Crypto-View

Legrandin/pycryptodome

Cryptographic posture

3883 cryptographic locations: 116 already broken, 3707 quantum-vulnerable, 17 reduced-margin, 37 undetermined, 6 quantum-safe

2506 establish keys, so traffic protected by them and recorded today becomes readable once the algorithm falls. 1 imported cryptographic library is listed separately. 660 files analysed.

Quantum-vulnerable 3707 Already broken 116 Reduced margin 17 Could not be determined 37 Quantum-safe 6
To address3636
Key establishment2506
Inventory only1
Total findings3884
What was analysed
Branch master
Commit a1e52c70302a51077e9d6a20a6abc6a04da1b5e6 Update actions in `codeql-analysis`
Committed 2025-06-28 21:06 UTC
Scanned 2026-09-21 10:58 UTC 9 hours ago
Coverage 660 files, 322 python, 2 javascript

List of cryptographic assets

RSAES-PKCS1v15 Already broken Recorded traffic 99 places See details

JOSE algorithm declared in configuration

An `alg` value in JSON or YAML. `none` is reported as a critical defect; HS* is an HMAC and is not quantum-vulnerable; RS*, PS*, ES* and EdDSA are.

This is already unsafe today, with no quantum computer involved. PKCS#1 v1.5 encryption padding is vulnerable to Bleichenbacher oracles today, and the underlying RSA is broken by Shor.

What to do. No standardised post-quantum JOSE algorithm exists yet. Keep token lifetimes short.

  1. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:20 test path "alg" : "RSA1_5",
  2. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:346 test path "alg" : "RSA1_5",
  3. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:378 test path "alg" : "RSA1_5",
  4. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:410 test path "alg" : "RSA1_5",
  5. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:442 test path "alg" : "RSA1_5",
  6. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:474 test path "alg" : "RSA1_5",
  7. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:506 test path "alg" : "RSA1_5",
  8. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:538 test path "alg" : "RSA1_5",
  9. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:570 test path "alg" : "RSA1_5",
  10. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:602 test path "alg" : "RSA1_5",
  11. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:634 test path "alg" : "RSA1_5",
  12. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:666 test path "alg" : "RSA1_5",
  13. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:698 test path "alg" : "RSA1_5",
  14. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:730 test path "alg" : "RSA1_5",
  15. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:762 test path "alg" : "RSA1_5",
  16. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:794 test path "alg" : "RSA1_5",
  17. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:826 test path "alg" : "RSA1_5",
  18. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:858 test path "alg" : "RSA1_5",
  19. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:890 test path "alg" : "RSA1_5",
  20. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:922 test path "alg" : "RSA1_5",
  21. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:954 test path "alg" : "RSA1_5",
  22. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:986 test path "alg" : "RSA1_5",
  23. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1018 test path "alg" : "RSA1_5",
  24. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1050 test path "alg" : "RSA1_5",
  25. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1082 test path "alg" : "RSA1_5",
  26. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1114 test path "alg" : "RSA1_5",
  27. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1146 test path "alg" : "RSA1_5",
  28. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1178 test path "alg" : "RSA1_5",
  29. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1210 test path "alg" : "RSA1_5",
  30. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1242 test path "alg" : "RSA1_5",
  31. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1274 test path "alg" : "RSA1_5",
  32. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1306 test path "alg" : "RSA1_5",
  33. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1338 test path "alg" : "RSA1_5",
  34. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:20 test path "alg" : "RSA1_5",
  35. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:346 test path "alg" : "RSA1_5",
  36. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:378 test path "alg" : "RSA1_5",
  37. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:410 test path "alg" : "RSA1_5",
  38. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:442 test path "alg" : "RSA1_5",
  39. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:474 test path "alg" : "RSA1_5",
  40. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:506 test path "alg" : "RSA1_5",
  41. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:538 test path "alg" : "RSA1_5",
  42. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:570 test path "alg" : "RSA1_5",
  43. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:602 test path "alg" : "RSA1_5",
  44. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:634 test path "alg" : "RSA1_5",
  45. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:666 test path "alg" : "RSA1_5",
  46. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:698 test path "alg" : "RSA1_5",
  47. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:730 test path "alg" : "RSA1_5",
  48. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:762 test path "alg" : "RSA1_5",
  49. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:794 test path "alg" : "RSA1_5",
  50. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:826 test path "alg" : "RSA1_5",
  51. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:858 test path "alg" : "RSA1_5",
  52. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:890 test path "alg" : "RSA1_5",
  53. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:922 test path "alg" : "RSA1_5",
  54. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:954 test path "alg" : "RSA1_5",
  55. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:986 test path "alg" : "RSA1_5",
  56. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1018 test path "alg" : "RSA1_5",
  57. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1050 test path "alg" : "RSA1_5",
  58. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1084 test path "alg" : "RSA1_5",
  59. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1116 test path "alg" : "RSA1_5",
  60. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1148 test path "alg" : "RSA1_5",
  61. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1180 test path "alg" : "RSA1_5",
  62. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1212 test path "alg" : "RSA1_5",
  63. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1244 test path "alg" : "RSA1_5",
  64. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1276 test path "alg" : "RSA1_5",
  65. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1308 test path "alg" : "RSA1_5",
  66. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1340 test path "alg" : "RSA1_5",
  67. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:20 test path "alg" : "RSA1_5",
  68. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:346 test path "alg" : "RSA1_5",
  69. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:378 test path "alg" : "RSA1_5",
  70. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:410 test path "alg" : "RSA1_5",
  71. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:442 test path "alg" : "RSA1_5",
  72. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:474 test path "alg" : "RSA1_5",
  73. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:506 test path "alg" : "RSA1_5",
  74. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:538 test path "alg" : "RSA1_5",
  75. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:570 test path "alg" : "RSA1_5",
  76. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:602 test path "alg" : "RSA1_5",
  77. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:634 test path "alg" : "RSA1_5",
  78. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:666 test path "alg" : "RSA1_5",
  79. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:698 test path "alg" : "RSA1_5",
  80. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:730 test path "alg" : "RSA1_5",
  81. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:762 test path "alg" : "RSA1_5",
  82. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:794 test path "alg" : "RSA1_5",
  83. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:826 test path "alg" : "RSA1_5",
  84. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:858 test path "alg" : "RSA1_5",
  85. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:890 test path "alg" : "RSA1_5",
  86. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:922 test path "alg" : "RSA1_5",
  87. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:954 test path "alg" : "RSA1_5",
  88. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:986 test path "alg" : "RSA1_5",
  89. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1018 test path "alg" : "RSA1_5",
  90. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1050 test path "alg" : "RSA1_5",
  91. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1082 test path "alg" : "RSA1_5",
  92. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1116 test path "alg" : "RSA1_5",
  93. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1148 test path "alg" : "RSA1_5",
  94. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1180 test path "alg" : "RSA1_5",
  95. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1212 test path "alg" : "RSA1_5",
  96. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1244 test path "alg" : "RSA1_5",
  97. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1276 test path "alg" : "RSA1_5",
  98. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1308 test path "alg" : "RSA1_5",
  99. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1340 test path "alg" : "RSA1_5",
jose.algorithm · CWE-327
RSA-10241024-bit Already broken Recorded traffic 8 places See details

RSA through PyCryptodome

`Crypto.PublicKey.RSA.generate()` or `RSA.import_key()`.

This is already unsafe today, with no quantum computer involved. A modulus of 1024 bits or less is below the NIST SP 800-57 floor and is within reach of classical factorisation. Shor is not the nearest problem here.

What to do. ML-KEM-768 for encryption, ML-DSA-65 for signatures.

  1. lib/Crypto/SelfTest/Cipher/test_pkcs1_15.py:55 test path self.key1024 = RSA.generate(1024, self.rng)
  2. lib/Crypto/SelfTest/Cipher/test_pkcs1_oaep.py:56 test path self.key1024 = RSA.generate(1024, self.rng)
  3. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:61 test path test_public_key = RSA.generate(1024).public_key()
  4. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:108 test path test_private_key = RSA.generate(1024)
  5. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:205 test path key = RSA.generate(1024)
  6. lib/Crypto/SelfTest/Signature/test_pss.py:108 test path test_public_key = RSA.generate(1024).public_key()
  7. lib/Crypto/SelfTest/Signature/test_pss.py:160 test path test_private_key = RSA.generate(1024)
  8. lib/Crypto/SelfTest/Signature/test_pss.py:213 test path key = RSA.generate(1024)
py.pycryptodome.rsa · CWE-327
SHA-1 Already broken Renamed import 4 places See details

Broken hash function

`hashlib.md5()` or `hashlib.sha1()`. Both have practical collisions. Where the call is annotated `usedforsecurity=False` the finding is recorded as inventory instead.

This is already unsafe today, with no quantum computer involved. SHAttered and subsequent work produced practical collisions; NIST withdrew SHA-1 in 2030 guidance and it is already unacceptable for signatures.

What to do. SHA-256, or SHA-384 for long-lived signatures.

  1. src/test/make_tests_poly1305_accumulate.py:47 test path prng1 = sha1(struct.pack('<II', 0, i)).digest()
  2. src/test/make_tests_poly1305_accumulate.py:48 test path prng2 = sha1(struct.pack('<II', 1, i)).digest()
  3. src/test/make_tests_poly1305_multiply.py:85 test path prng = sha1(struct.pack('<II', 0, i)).digest()
  4. src/test/make_tests_poly1305_multiply.py:89 test path secret = sha1(struct.pack('<II', 1, i)).digest()[:16]
py.hashlib.weak · CWE-328
RSA-10241024-bit Already broken 2 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:475 test path -----BEGIN CERTIFICATE-----
  2. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:515 test path -----BEGIN CERTIFICATE-----
pem.certificate
RSA-1024512-bit Already broken Recorded traffic 1 place See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:92 test path -----BEGIN PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
RSA-1024512-bit Already broken 1 place See details

Public key file

A PEM public-key block. The algorithm is read from the SubjectPublicKeyInfo.

