Crypto-View

cloudflare/cfssl

Cryptographic posture

1708 cryptographic locations: 332 already broken, 1196 quantum-vulnerable, 21 reduced-margin, 118 undetermined, 41 quantum-safe

463 establish keys, so traffic protected by them and recorded today becomes readable once the algorithm falls. 1 imported cryptographic library is listed separately. 562 files analysed.

Quantum-vulnerable 1196 Already broken 332 Reduced margin 21 Could not be determined 118 Quantum-safe 41
To address1457
Key establishment463
Inventory only1
Total findings1709
What was analysed
Branch master
Commit 82408a199099610d358a0971598c48a8802cae8a Merge pull request #1434 from elukey/master
Committed 2026-09-23 18:02 UTC
Scanned 2026-09-27 04:05 UTC 1 hour ago
Coverage 562 files, 251 go, 1 python, 1 javascript

Earlier scans of this repository

2 scans · compare any two
0 to 2000 locations Already broken 346 → 332 (down 14) Quantum-vulnerable 1521 → 1196 (down 325) Reduced margin 21 → 21 (unchanged) Could not be determined 116 → 118 (up 2) Quantum-safe 40 → 41 (up 1) The filled point is the scan you are reading.
Scanned Commit To address Key establishment
1 hour ago this scan 82408a199099 master 1457 463
5 days ago e429e72785df master 1798 458 Compare

Every repository in this history is re-scanned weekly.

List of cryptographic assets

RSA-10241024-bit Already broken 104 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. bundler/testdata/froyo.pem:1 test path -----BEGIN CERTIFICATE-----
  2. bundler/testdata/froyo.pem:14 test path -----BEGIN CERTIFICATE-----
  3. bundler/testdata/froyo.pem:28 test path -----BEGIN CERTIFICATE-----
  4. bundler/testdata/froyo.pem:112 test path -----BEGIN CERTIFICATE-----
  5. bundler/testdata/froyo.pem:214 test path -----BEGIN CERTIFICATE-----
  6. bundler/testdata/froyo.pem:240 test path -----BEGIN CERTIFICATE-----
  7. bundler/testdata/froyo.pem:256 test path -----BEGIN CERTIFICATE-----
  8. bundler/testdata/froyo.pem:297 test path -----BEGIN CERTIFICATE-----
  9. bundler/testdata/froyo.pem:321 test path -----BEGIN CERTIFICATE-----
  10. bundler/testdata/froyo.pem:335 test path -----BEGIN CERTIFICATE-----
  11. bundler/testdata/froyo.pem:374 test path -----BEGIN CERTIFICATE-----
  12. bundler/testdata/froyo.pem:511 test path -----BEGIN CERTIFICATE-----
  13. bundler/testdata/froyo.pem:546 test path -----BEGIN CERTIFICATE-----
  14. bundler/testdata/froyo.pem:583 test path -----BEGIN CERTIFICATE-----
  15. bundler/testdata/froyo.pem:797 test path -----BEGIN CERTIFICATE-----
  16. bundler/testdata/froyo.pem:939 test path -----BEGIN CERTIFICATE-----
  17. bundler/testdata/froyo.pem:1149 test path -----BEGIN CERTIFICATE-----
  18. bundler/testdata/nss.pem:12 test path -----BEGIN CERTIFICATE-----
  19. bundler/testdata/nss.pem:35 test path -----BEGIN CERTIFICATE-----
  20. bundler/testdata/nss.pem:62 test path -----BEGIN CERTIFICATE-----
  21. bundler/testdata/nss.pem:89 test path -----BEGIN CERTIFICATE-----
  22. bundler/testdata/nss.pem:116 test path -----BEGIN CERTIFICATE-----
  23. bundler/testdata/nss.pem:143 test path -----BEGIN CERTIFICATE-----
  24. bundler/testdata/nss.pem:170 test path -----BEGIN CERTIFICATE-----
  25. bundler/testdata/nss.pem:192 test path -----BEGIN CERTIFICATE-----
  26. bundler/testdata/nss.pem:278 test path -----BEGIN CERTIFICATE-----
  27. bundler/testdata/nss.pem:304 test path -----BEGIN CERTIFICATE-----
  28. bundler/testdata/nss.pem:330 test path -----BEGIN CERTIFICATE-----
  29. bundler/testdata/nss.pem:420 test path -----BEGIN CERTIFICATE-----
  30. bundler/testdata/nss.pem:519 test path -----BEGIN CERTIFICATE-----
  31. bundler/testdata/nss.pem:543 test path -----BEGIN CERTIFICATE-----
  32. bundler/testdata/nss.pem:567 test path -----BEGIN CERTIFICATE-----
  33. bundler/testdata/nss.pem:1582 test path -----BEGIN CERTIFICATE-----
  34. bundler/testdata/nss.pem:1621 test path -----BEGIN CERTIFICATE-----
  35. bundler/testdata/nss.pem:3658 test path -----BEGIN CERTIFICATE-----
  36. bundler/testdata/osx.pem:1331 test path -----BEGIN CERTIFICATE-----
  37. bundler/testdata/osx.pem:1346 test path -----BEGIN CERTIFICATE-----
  38. bundler/testdata/osx.pem:1360 test path -----BEGIN CERTIFICATE-----
  39. bundler/testdata/osx.pem:1401 test path -----BEGIN CERTIFICATE-----
  40. bundler/testdata/osx.pem:1415 test path -----BEGIN CERTIFICATE-----
  41. bundler/testdata/osx.pem:1429 test path -----BEGIN CERTIFICATE-----
  42. bundler/testdata/osx.pem:1448 test path -----BEGIN CERTIFICATE-----
  43. bundler/testdata/osx.pem:1462 test path -----BEGIN CERTIFICATE-----
  44. bundler/testdata/osx.pem:1476 test path -----BEGIN CERTIFICATE-----
  45. bundler/testdata/osx.pem:1495 test path -----BEGIN CERTIFICATE-----
  46. bundler/testdata/osx.pem:1929 test path -----BEGIN CERTIFICATE-----
  47. bundler/testdata/osx.pem:2099 test path -----BEGIN CERTIFICATE-----
  48. bundler/testdata/osx.pem:2289 test path -----BEGIN CERTIFICATE-----
  49. bundler/testdata/osx.pem:2350 test path -----BEGIN CERTIFICATE-----
  50. bundler/testdata/osx.pem:2369 test path -----BEGIN CERTIFICATE-----
  51. bundler/testdata/osx.pem:2385 test path -----BEGIN CERTIFICATE-----
  52. bundler/testdata/osx.pem:2404 test path -----BEGIN CERTIFICATE-----
  53. bundler/testdata/osx.pem:2766 test path -----BEGIN CERTIFICATE-----
  54. bundler/testdata/osx.pem:2826 test path -----BEGIN CERTIFICATE-----
  55. bundler/testdata/osx.pem:2844 test path -----BEGIN CERTIFICATE-----
  56. bundler/testdata/osx.pem:2862 test path -----BEGIN CERTIFICATE-----
  57. bundler/testdata/osx.pem:3174 test path -----BEGIN CERTIFICATE-----
  58. bundler/testdata/osx.pem:3281 test path -----BEGIN CERTIFICATE-----
  59. bundler/testdata/osx.pem:4615 test path -----BEGIN CERTIFICATE-----
  60. bundler/testdata/osx.pem:4635 test path -----BEGIN CERTIFICATE-----
  61. bundler/testdata/osx.pem:4654 test path -----BEGIN CERTIFICATE-----
  62. bundler/testdata/osx.pem:4674 test path -----BEGIN CERTIFICATE-----
  63. bundler/testdata/osx.pem:4694 test path -----BEGIN CERTIFICATE-----
  64. bundler/testdata/osx.pem:4714 test path -----BEGIN CERTIFICATE-----
  65. bundler/testdata/osx.pem:4733 test path -----BEGIN CERTIFICATE-----
  66. bundler/testdata/osx.pem:4753 test path -----BEGIN CERTIFICATE-----
  67. bundler/testdata/osx.pem:4838 test path -----BEGIN CERTIFICATE-----
  68. bundler/testdata/osx.pem:4857 test path -----BEGIN CERTIFICATE-----
  69. bundler/testdata/osx.pem:4876 test path -----BEGIN CERTIFICATE-----
  70. crl/testdata/server.crt:1 test path -----BEGIN CERTIFICATE-----
  71. multiroot/config/testdata/server.crt:1 test path -----BEGIN CERTIFICATE-----
  72. ocsp/testdata/server.crt:1 test path -----BEGIN CERTIFICATE-----
  73. scan/crypto/tls/handshake_server_test.go:922 test path -----BEGIN CERTIFICATE-----
  74. testdata/gd_bundle.crt:59 test path -----BEGIN CERTIFICATE-----
  75. testdata/roots/httplib2_cacerts.txt:63 test path -----BEGIN CERTIFICATE-----
  76. testdata/roots/httplib2_cacerts.txt:86 test path -----BEGIN CERTIFICATE-----
  77. testdata/roots/httplib2_cacerts.txt:109 test path -----BEGIN CERTIFICATE-----
  78. testdata/roots/httplib2_cacerts.txt:133 test path -----BEGIN CERTIFICATE-----
  79. testdata/roots/httplib2_cacerts.txt:156 test path -----BEGIN CERTIFICATE-----
  80. testdata/roots/httplib2_cacerts.txt:179 test path -----BEGIN CERTIFICATE-----
  81. testdata/roots/httplib2_cacerts.txt:202 test path -----BEGIN CERTIFICATE-----
  82. testdata/roots/httplib2_cacerts.txt:221 test path -----BEGIN CERTIFICATE-----
  83. testdata/roots/httplib2_cacerts.txt:239 test path -----BEGIN CERTIFICATE-----
  84. testdata/roots/httplib2_cacerts.txt:257 test path -----BEGIN CERTIFICATE-----
  85. testdata/roots/httplib2_cacerts.txt:280 test path -----BEGIN CERTIFICATE-----
  86. testdata/roots/httplib2_cacerts.txt:303 test path -----BEGIN CERTIFICATE-----
  87. testdata/roots/httplib2_cacerts.txt:326 test path -----BEGIN CERTIFICATE-----
  88. testdata/roots/httplib2_cacerts.txt:461 test path -----BEGIN CERTIFICATE-----
  89. testdata/roots/httplib2_cacerts.txt:481 test path -----BEGIN CERTIFICATE-----
  90. testdata/roots/httplib2_cacerts.txt:501 test path -----BEGIN CERTIFICATE-----
  91. testdata/roots/httplib2_cacerts.txt:524 test path -----BEGIN CERTIFICATE-----
  92. testdata/roots/httplib2_cacerts.txt:606 test path -----BEGIN CERTIFICATE-----
  93. testdata/roots/httplib2_cacerts.txt:696 test path -----BEGIN CERTIFICATE-----
  94. testdata/server.crt:1 test path -----BEGIN CERTIFICATE-----
  95. testdata/temp.crt:1 test path -----BEGIN CERTIFICATE-----
  96. transport/roots/system/root_darwin_armx.go:2437 -----BEGIN CERTIFICATE-----
  97. transport/roots/system/root_darwin_armx.go:3387 -----BEGIN CERTIFICATE-----
  98. transport/roots/system/root_darwin_armx.go:3866 -----BEGIN CERTIFICATE-----
  99. transport/roots/system/root_darwin_armx.go:4320 -----BEGIN CERTIFICATE-----
  100. transport/roots/system/root_darwin_armx.go:4739 -----BEGIN CERTIFICATE-----
  101. ubiquity/testdata/godzilla.pem:1 test path -----BEGIN CERTIFICATE-----
  102. ubiquity/testdata/macrosoft.pem:1 test path -----BEGIN CERTIFICATE-----
  103. ubiquity/testdata/pineapple.pem:1 test path -----BEGIN CERTIFICATE-----
  104. ubiquity/testdata/rsa1024sha1.pem:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
RSAES-PKCS1v15 Already broken Recorded traffic 90 places See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. doc/api/endpoint_scan.txt:379 "TLS_RSA_WITH_3DES_EDE_CBC_SHA": "SHA1WithRSA",
  2. doc/api/endpoint_scan.txt:380 "TLS_RSA_WITH_AES_128_CBC_SHA": "SHA1WithRSA",
  3. doc/api/endpoint_scan.txt:381 "TLS_RSA_WITH_AES_128_CBC_SHA256": "SHA1WithRSA",
  4. doc/api/endpoint_scan.txt:382 "TLS_RSA_WITH_AES_128_GCM_SHA256": "SHA1WithRSA",
  5. doc/api/endpoint_scan.txt:383 "TLS_RSA_WITH_AES_256_CBC_SHA": "SHA1WithRSA",
  6. doc/api/endpoint_scan.txt:384 "TLS_RSA_WITH_AES_256_CBC_SHA256": "SHA1WithRSA",
  7. doc/api/endpoint_scan.txt:385 "TLS_RSA_WITH_AES_256_GCM_SHA384": "SHA1WithRSA"
  8. scan/crypto/tls/cfsslscan_common.go:129 0x0001: {Name: "TLS_RSA_WITH_NULL_MD5"},
  9. scan/crypto/tls/cfsslscan_common.go:130 0x0002: {Name: "TLS_RSA_WITH_NULL_SHA"},
  10. scan/crypto/tls/cfsslscan_common.go:131 0x0003: {Name: "TLS_RSA_EXPORT_WITH_RC4_40_MD5", ShortName: "EXP-RC4-MD5"},
  11. scan/crypto/tls/cfsslscan_common.go:132 0x0004: {Name: "TLS_RSA_WITH_RC4_128_MD5", ShortName: "RC4-MD5"},
  12. scan/crypto/tls/cfsslscan_common.go:133 0x0005: {Name: "TLS_RSA_WITH_RC4_128_SHA", ShortName: "RC4-SHA"},
  13. scan/crypto/tls/cfsslscan_common.go:134 0x0006: {Name: "TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5", ShortName: "EXP-RC2-CBC-MD5"},
  14. scan/crypto/tls/cfsslscan_common.go:135 0x0007: {Name: "TLS_RSA_WITH_IDEA_CBC_SHA", ShortName: "IDEA-CBC-SHA"},
  15. scan/crypto/tls/cfsslscan_common.go:136 0x0008: {Name: "TLS_RSA_EXPORT_WITH_DES40_CBC_SHA", ShortName: "EXP-DES-CBC-SHA"},
  16. scan/crypto/tls/cfsslscan_common.go:137 0x0009: {Name: "TLS_RSA_WITH_DES_CBC_SHA", ShortName: "DES-CBC-SHA"},
  17. scan/crypto/tls/cfsslscan_common.go:138 0x000A: {Name: "TLS_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "DES-CBC3-SHA"},
  18. scan/crypto/tls/cfsslscan_common.go:172 0x002E: {Name: "TLS_RSA_PSK_WITH_NULL_SHA"},
  19. scan/crypto/tls/cfsslscan_common.go:173 0x002F: {Name: "TLS_RSA_WITH_AES_128_CBC_SHA", ShortName: "AES128-SHA"},
  20. scan/crypto/tls/cfsslscan_common.go:179 0x0035: {Name: "TLS_RSA_WITH_AES_256_CBC_SHA", ShortName: "AES256-SHA"},
  21. scan/crypto/tls/cfsslscan_common.go:185 0x003B: {Name: "TLS_RSA_WITH_NULL_SHA256"},
  22. scan/crypto/tls/cfsslscan_common.go:186 0x003C: {Name: "TLS_RSA_WITH_AES_128_CBC_SHA256", ShortName: "AES128-SHA256"},
  23. scan/crypto/tls/cfsslscan_common.go:187 0x003D: {Name: "TLS_RSA_WITH_AES_256_CBC_SHA256", ShortName: "AES256-SHA256"},
  24. scan/crypto/tls/cfsslscan_common.go:191 0x0041: {Name: "TLS_RSA_WITH_CAMELLIA_128_CBC_SHA", ShortName: "CAMELLIA128-SHA"},
  25. scan/crypto/tls/cfsslscan_common.go:204 0x0084: {Name: "TLS_RSA_WITH_CAMELLIA_256_CBC_SHA", ShortName: "CAMELLIA256-SHA"},
  26. scan/crypto/tls/cfsslscan_common.go:218 0x0092: {Name: "TLS_RSA_PSK_WITH_RC4_128_SHA"},
  27. scan/crypto/tls/cfsslscan_common.go:219 0x0093: {Name: "TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA"},
  28. scan/crypto/tls/cfsslscan_common.go:220 0x0094: {Name: "TLS_RSA_PSK_WITH_AES_128_CBC_SHA"},
  29. scan/crypto/tls/cfsslscan_common.go:221 0x0095: {Name: "TLS_RSA_PSK_WITH_AES_256_CBC_SHA"},
  30. scan/crypto/tls/cfsslscan_common.go:222 0x0096: {Name: "TLS_RSA_WITH_SEED_CBC_SHA", ShortName: "SEED-SHA"},
  31. scan/crypto/tls/cfsslscan_common.go:228 0x009C: {Name: "TLS_RSA_WITH_AES_128_GCM_SHA256", ShortName: "AES128-GCM-SHA256"},
  32. scan/crypto/tls/cfsslscan_common.go:229 0x009D: {Name: "TLS_RSA_WITH_AES_256_GCM_SHA384", ShortName: "AES256-GCM-SHA384"},
  33. scan/crypto/tls/cfsslscan_common.go:244 0x00AC: {Name: "TLS_RSA_PSK_WITH_AES_128_GCM_SHA256"},
  34. scan/crypto/tls/cfsslscan_common.go:245 0x00AD: {Name: "TLS_RSA_PSK_WITH_AES_256_GCM_SHA384"},
  35. scan/crypto/tls/cfsslscan_common.go:254 0x00B6: {Name: "TLS_RSA_PSK_WITH_AES_128_CBC_SHA256"},
  36. scan/crypto/tls/cfsslscan_common.go:255 0x00B7: {Name: "TLS_RSA_PSK_WITH_AES_256_CBC_SHA384"},
  37. scan/crypto/tls/cfsslscan_common.go:256 0x00B8: {Name: "TLS_RSA_PSK_WITH_NULL_SHA256"},
