smallstep/certificates
bb481fbf670c
(3 days ago)
→
fa946c527a6c
(3 hours ago)
| Measure | Before | After | Change |
|---|---|---|---|
| Readiness score | 0 | 0 | - |
| Findings to address | 458 | 895 | +437 |
| Key establishment | 212 | 233 | +21 |
| Files scanned | 456 | 456 | - |
Added
Present in the later scan and not in the earlier one.
| Finding | Assessment | Before | After |
|---|---|---|---|
RSA-1024
X.509 certificate · pem.certificate
|
Already broken | 0 | 37 |
RSAES-PKCS1v15
TLS cipher suite named in source · config.cipher-suite
|
Already broken | 0 | 21 |
RC4
TLS cipher suite named in source · config.cipher-suite
|
Already broken | 0 | 7 |
3DES
TLS cipher suite named in source · config.cipher-suite
|
Already broken | 0 | 6 |
RSA-1024
RSA in the Go standard library · go.rsa
|
Already broken | 0 | 5 |
RSA-1024
Certificate signing request · pem.certificate-request
|
Already broken | 0 | 1 |
RSA-1024
Certificate signing request · pem.certificate-request
|
Already broken | 0 | 1 |
ECDH
TLS cipher suite named in source · config.cipher-suite
|
Quantum-vulnerable | 0 | 117 |
ECDSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 0 | 56 |
ECDSA
ECDSA in the Go standard library · go.ecdsa
|
Quantum-vulnerable | 0 | 40 |
ECDSA
Public key declared as a JSON Web Key · jose.jwk
|
Quantum-vulnerable | 0 | 30 |
RSA
RSA in the Go standard library · go.rsa
|
Quantum-vulnerable | 0 | 19 |
ECDSA
SSH algorithms pinned in configuration · config.ssh-algorithms
|
Quantum-vulnerable | 0 | 16 |
Ed25519
Ed25519 in the Go standard library · go.ed25519
|
Quantum-vulnerable | 0 | 14 |
Ed25519
Public key file · pem.public-key
|
Quantum-vulnerable | 0 | 10 |
Ed25519
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 0 | 7 |
ECDSA
Certificate signing request · pem.certificate-request
|
Quantum-vulnerable | 0 | 5 |
ECDSA
Public key file · pem.public-key
|
Quantum-vulnerable | 0 | 4 |
ECDSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 0 | 3 |
RSA
Certificate signing request · pem.certificate-request
|
Quantum-vulnerable | 0 | 3 |
RSASSA-PKCS1v15
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 0 | 3 |
Ed25519
Certificate signing request · pem.certificate-request
|
Quantum-vulnerable | 0 | 2 |
RSA
Certificate signing request · pem.certificate-request
|
Quantum-vulnerable | 0 | 2 |
EC
X.509 certificate handling · go.x509
|
Quantum-vulnerable | 0 | 1 |
ECDH
Key agreement in Go · go.ecdh
|
Quantum-vulnerable | 0 | 1 |
ECDSA
ECDSA in the Go standard library · go.ecdsa
|
Quantum-vulnerable | 0 | 1 |
ECDSA
ECDSA in the Go standard library · go.ecdsa
|
Quantum-vulnerable | 0 | 1 |
ECDSA
ECDSA in the Go standard library · go.ecdsa
|
Quantum-vulnerable | 0 | 1 |
Ed25519
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 0 | 1 |
Ed25519
Private key committed to the repository · pem.private-key
|
Quantum-vulnerable | 0 | 1 |
RSASSA-PKCS1v15
SSH algorithms pinned in configuration · config.ssh-algorithms
|
Quantum-vulnerable | 0 | 1 |
HMAC
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-safe | 0 | 1 |
Resolved
Present in the earlier scan and gone in the later one.
| Finding | Assessment | Before | After |
|---|---|---|---|
ECDSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 61 | 0 |
ECDSA
ECDSA in the Go standard library · go.ecdsa
|
Quantum-vulnerable | 40 | 0 |
RSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 38 | 0 |
Ed25519
Ed25519 in the Go standard library · go.ed25519
|
Quantum-vulnerable | 14 | 0 |
Ed25519
Public key file · pem.public-key
|
Quantum-vulnerable | 10 | 0 |
ECDSA
Public key file · pem.public-key
|
Quantum-vulnerable | 4 | 0 |
ECDSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 3 | 0 |
Ed25519
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 3 | 0 |
ECDH
Key agreement in Go · go.ecdh
|
Quantum-vulnerable | 1 | 0 |
ECDSA
ECDSA in the Go standard library · go.ecdsa
|
Quantum-vulnerable | 1 | 0 |
ECDSA
ECDSA in the Go standard library · go.ecdsa
|
Quantum-vulnerable | 1 | 0 |
ECDSA
ECDSA in the Go standard library · go.ecdsa
|
Quantum-vulnerable | 1 | 0 |
Ed25519
Private key committed to the repository · pem.private-key
|
Quantum-vulnerable | 1 | 0 |
RSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 1 | 0 |
Count changed
The same finding, in a different number of places.
| Finding | Assessment | Before | After |
|---|---|---|---|
ECDSA
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 30 | 303 |
DSA
DSA in the Go standard library · go.dsa
|
Quantum-vulnerable | 46 | 2 |
RSA
RSA in the Go standard library · go.rsa
|
Quantum-vulnerable | 26 | 2 |
RSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 10 | 7 |
RSA
X.509 certificate · pem.certificate
|
Quantum-vulnerable | 5 | 3 |
unknown
X.509 certificate handling · go.x509
|
Could not be determined | 14 | 13 |
Unchanged
13 findings appear in both scans, in the same number of places. Each scan's own report lists them.