This is already unsafe today, with no quantum computer involved. A modulus of 1024 bits or less is below the NIST SP 800-57 floor and is within reach of classical factorisation. Shor is not the nearest problem here.

What to do. Inventory only; a public key is not itself a secret.

  1. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:136 test path -----BEGIN PUBLIC KEY-----
pem.public-key
RSA-10241280-bit Already broken Recorded traffic 1 place See details

RSA through PyCryptodome

`Crypto.PublicKey.RSA.generate()` or `RSA.import_key()`.

This is already unsafe today, with no quantum computer involved. A modulus of 1024 bits or less is below the NIST SP 800-57 floor and is within reach of classical factorisation. Shor is not the nearest problem here.

What to do. ML-KEM-768 for encryption, ML-DSA-65 for signatures.

  1. lib/Crypto/SelfTest/Signature/test_pss.py:232 test path key = RSA.generate(1280)
py.pycryptodome.rsa · CWE-327
X25519255-bitother/Curve25519 Quantum-vulnerable Recorded traffic 1052 places See details

Public key declared as a JSON Web Key

A `kty` field, with the curve read from the sibling `crv` where the family needs one. A JWKS document declares a key without naming an algorithm anywhere, so it is invisible to a scan that only looks for `alg`.

This file publishes the public keys other systems use to check this system's signatures. Everyone who trusts these keys has to accept the new kind of key before the old ones can be retired.

What to do. A published JWKS is what relying parties trust. It has to accept a post-quantum key type before the keys behind it can change, so put it early in the migration order.

  1. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:29 test path "kty" : "OKP",
  2. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:36 test path "kty" : "OKP",
  3. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:49 test path "kty" : "OKP",
  4. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:56 test path "kty" : "OKP",
  5. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:71 test path "kty" : "OKP",
  6. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:78 test path "kty" : "OKP",
  7. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:93 test path "kty" : "OKP",
  8. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:100 test path "kty" : "OKP",
  9. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:115 test path "kty" : "OKP",
  10. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:122 test path "kty" : "OKP",
  11. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:137 test path "kty" : "OKP",
  12. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:144 test path "kty" : "OKP",
  13. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:159 test path "kty" : "OKP",
  14. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:166 test path "kty" : "OKP",
  15. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:181 test path "kty" : "OKP",
  16. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:188 test path "kty" : "OKP",
  17. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:203 test path "kty" : "OKP",
  18. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:210 test path "kty" : "OKP",
  19. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:225 test path "kty" : "OKP",
  20. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:232 test path "kty" : "OKP",
  21. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:247 test path "kty" : "OKP",
  22. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:254 test path "kty" : "OKP",
  23. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:269 test path "kty" : "OKP",
  24. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:276 test path "kty" : "OKP",
  25. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:291 test path "kty" : "OKP",
  26. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:298 test path "kty" : "OKP",
  27. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:313 test path "kty" : "OKP",
  28. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:320 test path "kty" : "OKP",
  29. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:335 test path "kty" : "OKP",
  30. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:342 test path "kty" : "OKP",
  31. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:357 test path "kty" : "OKP",
  32. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:364 test path "kty" : "OKP",
  33. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:379 test path "kty" : "OKP",
  34. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:386 test path "kty" : "OKP",
  35. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:401 test path "kty" : "OKP",
  36. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:408 test path "kty" : "OKP",
  37. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:423 test path "kty" : "OKP",
  38. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:430 test path "kty" : "OKP",
  39. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:445 test path "kty" : "OKP",
  40. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:452 test path "kty" : "OKP",
  41. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:467 test path "kty" : "OKP",
  42. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:474 test path "kty" : "OKP",
  43. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:489 test path "kty" : "OKP",
  44. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:496 test path "kty" : "OKP",
  45. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:511 test path "kty" : "OKP",
  46. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:518 test path "kty" : "OKP",
  47. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:533 test path "kty" : "OKP",
  48. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:540 test path "kty" : "OKP",
  49. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:555 test path "kty" : "OKP",
  50. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:562 test path "kty" : "OKP",
  51. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:577 test path "kty" : "OKP",
  52. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:584 test path "kty" : "OKP",
  53. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:599 test path "kty" : "OKP",
  54. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:606 test path "kty" : "OKP",
  55. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:621 test path "kty" : "OKP",
  56. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:628 test path "kty" : "OKP",
  57. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:643 test path "kty" : "OKP",
  58. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:650 test path "kty" : "OKP",
  59. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:665 test path "kty" : "OKP",
  60. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:672 test path "kty" : "OKP",
  61. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:687 test path "kty" : "OKP",
  62. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:694 test path "kty" : "OKP",
  63. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:709 test path "kty" : "OKP",
  64. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:716 test path "kty" : "OKP",
  65. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:733 test path "kty" : "OKP",
  66. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:740 test path "kty" : "OKP",
  67. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:757 test path "kty" : "OKP",
  68. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:764 test path "kty" : "OKP",
  69. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:777 test path "kty" : "OKP",
  70. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:784 test path "kty" : "OKP",
  71. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:797 test path "kty" : "OKP",
  72. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:804 test path "kty" : "OKP",
  73. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:817 test path "kty" : "OKP",
  74. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:824 test path "kty" : "OKP",
  75. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:837 test path "kty" : "OKP",
  76. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:844 test path "kty" : "OKP",
  77. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:857 test path "kty" : "OKP",
  78. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:864 test path "kty" : "OKP",
  79. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:877 test path "kty" : "OKP",
  80. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:884 test path "kty" : "OKP",
  81. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:897 test path "kty" : "OKP",
  82. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:904 test path "kty" : "OKP",
  83. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:917 test path "kty" : "OKP",
  84. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:924 test path "kty" : "OKP",
  85. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:937 test path "kty" : "OKP",
  86. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:944 test path "kty" : "OKP",
  87. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:957 test path "kty" : "OKP",
  88. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:964 test path "kty" : "OKP",
  89. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:977 test path "kty" : "OKP",
  90. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:984 test path "kty" : "OKP",
  91. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:997 test path "kty" : "OKP",
  92. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1004 test path "kty" : "OKP",
  93. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1017 test path "kty" : "OKP",
  94. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1024 test path "kty" : "OKP",
  95. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1037 test path "kty" : "OKP",
  96. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1044 test path "kty" : "OKP",
  97. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1057 test path "kty" : "OKP",
  98. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1064 test path "kty" : "OKP",
  99. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1077 test path "kty" : "OKP",
  100. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1084 test path "kty" : "OKP",
  101. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1097 test path "kty" : "OKP",
  102. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1104 test path "kty" : "OKP",
  103. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1117 test path "kty" : "OKP",
  104. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1124 test path "kty" : "OKP",
  105. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1137 test path "kty" : "OKP",
  106. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1144 test path "kty" : "OKP",
  107. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1157 test path "kty" : "OKP",
  108. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1164 test path "kty" : "OKP",
  109. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1177 test path "kty" : "OKP",
  110. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1184 test path "kty" : "OKP",
  111. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1197 test path "kty" : "OKP",
  112. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1204 test path "kty" : "OKP",
  113. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1217 test path "kty" : "OKP",
  114. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1224 test path "kty" : "OKP",
  115. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1237 test path "kty" : "OKP",
  116. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1244 test path "kty" : "OKP",
  117. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1257 test path "kty" : "OKP",
  118. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1264 test path "kty" : "OKP",
  119. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1277 test path "kty" : "OKP",
  120. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1284 test path "kty" : "OKP",
  121. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1297 test path "kty" : "OKP",
  122. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1304 test path "kty" : "OKP",
  123. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1317 test path "kty" : "OKP",
  124. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1324 test path "kty" : "OKP",
  125. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1337 test path "kty" : "OKP",
  126. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1344 test path "kty" : "OKP",
  127. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1360 test path "kty" : "OKP",
  128. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1367 test path "kty" : "OKP",
  129. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1383 test path "kty" : "OKP",
  130. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1390 test path "kty" : "OKP",
  131. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1407 test path "kty" : "OKP",
  132. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1414 test path "kty" : "OKP",
  133. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1432 test path "kty" : "OKP",
  134. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1439 test path "kty" : "OKP",
  135. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1457 test path "kty" : "OKP",
  136. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1464 test path "kty" : "OKP",
  137. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1481 test path "kty" : "OKP",
  138. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1488 test path "kty" : "OKP",
  139. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1504 test path "kty" : "OKP",
  140. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1511 test path "kty" : "OKP",
  141. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1527 test path "kty" : "OKP",
  142. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1534 test path "kty" : "OKP",
  143. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1550 test path "kty" : "OKP",
  144. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1557 test path "kty" : "OKP",
  145. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1573 test path "kty" : "OKP",
  146. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1580 test path "kty" : "OKP",
  147. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1596 test path "kty" : "OKP",
  148. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1603 test path "kty" : "OKP",
  149. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1619 test path "kty" : "OKP",
  150. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1626 test path "kty" : "OKP",
  151. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1642 test path "kty" : "OKP",
  152. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1649 test path "kty" : "OKP",
  153. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1665 test path "kty" : "OKP",
  154. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1672 test path "kty" : "OKP",
  155. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1688 test path "kty" : "OKP",
  156. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1695 test path "kty" : "OKP",
  157. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1711 test path "kty" : "OKP",
  158. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1718 test path "kty" : "OKP",
  159. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1734 test path "kty" : "OKP",
  160. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1741 test path "kty" : "OKP",
  161. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1757 test path "kty" : "OKP",
  162. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1764 test path "kty" : "OKP",
  163. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1780 test path "kty" : "OKP",
  164. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1787 test path "kty" : "OKP",
  165. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1803 test path "kty" : "OKP",
  166. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1810 test path "kty" : "OKP",
  167. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1827 test path "kty" : "OKP",
  168. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1834 test path "kty" : "OKP",
  169. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1852 test path "kty" : "OKP",
  170. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1859 test path "kty" : "OKP",
  171. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1875 test path "kty" : "OKP",
  172. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1882 test path "kty" : "OKP",
  173. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1898 test path "kty" : "OKP",
  174. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1905 test path "kty" : "OKP",
  175. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1920 test path "kty" : "OKP",
  176. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1927 test path "kty" : "OKP",
  177. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1942 test path "kty" : "OKP",
  178. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1949 test path "kty" : "OKP",
  179. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1965 test path "kty" : "OKP",
  180. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1972 test path "kty" : "OKP",
  181. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1988 test path "kty" : "OKP",
  182. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:1995 test path "kty" : "OKP",
  183. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2010 test path "kty" : "OKP",
  184. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2017 test path "kty" : "OKP",
  185. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2032 test path "kty" : "OKP",
  186. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2039 test path "kty" : "OKP",
  187. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2054 test path "kty" : "OKP",
  188. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2061 test path "kty" : "OKP",
  189. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2077 test path "kty" : "OKP",
  190. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2084 test path "kty" : "OKP",
  191. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2099 test path "kty" : "OKP",
  192. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2106 test path "kty" : "OKP",
  193. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2121 test path "kty" : "OKP",
  194. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2128 test path "kty" : "OKP",
  195. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2143 test path "kty" : "OKP",
  196. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2150 test path "kty" : "OKP",
  197. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2168 test path "kty" : "OKP",
  198. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2175 test path "kty" : "OKP",
  199. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2194 test path "kty" : "OKP",
  200. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:2201 test path "kty" : "OKP",