  38. scan/crypto/tls/cfsslscan_common.go:257 0x00B9: {Name: "TLS_RSA_PSK_WITH_NULL_SHA384"},
  39. scan/crypto/tls/cfsslscan_common.go:258 0x00BA: {Name: "TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256"},
  40. scan/crypto/tls/cfsslscan_common.go:264 0x00C0: {Name: "TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256"},
  41. scan/crypto/tls/cfsslscan_common.go:330 0xC03C: {Name: "TLS_RSA_WITH_ARIA_128_CBC_SHA256"},
  42. scan/crypto/tls/cfsslscan_common.go:331 0xC03D: {Name: "TLS_RSA_WITH_ARIA_256_CBC_SHA384"},
  43. scan/crypto/tls/cfsslscan_common.go:350 0xC050: {Name: "TLS_RSA_WITH_ARIA_128_GCM_SHA256"},
  44. scan/crypto/tls/cfsslscan_common.go:351 0xC051: {Name: "TLS_RSA_WITH_ARIA_256_GCM_SHA384"},
  45. scan/crypto/tls/cfsslscan_common.go:374 0xC068: {Name: "TLS_RSA_PSK_WITH_ARIA_128_CBC_SHA256"},
  46. scan/crypto/tls/cfsslscan_common.go:375 0xC069: {Name: "TLS_RSA_PSK_WITH_ARIA_256_CBC_SHA384"},
  47. scan/crypto/tls/cfsslscan_common.go:380 0xC06E: {Name: "TLS_RSA_PSK_WITH_ARIA_128_GCM_SHA256"},
  48. scan/crypto/tls/cfsslscan_common.go:381 0xC06F: {Name: "TLS_RSA_PSK_WITH_ARIA_256_GCM_SHA384"},
  49. scan/crypto/tls/cfsslscan_common.go:392 0xC07A: {Name: "TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256"},
  50. scan/crypto/tls/cfsslscan_common.go:393 0xC07B: {Name: "TLS_RSA_WITH_CAMELLIA_256_GCM_SHA384"},
  51. scan/crypto/tls/cfsslscan_common.go:416 0xC092: {Name: "TLS_RSA_PSK_WITH_CAMELLIA_128_GCM_SHA256"},
  52. scan/crypto/tls/cfsslscan_common.go:417 0xC093: {Name: "TLS_RSA_PSK_WITH_CAMELLIA_256_GCM_SHA384"},
  53. scan/crypto/tls/cfsslscan_common.go:422 0xC098: {Name: "TLS_RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256"},
  54. scan/crypto/tls/cfsslscan_common.go:423 0xC099: {Name: "TLS_RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384"},
  55. scan/crypto/tls/cfsslscan_common.go:426 0xC09C: {Name: "TLS_RSA_WITH_AES_128_CCM"},
  56. scan/crypto/tls/cfsslscan_common.go:427 0xC09D: {Name: "TLS_RSA_WITH_AES_256_CCM"},
  57. scan/crypto/tls/cfsslscan_common.go:430 0xC0A0: {Name: "TLS_RSA_WITH_AES_128_CCM_8"},
  58. scan/crypto/tls/cfsslscan_common.go:431 0xC0A1: {Name: "TLS_RSA_WITH_AES_256_CCM_8"},
  59. scan/crypto/tls/cipher_suites.go:88 {TLS_RSA_WITH_AES_128_GCM_SHA256, 16, 0, 4, rsaKA, suiteTLS12, nil, nil, aeadAESGCM},
  60. scan/crypto/tls/cipher_suites.go:89 {TLS_RSA_WITH_AES_256_GCM_SHA384, 32, 0, 4, rsaKA, suiteTLS12 | suiteSHA384, nil, nil, aeadAESGCM},
  61. scan/crypto/tls/cipher_suites.go:90 {TLS_RSA_WITH_RC4_128_SHA, 16, 20, 0, rsaKA, suiteDefaultOff, cipherRC4, macSHA1, nil},
  62. scan/crypto/tls/cipher_suites.go:91 {TLS_RSA_WITH_AES_128_CBC_SHA, 16, 20, 16, rsaKA, 0, cipherAES, macSHA1, nil},
  63. scan/crypto/tls/cipher_suites.go:92 {TLS_RSA_WITH_AES_256_CBC_SHA, 32, 20, 16, rsaKA, 0, cipherAES, macSHA1, nil},
  64. scan/crypto/tls/cipher_suites.go:94 {TLS_RSA_WITH_3DES_EDE_CBC_SHA, 24, 20, 8, rsaKA, 0, cipher3DES, macSHA1, nil},
  65. scan/crypto/tls/cipher_suites.go:267 TLS_RSA_WITH_RC4_128_SHA uint16 = 0x0005
  66. scan/crypto/tls/cipher_suites.go:268 TLS_RSA_WITH_3DES_EDE_CBC_SHA uint16 = 0x000a
  67. scan/crypto/tls/cipher_suites.go:269 TLS_RSA_WITH_AES_128_CBC_SHA uint16 = 0x002f
  68. scan/crypto/tls/cipher_suites.go:270 TLS_RSA_WITH_AES_256_CBC_SHA uint16 = 0x0035
  69. scan/crypto/tls/cipher_suites.go:271 TLS_RSA_WITH_AES_128_GCM_SHA256 uint16 = 0x009c
  70. scan/crypto/tls/cipher_suites.go:272 TLS_RSA_WITH_AES_256_GCM_SHA384 uint16 = 0x009d
  71. scan/crypto/tls/handshake_client_test.go:423 test path CipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA, TLS_ECDHE_RSA_WITH_RC4_128_SHA},
  72. scan/crypto/tls/handshake_client_test.go:436 test path CipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  73. scan/crypto/tls/handshake_client_test.go:658 test path CipherSuites: []uint16{TLS_RSA_WITH_AES_128_GCM_SHA256},
  74. scan/crypto/tls/handshake_client_test.go:679 test path cipherSuite: TLS_RSA_WITH_AES_256_GCM_SHA384,
  75. scan/crypto/tls/handshake_server_test.go:118 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  76. scan/crypto/tls/handshake_server_test.go:127 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  77. scan/crypto/tls/handshake_server_test.go:192 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  78. scan/crypto/tls/handshake_server_test.go:248 test path TLS_RSA_WITH_RC4_128_SHA,
  79. scan/crypto/tls/handshake_server_test.go:276 test path if s := serverHello.cipherSuite; s != TLS_RSA_WITH_RC4_128_SHA {
  80. scan/crypto/tls/handshake_server_test.go:345 test path CipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA, TLS_RSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_RC4_128_SHA},
  81. scan/crypto/tls/handshake_server_test.go:350 test path CipherSuites: []uint16{TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_RC4_128_SHA},
  82. scan/crypto/tls/handshake_server_test.go:357 test path if state.CipherSuite != TLS_RSA_WITH_AES_128_CBC_SHA {
  83. scan/crypto/tls/handshake_server_test.go:367 test path if state.CipherSuite != TLS_RSA_WITH_RC4_128_SHA {
  84. scan/crypto/tls/handshake_server_test.go:792 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  85. scan/crypto/tls/handshake_server_test.go:812 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  86. scan/crypto/tls/handshake_server_test.go:823 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  87. scan/crypto/tls/prf_test.go:86 test path cipherSuiteById(TLS_RSA_WITH_RC4_128_SHA),
  88. scan/crypto/tls/prf_test.go:100 test path cipherSuiteById(TLS_RSA_WITH_RC4_128_SHA),
  89. scan/crypto/tls/prf_test.go:114 test path cipherSuiteById(TLS_RSA_WITH_RC4_128_SHA),
  90. scan/crypto/tls/prf_test.go:128 test path cipherSuiteById(TLS_RSA_WITH_RC4_128_SHA),
config.cipher-suite · CWE-757
RC4 Already broken 35 places See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. scan/crypto/tls/cfsslscan_common.go:131 0x0003: {Name: "TLS_RSA_EXPORT_WITH_RC4_40_MD5", ShortName: "EXP-RC4-MD5"},
  2. scan/crypto/tls/cfsslscan_common.go:132 0x0004: {Name: "TLS_RSA_WITH_RC4_128_MD5", ShortName: "RC4-MD5"},
  3. scan/crypto/tls/cfsslscan_common.go:133 0x0005: {Name: "TLS_RSA_WITH_RC4_128_SHA", ShortName: "RC4-SHA"},
  4. scan/crypto/tls/cfsslscan_common.go:214 0x008E: {Name: "TLS_DHE_PSK_WITH_RC4_128_SHA", ForwardSecret: true},
  5. scan/crypto/tls/cfsslscan_common.go:218 0x0092: {Name: "TLS_RSA_PSK_WITH_RC4_128_SHA"},
  6. scan/crypto/tls/cfsslscan_common.go:272 0xC002: {Name: "TLS_ECDH_ECDSA_WITH_RC4_128_SHA", ShortName: "ECDH-ECDSA-RC4-SHA", EllipticCurve: true},
  7. scan/crypto/tls/cfsslscan_common.go:277 0xC007: {Name: "TLS_ECDHE_ECDSA_WITH_RC4_128_SHA", ShortName: "ECDHE-ECDSA-RC4-SHA", ForwardSecret: true, EllipticCurve: true},
  8. scan/crypto/tls/cfsslscan_common.go:282 0xC00C: {Name: "TLS_ECDH_RSA_WITH_RC4_128_SHA", ShortName: "ECDH-RSA-RC4-SHA", EllipticCurve: true},
  9. scan/crypto/tls/cfsslscan_common.go:287 0xC011: {Name: "TLS_ECDHE_RSA_WITH_RC4_128_SHA", ShortName: "ECDHE-RSA-RC4-SHA", ForwardSecret: true, EllipticCurve: true},
  10. scan/crypto/tls/cfsslscan_common.go:321 0xC033: {Name: "TLS_ECDHE_PSK_WITH_RC4_128_SHA", ForwardSecret: true, EllipticCurve: true},
  11. scan/crypto/tls/cipher_suites.go:82 {TLS_ECDHE_RSA_WITH_RC4_128_SHA, 16, 20, 0, ecdheRSAKA, suiteECDHE | suiteDefaultOff, cipherRC4, macSHA1, nil},
  12. scan/crypto/tls/cipher_suites.go:83 {TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, 16, 20, 0, ecdheECDSAKA, suiteECDHE | suiteECDSA | suiteDefaultOff, cipherRC4, macSHA1, nil},
  13. scan/crypto/tls/cipher_suites.go:90 {TLS_RSA_WITH_RC4_128_SHA, 16, 20, 0, rsaKA, suiteDefaultOff, cipherRC4, macSHA1, nil},
  14. scan/crypto/tls/cipher_suites.go:267 TLS_RSA_WITH_RC4_128_SHA uint16 = 0x0005
  15. scan/crypto/tls/cipher_suites.go:273 TLS_ECDHE_ECDSA_WITH_RC4_128_SHA uint16 = 0xc007
  16. scan/crypto/tls/cipher_suites.go:276 TLS_ECDHE_RSA_WITH_RC4_128_SHA uint16 = 0xc011
  17. scan/crypto/tls/handshake_client_test.go:423 test path CipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA, TLS_ECDHE_RSA_WITH_RC4_128_SHA},
  18. scan/crypto/tls/handshake_client_test.go:436 test path CipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  19. scan/crypto/tls/handshake_client_test.go:487 test path clientConfig.CipherSuites = []uint16{TLS_ECDHE_RSA_WITH_RC4_128_SHA}
  20. scan/crypto/tls/handshake_server_test.go:118 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  21. scan/crypto/tls/handshake_server_test.go:127 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  22. scan/crypto/tls/handshake_server_test.go:192 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  23. scan/crypto/tls/handshake_server_test.go:248 test path TLS_RSA_WITH_RC4_128_SHA,
  24. scan/crypto/tls/handshake_server_test.go:276 test path if s := serverHello.cipherSuite; s != TLS_RSA_WITH_RC4_128_SHA {
  25. scan/crypto/tls/handshake_server_test.go:345 test path CipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA, TLS_RSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_RC4_128_SHA},
  26. scan/crypto/tls/handshake_server_test.go:367 test path if state.CipherSuite != TLS_RSA_WITH_RC4_128_SHA {
  27. scan/crypto/tls/handshake_server_test.go:792 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  28. scan/crypto/tls/handshake_server_test.go:812 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  29. scan/crypto/tls/handshake_server_test.go:823 test path cipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  30. scan/crypto/tls/prf_test.go:86 test path cipherSuiteById(TLS_RSA_WITH_RC4_128_SHA),
  31. scan/crypto/tls/prf_test.go:100 test path cipherSuiteById(TLS_RSA_WITH_RC4_128_SHA),
  32. scan/crypto/tls/prf_test.go:114 test path cipherSuiteById(TLS_RSA_WITH_RC4_128_SHA),
  33. scan/crypto/tls/prf_test.go:128 test path cipherSuiteById(TLS_RSA_WITH_RC4_128_SHA),
  34. scan/tls_handshake.go:131 0xC007: {Name: "TLS_ECDHE_ECDSA_WITH_RC4_128_SHA", ShortName: "ECDHE-ECDSA-RC4-SHA", ForwardSecret: true, EllipticCurve: true},
  35. scan/tls_handshake.go:136 0xC011: {Name: "TLS_ECDHE_RSA_WITH_RC4_128_SHA", ShortName: "ECDHE-RSA-RC4-SHA", ForwardSecret: true, EllipticCurve: true},
config.cipher-suite · CWE-757
3DES Already broken 22 places See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. doc/api/endpoint_scan.txt:208 "ECDHE-RSA-DES-CBC3-SHA": [
  2. doc/api/endpoint_scan.txt:371 "TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA": "SHA1WithRSA",
  3. doc/api/endpoint_scan.txt:379 "TLS_RSA_WITH_3DES_EDE_CBC_SHA": "SHA1WithRSA",
  4. doc/api/endpoint_scan.txt:520 "ECDHE-RSA-DES-CBC3-SHA": [
  5. scan/crypto/tls/cfsslscan_common.go:138 0x000A: {Name: "TLS_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "DES-CBC3-SHA"},
  6. scan/crypto/tls/cfsslscan_common.go:141 0x000D: {Name: "TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA", ShortName: "DH-DSS-DES-CBC3-SHA"},
  7. scan/crypto/tls/cfsslscan_common.go:144 0x0010: {Name: "TLS_DH_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "DH-RSA-DES-CBC3-SHA"},
  8. scan/crypto/tls/cfsslscan_common.go:147 0x0013: {Name: "TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA", ShortName: "EDH-DSS-DES-CBC3-SHA", ForwardSecret: true},
  9. scan/crypto/tls/cfsslscan_common.go:150 0x0016: {Name: "TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "EDH-RSA-DES-CBC3-SHA", ForwardSecret: true},
  10. scan/crypto/tls/cfsslscan_common.go:215 0x008F: {Name: "TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA", ForwardSecret: true},
  11. scan/crypto/tls/cfsslscan_common.go:219 0x0093: {Name: "TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA"},
  12. scan/crypto/tls/cfsslscan_common.go:273 0xC003: {Name: "TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDH-ECDSA-DES-CBC3-SHA", EllipticCurve: true},
  13. scan/crypto/tls/cfsslscan_common.go:278 0xC008: {Name: "TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDHE-ECDSA-DES-CBC3-SHA", ForwardSecret: true, EllipticCurve: true},
  14. scan/crypto/tls/cfsslscan_common.go:283 0xC00D: {Name: "TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDH-RSA-DES-CBC3-SHA", EllipticCurve: true},
  15. scan/crypto/tls/cfsslscan_common.go:288 0xC012: {Name: "TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDHE-RSA-DES-CBC3-SHA", ForwardSecret: true, EllipticCurve: true},
  16. scan/crypto/tls/cfsslscan_common.go:322 0xC034: {Name: "TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA", ForwardSecret: true, EllipticCurve: true},
  17. scan/crypto/tls/cipher_suites.go:93 {TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, 24, 20, 8, ecdheRSAKA, suiteECDHE, cipher3DES, macSHA1, nil},
  18. scan/crypto/tls/cipher_suites.go:94 {TLS_RSA_WITH_3DES_EDE_CBC_SHA, 24, 20, 8, rsaKA, 0, cipher3DES, macSHA1, nil},
  19. scan/crypto/tls/cipher_suites.go:268 TLS_RSA_WITH_3DES_EDE_CBC_SHA uint16 = 0x000a
  20. scan/crypto/tls/cipher_suites.go:277 TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA uint16 = 0xc012
  21. scan/tls_handshake.go:132 0xC008: {Name: "TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDHE-ECDSA-DES-CBC3-SHA", ForwardSecret: true, EllipticCurve: true},
  22. scan/tls_handshake.go:137 0xC012: {Name: "TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDHE-RSA-DES-CBC3-SHA", ForwardSecret: true, EllipticCurve: true},
config.cipher-suite · CWE-757
SHA-1 Already broken 20 places See details

