts/tlsca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  80. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/admincerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  81. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/cacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  82. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/signcerts/orderer.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  83. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/tlscacerts/tlsca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  84. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  85. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  86. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/tlsca/tlsca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  87. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/admincerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  88. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/cacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  89. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/signcerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  90. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/tlscacerts/tlsca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  91. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  92. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/tls/client.crt:1 test path -----BEGIN CERTIFICATE-----
  93. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/ca/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  94. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  95. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  96. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/msp/tlscacerts/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  97. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  98. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  99. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/signcerts/peer0.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  100. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/tlscacerts/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  101. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  102. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  103. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  104. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  105. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/signcerts/peer1.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  106. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/tlscacerts/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  107. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  108. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  109. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/tlsca/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  110. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  111. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  112. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/signcerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  113. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/tlscacerts/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  114. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  115. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/tls/client.crt:1 test path -----BEGIN CERTIFICATE-----
  116. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/admincerts/User1@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  117. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  118. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/signcerts/User1@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  119. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/tlscacerts/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  120. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  121. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/tls/client.crt:1 test path -----BEGIN CERTIFICATE-----
  122. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/ca/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  123. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/msp/admincerts/Admin@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  124. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/msp/cacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  125. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/msp/tlscacerts/tlsca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  126. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/msp/admincerts/Admin@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  127. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/msp/cacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  128. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/msp/signcerts/peer0.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  129. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/msp/tlscacerts/tlsca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  130. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  131. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  132. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/msp/admincerts/Admin@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  133. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/msp/cacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  134. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/msp/signcerts/peer1.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  135. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/msp/tlscacerts/tlsca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  136. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  137. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  138. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/tlsca/tlsca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  139. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp/admincerts/Admin@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  140. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp/cacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  141. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp/signcerts/Admin@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  142. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp/tlscacerts/tlsca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  143. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  144. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/tls/client.crt:1 test path -----BEGIN CERTIFICATE-----
  145. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/msp/admincerts/User1@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  146. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/msp/cacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  147. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/msp/signcerts/User1@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  148. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/msp/tlscacerts/tlsca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  149. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  150. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/tls/client.crt:1 test path -----BEGIN CERTIFICATE-----
  151. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/ca/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  152. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/msp/admincerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  153. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/msp/cacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  154. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/msp/tlscacerts/tlsca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  155. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/admincerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  156. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/cacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  157. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/signcerts/orderer.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  158. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/msp/tlscacerts/tlsca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  159. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  160. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  161. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/tlsca/tlsca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  162. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/admincerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  163. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/cacerts/ca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  164. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/signcerts/Admin@example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  165. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/msp/tlscacerts/tlsca.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  166. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  167. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/tls/client.crt:1 test path -----BEGIN CERTIFICATE-----
  168. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/ca/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  169. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  170. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  171. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/msp/tlscacerts/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  172. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  173. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  174. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/signcerts/peer0.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  175. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/msp/tlscacerts/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  176. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  177. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  178. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  179. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  180. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/signcerts/peer1.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  181. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/msp/tlscacerts/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  182. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  183. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/tls/server.crt:1 test path -----BEGIN CERTIFICATE-----
  184. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/tlsca/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  185. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/admincerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  186. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  187. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/signcerts/Admin@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  188. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp/tlscacerts/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  189. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  190. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/tls/client.crt:1 test path -----BEGIN CERTIFICATE-----
  191. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/admincerts/User1@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  192. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/cacerts/ca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  193. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/signcerts/User1@org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  194. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/msp/tlscacerts/tlsca.org1.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  195. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/tls/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  196. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/tls/client.crt:1 test path -----BEGIN CERTIFICATE-----
  197. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org2.example.com/ca/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  198. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org2.example.com/msp/admincerts/Admin@org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  199. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org2.example.com/msp/cacerts/ca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----
  200. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org2.example.com/msp/tlscacerts/tlsca.org2.example.com-cert.pem:1 test path -----BEGIN CERTIFICATE-----

Showing the first 200. The CBOM has every one.