Showing the first 200. The CBOM has every one.

jose.jwk · CWE-327
X448448-bitother/Curve448 Quantum-vulnerable Recorded traffic 153 places See details

Public key declared as a JSON Web Key

A `kty` field, with the curve read from the sibling `crv` where the family needs one. A JWKS document declares a key without naming an algorithm anywhere, so it is invisible to a scan that only looks for `alg`.

This file publishes the public keys other systems use to check this system's signatures. Everyone who trusts these keys has to accept the new kind of key before the old ones can be retired.

What to do. A published JWKS is what relying parties trust. It has to accept a post-quantum key type before the keys behind it can change, so put it early in the migration order.

  1. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x25519_jwk_test.json:11027 test path "kty" : "OKP",
  2. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:29 test path "kty" : "OKP",
  3. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:36 test path "kty" : "OKP",
  4. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:49 test path "kty" : "OKP",
  5. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:56 test path "kty" : "OKP",
  6. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:71 test path "kty" : "OKP",
  7. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:78 test path "kty" : "OKP",
  8. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:93 test path "kty" : "OKP",
  9. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:100 test path "kty" : "OKP",
  10. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:115 test path "kty" : "OKP",
  11. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:122 test path "kty" : "OKP",
  12. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:137 test path "kty" : "OKP",
  13. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:144 test path "kty" : "OKP",
  14. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:159 test path "kty" : "OKP",
  15. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:166 test path "kty" : "OKP",
  16. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:181 test path "kty" : "OKP",
  17. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:188 test path "kty" : "OKP",
  18. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:203 test path "kty" : "OKP",
  19. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:210 test path "kty" : "OKP",
  20. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:225 test path "kty" : "OKP",
  21. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:232 test path "kty" : "OKP",
  22. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:247 test path "kty" : "OKP",
  23. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:254 test path "kty" : "OKP",
  24. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:269 test path "kty" : "OKP",
  25. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:276 test path "kty" : "OKP",
  26. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:291 test path "kty" : "OKP",
  27. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:298 test path "kty" : "OKP",
  28. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:313 test path "kty" : "OKP",
  29. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:320 test path "kty" : "OKP",
  30. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:335 test path "kty" : "OKP",
  31. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:342 test path "kty" : "OKP",
  32. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:357 test path "kty" : "OKP",
  33. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:364 test path "kty" : "OKP",
  34. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:379 test path "kty" : "OKP",
  35. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:386 test path "kty" : "OKP",
  36. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:401 test path "kty" : "OKP",
  37. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:408 test path "kty" : "OKP",
  38. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:423 test path "kty" : "OKP",
  39. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:430 test path "kty" : "OKP",
  40. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:445 test path "kty" : "OKP",
  41. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:452 test path "kty" : "OKP",
  42. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:467 test path "kty" : "OKP",
  43. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:474 test path "kty" : "OKP",
  44. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:489 test path "kty" : "OKP",
  45. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:496 test path "kty" : "OKP",
  46. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:511 test path "kty" : "OKP",
  47. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:518 test path "kty" : "OKP",
  48. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:533 test path "kty" : "OKP",
  49. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:540 test path "kty" : "OKP",
  50. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:555 test path "kty" : "OKP",
  51. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:562 test path "kty" : "OKP",
  52. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:577 test path "kty" : "OKP",
  53. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:584 test path "kty" : "OKP",
  54. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:599 test path "kty" : "OKP",
  55. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:606 test path "kty" : "OKP",
  56. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:621 test path "kty" : "OKP",
  57. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:628 test path "kty" : "OKP",
  58. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:643 test path "kty" : "OKP",
  59. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:650 test path "kty" : "OKP",
  60. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:665 test path "kty" : "OKP",
  61. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:672 test path "kty" : "OKP",
  62. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:687 test path "kty" : "OKP",
  63. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:694 test path "kty" : "OKP",
  64. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:709 test path "kty" : "OKP",
  65. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:716 test path "kty" : "OKP",
  66. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:733 test path "kty" : "OKP",
  67. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:740 test path "kty" : "OKP",
  68. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:758 test path "kty" : "OKP",
  69. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:765 test path "kty" : "OKP",
  70. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:778 test path "kty" : "OKP",
  71. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:785 test path "kty" : "OKP",
  72. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:798 test path "kty" : "OKP",
  73. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:805 test path "kty" : "OKP",
  74. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:818 test path "kty" : "OKP",
  75. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:825 test path "kty" : "OKP",
  76. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:838 test path "kty" : "OKP",
  77. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:845 test path "kty" : "OKP",
  78. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:858 test path "kty" : "OKP",
  79. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:865 test path "kty" : "OKP",
  80. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:878 test path "kty" : "OKP",
  81. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:885 test path "kty" : "OKP",
  82. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:898 test path "kty" : "OKP",
  83. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:905 test path "kty" : "OKP",
  84. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:918 test path "kty" : "OKP",
  85. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:925 test path "kty" : "OKP",
  86. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:938 test path "kty" : "OKP",
  87. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:945 test path "kty" : "OKP",
  88. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:958 test path "kty" : "OKP",
  89. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:965 test path "kty" : "OKP",
  90. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:978 test path "kty" : "OKP",
  91. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:985 test path "kty" : "OKP",
  92. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:998 test path "kty" : "OKP",
  93. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1005 test path "kty" : "OKP",
  94. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1018 test path "kty" : "OKP",
  95. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1025 test path "kty" : "OKP",
  96. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1038 test path "kty" : "OKP",
  97. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1045 test path "kty" : "OKP",
  98. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1058 test path "kty" : "OKP",
  99. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1065 test path "kty" : "OKP",
  100. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1078 test path "kty" : "OKP",
  101. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1085 test path "kty" : "OKP",
  102. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1098 test path "kty" : "OKP",
  103. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1105 test path "kty" : "OKP",
  104. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1118 test path "kty" : "OKP",
  105. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1125 test path "kty" : "OKP",
  106. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1138 test path "kty" : "OKP",
  107. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1145 test path "kty" : "OKP",
  108. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1158 test path "kty" : "OKP",
  109. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1165 test path "kty" : "OKP",
  110. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1178 test path "kty" : "OKP",
  111. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1185 test path "kty" : "OKP",
  112. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1198 test path "kty" : "OKP",
  113. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1205 test path "kty" : "OKP",
  114. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1218 test path "kty" : "OKP",
  115. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1225 test path "kty" : "OKP",
  116. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1238 test path "kty" : "OKP",
  117. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1245 test path "kty" : "OKP",
  118. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1258 test path "kty" : "OKP",
  119. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1265 test path "kty" : "OKP",
  120. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1278 test path "kty" : "OKP",
  121. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1285 test path "kty" : "OKP",
  122. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1298 test path "kty" : "OKP",
  123. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1305 test path "kty" : "OKP",
  124. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1318 test path "kty" : "OKP",
  125. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1325 test path "kty" : "OKP",
  126. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1338 test path "kty" : "OKP",
  127. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1345 test path "kty" : "OKP",
  128. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1361 test path "kty" : "OKP",
  129. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1368 test path "kty" : "OKP",
  130. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1385 test path "kty" : "OKP",
  131. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1392 test path "kty" : "OKP",
  132. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1408 test path "kty" : "OKP",
  133. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1415 test path "kty" : "OKP",
  134. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1431 test path "kty" : "OKP",
  135. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1438 test path "kty" : "OKP",
  136. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1454 test path "kty" : "OKP",
  137. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1461 test path "kty" : "OKP",
  138. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1476 test path "kty" : "OKP",
  139. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1483 test path "kty" : "OKP",
  140. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1498 test path "kty" : "OKP",
  141. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1505 test path "kty" : "OKP",
  142. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1520 test path "kty" : "OKP",
  143. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1527 test path "kty" : "OKP",
  144. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1544 test path "kty" : "OKP",
  145. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1551 test path "kty" : "OKP",
  146. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1570 test path "kty" : "OKP",
  147. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1577 test path "kty" : "OKP",
  148. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1592 test path "kty" : "OKP",
  149. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1599 test path "kty" : "OKP",
  150. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1614 test path "kty" : "OKP",
  151. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1621 test path "kty" : "OKP",
  152. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1636 test path "kty" : "OKP",
  153. test_vectors/pycryptodome_test_vectors/Protocol/wycheproof/x448_jwk_test.json:1643 test path "kty" : "OKP",
jose.jwk · CWE-327
RSA Quantum-vulnerable Recorded traffic 112 places See details

Public key declared as a JSON Web Key

A `kty` field, with the curve read from the sibling `crv` where the family needs one. A JWKS document declares a key without naming an algorithm anywhere, so it is invisible to a scan that only looks for `alg`.