Broken hash function

An import of `crypto/md5` or `crypto/sha1`, or a call to `New()` on either.

This is already unsafe today, with no quantum computer involved. SHAttered and subsequent work produced practical collisions; NIST withdrew SHA-1 in 2030 guidance and it is already unacceptable for signatures.

What to do. `crypto/sha256`, or `crypto/sha512` for long-lived signatures.

  1. api/generator/generator.go:101 sha1Sum := sha1.Sum(data)
  2. scan/crypto/rsa/pkcs1v15_test.go:197 test path h := sha1.New()
  3. scan/crypto/rsa/pkcs1v15_test.go:215 test path h := sha1.New()
  4. scan/crypto/rsa/pss_test.go:60 test path hash := sha1.New()
  5. scan/crypto/rsa/pss_test.go:64 test path encoded, err := emsaPSSEncode(hashed, 1023, salt, sha1.New())
  6. scan/crypto/rsa/pss_test.go:72 test path if err = emsaPSSVerify(hashed, encoded, 1023, len(salt), sha1.New()); err != nil {
  7. scan/crypto/rsa/rsa_test.go:210 test path sha1 := sha1.New()
  8. scan/crypto/rsa/rsa_test.go:232 test path sha1 := sha1.New()
  9. scan/crypto/sha1/example_test.go:14 test path h := sha1.New()
  10. scan/crypto/sha1/example_test.go:23 test path fmt.Printf("% x", sha1.Sum(data))
  11. scan/crypto/tls/cipher_suites.go:122 h: sha1.New(),
  12. scan/crypto/tls/key_agreement.go:90 hsha1 := sha1.New()
  13. scan/crypto/tls/prf.go:83 hashSHA1 := sha1.New()
  14. scan/crypto/tls/prf.go:208 return finishedHash{sha1.New(), sha1.New(), md5.New(), md5.New(), buffer, version, prf}
  15. scan/crypto/tls/prf.go:272 sha1Digest := sha1.Sum(nil)
  16. scan/crypto/tls/prf.go:278 sha1Digest = sha1.Sum(nil)
  17. scan/crypto/tls/prf.go:343 sha1Hash := sha1.New()
  18. selfsign/selfsign.go:87 pubhash := sha1.New()
  19. signer/signer.go:331 pubHash := sha1.Sum(subPKI.SubjectPublicKey.Bytes)
  20. ubiquity/ubiquity_platform.go:22 return fmt.Sprintf("%x", sha1.Sum(cert.RawSubjectPublicKeyInfo))
go.hash.weak · CWE-328
NULL Already broken 18 places See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. scan/crypto/tls/cfsslscan_common.go:129 0x0001: {Name: "TLS_RSA_WITH_NULL_MD5"},
  2. scan/crypto/tls/cfsslscan_common.go:130 0x0002: {Name: "TLS_RSA_WITH_NULL_SHA"},
  3. scan/crypto/tls/cfsslscan_common.go:171 0x002D: {Name: "TLS_DHE_PSK_WITH_NULL_SHA", ForwardSecret: true},
  4. scan/crypto/tls/cfsslscan_common.go:172 0x002E: {Name: "TLS_RSA_PSK_WITH_NULL_SHA"},
  5. scan/crypto/tls/cfsslscan_common.go:185 0x003B: {Name: "TLS_RSA_WITH_NULL_SHA256"},
  6. scan/crypto/tls/cfsslscan_common.go:252 0x00B4: {Name: "TLS_DHE_PSK_WITH_NULL_SHA256", ForwardSecret: true},
  7. scan/crypto/tls/cfsslscan_common.go:253 0x00B5: {Name: "TLS_DHE_PSK_WITH_NULL_SHA384", ForwardSecret: true},
  8. scan/crypto/tls/cfsslscan_common.go:256 0x00B8: {Name: "TLS_RSA_PSK_WITH_NULL_SHA256"},
  9. scan/crypto/tls/cfsslscan_common.go:257 0x00B9: {Name: "TLS_RSA_PSK_WITH_NULL_SHA384"},
  10. scan/crypto/tls/cfsslscan_common.go:271 0xC001: {Name: "TLS_ECDH_ECDSA_WITH_NULL_SHA", EllipticCurve: true},
  11. scan/crypto/tls/cfsslscan_common.go:276 0xC006: {Name: "TLS_ECDHE_ECDSA_WITH_NULL_SHA", ForwardSecret: true, EllipticCurve: true},
  12. scan/crypto/tls/cfsslscan_common.go:281 0xC00B: {Name: "TLS_ECDH_RSA_WITH_NULL_SHA", EllipticCurve: true},
  13. scan/crypto/tls/cfsslscan_common.go:286 0xC010: {Name: "TLS_ECDHE_RSA_WITH_NULL_SHA", ForwardSecret: true, EllipticCurve: true},
  14. scan/crypto/tls/cfsslscan_common.go:327 0xC039: {Name: "TLS_ECDHE_PSK_WITH_NULL_SHA", ForwardSecret: true, EllipticCurve: true},
  15. scan/crypto/tls/cfsslscan_common.go:328 0xC03A: {Name: "TLS_ECDHE_PSK_WITH_NULL_SHA256", ForwardSecret: true, EllipticCurve: true},
  16. scan/crypto/tls/cfsslscan_common.go:329 0xC03B: {Name: "TLS_ECDHE_PSK_WITH_NULL_SHA384", ForwardSecret: true, EllipticCurve: true},
  17. scan/tls_handshake.go:130 0xC006: {Name: "TLS_ECDHE_ECDSA_WITH_NULL_SHA", ForwardSecret: true, EllipticCurve: true},
  18. scan/tls_handshake.go:135 0xC010: {Name: "TLS_ECDHE_RSA_WITH_NULL_SHA", ForwardSecret: true, EllipticCurve: true},
config.cipher-suite · CWE-757
MD5 Already broken 9 places See details

Broken hash function

An import of `crypto/md5` or `crypto/sha1`, or a call to `New()` on either.

This is already unsafe today, with no quantum computer involved. Practical chosen-prefix collisions exist; MD5 has no remaining security as a digest.

What to do. `crypto/sha256`, or `crypto/sha512` for long-lived signatures.

  1. api/generator/generator.go:100 md5Sum := md5.Sum(data)
  2. scan/crypto/md5/example_test.go:14 test path h := md5.New()
  3. scan/crypto/md5/example_test.go:23 test path fmt.Printf("%x", md5.Sum(data))
  4. scan/crypto/tls/key_agreement.go:101 hmd5 := md5.New()
  5. scan/crypto/tls/prf.go:84 hashMD5 := md5.New()
  6. scan/crypto/tls/prf.go:208 return finishedHash{sha1.New(), sha1.New(), md5.New(), md5.New(), buffer, version, prf}
  7. scan/crypto/tls/prf.go:261 md5Digest := md5.Sum(nil)
  8. scan/crypto/tls/prf.go:267 md5Digest = md5.Sum(nil)
  9. scan/crypto/tls/prf.go:341 md5Hash := md5.New()
go.hash.weak · CWE-328
DES Already broken 6 places See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. scan/crypto/tls/cfsslscan_common.go:136 0x0008: {Name: "TLS_RSA_EXPORT_WITH_DES40_CBC_SHA", ShortName: "EXP-DES-CBC-SHA"},
  2. scan/crypto/tls/cfsslscan_common.go:137 0x0009: {Name: "TLS_RSA_WITH_DES_CBC_SHA", ShortName: "DES-CBC-SHA"},
  3. scan/crypto/tls/cfsslscan_common.go:140 0x000C: {Name: "TLS_DH_DSS_WITH_DES_CBC_SHA", ShortName: "DH-DSS-DES-CBC-SHA"},
  4. scan/crypto/tls/cfsslscan_common.go:143 0x000F: {Name: "TLS_DH_RSA_WITH_DES_CBC_SHA", ShortName: "DH-RSA-DES-CBC-SHA"},
  5. scan/crypto/tls/cfsslscan_common.go:146 0x0012: {Name: "TLS_DHE_DSS_WITH_DES_CBC_SHA", ShortName: "EDH-DSS-DES-CBC-SHA", ForwardSecret: true},
  6. scan/crypto/tls/cfsslscan_common.go:149 0x0015: {Name: "TLS_DHE_RSA_WITH_DES_CBC_SHA", ShortName: "EDH-RSA-DES-CBC-SHA", ForwardSecret: true},
config.cipher-suite · CWE-757
RSA-10241024-bit Already broken 3 places See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

  1. signer/local/testdata/ex.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  2. signer/local/testdata/ip.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  3. testdata/server.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
pem.certificate-request
RSA-10241024-bit Already broken Recorded traffic 2 places See details

RSA in the Go standard library

`rsa.GenerateKey()`, `rsa.SignPKCS1v15()`, `rsa.EncryptOAEP()` or an import of `crypto/rsa`.

This is already unsafe today, with no quantum computer involved. A modulus of 1024 bits or less is below the NIST SP 800-57 floor and is within reach of classical factorisation. Shor is not the nearest problem here.

What to do. ML-KEM-768 for encryption, ML-DSA-65 for signatures. Go 1.24 ships ML-KEM as `crypto/mlkem`.

  1. certdb/ocspstapling/ocspstapling_test.go:134 test path privKey, err := rsa.GenerateKey(rand.Reader, 1024)
  2. signer/local/local_test.go:1392 test path k, err := rsa.GenerateKey(rand.Reader, 1024)
go.rsa · CWE-327
RSA-1024512-bit Already broken 2 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. crl/testdata/ca.pem:1 test path -----BEGIN CERTIFICATE-----
  2. scan/crypto/tls/tls_test.go:18 test path -----BEGIN CERTIFICATE-----
pem.certificate
DES Already broken 1 place See details

Withdrawn symmetric cipher

An import of `crypto/des` or `crypto/rc4`. Both fail classically.

This is already unsafe today, with no quantum computer involved. A 56-bit key is brute-forced classically in hours.

What to do. `crypto/aes` with GCM, or ChaCha20-Poly1305.

  1. scan/crypto/tls/cipher_suites.go:103 block, _ := des.NewTripleDESCipher(key)
go.cipher.legacy · CWE-327
RC4 Already broken 1 place See details

Withdrawn symmetric cipher

An import of `crypto/des` or `crypto/rc4`. Both fail classically.

This is already unsafe today, with no quantum computer involved. RC4 keystream biases break it classically; it is prohibited in TLS by RFC 7465.

What to do. `crypto/aes` with GCM, or ChaCha20-Poly1305.

  1. scan/crypto/tls/cipher_suites.go:98 cipher, _ := rc4.NewCipher(key)
go.cipher.legacy · CWE-327
RSA-10241000-bit Already broken 1 place See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. testdata/roots/httplib2_cacerts.txt:45 test path -----BEGIN CERTIFICATE-----
pem.certificate
RSA2048-bit Quantum-vulnerable 455 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. api/generator/testdata/ca.pem:1 test path -----BEGIN CERTIFICATE-----
  2. api/testdata/ca-bundle.pem:1 test path -----BEGIN CERTIFICATE-----
  3. api/testdata/ca.pem:1 test path -----BEGIN CERTIFICATE-----
  4. api/testdata/cert.pem:1 test path -----BEGIN CERTIFICATE-----
  5. api/testdata/int-bundle.pem:1 test path -----BEGIN CERTIFICATE-----
  6. api/testdata/leaf.pem:1 test path -----BEGIN CERTIFICATE-----
  7. bundler/bundle_from_pem_test.go:101 test path -----BEGIN CERTIFICATE-----
  8. bundler/bundle_from_pem_test.go:178 test path -----BEGIN CERTIFICATE-----
  9. bundler/testdata/ca-bundle.pem:1 test path -----BEGIN CERTIFICATE-----
  10. bundler/testdata/ca.pem:1 test path -----BEGIN CERTIFICATE-----
  11. bundler/testdata/cfssl-leaf-rsa2048.pem:1 test path -----BEGIN CERTIFICATE-----
  12. bundler/testdata/client-auth/int.pem:1 test path -----BEGIN CERTIFICATE-----
  13. bundler/testdata/client-auth/leaf-client.pem:1 test path -----BEGIN CERTIFICATE-----
  14. bundler/testdata/client-auth/leaf-server.pem:1 test path -----BEGIN CERTIFICATE-----
  15. bundler/testdata/client-auth/root.pem:1 test path -----BEGIN CERTIFICATE-----
  16. bundler/testdata/forcebundle.pem:1 test path -----BEGIN CERTIFICATE-----
  17. bundler/testdata/forcebundle.pem:30 test path -----BEGIN CERTIFICATE-----
  18. bundler/testdata/froyo.pem:44 test path -----BEGIN CERTIFICATE-----
  19. bundler/testdata/froyo.pem:77 test path -----BEGIN CERTIFICATE-----
  20. bundler/testdata/froyo.pem:93 test path -----BEGIN CERTIFICATE-----
  21. bundler/testdata/froyo.pem:138 test path -----BEGIN CERTIFICATE-----
  22. bundler/testdata/froyo.pem:161 test path -----BEGIN CERTIFICATE-----
  23. bundler/testdata/froyo.pem:190 test path -----BEGIN CERTIFICATE-----
  24. bundler/testdata/froyo.pem:273 test path -----BEGIN CERTIFICATE-----
  25. bundler/testdata/froyo.pem:353 test path -----BEGIN CERTIFICATE-----
  26. bundler/testdata/froyo.pem:392 test path -----BEGIN CERTIFICATE-----
  27. bundler/testdata/froyo.pem:413 test path -----BEGIN CERTIFICATE-----
  28. bundler/testdata/froyo.pem:460 test path -----BEGIN CERTIFICATE-----
  29. bundler/testdata/froyo.pem:527 test path -----BEGIN CERTIFICATE-----
  30. bundler/testdata/froyo.pem:562 test path -----BEGIN CERTIFICATE-----
  31. bundler/testdata/froyo.pem:596 test path -----BEGIN CERTIFICATE-----
  32. bundler/testdata/froyo.pem:618 test path -----BEGIN CERTIFICATE-----
  33. bundler/testdata/froyo.pem:637 test path -----BEGIN CERTIFICATE-----
  34. bundler/testdata/froyo.pem:659 test path -----BEGIN CERTIFICATE-----
  35. bundler/testdata/froyo.pem:676 test path -----BEGIN CERTIFICATE-----
  36. bundler/testdata/froyo.pem:697 test path -----BEGIN CERTIFICATE-----
  37. bundler/testdata/froyo.pem:719 test path -----BEGIN CERTIFICATE-----
  38. bundler/testdata/froyo.pem:740 test path -----BEGIN CERTIFICATE-----
  39. bundler/testdata/froyo.pem:759 test path -----BEGIN CERTIFICATE-----
  40. bundler/testdata/froyo.pem:778 test path -----BEGIN CERTIFICATE-----
  41. bundler/testdata/froyo.pem:814 test path -----BEGIN CERTIFICATE-----
  42. bundler/testdata/froyo.pem:873 test path -----BEGIN CERTIFICATE-----
  43. bundler/testdata/froyo.pem:896 test path -----BEGIN CERTIFICATE-----
  44. bundler/testdata/froyo.pem:920 test path -----BEGIN CERTIFICATE-----
  45. bundler/testdata/froyo.pem:955 test path -----BEGIN CERTIFICATE-----
  46. bundler/testdata/froyo.pem:985 test path -----BEGIN CERTIFICATE-----
  47. bundler/testdata/froyo.pem:1003 test path -----BEGIN CERTIFICATE-----
  48. bundler/testdata/froyo.pem:1035 test path -----BEGIN CERTIFICATE-----
  49. bundler/testdata/froyo.pem:1063 test path -----BEGIN CERTIFICATE-----
  50. bundler/testdata/froyo.pem:1080 test path -----BEGIN CERTIFICATE-----
  51. bundler/testdata/froyo.pem:1130 test path -----BEGIN CERTIFICATE-----
  52. bundler/testdata/int-bundle.pem:1 test path -----BEGIN CERTIFICATE-----
  53. bundler/testdata/nss.pem:219 test path -----BEGIN CERTIFICATE-----
  54. bundler/testdata/nss.pem:248 test path -----BEGIN CERTIFICATE-----
  55. bundler/testdata/nss.pem:356 test path -----BEGIN CERTIFICATE-----
  56. bundler/testdata/nss.pem:388 test path -----BEGIN CERTIFICATE-----
  57. bundler/testdata/nss.pem:456 test path -----BEGIN CERTIFICATE-----
  58. bundler/testdata/nss.pem:490 test path -----BEGIN CERTIFICATE-----
  59. bundler/testdata/nss.pem:594 test path -----BEGIN CERTIFICATE-----
  60. bundler/testdata/nss.pem:626 test path -----BEGIN CERTIFICATE-----
  61. bundler/testdata/nss.pem:659 test path -----BEGIN CERTIFICATE-----
  62. bundler/testdata/nss.pem:691 test path -----BEGIN CERTIFICATE-----
  63. bundler/testdata/nss.pem:724 test path -----BEGIN CERTIFICATE-----
  64. bundler/testdata/nss.pem:759 test path -----BEGIN CERTIFICATE-----
  65. bundler/testdata/nss.pem:788 test path -----BEGIN CERTIFICATE-----
  66. bundler/testdata/nss.pem:816 test path -----BEGIN CERTIFICATE-----
  67. bundler/testdata/nss.pem:923 test path -----BEGIN CERTIFICATE-----
  68. bundler/testdata/nss.pem:994 test path -----BEGIN CERTIFICATE-----
  69. bundler/testdata/nss.pem:1024 test path -----BEGIN CERTIFICATE-----
  70. bundler/testdata/nss.pem:1051 test path -----BEGIN CERTIFICATE-----
  71. bundler/testdata/nss.pem:1084 test path -----BEGIN CERTIFICATE-----
  72. bundler/testdata/nss.pem:1117 test path -----BEGIN CERTIFICATE-----
  73. bundler/testdata/nss.pem:1150 test path -----BEGIN CERTIFICATE-----
  74. bundler/testdata/nss.pem:1279 test path -----BEGIN CERTIFICATE-----
  75. bundler/testdata/nss.pem:1307 test path -----BEGIN CERTIFICATE-----
  76. bundler/testdata/nss.pem:1334 test path -----BEGIN CERTIFICATE-----
  77. bundler/testdata/nss.pem:1364 test path -----BEGIN CERTIFICATE-----
  78. bundler/testdata/nss.pem:1397 test path -----BEGIN CERTIFICATE-----
  79. bundler/testdata/nss.pem:1431 test path -----BEGIN CERTIFICATE-----
  80. bundler/testdata/nss.pem:1465 test path -----BEGIN CERTIFICATE-----
  81. bundler/testdata/nss.pem:1501 test path -----BEGIN CERTIFICATE-----
  82. bundler/testdata/nss.pem:1537 test path -----BEGIN CERTIFICATE-----
  83. bundler/testdata/nss.pem:1660 test path -----BEGIN CERTIFICATE-----
  84. bundler/testdata/nss.pem:1693 test path -----BEGIN CERTIFICATE-----
  85. bundler/testdata/nss.pem:1725 test path -----BEGIN CERTIFICATE-----
  86. bundler/testdata/nss.pem:1849 test path -----BEGIN CERTIFICATE-----
  87. bundler/testdata/nss.pem:1883 test path -----BEGIN CERTIFICATE-----
  88. bundler/testdata/nss.pem:1956 test path -----BEGIN CERTIFICATE-----
  89. bundler/testdata/nss.pem:1986 test path -----BEGIN CERTIFICATE-----
  90. bundler/testdata/nss.pem:2016 test path -----BEGIN CERTIFICATE-----
  91. bundler/testdata/nss.pem:2047 test path -----BEGIN CERTIFICATE-----
  92. bundler/testdata/nss.pem:2077 test path -----BEGIN CERTIFICATE-----
  93. bundler/testdata/nss.pem:2105 test path -----BEGIN CERTIFICATE-----
  94. bundler/testdata/nss.pem:2137 test path -----BEGIN CERTIFICATE-----
  95. bundler/testdata/nss.pem:2169 test path -----BEGIN CERTIFICATE-----
  96. bundler/testdata/nss.pem:2284 test path -----BEGIN CERTIFICATE-----
  97. bundler/testdata/nss.pem:2313 test path -----BEGIN CERTIFICATE-----
  98. bundler/testdata/nss.pem:2346 test path -----BEGIN CERTIFICATE-----
  99. bundler/testdata/nss.pem:2382 test path -----BEGIN CERTIFICATE-----
  100. bundler/testdata/nss.pem:2412 test path -----BEGIN CERTIFICATE-----
  101. bundler/testdata/nss.pem:2442 test path -----BEGIN CERTIFICATE-----
  102. bundler/testdata/nss.pem:2475 test path -----BEGIN CERTIFICATE-----
  103. bundler/testdata/nss.pem:2506 test path -----BEGIN CERTIFICATE-----
  104. bundler/testdata/nss.pem:2566 test path -----BEGIN CERTIFICATE-----
  105. bundler/testdata/nss.pem:2598 test path -----BEGIN CERTIFICATE-----
  106. bundler/testdata/nss.pem:2627 test path -----BEGIN CERTIFICATE-----
  107. bundler/testdata/nss.pem:2659 test path -----BEGIN CERTIFICATE-----
  108. bundler/testdata/nss.pem:2710 test path -----BEGIN CERTIFICATE-----
  109. bundler/testdata/nss.pem:2785 test path -----BEGIN CERTIFICATE-----
  110. bundler/testdata/nss.pem:2820 test path -----BEGIN CERTIFICATE-----
  111. bundler/testdata/nss.pem:2855 test path -----BEGIN CERTIFICATE-----
  112. bundler/testdata/nss.pem:2886 test path -----BEGIN CERTIFICATE-----
  113. bundler/testdata/nss.pem:2916 test path -----BEGIN CERTIFICATE-----
  114. bundler/testdata/nss.pem:2946 test path -----BEGIN CERTIFICATE-----
  115. bundler/testdata/nss.pem:3017 test path -----BEGIN CERTIFICATE-----
  116. bundler/testdata/nss.pem:3055 test path -----BEGIN CERTIFICATE-----
  117. bundler/testdata/nss.pem:3083 test path -----BEGIN CERTIFICATE-----
  118. bundler/testdata/nss.pem:3153 test path -----BEGIN CERTIFICATE-----
  119. bundler/testdata/nss.pem:3181 test path -----BEGIN CERTIFICATE-----
  120. bundler/testdata/nss.pem:3209 test path -----BEGIN CERTIFICATE-----
  121. bundler/testdata/nss.pem:3239 test path -----BEGIN CERTIFICATE-----
  122. bundler/testdata/nss.pem:3295 test path -----BEGIN CERTIFICATE-----
  123. bundler/testdata/nss.pem:3353 test path -----BEGIN CERTIFICATE-----
  124. bundler/testdata/nss.pem:3418 test path -----BEGIN CERTIFICATE-----
  125. bundler/testdata/nss.pem:3491 test path -----BEGIN CERTIFICATE-----
  126. bundler/testdata/nss.pem:3523 test path -----BEGIN CERTIFICATE-----
  127. bundler/testdata/nss.pem:3560 test path -----BEGIN CERTIFICATE-----
  128. bundler/testdata/nss.pem:3588 test path -----BEGIN CERTIFICATE-----
  129. bundler/testdata/nss.pem:3680 test path -----BEGIN CERTIFICATE-----
  130. bundler/testdata/nss.pem:3712 test path -----BEGIN CERTIFICATE-----
  131. bundler/testdata/nss.pem:3742 test path -----BEGIN CERTIFICATE-----
  132. bundler/testdata/nss.pem:3771 test path -----BEGIN CERTIFICATE-----
  133. bundler/testdata/nss.pem:3986 test path -----BEGIN CERTIFICATE-----
  134. bundler/testdata/nss.pem:4017 test path -----BEGIN CERTIFICATE-----
  135. bundler/testdata/nss.pem:4048 test path -----BEGIN CERTIFICATE-----
  136. bundler/testdata/nss.pem:4080 test path -----BEGIN CERTIFICATE-----
  137. bundler/testdata/nss.pem:4108 test path -----BEGIN CERTIFICATE-----
  138. bundler/testdata/nss.pem:4196 test path -----BEGIN CERTIFICATE-----
  139. bundler/testdata/nss.pem:4266 test path -----BEGIN CERTIFICATE-----
  140. bundler/testdata/nss.pem:4311 test path -----BEGIN CERTIFICATE-----
  141. bundler/testdata/nss.pem:4342 test path -----BEGIN CERTIFICATE-----
  142. bundler/testdata/nss.pem:4371 test path -----BEGIN CERTIFICATE-----
  143. bundler/testdata/nss.pem:4400 test path -----BEGIN CERTIFICATE-----
  144. bundler/testdata/nss.pem:4474 test path -----BEGIN CERTIFICATE-----
  145. bundler/testdata/nss.pem:4671 test path -----BEGIN CERTIFICATE-----
  146. bundler/testdata/nss.pem:4702 test path -----BEGIN CERTIFICATE-----
  147. bundler/testdata/osx.pem:1 test path -----BEGIN CERTIFICATE-----
  148. bundler/testdata/osx.pem:22 test path -----BEGIN CERTIFICATE-----
  149. bundler/testdata/osx.pem:45 test path -----BEGIN CERTIFICATE-----
  150. bundler/testdata/osx.pem:71 test path -----BEGIN CERTIFICATE-----
  151. bundler/testdata/osx.pem:94 test path -----BEGIN CERTIFICATE-----
  152. bundler/testdata/osx.pem:189 test path -----BEGIN CERTIFICATE-----
  153. bundler/testdata/osx.pem:213 test path -----BEGIN CERTIFICATE-----
  154. bundler/testdata/osx.pem:238 test path -----BEGIN CERTIFICATE-----
  155. bundler/testdata/osx.pem:262 test path -----BEGIN CERTIFICATE-----
  156. bundler/testdata/osx.pem:287 test path -----BEGIN CERTIFICATE-----
  157. bundler/testdata/osx.pem:318 test path -----BEGIN CERTIFICATE-----
  158. bundler/testdata/osx.pem:344 test path -----BEGIN CERTIFICATE-----
  159. bundler/testdata/osx.pem:364 test path -----BEGIN CERTIFICATE-----
  160. bundler/testdata/osx.pem:428 test path -----BEGIN CERTIFICATE-----
  161. bundler/testdata/osx.pem:483 test path -----BEGIN CERTIFICATE-----
  162. bundler/testdata/osx.pem:540 test path -----BEGIN CERTIFICATE-----
  163. bundler/testdata/osx.pem:615 test path -----BEGIN CERTIFICATE-----
  164. bundler/testdata/osx.pem:648 test path -----BEGIN CERTIFICATE-----
  165. bundler/testdata/osx.pem:670 test path -----BEGIN CERTIFICATE-----
  166. bundler/testdata/osx.pem:692 test path -----BEGIN CERTIFICATE-----
  167. bundler/testdata/osx.pem:805 test path -----BEGIN CERTIFICATE-----
  168. bundler/testdata/osx.pem:826 test path -----BEGIN CERTIFICATE-----
  169. bundler/testdata/osx.pem:848 test path -----BEGIN CERTIFICATE-----
  170. bundler/testdata/osx.pem:899 test path -----BEGIN CERTIFICATE-----
  171. bundler/testdata/osx.pem:950 test path -----BEGIN CERTIFICATE-----
  172. bundler/testdata/osx.pem:1036 test path -----BEGIN CERTIFICATE-----
  173. bundler/testdata/osx.pem:1122 test path -----BEGIN CERTIFICATE-----
  174. bundler/testdata/osx.pem:1142 test path -----BEGIN CERTIFICATE-----
  175. bundler/testdata/osx.pem:1161 test path -----BEGIN CERTIFICATE-----
  176. bundler/testdata/osx.pem:1217 test path -----BEGIN CERTIFICATE-----
  177. bundler/testdata/osx.pem:1287 test path -----BEGIN CERTIFICATE-----
  178. bundler/testdata/osx.pem:1311 test path -----BEGIN CERTIFICATE-----
  179. bundler/testdata/osx.pem:1379 test path -----BEGIN CERTIFICATE-----
  180. bundler/testdata/osx.pem:1514 test path -----BEGIN CERTIFICATE-----
  181. bundler/testdata/osx.pem:1534 test path -----BEGIN CERTIFICATE-----
  182. bundler/testdata/osx.pem:1556 test path -----BEGIN CERTIFICATE-----
  183. bundler/testdata/osx.pem:1581 test path -----BEGIN CERTIFICATE-----
  184. bundler/testdata/osx.pem:1638 test path -----BEGIN CERTIFICATE-----
  185. bundler/testdata/osx.pem:1660 test path -----BEGIN CERTIFICATE-----
  186. bundler/testdata/osx.pem:1685 test path -----BEGIN CERTIFICATE-----
  187. bundler/testdata/osx.pem:1710 test path -----BEGIN CERTIFICATE-----
  188. bundler/testdata/osx.pem:1732 test path -----BEGIN CERTIFICATE-----
  189. bundler/testdata/osx.pem:1756 test path -----BEGIN CERTIFICATE-----
  190. bundler/testdata/osx.pem:1778 test path -----BEGIN CERTIFICATE-----
  191. bundler/testdata/osx.pem:1815 test path -----BEGIN CERTIFICATE-----
  192. bundler/testdata/osx.pem:1837 test path -----BEGIN CERTIFICATE-----
  193. bundler/testdata/osx.pem:1874 test path -----BEGIN CERTIFICATE-----
  194. bundler/testdata/osx.pem:1944 test path -----BEGIN CERTIFICATE-----
  195. bundler/testdata/osx.pem:1965 test path -----BEGIN CERTIFICATE-----
  196. bundler/testdata/osx.pem:1989 test path -----BEGIN CERTIFICATE-----
  197. bundler/testdata/osx.pem:2009 test path -----BEGIN CERTIFICATE-----
  198. bundler/testdata/osx.pem:2115 test path -----BEGIN CERTIFICATE-----
  199. bundler/testdata/osx.pem:2144 test path -----BEGIN CERTIFICATE-----
  200. bundler/testdata/osx.pem:2168 test path -----BEGIN CERTIFICATE-----