pem.certificate
ECDSA256-bitsecg/secp256r1 Quantum-vulnerable 53 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  2. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  3. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  4. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  5. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  6. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  7. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  8. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  9. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  10. src/test/fixture/sdkintegration/e2e-2Orgs/v1.0/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  11. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  12. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  13. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  14. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  15. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  16. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  17. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  18. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  19. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  20. src/test/fixture/sdkintegration/e2e-2Orgs/v1.1/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  21. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  22. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  23. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  24. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  25. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  26. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  27. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  28. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  29. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  30. src/test/fixture/sdkintegration/e2e-2Orgs/v1.2/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  31. src/test/fixture/sdkintegration/e2e-2Orgs/v1.3/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  32. src/test/fixture/sdkintegration/e2e-2Orgs/v1.3/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  33. src/test/fixture/sdkintegration/e2e-2Orgs/v1.3/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  34. src/test/fixture/sdkintegration/e2e-2Orgs/v1.3/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  35. src/test/fixture/sdkintegration/e2e-2Orgs/v1.3/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  36. src/test/fixture/sdkintegration/e2e-2Orgs/v1.3/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  37. src/test/fixture/sdkintegration/e2e-2Orgs/v1.3/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  38. src/test/fixture/sdkintegration/e2e-2Orgs/v1.3/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  39. src/test/fixture/sdkintegration/e2e-2Orgs/v1.3/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  40. src/test/fixture/sdkintegration/e2e-2Orgs/v1.3/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  41. src/test/fixture/sdkintegration/e2e-2Orgs/v2.1/crypto-config/ordererOrganizations/example.com/orderers/orderer.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  42. src/test/fixture/sdkintegration/e2e-2Orgs/v2.1/crypto-config/ordererOrganizations/example.com/users/Admin@example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  43. src/test/fixture/sdkintegration/e2e-2Orgs/v2.1/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  44. src/test/fixture/sdkintegration/e2e-2Orgs/v2.1/crypto-config/peerOrganizations/org1.example.com/peers/peer1.org1.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  45. src/test/fixture/sdkintegration/e2e-2Orgs/v2.1/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  46. src/test/fixture/sdkintegration/e2e-2Orgs/v2.1/crypto-config/peerOrganizations/org1.example.com/users/User1@org1.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  47. src/test/fixture/sdkintegration/e2e-2Orgs/v2.1/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  48. src/test/fixture/sdkintegration/e2e-2Orgs/v2.1/crypto-config/peerOrganizations/org2.example.com/peers/peer1.org2.example.com/tls/server.key:1 test path -----BEGIN PRIVATE KEY-----
  49. src/test/fixture/sdkintegration/e2e-2Orgs/v2.1/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  50. src/test/fixture/sdkintegration/e2e-2Orgs/v2.1/crypto-config/peerOrganizations/org2.example.com/users/User1@org2.example.com/tls/client.key:1 test path -----BEGIN PRIVATE KEY-----
  51. src/test/fixture/sdkintegration/network_configs/network-config-tls.yaml:140 test path -----BEGIN PRIVATE KEY-----
  52. src/test/fixture/sdkintegration/network_configs/network-config.yaml:140 test path -----BEGIN PRIVATE KEY-----
  53. src/test/resources/tls-client.key:1 test path -----BEGIN PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
ECDSA Quantum-vulnerable 4 places See details

Elliptic-curve cryptography through BouncyCastle

A BouncyCastle elliptic-curve class. `ECDHBasicAgreement` in particular is key establishment and carries harvest-now-decrypt-later exposure.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 for signatures, ML-KEM-768 for key establishment.

  1. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:77 import org.bouncycastle.asn1.x9.ECNamedCurveTable;
  2. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:78 import org.bouncycastle.asn1.x9.X9ECParameters;
  3. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:625 X9ECParameters params = ECNamedCurveTable.getByName(lcurveName);
  4. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:728 X9ECParameters params = ECNamedCurveTable.getByName(curveName);
java.bouncycastle.ec · CWE-327
ECDSA Quantum-vulnerable 4 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. src/test/fixture/testPems/client.key:1 test path -----BEGIN EC PRIVATE KEY-----
  2. src/test/resources/ca.key:1 test path -----BEGIN EC PRIVATE KEY-----
  3. src/test/resources/keypair-signed.key:1 test path -----BEGIN EC PRIVATE KEY-----
  4. src/test/resources/tls-client-pk8.key:1 test path -----BEGIN EC PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
ECDH Quantum-vulnerable Recorded traffic 3 places See details

Classical key material handled through the JCA

`KeyFactory.getInstance()` for a classical algorithm. This indicates the code parses or produces keys of that family, which is a migration surface even where it does no cryptography itself.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Include this code path in the inventory: it has to accept post-quantum key encodings before the keys themselves can change.