This file publishes the public keys other systems use to check this system's signatures. Everyone who trusts these keys has to accept the new kind of key before the old ones can be retired.

What to do. A published JWKS is what relying parties trust. It has to accept a post-quantum key type before the keys behind it can change, so put it early in the migration order.

  1. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_2048_sha1_mgf1sha1_test.json:29 test path "kty" : "RSA",
  2. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_2048_sha256_mgf1sha256_test.json:29 test path "kty" : "RSA",
  3. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_3072_sha256_mgf1sha256_test.json:29 test path "kty" : "RSA",
  4. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_4096_sha256_mgf1sha256_test.json:29 test path "kty" : "RSA",
  5. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:29 test path "kty" : "RSA",
  6. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:1266 test path "kty" : "RSA",
  7. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:2754 test path "kty" : "RSA",
  8. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:4093 test path "kty" : "RSA",
  9. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:5138 test path "kty" : "RSA",
  10. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:6441 test path "kty" : "RSA",
  11. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:7744 test path "kty" : "RSA",
  12. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:8875 test path "kty" : "RSA",
  13. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:9001 test path "kty" : "RSA",
  14. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:26 test path "kty" : "RSA",
  15. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:352 test path "kty" : "RSA",
  16. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:384 test path "kty" : "RSA",
  17. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:416 test path "kty" : "RSA",
  18. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:448 test path "kty" : "RSA",
  19. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:480 test path "kty" : "RSA",
  20. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:512 test path "kty" : "RSA",
  21. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:544 test path "kty" : "RSA",
  22. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:576 test path "kty" : "RSA",
  23. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:608 test path "kty" : "RSA",
  24. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:640 test path "kty" : "RSA",
  25. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:672 test path "kty" : "RSA",
  26. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:704 test path "kty" : "RSA",
  27. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:736 test path "kty" : "RSA",
  28. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:768 test path "kty" : "RSA",
  29. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:800 test path "kty" : "RSA",
  30. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:832 test path "kty" : "RSA",
  31. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:864 test path "kty" : "RSA",
  32. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:896 test path "kty" : "RSA",
  33. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:928 test path "kty" : "RSA",
  34. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:960 test path "kty" : "RSA",
  35. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:992 test path "kty" : "RSA",
  36. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1024 test path "kty" : "RSA",
  37. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1056 test path "kty" : "RSA",
  38. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1088 test path "kty" : "RSA",
  39. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1120 test path "kty" : "RSA",
  40. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1152 test path "kty" : "RSA",
  41. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1184 test path "kty" : "RSA",
  42. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1216 test path "kty" : "RSA",
  43. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1248 test path "kty" : "RSA",
  44. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1280 test path "kty" : "RSA",
  45. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1312 test path "kty" : "RSA",
  46. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_2048_test.json:1344 test path "kty" : "RSA",
  47. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:26 test path "kty" : "RSA",
  48. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:352 test path "kty" : "RSA",
  49. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:384 test path "kty" : "RSA",
  50. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:416 test path "kty" : "RSA",
  51. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:448 test path "kty" : "RSA",
  52. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:480 test path "kty" : "RSA",
  53. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:512 test path "kty" : "RSA",
  54. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:544 test path "kty" : "RSA",
  55. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:576 test path "kty" : "RSA",
  56. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:608 test path "kty" : "RSA",
  57. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:640 test path "kty" : "RSA",
  58. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:672 test path "kty" : "RSA",
  59. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:704 test path "kty" : "RSA",
  60. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:736 test path "kty" : "RSA",
  61. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:768 test path "kty" : "RSA",
  62. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:800 test path "kty" : "RSA",
  63. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:832 test path "kty" : "RSA",
  64. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:864 test path "kty" : "RSA",
  65. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:896 test path "kty" : "RSA",
  66. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:928 test path "kty" : "RSA",
  67. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:960 test path "kty" : "RSA",
  68. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:992 test path "kty" : "RSA",
  69. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1024 test path "kty" : "RSA",
  70. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1056 test path "kty" : "RSA",
  71. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1090 test path "kty" : "RSA",
  72. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1122 test path "kty" : "RSA",
  73. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1154 test path "kty" : "RSA",
  74. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1186 test path "kty" : "RSA",
  75. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1218 test path "kty" : "RSA",
  76. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1250 test path "kty" : "RSA",
  77. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1282 test path "kty" : "RSA",
  78. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1314 test path "kty" : "RSA",
  79. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_3072_test.json:1346 test path "kty" : "RSA",
  80. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:26 test path "kty" : "RSA",
  81. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:352 test path "kty" : "RSA",
  82. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:384 test path "kty" : "RSA",
  83. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:416 test path "kty" : "RSA",
  84. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:448 test path "kty" : "RSA",
  85. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:480 test path "kty" : "RSA",
  86. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:512 test path "kty" : "RSA",
  87. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:544 test path "kty" : "RSA",
  88. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:576 test path "kty" : "RSA",
  89. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:608 test path "kty" : "RSA",
  90. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:640 test path "kty" : "RSA",
  91. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:672 test path "kty" : "RSA",
  92. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:704 test path "kty" : "RSA",
  93. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:736 test path "kty" : "RSA",
  94. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:768 test path "kty" : "RSA",
  95. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:800 test path "kty" : "RSA",
  96. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:832 test path "kty" : "RSA",
  97. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:864 test path "kty" : "RSA",
  98. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:896 test path "kty" : "RSA",
  99. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:928 test path "kty" : "RSA",
  100. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:960 test path "kty" : "RSA",
  101. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:992 test path "kty" : "RSA",
  102. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1024 test path "kty" : "RSA",
  103. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1056 test path "kty" : "RSA",
  104. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1088 test path "kty" : "RSA",
  105. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1122 test path "kty" : "RSA",
  106. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1154 test path "kty" : "RSA",
  107. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1186 test path "kty" : "RSA",
  108. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1218 test path "kty" : "RSA",
  109. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1250 test path "kty" : "RSA",
  110. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1282 test path "kty" : "RSA",
  111. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1314 test path "kty" : "RSA",
  112. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_pkcs1_4096_test.json:1346 test path "kty" : "RSA",
jose.jwk · CWE-327
RSA Quantum-vulnerable Recorded traffic 70 places See details

RSA through PyCryptodome

`Crypto.PublicKey.RSA.generate()` or `RSA.import_key()`.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-KEM-768 for encryption, ML-DSA-65 for signatures.

  1. bench_monty.py:56 key = RSA.import_key(rsa_pem)
  2. lib/Crypto/SelfTest/Cipher/test_pkcs1_15.py:111 test path key = RSA.importKey(test[0])
  3. lib/Crypto/SelfTest/Cipher/test_pkcs1_15.py:135 test path key = RSA.importKey(test[0])
  4. lib/Crypto/SelfTest/Cipher/test_pkcs1_15.py:222 test path return RSA.import_key(group['privateKeyPem'])
  5. lib/Crypto/SelfTest/Cipher/test_pkcs1_oaep.py:275 test path key = RSA.construct(comps)
  6. lib/Crypto/SelfTest/Cipher/test_pkcs1_oaep.py:306 test path key = RSA.construct(comps)
  7. lib/Crypto/SelfTest/Cipher/test_pkcs1_oaep.py:398 test path return RSA.import_key(group['privateKeyPem'])
  8. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:195 test path key = RSA.importKey(self.rsaKeyDER)
  9. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:205 test path key = RSA.importKey(self.rsaPublicKeyDER)
  10. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:212 test path key = RSA.importKey(self.rsaKeyPEM)
  11. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:222 test path key = RSA.importKey(b(self.rsaKeyPEM))
  12. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:232 test path key = RSA.importKey(self.rsaPublicKeyPEM)
  13. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:239 test path key = RSA.importKey(b(self.rsaPublicKeyPEM))
  14. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:246 test path key = RSA.importKey(self.rsaKeyPEM)
  15. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:252 test path key = RSA.importKey(self.rsaKeyDER)
  16. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:258 test path key = RSA.importKey(self.rsaPublicKeyOpenSSH)
  17. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:265 test path key = RSA.importKey(t[1], t[0])
  18. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:275 test path key = RSA.importKey(self.rsaKeyDER8)
  19. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:285 test path key = RSA.importKey(self.rsaKeyPEM8)
  20. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:296 test path key = RSA.importKey(der)
  21. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:304 test path key = RSA.importKey(pem)
  22. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:310 test path key = RSA.importKey(pem_cr_lf)
  23. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:322 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  24. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:327 test path key = RSA.construct([self.n, self.e])
  25. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:332 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  26. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:337 test path key = RSA.construct([self.n, self.e])
  27. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:342 test path key = RSA.construct([self.n, self.e])
  28. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:349 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  29. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:354 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  30. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:359 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  31. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:365 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  32. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:369 test path inkey = RSA.importKey(outkey, 'test')
  33. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:377 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  34. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:381 test path inkey = RSA.importKey(outkey, 'test')
  35. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:389 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  36. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:393 test path inkey = RSA.importKey(outkey, 'test')
  37. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:401 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  38. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:406 test path inkey = RSA.importKey(outkey, 'test')
  39. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:414 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  40. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:416 test path inkey = RSA.importKey(outkey, 'test')
  41. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:424 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  42. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:430 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  43. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:447 test path inkey = RSA.importKey(outkey, 'test')
  44. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:454 test path key = RSA.import_key(self.rsaPublicKeyDER)
  45. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:461 test path key = RSA.import_key(bytearray(self.rsaPublicKeyDER))
  46. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:462 test path key = RSA.import_key(memoryview(self.rsaPublicKeyDER))
  47. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:465 test path key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  48. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:506 test path key = RSA.importKey(x509_v1_cert)
  49. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:558 test path key = RSA.importKey(x509_v3_cert)
  50. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:568 test path pub_key = RSA.import_key(pub_key_file)
  51. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:571 test path priv_key = RSA.import_key(priv_key_file)
  52. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:583 test path key_ref = RSA.import_key(key_file_ref).public_key()
  53. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:584 test path key = RSA.import_key(key_file)
  54. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:595 test path key = RSA.import_key(key_file)
  55. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:596 test path key_old = RSA.import_key(key_file_old)
  56. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:608 test path key = RSA.import_key(key_file, b"password")
  57. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:609 test path key_old = RSA.import_key(key_file_old)
  58. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:620 test path key_ref = RSA.import_key(key_file_ref)
  59. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:621 test path key = RSA.import_key(key_file, b'secret')
  60. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:87 test path public_key = RSA.construct([bytes_to_long(x) for x in (modulus, tv.e)]) # type: ignore
  61. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:134 test path private_key = RSA.construct([bytes_to_long(x) for x in (modulus, tv.e, tv.d)]) # type: ignore
  62. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:172 test path verifier = pkcs1_15.new(RSA.importKey(self.rsakey))
  63. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:186 test path key = RSA.importKey(PKCS1_15_NoParams.rsakey)
  64. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:259 test path return RSA.import_key(group['keyPem'])
  65. lib/Crypto/SelfTest/Signature/test_pss.py:70 test path key = RSA.import_key(self.rsa_key)
  66. lib/Crypto/SelfTest/Signature/test_pss.py:76 test path key = RSA.import_key(self.rsa_key)
  67. lib/Crypto/SelfTest/Signature/test_pss.py:83 test path key = RSA.import_key(self.rsa_key)
  68. lib/Crypto/SelfTest/Signature/test_pss.py:135 test path public_key = RSA.construct([bytes_to_long(x) for x in (modulus, tv.e)]) # type: ignore
  69. lib/Crypto/SelfTest/Signature/test_pss.py:186 test path private_key = RSA.construct([bytes_to_long(x) for x in (modulus, tv.e, tv.d)]) # type: ignore
  70. lib/Crypto/SelfTest/Signature/test_pss.py:281 test path return RSA.import_key(group['keyPem'])
py.pycryptodome.rsa · CWE-327
RSA-PSS Quantum-vulnerable 66 places See details