Showing the first 200. The CBOM has every one.

pem.certificate
ECDH Quantum-vulnerable Recorded traffic 192 places See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. doc/api/endpoint_scan.txt:100 "ECDHE-RSA-AES128-GCM-SHA256": [
  2. doc/api/endpoint_scan.txt:109 "ECDHE-RSA-AES128-SHA256": [
  3. doc/api/endpoint_scan.txt:118 "ECDHE-RSA-AES128-SHA": [
  4. doc/api/endpoint_scan.txt:154 "ECDHE-RSA-AES256-GCM-SHA384": [
  5. doc/api/endpoint_scan.txt:163 "ECDHE-RSA-AES256-SHA384": [
  6. doc/api/endpoint_scan.txt:172 "ECDHE-RSA-AES256-SHA": [
  7. doc/api/endpoint_scan.txt:208 "ECDHE-RSA-DES-CBC3-SHA": [
  8. doc/api/endpoint_scan.txt:371 "TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA": "SHA1WithRSA",
  9. doc/api/endpoint_scan.txt:372 "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA": "SHA1WithRSA",
  10. doc/api/endpoint_scan.txt:373 "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256": "SHA1WithRSA",
  11. doc/api/endpoint_scan.txt:374 "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": "SHA1WithRSA",
  12. doc/api/endpoint_scan.txt:375 "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA": "SHA1WithRSA",
  13. doc/api/endpoint_scan.txt:376 "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384": "SHA1WithRSA",
  14. doc/api/endpoint_scan.txt:377 "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": "SHA1WithRSA",
  15. doc/api/endpoint_scan.txt:378 "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256": "SHA1WithRSA",
  16. doc/api/endpoint_scan.txt:412 "ECDHE-RSA-AES128-GCM-SHA256": [
  17. doc/api/endpoint_scan.txt:421 "ECDHE-RSA-AES128-SHA256": [
  18. doc/api/endpoint_scan.txt:430 "ECDHE-RSA-AES128-SHA": [
  19. doc/api/endpoint_scan.txt:466 "ECDHE-RSA-AES256-GCM-SHA384": [
  20. doc/api/endpoint_scan.txt:475 "ECDHE-RSA-AES256-SHA384": [
  21. doc/api/endpoint_scan.txt:484 "ECDHE-RSA-AES256-SHA": [
  22. doc/api/endpoint_scan.txt:520 "ECDHE-RSA-DES-CBC3-SHA": [
  23. scan/crypto/tls/cfsslscan_common.go:271 0xC001: {Name: "TLS_ECDH_ECDSA_WITH_NULL_SHA", EllipticCurve: true},
  24. scan/crypto/tls/cfsslscan_common.go:272 0xC002: {Name: "TLS_ECDH_ECDSA_WITH_RC4_128_SHA", ShortName: "ECDH-ECDSA-RC4-SHA", EllipticCurve: true},
  25. scan/crypto/tls/cfsslscan_common.go:273 0xC003: {Name: "TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDH-ECDSA-DES-CBC3-SHA", EllipticCurve: true},
  26. scan/crypto/tls/cfsslscan_common.go:274 0xC004: {Name: "TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA", ShortName: "ECDH-ECDSA-AES128-SHA", EllipticCurve: true},
  27. scan/crypto/tls/cfsslscan_common.go:275 0xC005: {Name: "TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA", ShortName: "ECDH-ECDSA-AES256-SHA", EllipticCurve: true},
  28. scan/crypto/tls/cfsslscan_common.go:276 0xC006: {Name: "TLS_ECDHE_ECDSA_WITH_NULL_SHA", ForwardSecret: true, EllipticCurve: true},
  29. scan/crypto/tls/cfsslscan_common.go:277 0xC007: {Name: "TLS_ECDHE_ECDSA_WITH_RC4_128_SHA", ShortName: "ECDHE-ECDSA-RC4-SHA", ForwardSecret: true, EllipticCurve: true},
  30. scan/crypto/tls/cfsslscan_common.go:278 0xC008: {Name: "TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDHE-ECDSA-DES-CBC3-SHA", ForwardSecret: true, EllipticCurve: true},
  31. scan/crypto/tls/cfsslscan_common.go:279 0xC009: {Name: "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA", ShortName: "ECDHE-ECDSA-AES128-SHA", ForwardSecret: true, EllipticCurve: true},
  32. scan/crypto/tls/cfsslscan_common.go:280 0xC00A: {Name: "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA", ShortName: "ECDHE-ECDSA-AES256-SHA", ForwardSecret: true, EllipticCurve: true},
  33. scan/crypto/tls/cfsslscan_common.go:281 0xC00B: {Name: "TLS_ECDH_RSA_WITH_NULL_SHA", EllipticCurve: true},
  34. scan/crypto/tls/cfsslscan_common.go:282 0xC00C: {Name: "TLS_ECDH_RSA_WITH_RC4_128_SHA", ShortName: "ECDH-RSA-RC4-SHA", EllipticCurve: true},
  35. scan/crypto/tls/cfsslscan_common.go:283 0xC00D: {Name: "TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDH-RSA-DES-CBC3-SHA", EllipticCurve: true},
  36. scan/crypto/tls/cfsslscan_common.go:284 0xC00E: {Name: "TLS_ECDH_RSA_WITH_AES_128_CBC_SHA", ShortName: "ECDH-RSA-AES128-SHA", EllipticCurve: true},
  37. scan/crypto/tls/cfsslscan_common.go:285 0xC00F: {Name: "TLS_ECDH_RSA_WITH_AES_256_CBC_SHA", ShortName: "ECDH-RSA-AES256-SHA", EllipticCurve: true},
  38. scan/crypto/tls/cfsslscan_common.go:286 0xC010: {Name: "TLS_ECDHE_RSA_WITH_NULL_SHA", ForwardSecret: true, EllipticCurve: true},
  39. scan/crypto/tls/cfsslscan_common.go:287 0xC011: {Name: "TLS_ECDHE_RSA_WITH_RC4_128_SHA", ShortName: "ECDHE-RSA-RC4-SHA", ForwardSecret: true, EllipticCurve: true},
  40. scan/crypto/tls/cfsslscan_common.go:288 0xC012: {Name: "TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDHE-RSA-DES-CBC3-SHA", ForwardSecret: true, EllipticCurve: true},
  41. scan/crypto/tls/cfsslscan_common.go:289 0xC013: {Name: "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA", ShortName: "ECDHE-RSA-AES128-SHA", ForwardSecret: true, EllipticCurve: true},
  42. scan/crypto/tls/cfsslscan_common.go:290 0xC014: {Name: "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA", ShortName: "ECDHE-RSA-AES256-SHA", ForwardSecret: true, EllipticCurve: true},
  43. scan/crypto/tls/cfsslscan_common.go:305 0xC023: {Name: "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256", ShortName: "ECDHE-ECDSA-AES128-SHA256", ForwardSecret: true, EllipticCurve: true},
  44. scan/crypto/tls/cfsslscan_common.go:306 0xC024: {Name: "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384", ShortName: "ECDHE-ECDSA-AES256-SHA384", ForwardSecret: true, EllipticCurve: true},
  45. scan/crypto/tls/cfsslscan_common.go:307 0xC025: {Name: "TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256", ShortName: "ECDH-ECDSA-AES128-SHA256", EllipticCurve: true},
  46. scan/crypto/tls/cfsslscan_common.go:308 0xC026: {Name: "TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384", ShortName: "ECDH-ECDSA-AES256-SHA384", EllipticCurve: true},
  47. scan/crypto/tls/cfsslscan_common.go:309 0xC027: {Name: "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256", ShortName: "ECDHE-RSA-AES128-SHA256", ForwardSecret: true, EllipticCurve: true},
  48. scan/crypto/tls/cfsslscan_common.go:310 0xC028: {Name: "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384", ShortName: "ECDHE-RSA-AES256-SHA384", ForwardSecret: true, EllipticCurve: true},
  49. scan/crypto/tls/cfsslscan_common.go:311 0xC029: {Name: "TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256", ShortName: "ECDH-RSA-AES128-SHA256", EllipticCurve: true},
  50. scan/crypto/tls/cfsslscan_common.go:312 0xC02A: {Name: "TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384", ShortName: "ECDH-RSA-AES256-SHA384", EllipticCurve: true},
  51. scan/crypto/tls/cfsslscan_common.go:313 0xC02B: {Name: "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256", ShortName: "ECDHE-ECDSA-AES128-GCM-SHA256", ForwardSecret: true, EllipticCurve: true},
  52. scan/crypto/tls/cfsslscan_common.go:314 0xC02C: {Name: "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384", ShortName: "ECDHE-ECDSA-AES256-GCM-SHA384", ForwardSecret: true, EllipticCurve: true},
  53. scan/crypto/tls/cfsslscan_common.go:315 0xC02D: {Name: "TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256", ShortName: "ECDH-ECDSA-AES128-GCM-SHA256", EllipticCurve: true},
  54. scan/crypto/tls/cfsslscan_common.go:316 0xC02E: {Name: "TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384", ShortName: "ECDH-ECDSA-AES256-GCM-SHA384", EllipticCurve: true},
  55. scan/crypto/tls/cfsslscan_common.go:317 0xC02F: {Name: "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256", ShortName: "ECDHE-RSA-AES128-GCM-SHA256", ForwardSecret: true, EllipticCurve: true},
  56. scan/crypto/tls/cfsslscan_common.go:318 0xC030: {Name: "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384", ShortName: "ECDHE-RSA-AES256-GCM-SHA384", ForwardSecret: true, EllipticCurve: true},
  57. scan/crypto/tls/cfsslscan_common.go:319 0xC031: {Name: "TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256", ShortName: "ECDH-RSA-AES128-GCM-SHA256", EllipticCurve: true},
  58. scan/crypto/tls/cfsslscan_common.go:320 0xC032: {Name: "TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384", ShortName: "ECDH-RSA-AES256-GCM-SHA384", EllipticCurve: true},
  59. scan/crypto/tls/cfsslscan_common.go:321 0xC033: {Name: "TLS_ECDHE_PSK_WITH_RC4_128_SHA", ForwardSecret: true, EllipticCurve: true},
  60. scan/crypto/tls/cfsslscan_common.go:322 0xC034: {Name: "TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA", ForwardSecret: true, EllipticCurve: true},
  61. scan/crypto/tls/cfsslscan_common.go:323 0xC035: {Name: "TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA", ForwardSecret: true, EllipticCurve: true},
  62. scan/crypto/tls/cfsslscan_common.go:324 0xC036: {Name: "TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA", ForwardSecret: true, EllipticCurve: true},
  63. scan/crypto/tls/cfsslscan_common.go:325 0xC037: {Name: "TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256", ForwardSecret: true, EllipticCurve: true},
  64. scan/crypto/tls/cfsslscan_common.go:326 0xC038: {Name: "TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384", ForwardSecret: true, EllipticCurve: true},
  65. scan/crypto/tls/cfsslscan_common.go:327 0xC039: {Name: "TLS_ECDHE_PSK_WITH_NULL_SHA", ForwardSecret: true, EllipticCurve: true},
  66. scan/crypto/tls/cfsslscan_common.go:328 0xC03A: {Name: "TLS_ECDHE_PSK_WITH_NULL_SHA256", ForwardSecret: true, EllipticCurve: true},
  67. scan/crypto/tls/cfsslscan_common.go:329 0xC03B: {Name: "TLS_ECDHE_PSK_WITH_NULL_SHA384", ForwardSecret: true, EllipticCurve: true},
  68. scan/crypto/tls/cfsslscan_common.go:342 0xC048: {Name: "TLS_ECDHE_ECDSA_WITH_ARIA_128_CBC_SHA256", ForwardSecret: true, EllipticCurve: true},
  69. scan/crypto/tls/cfsslscan_common.go:343 0xC049: {Name: "TLS_ECDHE_ECDSA_WITH_ARIA_256_CBC_SHA384", ForwardSecret: true, EllipticCurve: true},
  70. scan/crypto/tls/cfsslscan_common.go:344 0xC04A: {Name: "TLS_ECDH_ECDSA_WITH_ARIA_128_CBC_SHA256", EllipticCurve: true},
  71. scan/crypto/tls/cfsslscan_common.go:345 0xC04B: {Name: "TLS_ECDH_ECDSA_WITH_ARIA_256_CBC_SHA384", EllipticCurve: true},
  72. scan/crypto/tls/cfsslscan_common.go:346 0xC04C: {Name: "TLS_ECDHE_RSA_WITH_ARIA_128_CBC_SHA256", ForwardSecret: true, EllipticCurve: true},
  73. scan/crypto/tls/cfsslscan_common.go:347 0xC04D: {Name: "TLS_ECDHE_RSA_WITH_ARIA_256_CBC_SHA384", ForwardSecret: true, EllipticCurve: true},
  74. scan/crypto/tls/cfsslscan_common.go:348 0xC04E: {Name: "TLS_ECDH_RSA_WITH_ARIA_128_CBC_SHA256", EllipticCurve: true},
  75. scan/crypto/tls/cfsslscan_common.go:349 0xC04F: {Name: "TLS_ECDH_RSA_WITH_ARIA_256_CBC_SHA384", EllipticCurve: true},
  76. scan/crypto/tls/cfsslscan_common.go:362 0xC05C: {Name: "TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256", ForwardSecret: true, EllipticCurve: true},
  77. scan/crypto/tls/cfsslscan_common.go:363 0xC05D: {Name: "TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384", ForwardSecret: true, EllipticCurve: true},
  78. scan/crypto/tls/cfsslscan_common.go:364 0xC05E: {Name: "TLS_ECDH_ECDSA_WITH_ARIA_128_GCM_SHA256", EllipticCurve: true},
  79. scan/crypto/tls/cfsslscan_common.go:365 0xC05F: {Name: "TLS_ECDH_ECDSA_WITH_ARIA_256_GCM_SHA384", EllipticCurve: true},
  80. scan/crypto/tls/cfsslscan_common.go:366 0xC060: {Name: "TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256", ForwardSecret: true, EllipticCurve: true},
  81. scan/crypto/tls/cfsslscan_common.go:367 0xC061: {Name: "TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384", ForwardSecret: true, EllipticCurve: true},
  82. scan/crypto/tls/cfsslscan_common.go:368 0xC062: {Name: "TLS_ECDH_RSA_WITH_ARIA_128_GCM_SHA256", EllipticCurve: true},
  83. scan/crypto/tls/cfsslscan_common.go:369 0xC063: {Name: "TLS_ECDH_RSA_WITH_ARIA_256_GCM_SHA384", EllipticCurve: true},
  84. scan/crypto/tls/cfsslscan_common.go:382 0xC070: {Name: "TLS_ECDHE_PSK_WITH_ARIA_128_CBC_SHA256", ForwardSecret: true, EllipticCurve: true},
  85. scan/crypto/tls/cfsslscan_common.go:383 0xC071: {Name: "TLS_ECDHE_PSK_WITH_ARIA_256_CBC_SHA384", ForwardSecret: true, EllipticCurve: true},
  86. scan/crypto/tls/cfsslscan_common.go:384 0xC072: {Name: "TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256", ForwardSecret: true, EllipticCurve: true},
  87. scan/crypto/tls/cfsslscan_common.go:385 0xC073: {Name: "TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384", ForwardSecret: true, EllipticCurve: true},
  88. scan/crypto/tls/cfsslscan_common.go:386 0xC074: {Name: "TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256", EllipticCurve: true},
  89. scan/crypto/tls/cfsslscan_common.go:387 0xC075: {Name: "TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384", EllipticCurve: true},
  90. scan/crypto/tls/cfsslscan_common.go:388 0xC076: {Name: "TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256", ForwardSecret: true, EllipticCurve: true},
  91. scan/crypto/tls/cfsslscan_common.go:389 0xC077: {Name: "TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384", ForwardSecret: true, EllipticCurve: true},
  92. scan/crypto/tls/cfsslscan_common.go:390 0xC078: {Name: "TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256", EllipticCurve: true},
  93. scan/crypto/tls/cfsslscan_common.go:391 0xC079: {Name: "TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384", EllipticCurve: true},
  94. scan/crypto/tls/cfsslscan_common.go:404 0xC086: {Name: "TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_GCM_SHA256", ForwardSecret: true, EllipticCurve: true},
  95. scan/crypto/tls/cfsslscan_common.go:405 0xC087: {Name: "TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_GCM_SHA384", ForwardSecret: true, EllipticCurve: true},
  96. scan/crypto/tls/cfsslscan_common.go:406 0xC088: {Name: "TLS_ECDH_ECDSA_WITH_CAMELLIA_128_GCM_SHA256", EllipticCurve: true},
  97. scan/crypto/tls/cfsslscan_common.go:407 0xC089: {Name: "TLS_ECDH_ECDSA_WITH_CAMELLIA_256_GCM_SHA384", EllipticCurve: true},
  98. scan/crypto/tls/cfsslscan_common.go:408 0xC08A: {Name: "TLS_ECDHE_RSA_WITH_CAMELLIA_128_GCM_SHA256", ForwardSecret: true, EllipticCurve: true},
  99. scan/crypto/tls/cfsslscan_common.go:409 0xC08B: {Name: "TLS_ECDHE_RSA_WITH_CAMELLIA_256_GCM_SHA384", ForwardSecret: true, EllipticCurve: true},
  100. scan/crypto/tls/cfsslscan_common.go:410 0xC08C: {Name: "TLS_ECDH_RSA_WITH_CAMELLIA_128_GCM_SHA256", EllipticCurve: true},
  101. scan/crypto/tls/cfsslscan_common.go:411 0xC08D: {Name: "TLS_ECDH_RSA_WITH_CAMELLIA_256_GCM_SHA384", EllipticCurve: true},
