wultra/powerauth-crypto
dfb4ed9e96b0
(10 days ago)
→
469da6a2fb80
(3 hours ago)
| Measure | Before | After | Change |
|---|---|---|---|
| Readiness score | 34 | 7 | -27 |
| Findings to address | 48 | 77 | +29 |
| Key establishment | 68 | 2 | -66 |
| Files scanned | 287 | 287 | - |
Added
Present in the later scan and not in the earlier one.
| Finding | Assessment | Before | After |
|---|---|---|---|
EC
Classical key material handled through the JCA · java.keyfactory
|
Quantum-vulnerable | 0 | 4 |
ECDSA
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 0 | 4 |
EC
Classical key pair generated through the JCA · java.keypairgenerator
|
Quantum-vulnerable | 0 | 2 |
EC
Named elliptic curve requested · java.eccurve
|
Quantum-vulnerable | 0 | 1 |
EC
Named elliptic curve requested · java.eccurve
|
Quantum-vulnerable | 0 | 1 |
AES
Cipher transformation named away from the call · java.transformation
|
Reduced margin | 0 | 13 |
AES
Key material constructed for a named algorithm · java.keyspec
|
Reduced margin | 0 | 1 |
PBKDF2
Key material constructed for a named algorithm · java.keyspec
|
Reduced margin | 0 | 1 |
unknown
Key material constructed for a named algorithm · java.keyspec
|
Could not be determined | 0 | 10 |
ML-DSA-65
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-safe | 0 | 5 |
HMAC
Key material constructed for a named algorithm · java.keyspec
|
Quantum-safe | 0 | 2 |
ML-DSA-65
Classical signature algorithm through the JCA · java.signature
|
Quantum-safe | 0 | 2 |
ML-DSA-87
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-safe | 0 | 2 |
ML-DSA-65
Classical key pair generated through the JCA · java.keypairgenerator
|
Quantum-safe | 0 | 1 |
Resolved
Present in the earlier scan and gone in the later one.
| Finding | Assessment | Before | After |
|---|---|---|---|
ECDH
Classical key material handled through the JCA · java.keyfactory
|
Quantum-vulnerable | 4 | 0 |
ECDH
Named elliptic curve requested · java.eccurve
|
Quantum-vulnerable | 1 | 0 |
ECDH
Named elliptic curve requested · java.eccurve
|
Quantum-vulnerable | 1 | 0 |
Count changed
The same finding, in a different number of places.
| Finding | Assessment | Before | After |
|---|---|---|---|
ECDH
Classical key pair generated through the JCA · java.keypairgenerator
|
Quantum-vulnerable | 3 | 1 |
Unchanged
14 findings appear in both scans, in the same number of places. Each scan's own report lists them.