  1. src/main/java/org/hyperledger/fabric_ca/sdk/HFCAClient.java:1214 return KeyFactory.getInstance("EC").generatePublic(new X509EncodedKeySpec(der));
  2. src/test/java/org/hyperledger/fabric/sdk/identity/IdemixIdentitiesTest.java:471 test path return KeyFactory.getInstance("EC").generatePublic(new X509EncodedKeySpec(der));
  3. src/test/java/org/hyperledger/fabric/sdk/security/CryptoPrimitivesTest.java:112 test path kf = KeyFactory.getInstance("EC");
java.keyfactory · CWE-327
ECDSA Quantum-vulnerable 2 places See details

Classical signature algorithm through the JCA

`Signature.getInstance()` with a classical algorithm. The digest and the key algorithm are split out of the JCA name, so `SHA1withRSA` reports both the broken digest and the quantum-vulnerable key.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 (FIPS 204). Where the verifier cannot be changed, sign twice and publish both signatures.

  1. src/main/java/org/hyperledger/fabric/sdk/idemix/RevocationAuthority.java:106 Signature ecdsa = Signature.getInstance("SHA256withECDSA");
  2. src/main/java/org/hyperledger/fabric/sdk/idemix/RevocationAuthority.java:144 Signature dsa = Signature.getInstance("SHA256withECDSA");
java.signature · CWE-327
ECDH Quantum-vulnerable Recorded traffic 1 place See details

Classical key pair generated through the JCA

`KeyPairGenerator.getInstance()` with a classical algorithm. The concrete family and, where an `initialize()` call is close enough to read, the key size are resolved from the source and reported on the finding.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Generate the classical key alongside an ML-KEM or ML-DSA key and carry both until relying parties accept the post-quantum one.

  1. src/main/java/org/hyperledger/fabric/sdk/idemix/RevocationAuthority.java:67 KeyPairGenerator keyGen = KeyPairGenerator.getInstance("EC");
java.keypairgenerator · CWE-327
ECDH384-bitsecg/secp384r1 Quantum-vulnerable Recorded traffic 1 place See details

Named elliptic curve requested

`ECGenParameterSpec` names a curve explicitly. Every standardised prime curve is broken by Shor regardless of its size, so a larger curve is not a mitigation.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 for signatures, ML-KEM-768 for key establishment.

  1. src/main/java/org/hyperledger/fabric/sdk/idemix/RevocationAuthority.java:69 AlgorithmParameterSpec params = new ECGenParameterSpec("secp384r1");
java.eccurve · CWE-327
ECDSA Quantum-vulnerable 1 place See details

Classical key pair generated through the JCA

`KeyPairGenerator.getInstance()` with a classical algorithm. The concrete family and, where an `initialize()` call is close enough to read, the key size are resolved from the source and reported on the finding.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Generate the classical key alongside an ML-KEM or ML-DSA key and carry both until relying parties accept the post-quantum one.

  1. src/test/java/org/hyperledger/fabric_ca/sdk/HFCAClientTest.java:560 test path KeyPairGenerator keyGen = KeyPairGenerator.getInstance("ECDSA");
java.keypairgenerator · CWE-327
ECDSA384-bitsecg/secp384r1 Quantum-vulnerable 1 place See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. src/test/resources/notsigned.crt:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
TLS Quantum-vulnerable Recorded traffic 1 place See details

TLS context created in code

`SSLContext.getInstance()`. The protocol version is reported; the key exchange it negotiates is classical in every TLS 1.2 and 1.3 cipher suite available today.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Every TLS cipher suite in general use negotiates a classical key exchange, so a recorded session is decryptable once that exchange falls.

What to do. Keep TLS 1.3, and track the hybrid key-exchange groups as they reach the JDK. TLS is where harvest-now-decrypt-later exposure is largest.