  102. scan/crypto/tls/cfsslscan_common.go:424 0xC09A: {Name: "TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256", ForwardSecret: true, EllipticCurve: true},
  103. scan/crypto/tls/cfsslscan_common.go:425 0xC09B: {Name: "TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384", ForwardSecret: true, EllipticCurve: true},
  104. scan/crypto/tls/cfsslscan_common.go:442 0xC0AC: {Name: "TLS_ECDHE_ECDSA_WITH_AES_128_CCM", ForwardSecret: true, EllipticCurve: true},
  105. scan/crypto/tls/cfsslscan_common.go:443 0xC0AD: {Name: "TLS_ECDHE_ECDSA_WITH_AES_256_CCM", ForwardSecret: true, EllipticCurve: true},
  106. scan/crypto/tls/cfsslscan_common.go:444 0xC0AE: {Name: "TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8", ForwardSecret: true, EllipticCurve: true},
  107. scan/crypto/tls/cfsslscan_common.go:445 0xC0AF: {Name: "TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8", ForwardSecret: true, EllipticCurve: true},
  108. scan/crypto/tls/cfsslscan_common.go:449 0xCC13: {Name: "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256", ForwardSecret: true, EllipticCurve: true},
  109. scan/crypto/tls/cfsslscan_common.go:450 0xCC14: {Name: "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256", ForwardSecret: true, EllipticCurve: true},
  110. scan/crypto/tls/cipher_suites.go:78 {TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, 16, 0, 4, ecdheRSAKA, suiteECDHE | suiteTLS12, nil, nil, aeadAESGCM},
  111. scan/crypto/tls/cipher_suites.go:79 {TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, 16, 0, 4, ecdheECDSAKA, suiteECDHE | suiteECDSA | suiteTLS12, nil, nil, aeadAESGCM},
  112. scan/crypto/tls/cipher_suites.go:80 {TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, 32, 0, 4, ecdheRSAKA, suiteECDHE | suiteTLS12 | suiteSHA384, nil, nil, aeadAESGCM},
  113. scan/crypto/tls/cipher_suites.go:81 {TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, 32, 0, 4, ecdheECDSAKA, suiteECDHE | suiteECDSA | suiteTLS12 | suiteSHA384, nil, nil, aeadAESGCM},
  114. scan/crypto/tls/cipher_suites.go:82 {TLS_ECDHE_RSA_WITH_RC4_128_SHA, 16, 20, 0, ecdheRSAKA, suiteECDHE | suiteDefaultOff, cipherRC4, macSHA1, nil},
  115. scan/crypto/tls/cipher_suites.go:83 {TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, 16, 20, 0, ecdheECDSAKA, suiteECDHE | suiteECDSA | suiteDefaultOff, cipherRC4, macSHA1, nil},
  116. scan/crypto/tls/cipher_suites.go:84 {TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, 16, 20, 16, ecdheRSAKA, suiteECDHE, cipherAES, macSHA1, nil},
  117. scan/crypto/tls/cipher_suites.go:85 {TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA, 16, 20, 16, ecdheECDSAKA, suiteECDHE | suiteECDSA, cipherAES, macSHA1, nil},
  118. scan/crypto/tls/cipher_suites.go:86 {TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, 32, 20, 16, ecdheRSAKA, suiteECDHE, cipherAES, macSHA1, nil},
  119. scan/crypto/tls/cipher_suites.go:87 {TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, 32, 20, 16, ecdheECDSAKA, suiteECDHE | suiteECDSA, cipherAES, macSHA1, nil},
  120. scan/crypto/tls/cipher_suites.go:93 {TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, 24, 20, 8, ecdheRSAKA, suiteECDHE, cipher3DES, macSHA1, nil},
  121. scan/crypto/tls/cipher_suites.go:273 TLS_ECDHE_ECDSA_WITH_RC4_128_SHA uint16 = 0xc007
  122. scan/crypto/tls/cipher_suites.go:274 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA uint16 = 0xc009
  123. scan/crypto/tls/cipher_suites.go:275 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA uint16 = 0xc00a
  124. scan/crypto/tls/cipher_suites.go:276 TLS_ECDHE_RSA_WITH_RC4_128_SHA uint16 = 0xc011
  125. scan/crypto/tls/cipher_suites.go:277 TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA uint16 = 0xc012
  126. scan/crypto/tls/cipher_suites.go:278 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA uint16 = 0xc013
  127. scan/crypto/tls/cipher_suites.go:279 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA uint16 = 0xc014
  128. scan/crypto/tls/cipher_suites.go:280 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 uint16 = 0xc02f
  129. scan/crypto/tls/cipher_suites.go:281 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 uint16 = 0xc02b
  130. scan/crypto/tls/cipher_suites.go:282 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 uint16 = 0xc030
  131. scan/crypto/tls/cipher_suites.go:283 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 uint16 = 0xc02c
  132. scan/crypto/tls/handshake_client_test.go:319 test path name: "ECDHE-RSA-AES",
  133. scan/crypto/tls/handshake_client_test.go:320 test path command: []string{"openssl", "s_server", "-cipher", "ECDHE-RSA-AES128-SHA"},
  134. scan/crypto/tls/handshake_client_test.go:329 test path name: "ECDHE-ECDSA-AES",
  135. scan/crypto/tls/handshake_client_test.go:330 test path command: []string{"openssl", "s_server", "-cipher", "ECDHE-ECDSA-AES128-SHA"},
  136. scan/crypto/tls/handshake_client_test.go:341 test path name: "ECDHE-ECDSA-AES-GCM",
  137. scan/crypto/tls/handshake_client_test.go:342 test path command: []string{"openssl", "s_server", "-cipher", "ECDHE-ECDSA-AES128-GCM-SHA256"},
  138. scan/crypto/tls/handshake_client_test.go:351 test path name: "ECDHE-ECDSA-AES256-GCM-SHA384",
  139. scan/crypto/tls/handshake_client_test.go:352 test path command: []string{"openssl", "s_server", "-cipher", "ECDHE-ECDSA-AES256-GCM-SHA384"},
  140. scan/crypto/tls/handshake_client_test.go:375 test path command: []string{"openssl", "s_server", "-cipher", "ECDHE-ECDSA-AES128-SHA", "-verify", "1"},
  141. scan/crypto/tls/handshake_client_test.go:386 test path command: []string{"openssl", "s_server", "-cipher", "ECDHE-RSA-AES256-GCM-SHA384", "-verify", "1"},
  142. scan/crypto/tls/handshake_client_test.go:411 test path command: []string{"openssl", "s_server", "-cipher", "ECDHE-ECDSA-AES128-SHA", "-verify", "1"},
  143. scan/crypto/tls/handshake_client_test.go:487 test path clientConfig.CipherSuites = []uint16{TLS_ECDHE_RSA_WITH_RC4_128_SHA}
  144. scan/crypto/tls/handshake_server_test.go:142 test path cipherSuites: []uint16{TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA},
  145. scan/crypto/tls/handshake_server_test.go:167 test path cipherSuites: []uint16{TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA},
  146. scan/crypto/tls/handshake_server_test.go:247 test path TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
  147. scan/crypto/tls/handshake_server_test.go:659 test path command: []string{"openssl", "s_client", "-no_ticket", "-cipher", "ECDHE-RSA-AES128-GCM-SHA256"},
  148. scan/crypto/tls/handshake_server_test.go:667 test path command: []string{"openssl", "s_client", "-no_ticket", "-cipher", "ECDHE-RSA-AES256-GCM-SHA384"},
  149. scan/crypto/tls/handshake_server_test.go:680 test path name: "ECDHE-ECDSA-AES",
  150. scan/crypto/tls/handshake_server_test.go:681 test path command: []string{"openssl", "s_client", "-no_ticket", "-cipher", "ECDHE-ECDSA-AES256-SHA"},
  151. scan/crypto/tls/handshake_server_test.go:833 test path config.CipherSuites = []uint16{TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA}
  152. scan/crypto/tls/handshake_server_test.go:843 test path config.CipherSuites = []uint16{TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA}
  153. scan/tls_handshake.go:130 0xC006: {Name: "TLS_ECDHE_ECDSA_WITH_NULL_SHA", ForwardSecret: true, EllipticCurve: true},
  154. scan/tls_handshake.go:131 0xC007: {Name: "TLS_ECDHE_ECDSA_WITH_RC4_128_SHA", ShortName: "ECDHE-ECDSA-RC4-SHA", ForwardSecret: true, EllipticCurve: true},
  155. scan/tls_handshake.go:132 0xC008: {Name: "TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDHE-ECDSA-DES-CBC3-SHA", ForwardSecret: true, EllipticCurve: true},
  156. scan/tls_handshake.go:133 0xC009: {Name: "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA", ShortName: "ECDHE-ECDSA-AES128-SHA", ForwardSecret: true, EllipticCurve: true},
  157. scan/tls_handshake.go:134 0xC00A: {Name: "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA", ShortName: "ECDHE-ECDSA-AES256-SHA", ForwardSecret: true, EllipticCurve: true},
  158. scan/tls_handshake.go:135 0xC010: {Name: "TLS_ECDHE_RSA_WITH_NULL_SHA", ForwardSecret: true, EllipticCurve: true},
  159. scan/tls_handshake.go:136 0xC011: {Name: "TLS_ECDHE_RSA_WITH_RC4_128_SHA", ShortName: "ECDHE-RSA-RC4-SHA", ForwardSecret: true, EllipticCurve: true},
  160. scan/tls_handshake.go:137 0xC012: {Name: "TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "ECDHE-RSA-DES-CBC3-SHA", ForwardSecret: true, EllipticCurve: true},
  161. scan/tls_handshake.go:138 0xC013: {Name: "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA", ShortName: "ECDHE-RSA-AES128-SHA", ForwardSecret: true, EllipticCurve: true},
  162. scan/tls_handshake.go:139 0xC014: {Name: "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA", ShortName: "ECDHE-RSA-AES256-SHA", ForwardSecret: true, EllipticCurve: true},
  163. scan/tls_handshake.go:140 0xC023: {Name: "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256", ShortName: "ECDHE-ECDSA-AES128-SHA256", ForwardSecret: true, EllipticCurve: true},
  164. scan/tls_handshake.go:141 0xC024: {Name: "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384", ShortName: "ECDHE-ECDSA-AES256-SHA384", ForwardSecret: true, EllipticCurve: true},
  165. scan/tls_handshake.go:142 0xC027: {Name: "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256", ShortName: "ECDHE-RSA-AES128-SHA256", ForwardSecret: true, EllipticCurve: true},
  166. scan/tls_handshake.go:143 0xC028: {Name: "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384", ShortName: "ECDHE-RSA-AES256-SHA384", ForwardSecret: true, EllipticCurve: true},
  167. scan/tls_handshake.go:144 0xC02B: {Name: "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256", ShortName: "ECDHE-ECDSA-AES128-GCM-SHA256", ForwardSecret: true, EllipticCurve: true},
  168. scan/tls_handshake.go:145 0xC02C: {Name: "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384", ShortName: "ECDHE-ECDSA-AES256-GCM-SHA384", ForwardSecret: true, EllipticCurve: true},
  169. scan/tls_handshake.go:146 0xC02F: {Name: "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256", ShortName: "ECDHE-RSA-AES128-GCM-SHA256", ForwardSecret: true, EllipticCurve: true},
  170. scan/tls_handshake.go:147 0xC030: {Name: "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384", ShortName: "ECDHE-RSA-AES256-GCM-SHA384", ForwardSecret: true, EllipticCurve: true},
  171. scan/tls_handshake.go:148 0xC048: {Name: "TLS_ECDHE_ECDSA_WITH_ARIA_128_CBC_SHA256", ForwardSecret: true, EllipticCurve: true},
  172. scan/tls_handshake.go:149 0xC049: {Name: "TLS_ECDHE_ECDSA_WITH_ARIA_256_CBC_SHA384", ForwardSecret: true, EllipticCurve: true},
  173. scan/tls_handshake.go:150 0xC04C: {Name: "TLS_ECDHE_RSA_WITH_ARIA_128_CBC_SHA256", ForwardSecret: true, EllipticCurve: true},
  174. scan/tls_handshake.go:151 0xC04D: {Name: "TLS_ECDHE_RSA_WITH_ARIA_256_CBC_SHA384", ForwardSecret: true, EllipticCurve: true},
  175. scan/tls_handshake.go:152 0xC05D: {Name: "TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384", ForwardSecret: true, EllipticCurve: true},
  176. scan/tls_handshake.go:153 0xC060: {Name: "TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256", ForwardSecret: true, EllipticCurve: true},
  177. scan/tls_handshake.go:154 0xC061: {Name: "TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384", ForwardSecret: true, EllipticCurve: true},
  178. scan/tls_handshake.go:155 0xC072: {Name: "TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256", ForwardSecret: true, EllipticCurve: true},
  179. scan/tls_handshake.go:156 0xC073: {Name: "TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384", ForwardSecret: true, EllipticCurve: true},
  180. scan/tls_handshake.go:157 0xC076: {Name: "TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256", ForwardSecret: true, EllipticCurve: true},
  181. scan/tls_handshake.go:158 0xC077: {Name: "TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384", ForwardSecret: true, EllipticCurve: true},
  182. scan/tls_handshake.go:159 0xC086: {Name: "TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_GCM_SHA256", ForwardSecret: true, EllipticCurve: true},
  183. scan/tls_handshake.go:160 0xC087: {Name: "TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_GCM_SHA384", ForwardSecret: true, EllipticCurve: true},
  184. scan/tls_handshake.go:161 0xC08A: {Name: "TLS_ECDHE_RSA_WITH_CAMELLIA_128_GCM_SHA256", ForwardSecret: true, EllipticCurve: true},
  185. scan/tls_handshake.go:162 0xC08B: {Name: "TLS_ECDHE_RSA_WITH_CAMELLIA_256_GCM_SHA384", ForwardSecret: true, EllipticCurve: true},
  186. scan/tls_handshake.go:163 0xC08C: {Name: "TLS_ECDH_RSA_WITH_CAMELLIA_128_GCM_SHA256", EllipticCurve: true},
  187. scan/tls_handshake.go:164 0xC0AC: {Name: "TLS_ECDHE_ECDSA_WITH_AES_128_CCM", ForwardSecret: true, EllipticCurve: true},
  188. scan/tls_handshake.go:165 0xC0AD: {Name: "TLS_ECDHE_ECDSA_WITH_AES_256_CCM", ForwardSecret: true, EllipticCurve: true},
  189. scan/tls_handshake.go:166 0xC0AE: {Name: "TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8", ForwardSecret: true, EllipticCurve: true},
  190. scan/tls_handshake.go:167 0xC0AF: {Name: "TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8", ForwardSecret: true, EllipticCurve: true},
  191. scan/tls_handshake.go:171 0xCC13: {Name: "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256", ForwardSecret: true, EllipticCurve: true},
  192. scan/tls_handshake.go:172 0xCC14: {Name: "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256", ForwardSecret: true, EllipticCurve: true},
config.cipher-suite · CWE-757
RSA4096-bit Quantum-vulnerable 131 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. bundler/testdata/cfssl-leaf-rsa4096.pem:1 test path -----BEGIN CERTIFICATE-----
  2. bundler/testdata/cfssl-leaflet-rsa4096.pem:1 test path -----BEGIN CERTIFICATE-----
  3. bundler/testdata/froyo.pem:433 test path -----BEGIN CERTIFICATE-----
  4. bundler/testdata/froyo.pem:482 test path -----BEGIN CERTIFICATE-----
  5. bundler/testdata/froyo.pem:835 test path -----BEGIN CERTIFICATE-----
  6. bundler/testdata/froyo.pem:1098 test path -----BEGIN CERTIFICATE-----
  7. bundler/testdata/froyo.pem:1165 test path -----BEGIN CERTIFICATE-----
  8. bundler/testdata/inter-L1-expired.pem:1 test path -----BEGIN CERTIFICATE-----
  9. bundler/testdata/inter-L1-sha1.pem:1 test path -----BEGIN CERTIFICATE-----
  10. bundler/testdata/inter-L1.pem:1 test path -----BEGIN CERTIFICATE-----
  11. bundler/testdata/intermediates.crt:1 test path -----BEGIN CERTIFICATE-----
  12. bundler/testdata/nss.pem:845 test path -----BEGIN CERTIFICATE-----
  13. bundler/testdata/nss.pem:884 test path -----BEGIN CERTIFICATE-----
  14. bundler/testdata/nss.pem:953 test path -----BEGIN CERTIFICATE-----