Signature scheme through PyCryptodome

`Crypto.Signature.pkcs1_15`, `pss` or `DSS`. All three sign with a key Shor breaks.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65.

  1. lib/Crypto/PublicKey/DSA.py:342 raise NotImplementedError("Use module Crypto.Signature.DSS instead")
  2. lib/Crypto/PublicKey/DSA.py:345 raise NotImplementedError("Use module Crypto.Signature.DSS instead")
  3. lib/Crypto/PublicKey/RSA.py:430 raise NotImplementedError("Use module Crypto.Signature.pkcs1_15 instead")
  4. lib/Crypto/PublicKey/RSA.py:434 raise NotImplementedError("Use module Crypto.Signature.pkcs1_15 instead")
  5. lib/Crypto/SelfTest/Signature/test_dss.py:94 test path signer = DSS.new(self.key_priv, 'fips-186-3')
  6. lib/Crypto/SelfTest/Signature/test_dss.py:97 test path verifier = DSS.new(self.key_pub, 'fips-186-3')
  7. lib/Crypto/SelfTest/Signature/test_dss.py:107 test path signer = DSS.new(self.key_priv, 'fips-186-3')
  8. lib/Crypto/SelfTest/Signature/test_dss.py:125 test path signer = DSS.new(self.key_priv, 'fips-186-3', 'der')
  9. lib/Crypto/SelfTest/Signature/test_dss.py:140 test path signer = DSS.new(self.key_priv, 'fips-186-3')
  10. lib/Crypto/SelfTest/Signature/test_dss.py:143 test path signer = DSS.new(self.key_pub, 'fips-186-3')
  11. lib/Crypto/SelfTest/Signature/test_dss.py:183 test path verifier = DSS.new(key, 'fips-186-3')
  12. lib/Crypto/SelfTest/Signature/test_dss.py:220 test path signer = DSS.new(key, 'fips-186-3', randfunc=StrRNG(tv.k))
  13. lib/Crypto/SelfTest/Signature/test_dss.py:237 test path signer = DSS.new(self.key_priv, 'fips-186-3')
  14. lib/Crypto/SelfTest/Signature/test_dss.py:240 test path verifier = DSS.new(self.key_pub, 'fips-186-3')
  15. lib/Crypto/SelfTest/Signature/test_dss.py:250 test path signer = DSS.new(self.key_priv, 'fips-186-3')
  16. lib/Crypto/SelfTest/Signature/test_dss.py:262 test path signer = DSS.new(self.key_priv, 'fips-186-3')
  17. lib/Crypto/SelfTest/Signature/test_dss.py:265 test path signer = DSS.new(self.key_pub, 'fips-186-3')
  18. lib/Crypto/SelfTest/Signature/test_dss.py:291 test path signer = DSS.new(self.key_priv, 'fips-186-3', 'der')
  19. lib/Crypto/SelfTest/Signature/test_dss.py:343 test path verifier = DSS.new(ecc_key, 'fips-186-3')
  20. lib/Crypto/SelfTest/Signature/test_dss.py:374 test path signer = DSS.new(ecc_key, 'fips-186-3', randfunc=StrRNG(tv.k))
  21. lib/Crypto/SelfTest/Signature/test_dss.py:638 test path signer = DSS.new(key, 'deterministic-rfc6979')
  22. lib/Crypto/SelfTest/Signature/test_dss.py:654 test path signer = DSS.new(key, 'deterministic-rfc6979')
  23. lib/Crypto/SelfTest/Signature/test_dss.py:1076 test path signer = DSS.new(self.key_priv_p192, 'deterministic-rfc6979')
  24. lib/Crypto/SelfTest/Signature/test_dss.py:1079 test path verifier = DSS.new(self.key_pub_p192, 'deterministic-rfc6979')
  25. lib/Crypto/SelfTest/Signature/test_dss.py:1084 test path signer = DSS.new(self.key_priv_p224, 'deterministic-rfc6979')
  26. lib/Crypto/SelfTest/Signature/test_dss.py:1087 test path verifier = DSS.new(self.key_pub_p224, 'deterministic-rfc6979')
  27. lib/Crypto/SelfTest/Signature/test_dss.py:1092 test path signer = DSS.new(self.key_priv_p256, 'deterministic-rfc6979')
  28. lib/Crypto/SelfTest/Signature/test_dss.py:1095 test path verifier = DSS.new(self.key_pub_p256, 'deterministic-rfc6979')
  29. lib/Crypto/SelfTest/Signature/test_dss.py:1100 test path signer = DSS.new(self.key_priv_p384, 'deterministic-rfc6979')
  30. lib/Crypto/SelfTest/Signature/test_dss.py:1103 test path verifier = DSS.new(self.key_pub_p384, 'deterministic-rfc6979')
  31. lib/Crypto/SelfTest/Signature/test_dss.py:1108 test path signer = DSS.new(self.key_priv_p521, 'deterministic-rfc6979')
  32. lib/Crypto/SelfTest/Signature/test_dss.py:1111 test path verifier = DSS.new(self.key_pub_p521, 'deterministic-rfc6979')
  33. lib/Crypto/SelfTest/Signature/test_dss.py:1115 test path signer = DSS.new(self.key_priv_p192, 'deterministic-rfc6979')
  34. lib/Crypto/SelfTest/Signature/test_dss.py:1122 test path signer = DSS.new(self.key_priv_p224, 'deterministic-rfc6979')
  35. lib/Crypto/SelfTest/Signature/test_dss.py:1129 test path signer = DSS.new(self.key_priv_p256, 'deterministic-rfc6979')
  36. lib/Crypto/SelfTest/Signature/test_dss.py:1136 test path signer = DSS.new(self.key_priv_p384, 'deterministic-rfc6979')
  37. lib/Crypto/SelfTest/Signature/test_dss.py:1143 test path signer = DSS.new(self.key_priv_p521, 'deterministic-rfc6979')
  38. lib/Crypto/SelfTest/Signature/test_dss.py:1221 test path signer = DSS.new(tv.key, 'fips-186-3', encoding='der')
  39. lib/Crypto/SelfTest/Signature/test_dss.py:1328 test path signer = DSS.new(tv.key, 'fips-186-3', encoding=tv.encoding)
  40. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:62 test path verifier = pkcs1_15.new(test_public_key)
  41. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:88 test path verifier = pkcs1_15.new(public_key)
  42. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:109 test path signer = pkcs1_15.new(test_private_key)
  43. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:135 test path signer = pkcs1_15.new(private_key)
  44. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:172 test path verifier = pkcs1_15.new(RSA.importKey(self.rsakey))
  45. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:206 test path signer = pkcs1_15.new(key)
  46. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:313 test path signer = pkcs1_15.new(tv.key)
  47. lib/Crypto/SelfTest/Signature/test_pss.py:72 test path verifier = pss.new(key)
  48. lib/Crypto/SelfTest/Signature/test_pss.py:78 test path verifier = pss.new(key)
  49. lib/Crypto/SelfTest/Signature/test_pss.py:85 test path verifier = pss.new(key, salt_bytes=1000)
  50. lib/Crypto/SelfTest/Signature/test_pss.py:98 test path verifier = pss.new(public_key, salt_bytes=len(salt), rand_func=prng)
  51. lib/Crypto/SelfTest/Signature/test_pss.py:104 test path verifier = pss.new(public_key, salt_bytes=len(salt), rand_func=prng)
  52. lib/Crypto/SelfTest/Signature/test_pss.py:109 test path verifier = pss.new(test_public_key)
  53. lib/Crypto/SelfTest/Signature/test_pss.py:138 test path verifier = pss.new(public_key, salt_bytes=len(tv.saltval), rand_func=prng)
  54. lib/Crypto/SelfTest/Signature/test_pss.py:140 test path verifier = pss.new(public_key, salt_bytes=0)
  55. lib/Crypto/SelfTest/Signature/test_pss.py:161 test path signer = pss.new(test_private_key)
  56. lib/Crypto/SelfTest/Signature/test_pss.py:193 test path signer = pss.new(private_key, salt_bytes=len(tv.saltval), rand_func=prng)
  57. lib/Crypto/SelfTest/Signature/test_pss.py:195 test path signer = pss.new(private_key, salt_bytes=0)
  58. lib/Crypto/SelfTest/Signature/test_pss.py:233 test path signer = pss.new(key)
  59. lib/Crypto/SelfTest/Signature/test_pss.py:339 test path signer = pss.new(tv.key, mask_func=tv.mgf, salt_bytes=tv.sLen)
  60. lib/Crypto/Signature/DSS.py:48 Use :func:`Crypto.Signature.DSS.new`.
  61. lib/Crypto/Signature/DSS.py:55 use `Crypto.Signature.DSS.new` instead.
  62. lib/Crypto/Signature/PKCS1_PSS.py:51 pkcs1 = pss.new(rsa_key, mask_func=mgfunc,
  63. lib/Crypto/Signature/PKCS1_v1_5.py:49 pkcs1 = pkcs1_15.new(rsa_key)
  64. lib/Crypto/Signature/eddsa.py:109 use `Crypto.Signature.DSS.new` instead.
  65. lib/Crypto/Signature/pkcs1_15.py:38 Use :func:`Crypto.Signature.pkcs1_15.new`.
  66. lib/Crypto/Signature/pss.py:44 Use :func:`Crypto.Signature.pss.new`.
py.pycryptodome.signature · CWE-327
ECDSA Quantum-vulnerable 60 places See details