  1. src/main/java/org/hyperledger/fabric_ca/sdk/HFCAClient.java:1665 final SSLContext sslContext = SSLContext.getInstance("TLS");
java.sslcontext · CWE-757
AES Reduced margin From a constant 1 place See details

Cipher transformation named away from the call

A JCA transformation string - `algorithm/mode/padding` - written somewhere other than a `getInstance()` argument, which is how a codebase that centralises its cryptography passes the choice to a helper. The string is unambiguous wherever it appears: nothing but a transformation is spelled that way.

This names an encryption method as text, and passes it to code elsewhere that does the work. It is the same choice, made in a different place.

What to do. The same migration applies as to the call that consumes it. Move the constant and the call together, so the inventory keeps naming the algorithm after the change.

  1. src/main/java/org/hyperledger/fabric_ca/sdk/helper/Config.java:87 defaultProperty(SYMMETRIC_ALGORITHM, "AES/CFB/NoPadding");
java.transformation · CWE-327
SHA3-256 Reduced margin 8 places See details

Digest through BouncyCastle

A BouncyCastle digest class. The digest name is read from the class, so `MD5Digest` and `SHA512Digest` are the same rule with opposite conclusions.

A quantum computer weakens this but does not break it. Increasing the key or digest size restores the margin. Grover's algorithm halves the effective strength; the parameter, not the design, is the problem.

What to do. SHA-256 as the floor, SHA-384 where the digest protects something long-lived. MD5 and SHA-1 need replacing now.

  1. src/main/java/org/hyperledger/fabric/sdk/helper/Utils.java:28 import org.bouncycastle.crypto.digests.SHA3Digest;
  2. src/main/java/org/hyperledger/fabric/sdk/helper/Utils.java:109 return Hex.toHexString(hash(param.toString().getBytes(UTF_8), new SHA3Digest()));
  3. src/main/java/org/hyperledger/fabric/sdk/helper/Utils.java:145 hashBuilder.append(Hex.toHexString(hash(toHash, new SHA3Digest())));
  4. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:81 import org.bouncycastle.crypto.digests.SHA3Digest;
  5. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:868 return new SHA3Digest();
  6. src/test/java/org/hyperledger/fabric/sdk/helper/UtilsTest.java:27 test path import org.bouncycastle.crypto.digests.SHA3Digest;
  7. src/test/java/org/hyperledger/fabric/sdk/helper/UtilsTest.java:64 test path Assert.assertEquals(Hex.toHexString(Utils.hash("mypathmyfuncab".getBytes(UTF_8), new SHA3Digest())), hash);
  8. src/test/java/org/hyperledger/fabric/sdk/helper/UtilsTest.java:309 test path byte[] hash = Utils.hash(input, new SHA3Digest());
java.bouncycastle.digest · CWE-328
SHA-256 Reduced margin 4 places See details

Digest through BouncyCastle

A BouncyCastle digest class. The digest name is read from the class, so `MD5Digest` and `SHA512Digest` are the same rule with opposite conclusions.

A quantum computer weakens this but does not break it. Increasing the key or digest size restores the margin. Pre-image resistance falls to about 128 bits of quantum work. Adequate for most uses; SHA-384 restores the full margin where a signature must last decades.

What to do. SHA-256 as the floor, SHA-384 where the digest protects something long-lived. MD5 and SHA-1 need replacing now.

java.bouncycastle.digest · CWE-328
SHA-256 Reduced margin 2 places See details

Hash algorithm through the JCA

`MessageDigest.getInstance()`. MD5 and SHA-1 are reported as already broken; SHA-256 is reported as a reduced margin rather than a defect.

A quantum computer weakens this but does not break it. Increasing the key or digest size restores the margin. Pre-image resistance falls to about 128 bits of quantum work. Adequate for most uses; SHA-384 restores the full margin where a signature must last decades.

What to do. SHA-256 as the floor, SHA-384 where the digest protects something that must remain verifiable for decades.

  1. src/main/java/org/hyperledger/fabric/sdk/idemix/RevocationAuthority.java:106 Signature ecdsa = Signature.getInstance("SHA256withECDSA");
  2. src/main/java/org/hyperledger/fabric/sdk/idemix/RevocationAuthority.java:144 Signature dsa = Signature.getInstance("SHA256withECDSA");
java.messagedigest · CWE-328
unknown Could not be determined 6 places See details

Key pair algorithm chosen at runtime

`KeyPairGenerator.getInstance(x)` where the argument is an identifier. The algorithm cannot be resolved without running the program, so this is reported as an unknown rather than assumed to be classical.

