keycloak/keycloak
13f76e360154
(20 hours ago)
→
61a4555fe865
(5 hours ago)
| Measure | Before | After | Change |
|---|---|---|---|
| Readiness score | 0 | 0 | - |
| Findings to address | 270 | 804 | +534 |
| Key establishment | 109 | 109 | - |
| Files scanned | 10502 | 10716 | +214 |
Added
Present in the later scan and not in the earlier one.
| Finding | Assessment | Before | After |
|---|---|---|---|
SHA-1
XML signature or encryption algorithm · xmldsig.algorithm
|
Already broken | 0 | 23 |
RSAES-PKCS1v15
XML signature or encryption algorithm · xmldsig.algorithm
|
Already broken | 0 | 10 |
RSAES-PKCS1v15
JOSE algorithm declared in configuration · jose.algorithm
|
Already broken | 0 | 7 |
3DES
XML signature or encryption algorithm · xmldsig.algorithm
|
Already broken | 0 | 4 |
RSA-PSS
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 0 | 73 |
RSA-OAEP
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 0 | 19 |
ECDSA
COSE algorithm identifier · cose.algorithm
|
Quantum-vulnerable | 0 | 16 |
EC
Classical key material handled through the JCA · java.keyfactory
|
Quantum-vulnerable | 0 | 14 |
EC
Classical key pair generated through the JCA · java.keypairgenerator
|
Quantum-vulnerable | 0 | 14 |
RSASSA-PKCS1v15
XML signature or encryption algorithm · xmldsig.algorithm
|
Quantum-vulnerable | 0 | 14 |
RSA-OAEP
XML signature or encryption algorithm · xmldsig.algorithm
|
Quantum-vulnerable | 0 | 12 |
EC
Named elliptic curve requested · java.eccurve
|
Quantum-vulnerable | 0 | 10 |
EdDSA
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 0 | 7 |
ECDH
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 0 | 6 |
RSASSA-PKCS1v15
COSE algorithm identifier · cose.algorithm
|
Quantum-vulnerable | 0 | 6 |
RSA-PSS
COSE algorithm identifier · cose.algorithm
|
Quantum-vulnerable | 0 | 5 |
ECDH
TLS cipher suite named in source · config.cipher-suite
|
Quantum-vulnerable | 0 | 4 |
DSA
XML signature or encryption algorithm · xmldsig.algorithm
|
Quantum-vulnerable | 0 | 3 |
Ed25519
COSE algorithm identifier · cose.algorithm
|
Quantum-vulnerable | 0 | 3 |
RSA
Certificate signing request · pem.certificate-request
|
Quantum-vulnerable | 0 | 3 |
EC
Named elliptic curve requested · java.eccurve
|
Quantum-vulnerable | 0 | 1 |
EC
Classical key pair generated through the JCA · java.keypairgenerator
|
Quantum-vulnerable | 0 | 1 |
ECDSA
Classical key pair generated through the JCA · java.keypairgenerator
|
Quantum-vulnerable | 0 | 1 |
AES-128
JOSE algorithm declared in configuration · jose.algorithm
|
Reduced margin | 0 | 12 |
AES-128
XML signature or encryption algorithm · xmldsig.algorithm
|
Reduced margin | 0 | 12 |
AES-192
JOSE algorithm declared in configuration · jose.algorithm
|
Reduced margin | 0 | 7 |
SHA-256
XML signature or encryption algorithm · xmldsig.algorithm
|
Reduced margin | 0 | 7 |
AES-192
XML signature or encryption algorithm · xmldsig.algorithm
|
Reduced margin | 0 | 5 |
AES-256
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-safe | 0 | 11 |
AES-256
XML signature or encryption algorithm · xmldsig.algorithm
|
Quantum-safe | 0 | 6 |
SHA-512
XML signature or encryption algorithm · xmldsig.algorithm
|
Quantum-safe | 0 | 2 |
ML-DSA-44
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-safe | 0 | 1 |
ML-DSA-65
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-safe | 0 | 1 |
ML-DSA-87
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-safe | 0 | 1 |
Resolved
Present in the earlier scan and gone in the later one.
| Finding | Assessment | Before | After |
|---|---|---|---|
ECDH
Classical key pair generated through the JCA · java.keypairgenerator
|
Quantum-vulnerable | 11 | 0 |
ECDH
Named elliptic curve requested · java.eccurve
|
Quantum-vulnerable | 7 | 0 |
ECDH
Classical key pair generated through the JCA · java.keypairgenerator
|
Quantum-vulnerable | 1 | 0 |
Count changed
The same finding, in a different number of places.
| Finding | Assessment | Before | After |
|---|---|---|---|
MD5
Hash algorithm through the JCA · java.messagedigest
|
Already broken | 1 | 2 |
SHA-1
Hash algorithm through the JCA · java.messagedigest
|
Already broken | 3 | 4 |
ECDSA
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 3 | 141 |
RSASSA-PKCS1v15
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 1 | 133 |
Ed25519
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 1 | 19 |
ECDH
Classical key material handled through the JCA · java.keyfactory
|
Quantum-vulnerable | 15 | 1 |
RSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 26 | 23 |
RSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 16 | 17 |
Kerberos
Kerberos or SPNEGO authentication · java.kerberos
|
Reduced margin | 8 | 9 |
unknown
Private key committed to the repository · pem.private-key
|
Could not be determined | 1 | 2 |
HMAC
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-safe | 1 | 49 |
CSPRNG
Random number generation · java.rng
|
Quantum-safe | 36 | 38 |
Unchanged
35 findings appear in both scans, in the same number of places. Each scan's own report lists them.