Elliptic curves through PyCryptodome

`Crypto.PublicKey.ECC.generate(curve=...)`.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65.

  1. lib/Crypto/Protocol/HPKE.py:160 eph_key = ECC.generate(curve=receiver_key.curve)
  2. lib/Crypto/SelfTest/Protocol/test_HPKE.py:18 test path key1 = ECC.generate(curve='p256')
  3. lib/Crypto/SelfTest/Protocol/test_HPKE.py:19 test path key2 = ECC.generate(curve='p256')
  4. lib/Crypto/SelfTest/Protocol/test_HPKE.py:31 test path key1 = ECC.generate(curve=curve)
  5. lib/Crypto/SelfTest/Protocol/test_HPKE.py:71 test path key3 = ECC.generate(curve='p224')
  6. lib/Crypto/SelfTest/Protocol/test_HPKE.py:85 test path key3 = ECC.generate(curve='p384')
  7. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve25519.py:188 test path key = ECC.generate(curve='curve25519')
  8. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve25519.py:197 test path key = ECC.generate(curve="Curve25519")
  9. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve25519.py:203 test path key2 = ECC.generate(curve="Curve25519")
  10. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve25519.py:207 test path ECC.generate(curve="curve25519")
  11. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve25519.py:210 test path key1 = ECC.generate(curve="Curve25519", randfunc=SHAKE128.new().read)
  12. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve25519.py:211 test path key2 = ECC.generate(curve="Curve25519", randfunc=SHAKE128.new().read)
  13. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve448.py:163 test path key = ECC.generate(curve='curve448')
  14. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve448.py:172 test path key = ECC.generate(curve="Curve448")
  15. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve448.py:178 test path key2 = ECC.generate(curve="Curve448")
  16. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve448.py:182 test path ECC.generate(curve="curve448")
  17. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve448.py:185 test path key1 = ECC.generate(curve="Curve448", randfunc=SHAKE128.new().read)
  18. lib/Crypto/SelfTest/PublicKey/test_ECC_Curve448.py:186 test path key2 = ECC.generate(curve="Curve448", randfunc=SHAKE128.new().read)
  19. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:270 test path key = ECC.generate(curve='ed25519')
  20. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:279 test path key = ECC.generate(curve="Ed25519")
  21. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:285 test path key2 = ECC.generate(curve="Ed25519")
  22. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:289 test path ECC.generate(curve="Ed25519")
  23. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:292 test path key1 = ECC.generate(curve="Ed25519", randfunc=SHAKE128.new().read)
  24. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:293 test path key2 = ECC.generate(curve="Ed25519", randfunc=SHAKE128.new().read)
  25. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:265 test path key = ECC.generate(curve='ed448')
  26. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:274 test path key = ECC.generate(curve="Ed448")
  27. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:280 test path key2 = ECC.generate(curve="Ed448")
  28. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:284 test path ECC.generate(curve="Ed448")
  29. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:287 test path key1 = ECC.generate(curve="Ed448", randfunc=SHAKE128.new().read)
  30. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:288 test path key2 = ECC.generate(curve="Ed448", randfunc=SHAKE128.new().read)
  31. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:47 test path p1 = ECC.generate(curve='P-256').pointQ
  32. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:48 test path p2 = ECC.generate(curve='P-384').pointQ
  33. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:938 test path key = ECC.generate(curve='p192')
  34. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1005 test path key = ECC.generate(curve='p224')
  35. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1074 test path key = ECC.generate(curve='p256')
  36. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1145 test path key = ECC.generate(curve='p384')
  37. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1216 test path key = ECC.generate(curve='p521')
  38. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1226 test path key = ECC.generate(curve="P-192")
  39. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1234 test path ECC.generate(curve="secp192r1")
  40. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1235 test path ECC.generate(curve="prime192v1")
  41. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1265 test path key = ECC.generate(curve="P-224")
  42. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1273 test path ECC.generate(curve="secp224r1")
  43. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1274 test path ECC.generate(curve="prime224v1")
  44. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1304 test path key = ECC.generate(curve="P-256")
  45. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1311 test path ECC.generate(curve="secp256r1")
  46. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1312 test path ECC.generate(curve="prime256v1")
  47. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1343 test path key = ECC.generate(curve="P-384")
  48. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1348 test path ECC.generate(curve="secp384r1")
  49. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1349 test path ECC.generate(curve="prime384v1")
  50. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1380 test path key = ECC.generate(curve="P-521")
  51. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1385 test path ECC.generate(curve="secp521r1")
  52. lib/Crypto/SelfTest/PublicKey/test_ECC_NIST.py:1386 test path ECC.generate(curve="prime521v1")
  53. lib/Crypto/SelfTest/Signature/test_dss.py:229 test path key_priv = ECC.generate(curve="P-256")
  54. lib/Crypto/SelfTest/Signature/test_dss.py:255 test path key = ECC.generate(curve="ed25519")
  55. lib/Crypto/SelfTest/Signature/test_eddsa.py:437 test path key = ECC.generate(curve='ed25519')
  56. lib/Crypto/SelfTest/Signature/test_eddsa.py:450 test path key = ECC.generate(curve='ed448')
  57. lib/Crypto/SelfTest/Signature/test_eddsa.py:462 test path key = ECC.generate(curve="ed25519")
  58. lib/Crypto/SelfTest/Signature/test_eddsa.py:465 test path nist_key = ECC.generate(curve="p256")
  59. lib/Crypto/SelfTest/Signature/test_eddsa.py:472 test path key = ECC.generate(curve="Ed25519")
  60. lib/Crypto/SelfTest/Signature/test_eddsa.py:489 test path key = ECC.generate(curve="Ed448")
py.pycryptodome.ecc · CWE-327
Ed25519255-bitother/Ed25519 Quantum-vulnerable 40 places See details

JOSE algorithm declared in configuration

An `alg` value in JSON or YAML. `none` is reported as a critical defect; HS* is an HMAC and is not quantum-vulnerable; RS*, PS*, ES* and EdDSA are.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. No standardised post-quantum JOSE algorithm exists yet. Keep token lifetimes short.

  1. lib/Crypto/PublicKey/ECC.py:765 "1.3.101.112": ("Ed25519", _import_ed25519_public_key), # id-Ed25519
  2. lib/Crypto/PublicKey/ECC.py:888 "1.3.101.112": "Ed25519", # id-Ed25519
  3. lib/Crypto/PublicKey/ECC.py:992 ecc_key = construct(curve="Ed25519", point_x=x, point_y=y)
  4. lib/Crypto/PublicKey/ECC.py:1010 "ssh-ed25519": ("Ed25519", _import_ed25519_public_key, 32),
  5. lib/Crypto/PublicKey/_edwards.py:53 "Ed25519",
  6. lib/Crypto/PublicKey/_point.py:41 ed25519_names = ["ed25519", "Ed25519"]
  7. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:61 test path self.assertEqual(self.pointG.curve, "Ed25519")
  8. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:64 test path EccPoint(self.Gxy['x'], self.Gxy['y'], curve="Ed25519")
  9. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:67 test path pai = EccPoint(0, 1, curve="Ed25519")
  10. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:87 test path curve="Ed25519")
  11. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:90 test path self.assertRaises(ValueError, EccPoint, 34, 35, curve="Ed25519")
  12. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:93 test path pointW = EccPoint(0, 1, curve="Ed25519")
  13. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:110 test path pai = EccPoint(0, 1, curve="Ed25519")
  14. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:218 test path key = EccKey(curve="Ed25519", seed=seed)
  15. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:226 test path key = EccKey(curve="Ed25519", seed=seed, point=point)
  16. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:253 test path private_key = ECC.construct(seed=b'H'*32, curve="Ed25519")
  17. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:255 test path private_key3 = ECC.construct(seed=b'C'*32, curve="Ed25519")
  18. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:271 test path self.assertIn("curve='Ed25519'", repr(key))
  19. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:272 test path self.assertEqual(key.curve, 'Ed25519')
  20. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:273 test path self.assertEqual(key.public_key().curve, 'Ed25519')
  21. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:279 test path key = ECC.generate(curve="Ed25519")
  22. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:281 test path point = EccPoint(_curves['Ed25519'].Gx, _curves['Ed25519'].Gy, curve="Ed25519") * key.d
  23. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:285 test path key2 = ECC.generate(curve="Ed25519")
  24. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:289 test path ECC.generate(curve="Ed25519")
  25. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:292 test path key1 = ECC.generate(curve="Ed25519", randfunc=SHAKE128.new().read)
  26. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:293 test path key2 = ECC.generate(curve="Ed25519", randfunc=SHAKE128.new().read)
  27. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:301 test path point = EccPoint(Px, Py, curve="Ed25519")
  28. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:304 test path key = ECC.construct(curve="Ed25519", seed=seed)
  29. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:309 test path key = ECC.construct(curve="Ed25519", point_x=Px, point_y=Py)
  30. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:314 test path key = ECC.construct(curve="Ed25519", seed=seed, point_x=Px, point_y=Py)
  31. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:325 test path self.assertRaises(ValueError, ECC.construct, curve="Ed25519", **coord)
  32. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:326 test path self.assertRaises(ValueError, ECC.construct, curve="Ed25519", d=2, **coordG)
  33. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed25519.py:327 test path self.assertRaises(ValueError, ECC.construct, curve="Ed25519", seed=b'H'*31)
  34. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:157 test path key = ECC.construct(curve="Ed25519", seed=seed)
  35. lib/Crypto/SelfTest/Signature/test_eddsa.py:472 test path key = ECC.generate(curve="Ed25519")
  36. lib/Crypto/SelfTest/Signature/test_eddsa.py:481 test path key = ECC.construct(point_x=0, point_y=1, curve="Ed25519")
  37. lib/Crypto/Signature/eddsa.py:60 curve_name = "Ed25519"
  38. lib/Crypto/Signature/eddsa.py:141 if self._key.curve == "Ed25519":
  39. lib/Crypto/Signature/eddsa.py:227 if self._key.curve == "Ed25519":
  40. lib/Crypto/Signature/eddsa.py:332 if not isinstance(key, EccKey) or key.curve not in ("Ed25519", "Ed448"):
jose.algorithm · CWE-327
EdDSA Quantum-vulnerable 38 places See details