  15. bundler/testdata/nss.pem:1192 test path -----BEGIN CERTIFICATE-----
  16. bundler/testdata/nss.pem:1233 test path -----BEGIN CERTIFICATE-----
  17. bundler/testdata/nss.pem:1757 test path -----BEGIN CERTIFICATE-----
  18. bundler/testdata/nss.pem:1809 test path -----BEGIN CERTIFICATE-----
  19. bundler/testdata/nss.pem:1914 test path -----BEGIN CERTIFICATE-----
  20. bundler/testdata/nss.pem:2202 test path -----BEGIN CERTIFICATE-----
  21. bundler/testdata/nss.pem:2243 test path -----BEGIN CERTIFICATE-----
  22. bundler/testdata/nss.pem:2740 test path -----BEGIN CERTIFICATE-----
  23. bundler/testdata/nss.pem:2976 test path -----BEGIN CERTIFICATE-----
  24. bundler/testdata/nss.pem:3111 test path -----BEGIN CERTIFICATE-----
  25. bundler/testdata/nss.pem:3450 test path -----BEGIN CERTIFICATE-----
  26. bundler/testdata/nss.pem:3617 test path -----BEGIN CERTIFICATE-----
  27. bundler/testdata/nss.pem:3802 test path -----BEGIN CERTIFICATE-----
  28. bundler/testdata/nss.pem:3845 test path -----BEGIN CERTIFICATE-----
  29. bundler/testdata/nss.pem:3887 test path -----BEGIN CERTIFICATE-----
  30. bundler/testdata/nss.pem:3937 test path -----BEGIN CERTIFICATE-----
  31. bundler/testdata/nss.pem:4136 test path -----BEGIN CERTIFICATE-----
  32. bundler/testdata/nss.pem:4226 test path -----BEGIN CERTIFICATE-----
  33. bundler/testdata/nss.pem:4433 test path -----BEGIN CERTIFICATE-----
  34. bundler/testdata/nss.pem:4503 test path -----BEGIN CERTIFICATE-----
  35. bundler/testdata/nss.pem:4554 test path -----BEGIN CERTIFICATE-----
  36. bundler/testdata/nss.pem:4593 test path -----BEGIN CERTIFICATE-----
  37. bundler/testdata/nss.pem:4632 test path -----BEGIN CERTIFICATE-----
  38. bundler/testdata/osx.pem:119 test path -----BEGIN CERTIFICATE-----
  39. bundler/testdata/osx.pem:156 test path -----BEGIN CERTIFICATE-----
  40. bundler/testdata/osx.pem:384 test path -----BEGIN CERTIFICATE-----
  41. bundler/testdata/osx.pem:450 test path -----BEGIN CERTIFICATE-----
  42. bundler/testdata/osx.pem:506 test path -----BEGIN CERTIFICATE-----
  43. bundler/testdata/osx.pem:568 test path -----BEGIN CERTIFICATE-----
  44. bundler/testdata/osx.pem:716 test path -----BEGIN CERTIFICATE-----
  45. bundler/testdata/osx.pem:751 test path -----BEGIN CERTIFICATE-----
  46. bundler/testdata/osx.pem:868 test path -----BEGIN CERTIFICATE-----
  47. bundler/testdata/osx.pem:919 test path -----BEGIN CERTIFICATE-----
  48. bundler/testdata/osx.pem:974 test path -----BEGIN CERTIFICATE-----
  49. bundler/testdata/osx.pem:1005 test path -----BEGIN CERTIFICATE-----
  50. bundler/testdata/osx.pem:1058 test path -----BEGIN CERTIFICATE-----
  51. bundler/testdata/osx.pem:1090 test path -----BEGIN CERTIFICATE-----
  52. bundler/testdata/osx.pem:1183 test path -----BEGIN CERTIFICATE-----
  53. bundler/testdata/osx.pem:1245 test path -----BEGIN CERTIFICATE-----
  54. bundler/testdata/osx.pem:1603 test path -----BEGIN CERTIFICATE-----
  55. bundler/testdata/osx.pem:1897 test path -----BEGIN CERTIFICATE-----
  56. bundler/testdata/osx.pem:2029 test path -----BEGIN CERTIFICATE-----
  57. bundler/testdata/osx.pem:2065 test path -----BEGIN CERTIFICATE-----
  58. bundler/testdata/osx.pem:2317 test path -----BEGIN CERTIFICATE-----
  59. bundler/testdata/osx.pem:2556 test path -----BEGIN CERTIFICATE-----
  60. bundler/testdata/osx.pem:2735 test path -----BEGIN CERTIFICATE-----
  61. bundler/testdata/osx.pem:2910 test path -----BEGIN CERTIFICATE-----
  62. bundler/testdata/osx.pem:2970 test path -----BEGIN CERTIFICATE-----
  63. bundler/testdata/osx.pem:3359 test path -----BEGIN CERTIFICATE-----
  64. bundler/testdata/osx.pem:3392 test path -----BEGIN CERTIFICATE-----
  65. bundler/testdata/osx.pem:3675 test path -----BEGIN CERTIFICATE-----
  66. bundler/testdata/osx.pem:3729 test path -----BEGIN CERTIFICATE-----
  67. bundler/testdata/osx.pem:3833 test path -----BEGIN CERTIFICATE-----
  68. bundler/testdata/osx.pem:3877 test path -----BEGIN CERTIFICATE-----
  69. bundler/testdata/osx.pem:3920 test path -----BEGIN CERTIFICATE-----
  70. bundler/testdata/osx.pem:3951 test path -----BEGIN CERTIFICATE-----
  71. bundler/testdata/osx.pem:3985 test path -----BEGIN CERTIFICATE-----
  72. bundler/testdata/osx.pem:4019 test path -----BEGIN CERTIFICATE-----
  73. bundler/testdata/osx.pem:4075 test path -----BEGIN CERTIFICATE-----
  74. bundler/testdata/osx.pem:4108 test path -----BEGIN CERTIFICATE-----
  75. bundler/testdata/osx.pem:4141 test path -----BEGIN CERTIFICATE-----
  76. bundler/testdata/osx.pem:4273 test path -----BEGIN CERTIFICATE-----
  77. bundler/testdata/osx.pem:4473 test path -----BEGIN CERTIFICATE-----
  78. bundler/testdata/osx.pem:4585 test path -----BEGIN CERTIFICATE-----
  79. bundler/testdata/osx.pem:4893 test path -----BEGIN CERTIFICATE-----
  80. bundler/testdata/osx.pem:5078 test path -----BEGIN CERTIFICATE-----
  81. bundler/testdata/osx.pem:5130 test path -----BEGIN CERTIFICATE-----
  82. bundler/testdata/osx.pem:5314 test path -----BEGIN CERTIFICATE-----
  83. cmd/mkbundle/cert-bundle.crt:27 -----BEGIN CERTIFICATE-----
  84. cmd/mkbundle/cert-bundle.crt:59 -----BEGIN CERTIFICATE-----
  85. helpers/testdata/bundle.pem:27 test path -----BEGIN CERTIFICATE-----
  86. helpers/testdata/bundle_with_whitespace.pem:29 test path -----BEGIN CERTIFICATE-----
  87. helpers/testdata/messed_up_bundle.pem:21 test path -----BEGIN CERTIFICATE-----
  88. transport/roots/system/root_darwin_armx.go:20 -----BEGIN CERTIFICATE-----
  89. transport/roots/system/root_darwin_armx.go:79 -----BEGIN CERTIFICATE-----
  90. transport/roots/system/root_darwin_armx.go:112 -----BEGIN CERTIFICATE-----
  91. transport/roots/system/root_darwin_armx.go:383 -----BEGIN CERTIFICATE-----
  92. transport/roots/system/root_darwin_armx.go:440 -----BEGIN CERTIFICATE-----
  93. transport/roots/system/root_darwin_armx.go:555 -----BEGIN CERTIFICATE-----
  94. transport/roots/system/root_darwin_armx.go:773 -----BEGIN CERTIFICATE-----
  95. transport/roots/system/root_darwin_armx.go:940 -----BEGIN CERTIFICATE-----
  96. transport/roots/system/root_darwin_armx.go:1022 -----BEGIN CERTIFICATE-----
  97. transport/roots/system/root_darwin_armx.go:1069 -----BEGIN CERTIFICATE-----
  98. transport/roots/system/root_darwin_armx.go:1110 -----BEGIN CERTIFICATE-----
  99. transport/roots/system/root_darwin_armx.go:1144 -----BEGIN CERTIFICATE-----
  100. transport/roots/system/root_darwin_armx.go:1364 -----BEGIN CERTIFICATE-----
  101. transport/roots/system/root_darwin_armx.go:1448 -----BEGIN CERTIFICATE-----
  102. transport/roots/system/root_darwin_armx.go:1695 -----BEGIN CERTIFICATE-----
  103. transport/roots/system/root_darwin_armx.go:1850 -----BEGIN CERTIFICATE-----
  104. transport/roots/system/root_darwin_armx.go:1894 -----BEGIN CERTIFICATE-----
  105. transport/roots/system/root_darwin_armx.go:2156 -----BEGIN CERTIFICATE-----
  106. transport/roots/system/root_darwin_armx.go:2209 -----BEGIN CERTIFICATE-----
  107. transport/roots/system/root_darwin_armx.go:2243 -----BEGIN CERTIFICATE-----
  108. transport/roots/system/root_darwin_armx.go:2365 -----BEGIN CERTIFICATE-----
  109. transport/roots/system/root_darwin_armx.go:2522 -----BEGIN CERTIFICATE-----
  110. transport/roots/system/root_darwin_armx.go:2564 -----BEGIN CERTIFICATE-----
  111. transport/roots/system/root_darwin_armx.go:2685 -----BEGIN CERTIFICATE-----
  112. transport/roots/system/root_darwin_armx.go:3130 -----BEGIN CERTIFICATE-----
  113. transport/roots/system/root_darwin_armx.go:3327 -----BEGIN CERTIFICATE-----
  114. transport/roots/system/root_darwin_armx.go:3448 -----BEGIN CERTIFICATE-----
  115. transport/roots/system/root_darwin_armx.go:3513 -----BEGIN CERTIFICATE-----
  116. transport/roots/system/root_darwin_armx.go:3570 -----BEGIN CERTIFICATE-----
  117. transport/roots/system/root_darwin_armx.go:3622 -----BEGIN CERTIFICATE-----
  118. transport/roots/system/root_darwin_armx.go:3811 -----BEGIN CERTIFICATE-----
  119. transport/roots/system/root_darwin_armx.go:3882 -----BEGIN CERTIFICATE-----
  120. transport/roots/system/root_darwin_armx.go:4125 -----BEGIN CERTIFICATE-----
  121. transport/roots/system/root_darwin_armx.go:4156 -----BEGIN CERTIFICATE-----
  122. transport/roots/system/root_darwin_armx.go:4231 -----BEGIN CERTIFICATE-----
  123. transport/roots/system/root_darwin_armx.go:4285 -----BEGIN CERTIFICATE-----
  124. transport/roots/system/root_darwin_armx.go:4358 -----BEGIN CERTIFICATE-----
  125. transport/roots/system/root_darwin_armx.go:4402 -----BEGIN CERTIFICATE-----
  126. transport/roots/system/root_darwin_armx.go:4433 -----BEGIN CERTIFICATE-----
  127. transport/roots/system/root_darwin_armx.go:4488 -----BEGIN CERTIFICATE-----
  128. transport/roots/system/root_darwin_armx.go:4661 -----BEGIN CERTIFICATE-----
  129. transport/roots/system/root_darwin_armx.go:4775 -----BEGIN CERTIFICATE-----
  130. transport/roots/system/root_darwin_armx.go:4829 -----BEGIN CERTIFICATE-----
  131. ubiquity/testdata/rsa4096sha2.pem:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
DH Quantum-vulnerable Recorded traffic 104 places See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. scan/crypto/tls/cfsslscan_common.go:140 0x000C: {Name: "TLS_DH_DSS_WITH_DES_CBC_SHA", ShortName: "DH-DSS-DES-CBC-SHA"},
  2. scan/crypto/tls/cfsslscan_common.go:141 0x000D: {Name: "TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA", ShortName: "DH-DSS-DES-CBC3-SHA"},
  3. scan/crypto/tls/cfsslscan_common.go:143 0x000F: {Name: "TLS_DH_RSA_WITH_DES_CBC_SHA", ShortName: "DH-RSA-DES-CBC-SHA"},
  4. scan/crypto/tls/cfsslscan_common.go:144 0x0010: {Name: "TLS_DH_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "DH-RSA-DES-CBC3-SHA"},
  5. scan/crypto/tls/cfsslscan_common.go:145 0x0011: {Name: "TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA", ShortName: "EXP-EDH-DSS-DES-CBC-SHA", ForwardSecret: true},
  6. scan/crypto/tls/cfsslscan_common.go:146 0x0012: {Name: "TLS_DHE_DSS_WITH_DES_CBC_SHA", ShortName: "EDH-DSS-DES-CBC-SHA", ForwardSecret: true},
  7. scan/crypto/tls/cfsslscan_common.go:147 0x0013: {Name: "TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA", ShortName: "EDH-DSS-DES-CBC3-SHA", ForwardSecret: true},
  8. scan/crypto/tls/cfsslscan_common.go:148 0x0014: {Name: "TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA", ShortName: "EXP-EDH-RSA-DES-CBC-SHA", ForwardSecret: true},
  9. scan/crypto/tls/cfsslscan_common.go:149 0x0015: {Name: "TLS_DHE_RSA_WITH_DES_CBC_SHA", ShortName: "EDH-RSA-DES-CBC-SHA", ForwardSecret: true},
  10. scan/crypto/tls/cfsslscan_common.go:150 0x0016: {Name: "TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA", ShortName: "EDH-RSA-DES-CBC3-SHA", ForwardSecret: true},
  11. scan/crypto/tls/cfsslscan_common.go:171 0x002D: {Name: "TLS_DHE_PSK_WITH_NULL_SHA", ForwardSecret: true},
  12. scan/crypto/tls/cfsslscan_common.go:174 0x0030: {Name: "TLS_DH_DSS_WITH_AES_128_CBC_SHA", ShortName: "DH-DSS-AES128-SHA"},
  13. scan/crypto/tls/cfsslscan_common.go:175 0x0031: {Name: "TLS_DH_RSA_WITH_AES_128_CBC_SHA", ShortName: "DH-RSA-AES128-SHA"},
  14. scan/crypto/tls/cfsslscan_common.go:176 0x0032: {Name: "TLS_DHE_DSS_WITH_AES_128_CBC_SHA", ShortName: "DHE-DSS-AES128-SHA", ForwardSecret: true},
  15. scan/crypto/tls/cfsslscan_common.go:177 0x0033: {Name: "TLS_DHE_RSA_WITH_AES_128_CBC_SHA", ShortName: "DHE-RSA-AES128-SHA", ForwardSecret: true},
  16. scan/crypto/tls/cfsslscan_common.go:180 0x0036: {Name: "TLS_DH_DSS_WITH_AES_256_CBC_SHA", ShortName: "DH-DSS-AES256-SHA"},
  17. scan/crypto/tls/cfsslscan_common.go:181 0x0037: {Name: "TLS_DH_RSA_WITH_AES_256_CBC_SHA", ShortName: "DH-RSA-AES256-SHA"},
  18. scan/crypto/tls/cfsslscan_common.go:182 0x0038: {Name: "TLS_DHE_DSS_WITH_AES_256_CBC_SHA", ShortName: "DHE-DSS-AES256-SHA", ForwardSecret: true},
  19. scan/crypto/tls/cfsslscan_common.go:183 0x0039: {Name: "TLS_DHE_RSA_WITH_AES_256_CBC_SHA", ShortName: "DHE-RSA-AES256-SHA", ForwardSecret: true},
  20. scan/crypto/tls/cfsslscan_common.go:188 0x003E: {Name: "TLS_DH_DSS_WITH_AES_128_CBC_SHA256", ShortName: "DH-DSS-AES128-SHA256"},
  21. scan/crypto/tls/cfsslscan_common.go:189 0x003F: {Name: "TLS_DH_RSA_WITH_AES_128_CBC_SHA256", ShortName: "DH-RSA-AES128-SHA256"},
  22. scan/crypto/tls/cfsslscan_common.go:190 0x0040: {Name: "TLS_DHE_DSS_WITH_AES_128_CBC_SHA256", ShortName: "DHE-DSS-AES128-SHA256", ForwardSecret: true},
  23. scan/crypto/tls/cfsslscan_common.go:192 0x0042: {Name: "TLS_DH_DSS_WITH_CAMELLIA_128_CBC_SHA", ShortName: "DH-DSS-CAMELLIA128-SHA"},
  24. scan/crypto/tls/cfsslscan_common.go:193 0x0043: {Name: "TLS_DH_RSA_WITH_CAMELLIA_128_CBC_SHA", ShortName: "DH-RSA-CAMELLIA128-SHA"},
  25. scan/crypto/tls/cfsslscan_common.go:194 0x0044: {Name: "TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA", ShortName: "DHE-DSS-CAMELLIA128-SHA", ForwardSecret: true},
  26. scan/crypto/tls/cfsslscan_common.go:195 0x0045: {Name: "TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA", ShortName: "DHE-RSA-CAMELLIA128-SHA", ForwardSecret: true},
  27. scan/crypto/tls/cfsslscan_common.go:197 0x0067: {Name: "TLS_DHE_RSA_WITH_AES_128_CBC_SHA256", ShortName: "DHE-RSA-AES128-SHA256", ForwardSecret: true},
  28. scan/crypto/tls/cfsslscan_common.go:198 0x0068: {Name: "TLS_DH_DSS_WITH_AES_256_CBC_SHA256", ShortName: "DH-DSS-AES256-SHA256"},
  29. scan/crypto/tls/cfsslscan_common.go:199 0x0069: {Name: "TLS_DH_RSA_WITH_AES_256_CBC_SHA256", ShortName: "DH-RSA-AES256-SHA256"},
  30. scan/crypto/tls/cfsslscan_common.go:200 0x006A: {Name: "TLS_DHE_DSS_WITH_AES_256_CBC_SHA256", ShortName: "DHE-DSS-AES256-SHA256", ForwardSecret: true},
  31. scan/crypto/tls/cfsslscan_common.go:201 0x006B: {Name: "TLS_DHE_RSA_WITH_AES_256_CBC_SHA256", ShortName: "DHE-RSA-AES256-SHA256", ForwardSecret: true},
  32. scan/crypto/tls/cfsslscan_common.go:205 0x0085: {Name: "TLS_DH_DSS_WITH_CAMELLIA_256_CBC_SHA", ShortName: "DH-DSS-CAMELLIA256-SHA"},
  33. scan/crypto/tls/cfsslscan_common.go:206 0x0086: {Name: "TLS_DH_RSA_WITH_CAMELLIA_256_CBC_SHA", ShortName: "DH-RSA-CAMELLIA256-SHA"},
  34. scan/crypto/tls/cfsslscan_common.go:207 0x0087: {Name: "TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA", ShortName: "DHE-DSS-CAMELLIA256-SHA", ForwardSecret: true},
  35. scan/crypto/tls/cfsslscan_common.go:208 0x0088: {Name: "TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA", ShortName: "DHE-RSA-CAMELLIA256-SHA", ForwardSecret: true},
  36. scan/crypto/tls/cfsslscan_common.go:214 0x008E: {Name: "TLS_DHE_PSK_WITH_RC4_128_SHA", ForwardSecret: true},
  37. scan/crypto/tls/cfsslscan_common.go:215 0x008F: {Name: "TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA", ForwardSecret: true},
  38. scan/crypto/tls/cfsslscan_common.go:216 0x0090: {Name: "TLS_DHE_PSK_WITH_AES_128_CBC_SHA", ForwardSecret: true},