This code picks its encryption method while it runs, so a scan cannot tell which one it ends up using. Somebody has to check the configuration.

What to do. Trace the value to its configuration source and record the concrete algorithm in the cryptographic inventory by hand.

  1. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:305 Signature sig = Signature.getInstance(signatureAlgorithm);
  2. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:663 KeyPairGenerator g = SECURITY_PROVIDER == null ? KeyPairGenerator.getInstance(encryptionName) :
  3. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:664 KeyPairGenerator.getInstance(encryptionName, SECURITY_PROVIDER);
  4. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:731 Signature sig = SECURITY_PROVIDER == null ? Signature.getInstance(DEFAULT_SIGNATURE_ALGORITHM) :
  5. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:732 Signature.getInstance(DEFAULT_SIGNATURE_ALGORITHM, SECURITY_PROVIDER);
  6. src/main/java/org/hyperledger/fabric/sdk/security/certgen/TLSCertificateBuilder.java:159 KeyPairGenerator keypairGen = KeyPairGenerator.getInstance(keyType, new BouncyCastleProvider());
java.keypairgenerator.variable · CWE-327
unknown Could not be determined 1 place See details

Cryptographic library in the dependency manifest

A dependency known to implement classical asymmetric cryptography. Its presence is inventory, not a finding about this codebase: the library may never be called with a quantum-vulnerable algorithm.

The project depends on a cryptography library. Listed so the inventory is complete; it is not by itself a problem.

What to do. Check the version. Several of these libraries have shipped ML-KEM and ML-DSA support since 2024, so the migration may need an upgrade rather than a replacement.

  1. pom.xml:108 <artifactId>bcprov-jdk18on</artifactId>
dep.crypto-library
CSPRNG Quantum-safe 5 places See details

Random number generation

`SecureRandom`. A platform CSPRNG is not a quantum exposure; it is recorded because an inventory that omits the randomness source is incomplete. `SHA1PRNG` is named explicitly where it appears, since it is a legacy algorithm even though its output is adequate.

This is where the software gets its random numbers. Quantum computers do not weaken it.

What to do. No action. Prefer the platform default over naming an algorithm.

  1. src/main/java/org/hyperledger/fabric/sdk/helper/Utils.java:402 private static final SecureRandom RANDOM = new SecureRandom();
  2. src/main/java/org/hyperledger/fabric/sdk/idemix/IdemixUtils.java:67 SecureRandom random = new SecureRandom();
  3. src/main/java/org/hyperledger/fabric/sdk/idemix/RevocationAuthority.java:68 SecureRandom random = new SecureRandom();
  4. src/main/java/org/hyperledger/fabric/sdk/security/CryptoPrimitives.java:665 g.initialize(ecGenSpec, new SecureRandom());
  5. src/main/java/org/hyperledger/fabric/sdk/security/certgen/TLSCertificateBuilder.java:52 private static final SecureRandom rand = new SecureRandom();
java.rng

Cryptographic assets

Algorithm Assessment What it means Occurrences
ECDSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 454
unknown Could not be determined The algorithm could not be established from the source - chosen at runtime, or decided somewhere this scan does not reach. 32
RSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 17
SHA3-256 Reduced margin Grover's algorithm halves the effective strength; the parameter, not the design, is the problem. 8
SHA-256 Reduced margin Pre-image resistance falls to about 128 bits of quantum work. Adequate for most uses; SHA-384 restores the full margin where a signature must last decades. 6
ECDH Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 5
CSPRNG Quantum-safe A cryptographically secure random number generator provided by the platform. Not weakened by a quantum computer. 5
TLS Quantum-vulnerable Every TLS cipher suite in general use negotiates a classical key exchange, so a recorded session is decryptable once that exchange falls. 3
AES Reduced margin Grover's algorithm halves the effective strength; the parameter, not the design, is the problem. The key size was not visible at this call site, so the weaker case is assumed. 1

Imported cryptographic libraries

Library Files
org.bouncycastle BouncyCastle, whose low-level API bypasses the JCA algorithm strings. It has shipped ML-KEM and ML-DSA since 1.79 17
javax.net.ssl the TLS client and server 2
java.security the JCA 26