JOSE algorithm declared in configuration

An `alg` value in JSON or YAML. `none` is reported as a critical defect; HS* is an HMAC and is not quantum-vulnerable; RS*, PS*, ES* and EdDSA are.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. No standardised post-quantum JOSE algorithm exists yet. Keep token lifetimes short.

  1. lib/Crypto/PublicKey/ECC.py:766 "1.3.101.113": ("Ed448", _import_ed448_public_key) # id-Ed448
  2. lib/Crypto/PublicKey/ECC.py:889 "1.3.101.113": "Ed448", # id-Ed448
  3. lib/Crypto/PublicKey/_edwards.py:113 "Ed448",
  4. lib/Crypto/PublicKey/_point.py:42 ed448_names = ["ed448", "Ed448"]
  5. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:61 test path self.assertEqual(self.pointG.curve, "Ed448")
  6. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:64 test path EccPoint(self.Gxy['x'], self.Gxy['y'], curve="Ed448")
  7. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:67 test path pai = EccPoint(0, 1, curve="Ed448")
  8. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:87 test path curve="Ed448")
  9. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:90 test path self.assertRaises(ValueError, EccPoint, 34, 35, curve="Ed448")
  10. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:93 test path pointW = EccPoint(0, 1, curve="Ed448")
  11. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:110 test path pai = EccPoint(0, 1, curve="Ed448")
  12. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:213 test path key = EccKey(curve="Ed448", seed=seed)
  13. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:221 test path key = EccKey(curve="Ed448", seed=seed, point=point)
  14. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:248 test path private_key = ECC.construct(seed=b'H'*57, curve="Ed448")
  15. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:250 test path private_key3 = ECC.construct(seed=b'C'*57, curve="Ed448")
  16. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:266 test path self.assertIn("curve='Ed448'", repr(key))
  17. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:267 test path self.assertEqual(key.curve, 'Ed448')
  18. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:268 test path self.assertEqual(key.public_key().curve, 'Ed448')
  19. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:274 test path key = ECC.generate(curve="Ed448")
  20. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:276 test path point = EccPoint(_curves['Ed448'].Gx, _curves['Ed448'].Gy, curve="Ed448") * key.d
  21. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:280 test path key2 = ECC.generate(curve="Ed448")
  22. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:284 test path ECC.generate(curve="Ed448")
  23. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:287 test path key1 = ECC.generate(curve="Ed448", randfunc=SHAKE128.new().read)
  24. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:288 test path key2 = ECC.generate(curve="Ed448", randfunc=SHAKE128.new().read)
  25. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:296 test path point = EccPoint(Px, Py, curve="Ed448")
  26. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:299 test path key = ECC.construct(curve="Ed448", seed=seed)
  27. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:304 test path key = ECC.construct(curve="Ed448", point_x=Px, point_y=Py)
  28. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:309 test path key = ECC.construct(curve="Ed448", seed=seed, point_x=Px, point_y=Py)
  29. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:320 test path self.assertRaises(ValueError, ECC.construct, curve="Ed448", **coord)
  30. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:321 test path self.assertRaises(ValueError, ECC.construct, curve="Ed448", d=2, **coordG)
  31. lib/Crypto/SelfTest/PublicKey/test_ECC_Ed448.py:322 test path self.assertRaises(ValueError, ECC.construct, curve="Ed448", seed=b'H'*58)
  32. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:164 test path key = ECC.construct(curve="Ed448", seed=seed)
  33. lib/Crypto/SelfTest/Signature/test_eddsa.py:489 test path key = ECC.generate(curve="Ed448")
  34. lib/Crypto/SelfTest/Signature/test_eddsa.py:498 test path key = ECC.construct(point_x=0, point_y=1, curve="Ed448")
  35. lib/Crypto/Signature/eddsa.py:63 curve_name = "Ed448"
  36. lib/Crypto/Signature/eddsa.py:147 elif self._key.curve == "Ed448":
  37. lib/Crypto/Signature/eddsa.py:233 elif self._key.curve == "Ed448":
  38. lib/Crypto/Signature/eddsa.py:332 if not isinstance(key, EccKey) or key.curve not in ("Ed25519", "Ed448"):
jose.algorithm · CWE-327
RSA-OAEP Quantum-vulnerable Recorded traffic 13 places See details

JOSE algorithm declared in configuration

An `alg` value in JSON or YAML. `none` is reported as a critical defect; HS* is an HMAC and is not quantum-vulnerable; RS*, PS*, ES* and EdDSA are.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. No standardised post-quantum JOSE algorithm exists yet. Keep token lifetimes short.

  1. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_2048_sha1_mgf1sha1_test.json:23 test path "alg" : "RSA-OAEP",
  2. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_2048_sha256_mgf1sha256_test.json:23 test path "alg" : "RSA-OAEP-256",
  3. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_3072_sha256_mgf1sha256_test.json:23 test path "alg" : "RSA-OAEP-256",
  4. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_4096_sha256_mgf1sha256_test.json:23 test path "alg" : "RSA-OAEP-256",
  5. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:23 test path "alg" : "RSA-OAEP",
  6. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:1260 test path "alg" : "RSA-OAEP-256",
  7. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:2748 test path "alg" : "RSA-OAEP-256",
  8. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:4087 test path "alg" : "RSA-OAEP",
  9. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:5132 test path "alg" : "RSA-OAEP-256",
  10. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:6435 test path "alg" : "RSA-OAEP-256",
  11. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:7738 test path "alg" : "RSA-OAEP-256",
  12. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:8869 test path "alg" : "RSA-OAEP-256",
  13. test_vectors/pycryptodome_test_vectors/Cipher/wycheproof/rsa_oaep_misc_test.json:8995 test path "alg" : "RSA-OAEP-256",
jose.algorithm · CWE-327
ECDSA Quantum-vulnerable 10 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:1123 test path -----BEGIN EC PRIVATE KEY-----
  2. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:1130 test path -----BEGIN EC PRIVATE KEY-----
  3. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:1378 test path -----BEGIN EC PRIVATE KEY-----
  4. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:1385 test path -----BEGIN EC PRIVATE KEY-----
  5. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:1668 test path -----BEGIN EC PRIVATE KEY-----
  6. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:1674 test path -----BEGIN EC PRIVATE KEY-----
  7. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:1957 test path -----BEGIN EC PRIVATE KEY-----
  8. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:1965 test path -----BEGIN EC PRIVATE KEY-----
  9. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:2256 test path -----BEGIN EC PRIVATE KEY-----
  10. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:2265 test path -----BEGIN EC PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
RSA Quantum-vulnerable Recorded traffic 6 places See details

RSA key generated with pyca/cryptography

`rsa.generate_private_key()`. The `key_size` argument is read where it is a literal and reported on the finding; it does not change the classification, because Shor is polynomial in the modulus size.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-KEM-768 for encryption and ML-DSA-65 for signatures.