  39. scan/crypto/tls/cfsslscan_common.go:217 0x0091: {Name: "TLS_DHE_PSK_WITH_AES_256_CBC_SHA", ForwardSecret: true},
  40. scan/crypto/tls/cfsslscan_common.go:223 0x0097: {Name: "TLS_DH_DSS_WITH_SEED_CBC_SHA", ShortName: "DH-DSS-SEED-SHA"},
  41. scan/crypto/tls/cfsslscan_common.go:224 0x0098: {Name: "TLS_DH_RSA_WITH_SEED_CBC_SHA", ShortName: "DH-RSA-SEED-SHA"},
  42. scan/crypto/tls/cfsslscan_common.go:225 0x0099: {Name: "TLS_DHE_DSS_WITH_SEED_CBC_SHA", ShortName: "DHE-DSS-SEED-SHA", ForwardSecret: true},
  43. scan/crypto/tls/cfsslscan_common.go:226 0x009A: {Name: "TLS_DHE_RSA_WITH_SEED_CBC_SHA", ShortName: "DHE-RSA-SEED-SHA", ForwardSecret: true},
  44. scan/crypto/tls/cfsslscan_common.go:230 0x009E: {Name: "TLS_DHE_RSA_WITH_AES_128_GCM_SHA256", ShortName: "DHE-RSA-AES128-GCM-SHA256", ForwardSecret: true},
  45. scan/crypto/tls/cfsslscan_common.go:231 0x009F: {Name: "TLS_DHE_RSA_WITH_AES_256_GCM_SHA384", ShortName: "DHE-RSA-AES256-GCM-SHA384", ForwardSecret: true},
  46. scan/crypto/tls/cfsslscan_common.go:232 0x00A0: {Name: "TLS_DH_RSA_WITH_AES_128_GCM_SHA256", ShortName: "DH-RSA-AES128-GCM-SHA256"},
  47. scan/crypto/tls/cfsslscan_common.go:233 0x00A1: {Name: "TLS_DH_RSA_WITH_AES_256_GCM_SHA384", ShortName: "DH-RSA-AES256-GCM-SHA384"},
  48. scan/crypto/tls/cfsslscan_common.go:234 0x00A2: {Name: "TLS_DHE_DSS_WITH_AES_128_GCM_SHA256", ShortName: "DHE-DSS-AES128-GCM-SHA256", ForwardSecret: true},
  49. scan/crypto/tls/cfsslscan_common.go:235 0x00A3: {Name: "TLS_DHE_DSS_WITH_AES_256_GCM_SHA384", ShortName: "DHE-DSS-AES256-GCM-SHA384", ForwardSecret: true},
  50. scan/crypto/tls/cfsslscan_common.go:236 0x00A4: {Name: "TLS_DH_DSS_WITH_AES_128_GCM_SHA256", ShortName: "DH-DSS-AES128-GCM-SHA256"},
  51. scan/crypto/tls/cfsslscan_common.go:237 0x00A5: {Name: "TLS_DH_DSS_WITH_AES_256_GCM_SHA384", ShortName: "DH-DSS-AES256-GCM-SHA384"},
  52. scan/crypto/tls/cfsslscan_common.go:242 0x00AA: {Name: "TLS_DHE_PSK_WITH_AES_128_GCM_SHA256", ForwardSecret: true},
  53. scan/crypto/tls/cfsslscan_common.go:243 0x00AB: {Name: "TLS_DHE_PSK_WITH_AES_256_GCM_SHA384", ForwardSecret: true},
  54. scan/crypto/tls/cfsslscan_common.go:250 0x00B2: {Name: "TLS_DHE_PSK_WITH_AES_128_CBC_SHA256", ForwardSecret: true},
  55. scan/crypto/tls/cfsslscan_common.go:251 0x00B3: {Name: "TLS_DHE_PSK_WITH_AES_256_CBC_SHA384", ForwardSecret: true},
  56. scan/crypto/tls/cfsslscan_common.go:252 0x00B4: {Name: "TLS_DHE_PSK_WITH_NULL_SHA256", ForwardSecret: true},
  57. scan/crypto/tls/cfsslscan_common.go:253 0x00B5: {Name: "TLS_DHE_PSK_WITH_NULL_SHA384", ForwardSecret: true},
  58. scan/crypto/tls/cfsslscan_common.go:259 0x00BB: {Name: "TLS_DH_DSS_WITH_CAMELLIA_128_CBC_SHA256"},
  59. scan/crypto/tls/cfsslscan_common.go:260 0x00BC: {Name: "TLS_DH_RSA_WITH_CAMELLIA_128_CBC_SHA256"},
  60. scan/crypto/tls/cfsslscan_common.go:261 0x00BD: {Name: "TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA256", ForwardSecret: true},
  61. scan/crypto/tls/cfsslscan_common.go:262 0x00BE: {Name: "TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256", ForwardSecret: true},
  62. scan/crypto/tls/cfsslscan_common.go:265 0x00C1: {Name: "TLS_DH_DSS_WITH_CAMELLIA_256_CBC_SHA256"},
  63. scan/crypto/tls/cfsslscan_common.go:266 0x00C2: {Name: "TLS_DH_RSA_WITH_CAMELLIA_256_CBC_SHA256"},
  64. scan/crypto/tls/cfsslscan_common.go:267 0x00C3: {Name: "TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA256", ForwardSecret: true},
  65. scan/crypto/tls/cfsslscan_common.go:268 0x00C4: {Name: "TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256", ForwardSecret: true},
  66. scan/crypto/tls/cfsslscan_common.go:332 0xC03E: {Name: "TLS_DH_DSS_WITH_ARIA_128_CBC_SHA256"},
  67. scan/crypto/tls/cfsslscan_common.go:333 0xC03F: {Name: "TLS_DH_DSS_WITH_ARIA_256_CBC_SHA384"},
  68. scan/crypto/tls/cfsslscan_common.go:334 0xC040: {Name: "TLS_DH_RSA_WITH_ARIA_128_CBC_SHA256"},
  69. scan/crypto/tls/cfsslscan_common.go:335 0xC041: {Name: "TLS_DH_RSA_WITH_ARIA_256_CBC_SHA384"},
  70. scan/crypto/tls/cfsslscan_common.go:336 0xC042: {Name: "TLS_DHE_DSS_WITH_ARIA_128_CBC_SHA256", ForwardSecret: true},
  71. scan/crypto/tls/cfsslscan_common.go:337 0xC043: {Name: "TLS_DHE_DSS_WITH_ARIA_256_CBC_SHA384", ForwardSecret: true},
  72. scan/crypto/tls/cfsslscan_common.go:338 0xC044: {Name: "TLS_DHE_RSA_WITH_ARIA_128_CBC_SHA256", ForwardSecret: true},
  73. scan/crypto/tls/cfsslscan_common.go:339 0xC045: {Name: "TLS_DHE_RSA_WITH_ARIA_256_CBC_SHA384", ForwardSecret: true},
  74. scan/crypto/tls/cfsslscan_common.go:352 0xC052: {Name: "TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256", ForwardSecret: true},
  75. scan/crypto/tls/cfsslscan_common.go:353 0xC053: {Name: "TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384", ForwardSecret: true},
  76. scan/crypto/tls/cfsslscan_common.go:354 0xC054: {Name: "TLS_DH_RSA_WITH_ARIA_128_GCM_SHA256"},
  77. scan/crypto/tls/cfsslscan_common.go:355 0xC055: {Name: "TLS_DH_RSA_WITH_ARIA_256_GCM_SHA384"},
  78. scan/crypto/tls/cfsslscan_common.go:356 0xC056: {Name: "TLS_DHE_DSS_WITH_ARIA_128_GCM_SHA256", ForwardSecret: true},
  79. scan/crypto/tls/cfsslscan_common.go:357 0xC057: {Name: "TLS_DHE_DSS_WITH_ARIA_256_GCM_SHA384", ForwardSecret: true},
  80. scan/crypto/tls/cfsslscan_common.go:358 0xC058: {Name: "TLS_DH_DSS_WITH_ARIA_128_GCM_SHA256"},
  81. scan/crypto/tls/cfsslscan_common.go:359 0xC059: {Name: "TLS_DH_DSS_WITH_ARIA_256_GCM_SHA384"},
  82. scan/crypto/tls/cfsslscan_common.go:372 0xC066: {Name: "TLS_DHE_PSK_WITH_ARIA_128_CBC_SHA256", ForwardSecret: true},
  83. scan/crypto/tls/cfsslscan_common.go:373 0xC067: {Name: "TLS_DHE_PSK_WITH_ARIA_256_CBC_SHA384", ForwardSecret: true},
  84. scan/crypto/tls/cfsslscan_common.go:378 0xC06C: {Name: "TLS_DHE_PSK_WITH_ARIA_128_GCM_SHA256", ForwardSecret: true},
  85. scan/crypto/tls/cfsslscan_common.go:379 0xC06D: {Name: "TLS_DHE_PSK_WITH_ARIA_256_GCM_SHA384", ForwardSecret: true},
  86. scan/crypto/tls/cfsslscan_common.go:394 0xC07C: {Name: "TLS_DHE_RSA_WITH_CAMELLIA_128_GCM_SHA256", ForwardSecret: true},
  87. scan/crypto/tls/cfsslscan_common.go:395 0xC07D: {Name: "TLS_DHE_RSA_WITH_CAMELLIA_256_GCM_SHA384", ForwardSecret: true},
  88. scan/crypto/tls/cfsslscan_common.go:396 0xC07E: {Name: "TLS_DH_RSA_WITH_CAMELLIA_128_GCM_SHA256"},
  89. scan/crypto/tls/cfsslscan_common.go:397 0xC07F: {Name: "TLS_DH_RSA_WITH_CAMELLIA_256_GCM_SHA384"},
  90. scan/crypto/tls/cfsslscan_common.go:398 0xC080: {Name: "TLS_DHE_DSS_WITH_CAMELLIA_128_GCM_SHA256", ForwardSecret: true},
  91. scan/crypto/tls/cfsslscan_common.go:399 0xC081: {Name: "TLS_DHE_DSS_WITH_CAMELLIA_256_GCM_SHA384", ForwardSecret: true},
  92. scan/crypto/tls/cfsslscan_common.go:400 0xC082: {Name: "TLS_DH_DSS_WITH_CAMELLIA_128_GCM_SHA256"},
  93. scan/crypto/tls/cfsslscan_common.go:401 0xC083: {Name: "TLS_DH_DSS_WITH_CAMELLIA_256_GCM_SHA384"},
  94. scan/crypto/tls/cfsslscan_common.go:414 0xC090: {Name: "TLS_DHE_PSK_WITH_CAMELLIA_128_GCM_SHA256", ForwardSecret: true},
  95. scan/crypto/tls/cfsslscan_common.go:415 0xC091: {Name: "TLS_DHE_PSK_WITH_CAMELLIA_256_GCM_SHA384", ForwardSecret: true},
  96. scan/crypto/tls/cfsslscan_common.go:420 0xC096: {Name: "TLS_DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256", ForwardSecret: true},
  97. scan/crypto/tls/cfsslscan_common.go:421 0xC097: {Name: "TLS_DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384", ForwardSecret: true},
  98. scan/crypto/tls/cfsslscan_common.go:428 0xC09E: {Name: "TLS_DHE_RSA_WITH_AES_128_CCM", ForwardSecret: true},
  99. scan/crypto/tls/cfsslscan_common.go:429 0xC09F: {Name: "TLS_DHE_RSA_WITH_AES_256_CCM", ForwardSecret: true},
  100. scan/crypto/tls/cfsslscan_common.go:432 0xC0A2: {Name: "TLS_DHE_RSA_WITH_AES_128_CCM_8", ForwardSecret: true},
  101. scan/crypto/tls/cfsslscan_common.go:433 0xC0A3: {Name: "TLS_DHE_RSA_WITH_AES_256_CCM_8", ForwardSecret: true},
  102. scan/crypto/tls/cfsslscan_common.go:436 0xC0A6: {Name: "TLS_DHE_PSK_WITH_AES_128_CCM", ForwardSecret: true},
  103. scan/crypto/tls/cfsslscan_common.go:437 0xC0A7: {Name: "TLS_DHE_PSK_WITH_AES_256_CCM", ForwardSecret: true},
  104. scan/crypto/tls/cfsslscan_common.go:451 0xCC15: {Name: "TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256", ForwardSecret: true, EllipticCurve: true},
config.cipher-suite · CWE-757
ECDSA384-bitsecg/secp384r1 Quantum-vulnerable 39 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. bundler/testdata/bad-bundle.pem:15 test path -----BEGIN CERTIFICATE-----
  2. bundler/testdata/cfssl-leaf-ecdsa384.pem:1 test path -----BEGIN CERTIFICATE-----
  3. bundler/testdata/inter-L2-direct.pem:1 test path -----BEGIN CERTIFICATE-----
  4. bundler/testdata/inter-L2.pem:1 test path -----BEGIN CERTIFICATE-----
  5. bundler/testdata/intermediates.crt:27 test path -----BEGIN CERTIFICATE-----
  6. bundler/testdata/nss.pem:2542 test path -----BEGIN CERTIFICATE-----
  7. bundler/testdata/nss.pem:3271 test path -----BEGIN CERTIFICATE-----
  8. bundler/testdata/nss.pem:3328 test path -----BEGIN CERTIFICATE-----
  9. bundler/testdata/nss.pem:3389 test path -----BEGIN CERTIFICATE-----
  10. bundler/testdata/nss.pem:4175 test path -----BEGIN CERTIFICATE-----
  11. bundler/testdata/osx.pem:415 test path -----BEGIN CERTIFICATE-----
  12. bundler/testdata/osx.pem:600 test path -----BEGIN CERTIFICATE-----
  13. bundler/testdata/osx.pem:1800 test path -----BEGIN CERTIFICATE-----
  14. bundler/testdata/osx.pem:1859 test path -----BEGIN CERTIFICATE-----
  15. bundler/testdata/osx.pem:2195 test path -----BEGIN CERTIFICATE-----
  16. bundler/testdata/osx.pem:2487 test path -----BEGIN CERTIFICATE-----
  17. bundler/testdata/osx.pem:2631 test path -----BEGIN CERTIFICATE-----
  18. bundler/testdata/osx.pem:4174 test path -----BEGIN CERTIFICATE-----
  19. bundler/testdata/osx.pem:4215 test path -----BEGIN CERTIFICATE-----
  20. bundler/testdata/osx.pem:4256 test path -----BEGIN CERTIFICATE-----
  21. bundler/testdata/osx.pem:4797 test path -----BEGIN CERTIFICATE-----
  22. bundler/testdata/osx.pem:5429 test path -----BEGIN CERTIFICATE-----
  23. bundler/testdata/partial-bundle.pem:15 test path -----BEGIN CERTIFICATE-----
  24. bundler/testdata/reverse-partial-bundle.pem:1 test path -----BEGIN CERTIFICATE-----
  25. helpers/testdata/bundle.pem:1 test path -----BEGIN CERTIFICATE-----
  26. helpers/testdata/bundle_with_whitespace.pem:2 test path -----BEGIN CERTIFICATE-----
  27. transport/roots/system/root_darwin_armx.go:1055 -----BEGIN CERTIFICATE-----
  28. transport/roots/system/root_darwin_armx.go:1256 -----BEGIN CERTIFICATE-----
  29. transport/roots/system/root_darwin_armx.go:1510 -----BEGIN CERTIFICATE-----
  30. transport/roots/system/root_darwin_armx.go:2029 -----BEGIN CERTIFICATE-----
  31. transport/roots/system/root_darwin_armx.go:2141 -----BEGIN CERTIFICATE-----
  32. transport/roots/system/root_darwin_armx.go:2504 -----BEGIN CERTIFICATE-----
  33. transport/roots/system/root_darwin_armx.go:3771 -----BEGIN CERTIFICATE-----
  34. transport/roots/system/root_darwin_armx.go:3997 -----BEGIN CERTIFICATE-----
  35. transport/roots/system/root_darwin_armx.go:4108 -----BEGIN CERTIFICATE-----
  36. transport/roots/system/root_darwin_armx.go:4190 -----BEGIN CERTIFICATE-----
  37. transport/roots/system/root_darwin_armx.go:4389 -----BEGIN CERTIFICATE-----
  38. transport/roots/system/root_darwin_armx.go:4758 -----BEGIN CERTIFICATE-----
  39. ubiquity/testdata/ecdsa384sha2.pem:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
RSA Quantum-vulnerable Recorded traffic 35 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. api/testdata/ca_key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  2. api/testdata/leaf.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  3. bundler/testdata/ca.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  4. bundler/testdata/cfssl-leaf-rsa2048.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  5. bundler/testdata/cfssl-leaf-rsa3072.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  6. bundler/testdata/cfssl-leaf-rsa4096.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  7. bundler/testdata/client-auth/int.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  8. bundler/testdata/client-auth/leaf-client.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  9. bundler/testdata/client-auth/leaf-server.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  10. bundler/testdata/client-auth/root.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  11. bundler/testdata/inter-L1.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  12. cli/gencrl/testdata/ca-keyTwo.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  13. cli/gencsr/testdata/test-key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  14. cli/testdata/ca-key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  15. crl/testdata/ca-key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  16. crl/testdata/ca-keyTwo.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  17. crl/testdata/server.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  18. helpers/testdata/enc_priv_key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  19. helpers/testdata/messed_up_priv_key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  20. helpers/testdata/priv_rsa_key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  21. initca/testdata/5min-rsa-key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  22. multiroot/config/testdata/server.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  23. ocsp/testdata/ca-key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  24. ocsp/testdata/server.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  25. ocsp/testdata/server_broken.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  26. scan/crypto/rsa/pkcs1v15_test.go:279 test path -----BEGIN RSA PRIVATE KEY-----
  27. scan/crypto/tls/handshake_server_test.go:937 test path -----BEGIN RSA PRIVATE KEY-----
  28. scan/crypto/tls/tls_test.go:32 test path -----BEGIN RSA PRIVATE KEY-----
  29. selfsign/testdata/localhost.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  30. signer/local/testdata/key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  31. signer/local/testdata/rsa2048-inter.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  32. signer/remote/testdata/client-key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  33. signer/remote/testdata/server-key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  34. testdata/garbage.key:1 test path -----BEGIN RSA PRIVATE KEY-----
  35. testdata/server.key:1 test path -----BEGIN RSA PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
TLS Quantum-vulnerable Recorded traffic 26 places See details

