Crypto-View

smallstep/certificates

fa946c527a6c (3 days ago) → fa946c527a6c (2 hours ago)

Measure Before After Change
Findings to address 444 900 +456
Quantum-vulnerable locations 522 945 +423
Quantum-safe locations 42 43 +1
Key establishment 96 235 +139
Files scanned 456 477 +21

Added

Present in the later scan and not in the earlier one.

Finding Assessment Before After
RSAES-PKCS1v15 TLS cipher suite named in source · config.cipher-suite Already broken 0 21
RC4 TLS cipher suite named in source · config.cipher-suite Already broken 0 7
3DES TLS cipher suite named in source · config.cipher-suite Already broken 0 6
RSA-1024 Certificate signing request · pem.certificate-request Already broken 0 1
RSA-1024 Certificate signing request · pem.certificate-request Already broken 0 1
ECDH TLS cipher suite named in source · config.cipher-suite Quantum-vulnerable 0 119
ECDSA SSH algorithms pinned in configuration · config.ssh-algorithms Quantum-vulnerable 0 16
Ed25519 JOSE algorithm declared in configuration · jose.algorithm Quantum-vulnerable 0 7
ECDSA Certificate signing request · pem.certificate-request Quantum-vulnerable 0 5
ECDSA Algorithm named in a setting · config.algorithm-setting Quantum-vulnerable 0 3
RSA Certificate signing request · pem.certificate-request Quantum-vulnerable 0 3
RSASSA-PKCS1v15 JOSE algorithm declared in configuration · jose.algorithm Quantum-vulnerable 0 3
Ed25519 Certificate signing request · pem.certificate-request Quantum-vulnerable 0 2
RSA Certificate signing request · pem.certificate-request Quantum-vulnerable 0 2
EC X.509 certificate handling · go.x509 Quantum-vulnerable 0 1
RSASSA-PKCS1v15 SSH algorithms pinned in configuration · config.ssh-algorithms Quantum-vulnerable 0 1
HMAC JOSE algorithm declared in configuration · jose.algorithm Quantum-safe 0 1

Resolved

Present in the earlier scan and gone in the later one.

Finding Assessment Before After
RSA-1024 X.509 certificate · pem.certificate Already broken 1 0

Count changed

The same finding, in a different number of places.

Finding Assessment Before After
RSA-1024 X.509 certificate · pem.certificate Already broken 38 37
ECDSA JOSE algorithm declared in configuration · jose.algorithm Quantum-vulnerable 30 303
ECDSA X.509 certificate · pem.certificate Quantum-vulnerable 61 56
RSA X.509 certificate · pem.certificate Quantum-vulnerable 10 7
Ed25519 X.509 certificate · pem.certificate Quantum-vulnerable 3 1
RSA X.509 certificate · pem.certificate Quantum-vulnerable 5 3
unknown X.509 certificate handling · go.x509 Could not be determined 14 13

Unchanged

28 findings appear in both scans, in the same number of places. Each scan's own report lists them.