  1. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:194 test path """Verify import of RSAPrivateKey DER SEQUENCE"""
  2. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:211 test path """Verify import of RSAPrivateKey DER SEQUENCE, encoded with PEM as unicode"""
  3. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:221 test path """Verify import of RSAPrivateKey DER SEQUENCE, encoded with PEM as byte string"""
  4. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:231 test path """Verify import of RSAPrivateKey DER SEQUENCE, encoded with PEM as unicode"""
  5. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:294 test path """Verify import of RSAPublicKey DER SEQUENCE"""
  6. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:301 test path """Verify import of RSAPublicKey DER SEQUENCE, encoded with PEM"""
py.cryptography.rsa · CWE-327
DSA Quantum-vulnerable 5 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

  1. lib/Crypto/PublicKey/DSA.py:285 keyparts = [b'ssh-dss'] + tup2
  2. lib/Crypto/PublicKey/DSA.py:289 return b'ssh-dss ' + binascii.b2a_base64(keystring)[:-1]
  3. lib/Crypto/PublicKey/DSA.py:655 if extern_key.startswith(b'ssh-dss '):
  4. lib/Crypto/PublicKey/DSA.py:663 if keyparts[0] == b"ssh-dss":
  5. lib/Crypto/SelfTest/PublicKey/test_import_DSA.py:237 test path ssh_pub="""ssh-dss AAAAB3NzaC1kc3MAAACBAOdW7hcX9LZ5THwhRyShl2N0LEVXK0s/j/O0Tzvp9EzgOaJ1dpXskVaX2nTvkU/NGwVmDiQZx2HWOfRdLXm4AtvSPnq4uBtHmjgOHzCTJYS6KguVUDI0LryDy1ypBuew181v5lbOy0yLWncSOoxnUKSB47BgV6/2qm66YguDLWDDAAAAFQCtMvSM064MRaGYph+kteIDI
config.ssh-algorithms · CWE-757
Ed25519255-bitother/Ed25519 Quantum-vulnerable 5 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

  1. lib/Crypto/PublicKey/ECC.py:409 elif desc == "ssh-ed25519":
  2. lib/Crypto/PublicKey/ECC.py:990 elif parts[0] == b"ssh-ed25519":
  3. lib/Crypto/PublicKey/ECC.py:1010 "ssh-ed25519": ("Ed25519", _import_ed25519_public_key, 32),
  4. lib/Crypto/PublicKey/ECC.py:1309 if encoded.startswith((b'ecdsa-sha2-', b'ssh-ed25519')):
  5. lib/Crypto/PublicKey/_edwards.py:54 "ssh-ed25519",
config.ssh-algorithms · CWE-757
RSA Quantum-vulnerable Recorded traffic 5 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. bench_monty.py:16 -----BEGIN RSA PRIVATE KEY-----
  2. lib/Crypto/SelfTest/Cipher/test_pkcs1_15.py:71 test path -----BEGIN RSA PRIVATE KEY-----
  3. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:81 test path -----BEGIN RSA PRIVATE KEY-----
  4. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:108 test path -----BEGIN RSA PRIVATE KEY-----
  5. lib/Crypto/SelfTest/Signature/test_pkcs1_15.py:152 test path -----BEGIN RSA PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
RSASSA-PKCS1v15 Quantum-vulnerable 5 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer. The v1.5 signature scheme of RFC 8017 section 8.2 has no classical break of its own; RSA-PSS is preferred for new work, but the quantum exposure is the same for both.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

  1. lib/Crypto/PublicKey/RSA.py:361 keyparts = [b'ssh-rsa', e_bytes, n_bytes]
  2. lib/Crypto/PublicKey/RSA.py:363 return b'ssh-rsa ' + binascii.b2a_base64(keystring)[:-1]
  3. lib/Crypto/PublicKey/RSA.py:764 if ssh_name != "ssh-rsa":
  4. lib/Crypto/PublicKey/RSA.py:841 if extern_key.startswith(b'ssh-rsa '):
  5. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:142 test path rsaPublicKeyOpenSSH = b('''ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAAQQC/HieQCqCLI1EaXBKBrm2TMSw+/pE/ky6+1JLxLRa0YQwyjLbiCKtfRay+KVCDMpjzEiwZ94SS3t9A8OPBkDOF comment\n''')
config.ssh-algorithms · CWE-757
DSA Quantum-vulnerable 3 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. lib/Crypto/SelfTest/PublicKey/test_import_DSA.py:146 test path -----BEGIN DSA PRIVATE KEY-----
  2. lib/Crypto/SelfTest/PublicKey/test_import_DSA.py:208 test path -----BEGIN PRIVATE KEY-----
  3. lib/Crypto/SelfTest/PublicKey/test_import_DSA.py:256 test path -----BEGIN DSA PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
ECDSA Quantum-vulnerable 3 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

config.ssh-algorithms · CWE-757
Ed25519255-bitother/Ed25519 Quantum-vulnerable 3 places See details

Public key declared as a JSON Web Key

A `kty` field, with the curve read from the sibling `crv` where the family needs one. A JWKS document declares a key without naming an algorithm anywhere, so it is invisible to a scan that only looks for `alg`.

This file publishes the public keys other systems use to check this system's signatures. Everyone who trusts these keys has to accept the new kind of key before the old ones can be retired.

What to do. A published JWKS is what relying parties trust. It has to accept a post-quantum key type before the keys behind it can change, so put it early in the migration order.

jose.jwk · CWE-327
DSA Quantum-vulnerable 2 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. lib/Crypto/SelfTest/PublicKey/test_import_DSA.py:389 test path -----BEGIN CERTIFICATE-----
  2. lib/Crypto/SelfTest/PublicKey/test_import_DSA.py:461 test path -----BEGIN CERTIFICATE-----
pem.certificate
RSA2048-bit Quantum-vulnerable Recorded traffic 2 places See details

RSA through PyCryptodome

`Crypto.PublicKey.RSA.generate()` or `RSA.import_key()`.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-KEM-768 for encryption, ML-DSA-65 for signatures.

  1. pct-speedtest.py:246 k = RSA.generate(2048)
  2. pct-speedtest.py:268 k = RSA.generate(2048)
py.pycryptodome.rsa · CWE-327
DSA Quantum-vulnerable 1 place See details

Public key file

A PEM public-key block. The algorithm is read from the SubjectPublicKeyInfo.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Inventory only; a public key is not itself a secret.

  1. lib/Crypto/SelfTest/PublicKey/test_import_DSA.py:84 test path -----BEGIN PUBLIC KEY-----
pem.public-key
DSA Quantum-vulnerable 1 place See details

SSH public key

An `ssh-rsa`, `ecdsa-sha2-*`, `ssh-ed25519` or `ssh-dss` key. `ssh-dss` is disabled by default in current OpenSSH and is reported as broken.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Replace `ssh-dss` now. For the rest, enable the `sntrup761x25519-sha512` key exchange, which protects recorded sessions even while host keys stay classical.

  1. lib/Crypto/SelfTest/PublicKey/test_import_DSA.py:237 test path ssh_pub="""ssh-dss AAAAB3NzaC1kc3MAAACBAOdW7hcX9LZ5THwhRyShl2N0LEVXK0s/j/O0Tzvp9
ssh.public-key · CWE-327
ECDSA384-bitsecg/secp384r1 Quantum-vulnerable 1 place See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. lib/Crypto/SelfTest/PublicKey/test_import_ECC.py:190 test path -----BEGIN PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
ECDSA256-bitsecg/secp256r1 Quantum-vulnerable 1 place See details

Public key declared as a JSON Web Key

A `kty` field, with the curve read from the sibling `crv` where the family needs one. A JWKS document declares a key without naming an algorithm anywhere, so it is invisible to a scan that only looks for `alg`.

This file publishes the public keys other systems use to check this system's signatures. Everyone who trusts these keys has to accept the new kind of key before the old ones can be retired.

What to do. A published JWKS is what relying parties trust. It has to accept a post-quantum key type before the keys behind it can change, so put it early in the migration order.

jose.jwk · CWE-327
ECDSA384-bitsecg/secp384r1 Quantum-vulnerable 1 place See details

Public key declared as a JSON Web Key

A `kty` field, with the curve read from the sibling `crv` where the family needs one. A JWKS document declares a key without naming an algorithm anywhere, so it is invisible to a scan that only looks for `alg`.

This file publishes the public keys other systems use to check this system's signatures. Everyone who trusts these keys has to accept the new kind of key before the old ones can be retired.

What to do. A published JWKS is what relying parties trust. It has to accept a post-quantum key type before the keys behind it can change, so put it early in the migration order.

jose.jwk · CWE-327
ECDSA521-bitsecg/secp521r1 Quantum-vulnerable 1 place See details

Public key declared as a JSON Web Key

A `kty` field, with the curve read from the sibling `crv` where the family needs one. A JWKS document declares a key without naming an algorithm anywhere, so it is invisible to a scan that only looks for `alg`.

This file publishes the public keys other systems use to check this system's signatures. Everyone who trusts these keys has to accept the new kind of key before the old ones can be retired.

What to do. A published JWKS is what relying parties trust. It has to accept a post-quantum key type before the keys behind it can change, so put it early in the migration order.

jose.jwk · CWE-327
RSA Quantum-vulnerable 1 place See details

SSH public key

An `ssh-rsa`, `ecdsa-sha2-*`, `ssh-ed25519` or `ssh-dss` key. `ssh-dss` is disabled by default in current OpenSSH and is reported as broken.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Replace `ssh-dss` now. For the rest, enable the `sntrup761x25519-sha512` key exchange, which protects recorded sessions even while host keys stay classical.

  1. lib/Crypto/SelfTest/PublicKey/test_import_RSA.py:142 test path rsaPublicKeyOpenSSH = b('''ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAAQQC/HieQCqCLI1EaX
ssh.public-key · CWE-327

Cryptographic assets

Algorithm Assessment What it means Occurrences
X25519 Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 1057
X448 Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 1041
ECDSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 689
RSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 506
Ed25519 Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 162
RSAES-PKCS1v15 Already broken PKCS#1 v1.5 encryption padding is vulnerable to Bleichenbacher oracles today, and the underlying RSA is broken by Shor. 99
RSASSA-PKCS1v15 Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. The v1.5 signature scheme of RFC 8017 section 8.2 has no classical break of its own; RSA-PSS is preferred for new work, but the quantum exposure is the same for both. 87
RSA-PSS Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 68
EdDSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 59
unknown Could not be determined The algorithm could not be established from the source - chosen at runtime, or decided somewhere this scan does not reach. 37
SHA-256 Reduced margin Pre-image resistance falls to about 128 bits of quantum work. Adequate for most uses; SHA-384 restores the full margin where a signature must last decades. 17
ECDH Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 13
RSA-1024 Already broken A modulus of 1024 bits or less is below the NIST SP 800-57 floor and is within reach of classical factorisation. Shor is not the nearest problem here. 13
RSA-OAEP Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 13
DSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 12
HMAC Quantum-safe A keyed MAC is not affected by Shor and only marginally by Grover. 4
SHA-1 Already broken SHAttered and subsequent work produced practical collisions; NIST withdrew SHA-1 in 2030 guidance and it is already unacceptable for signatures. 4
CSPRNG Quantum-safe A cryptographically secure random number generator provided by the platform. Not weakened by a quantum computer. 2

Imported cryptographic libraries

Library Files
Crypto PyCryptodome 223