TLS configuration in code

A `tls.Config` field pinning versions, cipher suites or curve preferences. Every available suite negotiates a classical key exchange.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Every TLS cipher suite in general use negotiates a classical key exchange, so a recorded session is decryptable once that exchange falls.

What to do. Set `MinVersion: tls.VersionTLS13`. Go 1.24 enables the hybrid X25519MLKEM768 group by default, which is the single highest-value change available today.

  1. bundler/bundle_from_remote_test.go:192 test path listener, err := tls.Listen("tcp", "127.0.0.1:0", &tls.Config{
  2. bundler/bundler.go:274 config := &tls.Config{
  3. certinfo/certinfo.go:155 conn, err = tls.DialWithDialer(&net.Dialer{Timeout: 10 * time.Second}, "tcp", net.JoinHostPort(host, port), &tls.Config{InsecureSkipVerify: true})
  4. cli/serve/serve.go:314 tlscfg := tls.Config{}
  5. helpers/helpers.go:525 func CreateTLSConfig(remoteCAs *x509.CertPool, cert *tls.Certificate) *tls.Config {
  6. helpers/helpers.go:530 return &tls.Config{
  7. scan/broad.go:53 config := &tls.Config{InsecureSkipVerify: true}
  8. scan/crypto/tls/example_test.go:50 test path conn, err := tls.Dial("tcp", "mail.google.com:443", &tls.Config{
  9. scan/crypto/tls/handshake_client.go:73 possibleCipherSuites := c.config.cipherSuites()
  10. scan/crypto/tls/handshake_client_test.go:423 test path CipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA, TLS_ECDHE_RSA_WITH_RC4_128_SHA},
  11. scan/crypto/tls/handshake_client_test.go:436 test path CipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA},
  12. scan/crypto/tls/handshake_client_test.go:658 test path CipherSuites: []uint16{TLS_RSA_WITH_AES_128_GCM_SHA256},
  13. scan/crypto/tls/handshake_messages.go:314 numCipherSuites := cipherSuiteLen / 2
  14. scan/crypto/tls/handshake_server.go:191 CipherSuites: hs.clientHello.cipherSuites,
  15. scan/crypto/tls/handshake_server_test.go:57 test path CipherSuites: allCipherSuites(),
  16. scan/crypto/tls/handshake_server_test.go:345 test path CipherSuites: []uint16{TLS_RSA_WITH_RC4_128_SHA, TLS_RSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_RC4_128_SHA},
  17. scan/crypto/tls/handshake_server_test.go:350 test path CipherSuites: []uint16{TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_RC4_128_SHA},
  18. scan/scan_common.go:275 func defaultTLSConfig(hostname string) *tls.Config {
  19. scan/scan_common.go:276 return &tls.Config{
  20. signer/remote/remote_test.go:291 test path ts.TLS = &tls.Config{
  21. transport/client.go:91 return &tls.Config{
  22. transport/client.go:95 CipherSuites: core.CipherSuites,
  23. transport/client.go:111 return &tls.Config{
  24. transport/client.go:116 CipherSuites: core.CipherSuites,
  25. transport/client.go:129 return &tls.Config{
  26. transport/client.go:131 CipherSuites: core.CipherSuites,
go.tls.config · CWE-757
ECDSA256-bitsecg/secp256r1 Quantum-vulnerable 16 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. api/testdata/ca2.pem:1 test path -----BEGIN CERTIFICATE-----
  2. bundler/bundle_from_pem_test.go:227 test path -----BEGIN CERTIFICATE-----
  3. bundler/testdata/bad-bundle.pem:1 test path -----BEGIN CERTIFICATE-----
  4. bundler/testdata/cfssl-leaf-ecdsa256.pem:1 test path -----BEGIN CERTIFICATE-----
  5. bundler/testdata/osx.pem:2618 test path -----BEGIN CERTIFICATE-----
  6. bundler/testdata/partial-bundle.pem:1 test path -----BEGIN CERTIFICATE-----
  7. bundler/testdata/reverse-partial-bundle.pem:24 test path -----BEGIN CERTIFICATE-----
  8. cmd/mkbundle/cert-bundle.crt:327 -----BEGIN CERTIFICATE-----
  9. csr/testdata/test-ecdsa-ca.pem:1 test path -----BEGIN CERTIFICATE-----
  10. helpers/testdata/cert.pem:1 test path -----BEGIN CERTIFICATE-----
  11. helpers/testdata/cert_with_whitespace.pem:2 test path -----BEGIN CERTIFICATE-----
  12. initca/testdata/5min-ecdsa.pem:1 test path -----BEGIN CERTIFICATE-----
  13. signer/local/testdata/ecdsa256_ca.pem:1 test path -----BEGIN CERTIFICATE-----
  14. transport/roots/system/root_darwin_armx.go:703 -----BEGIN CERTIFICATE-----
  15. ubiquity/testdata/ecdsa256sha2.pem:1 test path -----BEGIN CERTIFICATE-----
  16. ubiquity/testdata/macrosoft.pem:35 test path -----BEGIN CERTIFICATE-----
pem.certificate
ECDSA Quantum-vulnerable 13 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. api/testdata/ca2-key.pem:1 test path -----BEGIN EC PRIVATE KEY-----
  2. bundler/testdata/cfssl-leaf-ecdsa256.key:1 test path -----BEGIN EC PRIVATE KEY-----
  3. bundler/testdata/cfssl-leaf-ecdsa384.key:1 test path -----BEGIN EC PRIVATE KEY-----
  4. bundler/testdata/cfssl-leaf-ecdsa521.key:1 test path -----BEGIN EC PRIVATE KEY-----
  5. bundler/testdata/inter-L2.key:1 test path -----BEGIN EC PRIVATE KEY-----
  6. helpers/testdata/openssl_secp384.pem:4 test path -----BEGIN EC PRIVATE KEY-----
  7. helpers/testdata/private_ecdsa_key.pem:1 test path -----BEGIN EC PRIVATE KEY-----
  8. helpers/testdata/secp256k1-key.pem:1 test path -----BEGIN EC PRIVATE KEY-----
  9. initca/testdata/5min-ecdsa-key.pem:1 test path -----BEGIN EC PRIVATE KEY-----
  10. scan/crypto/tls/handshake_server_test.go:972 test path -----BEGIN EC PRIVATE KEY-----
  11. scan/crypto/tls/tls_test.go:74 test path -----BEGIN EC PRIVATE KEY-----
  12. signer/local/testdata/ecdsa256-inter.key:1 test path -----BEGIN EC PRIVATE KEY-----
  13. signer/local/testdata/ecdsa256_ca_key.pem:1 test path -----BEGIN EC PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
RSA2048-bit Quantum-vulnerable 10 places See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

  1. bundler/testdata/cfssl-leaf-rsa2048.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  2. cli/testdata/ca.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  3. helpers/testdata/rsa-old.csr:1 test path -----BEGIN NEW CERTIFICATE REQUEST-----
  4. helpers/testdata/test.csr.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  5. initca/testdata/rsa2048.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  6. signer/local/testdata/rsa-old.csr:1 test path -----BEGIN NEW CERTIFICATE REQUEST-----
  7. signer/local/testdata/rsa2048-inter.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  8. signer/local/testdata/rsa2048.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  9. signer/local/testdata/san_domain.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  10. signer/local/testdata/test.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
pem.certificate-request
ECDSA256-bitsecg/secp256r1 Quantum-vulnerable 9 places See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

  1. bundler/testdata/cfssl-leaf-ecdsa256.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  2. helpers/testdata/ecdsa256.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  3. initca/testdata/ecdsa256.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  4. selfsign/testdata/sans.csr:24 test path -----BEGIN CERTIFICATE REQUEST-----
  5. signer/local/testdata/ecdsa256-inter.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  6. signer/local/testdata/ecdsa256.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  7. signer/local/testdata/inter_pathlen_0.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  8. signer/local/testdata/inter_pathlen_1.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  9. signer/local/testdata/inter_pathlen_unspecified.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
pem.certificate-request
RSA Quantum-vulnerable Recorded traffic 7 places See details

RSA in the Go standard library

`rsa.GenerateKey()`, `rsa.SignPKCS1v15()`, `rsa.EncryptOAEP()` or an import of `crypto/rsa`.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-KEM-768 for encryption, ML-DSA-65 for signatures. Go 1.24 ships ML-KEM as `crypto/mlkem`.

  1. csr/csr.go:81 return rsa.GenerateKey(rand.Reader, kr.Size())
  2. helpers/helpers_test.go:102 test path rsaPriv, _ := rsa.GenerateKey(rand.Reader, 256)
  3. scan/crypto/tls/generate_cert.go:90 priv, err = rsa.GenerateKey(rand.Reader, *rsaBits)
  4. scan/crypto/tls/handshake_server.go:530 err = rsa.VerifyPKCS1v15(key, hashFunc, digest, certVerify.signature)
  5. scan/crypto/tls/key_agreement.go:76 encrypted, err := rsa.EncryptPKCS1v15(config.rand(), cert.PublicKey.(*rsa.PublicKey), preMasterSecret)
  6. scan/crypto/tls/key_agreement.go:374 if err := rsa.VerifyPKCS1v15(pubKey, hashFunc, digest, sig); err != nil {
  7. transport/kp/key_provider.go:204 priv, err = rsa.GenerateKey(rand.Reader, size)
go.rsa · CWE-327
RSA3072-bit Quantum-vulnerable 6 places See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

  1. auth/testdata/request.json:3 test path -----BEGIN CERTIFICATE REQUEST-----
  2. bundler/testdata/cfssl-leaf-rsa3072.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  3. initca/testdata/rsa3072.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  4. selfsign/testdata/extension.csr:71 test path -----BEGIN CERTIFICATE REQUEST-----
  5. selfsign/testdata/localhost.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  6. signer/local/testdata/rsa3072.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
pem.certificate-request
ECDSA384-bitsecg/secp384r1 Quantum-vulnerable 5 places See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

  1. api/testdata/csr.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  2. bundler/testdata/cfssl-leaf-ecdsa384.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  3. bundler/testdata/inter-L2.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  4. initca/testdata/ecdsa384.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  5. signer/local/testdata/ecdsa384.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
pem.certificate-request
ECDSA256-bitsecg/secp256r1 Quantum-vulnerable 5 places See details

ECDSA in the Go standard library

`ecdsa.GenerateKey()` or `ecdsa.Sign*()`. The curve is read from the `elliptic.P###()` argument.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 (FIPS 204).

  1. bundler/bundle_from_remote_test.go:236 test path leafKey, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
  2. scan/crypto/tls/generate_cert.go:96 priv, err = ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
  3. signer/local/local.go:79 k, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
  4. signer/local/local_test.go:1493 test path k, _ := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
  5. signer/local/local_test.go:1644 test path key, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
go.ecdsa · CWE-327
Ed25519255-bitother/Ed25519 Quantum-vulnerable 5 places See details

JOSE algorithm declared in configuration

An `alg` value in JSON or YAML. `none` is reported as a critical defect; HS* is an HMAC and is not quantum-vulnerable; RS*, PS*, ES* and EdDSA are.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. No standardised post-quantum JOSE algorithm exists yet. Keep token lifetimes short.

  1. bundler/bundle.go:114 keyType = "Ed25519"
  2. helpers/helpers.go:158 return "Ed25519"
  3. helpers/helpers.go:193 return "Ed25519"
  4. helpers/helpers_test.go:233 test path if HashAlgoString(x509.PureEd25519) != "Ed25519" {
  5. helpers/helpers_test.go:278 test path if SignatureString(x509.PureEd25519) != "Ed25519" {
jose.algorithm · CWE-327
Ed25519255-bitother/Ed25519 Quantum-vulnerable 5 places See details

Ed25519 in the Go standard library

`ed25519.GenerateKey()` or `ed25519.Sign()`.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 (FIPS 204). Go 1.24 ships ML-DSA as `crypto/mldsa`.

  1. csr/csr.go:100 return ed25519.NewKeyFromSeed(seed), nil
  2. helpers/derhelpers/ed25519.go:131 return ed25519.NewKeyFromSeed(*seed), nil
  3. helpers/helpers_test.go:112 test path _, ed25519priv, _ := ed25519.GenerateKey(rand.Reader)
  4. scan/crypto/tls/generate_cert.go:92 _, priv, err = ed25519.GenerateKey(rand.Reader)
  5. transport/kp/key_provider.go:253 priv := ed25519.NewKeyFromSeed(seed)
go.ed25519 · CWE-327
RSA4096-bit Quantum-vulnerable 5 places See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

  1. api/testdata/broken_csr.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  2. bundler/testdata/cfssl-leaf-rsa4096.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  3. bundler/testdata/inter-L1.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  4. initca/testdata/rsa4096.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  5. signer/local/testdata/rsa4096.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
pem.certificate-request
ECDSA521-bitsecg/secp521r1 Quantum-vulnerable 4 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. bundler/testdata/cfssl-leaf-ecdsa521.pem:1 test path -----BEGIN CERTIFICATE-----
  2. scan/crypto/tls/handshake_server_test.go:954 test path -----BEGIN CERTIFICATE-----
  3. scan/crypto/tls/tls_test.go:56 test path -----BEGIN CERTIFICATE-----
  4. ubiquity/testdata/ecdsa521sha2.pem:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
ECDSA Quantum-vulnerable 4 places See details

ECDSA in the Go standard library

`ecdsa.GenerateKey()` or `ecdsa.Sign*()`. The curve is read from the `elliptic.P###()` argument.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 (FIPS 204).

  1. csr/csr.go:94 return ecdsa.GenerateKey(curve, rand.Reader)
  2. scan/crypto/tls/handshake_server.go:517 if !ecdsa.Verify(key, digest, ecdsaSig.R, ecdsaSig.S) {
  3. scan/crypto/tls/key_agreement.go:366 if !ecdsa.Verify(pubKey, digest, ecdsaSig.R, ecdsaSig.S) {
  4. transport/kp/key_provider.go:230 priv, err = ecdsa.GenerateKey(curve, rand.Reader)
go.ecdsa · CWE-327
RSA2048-bit Quantum-vulnerable Recorded traffic 4 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. api/generator/testdata/ca_key.pem:1 test path -----BEGIN PRIVATE KEY-----
  2. helpers/testdata/ca_key.pem:1 test path -----BEGIN PRIVATE KEY-----
  3. signer/local/testdata/ca_key.pem:1 test path -----BEGIN PRIVATE KEY-----
  4. signer/remote/testdata/ca_key.pem:1 test path -----BEGIN PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
ECDSA521-bitsecg/secp521r1 Quantum-vulnerable 3 places See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

  1. bundler/testdata/cfssl-leaf-ecdsa521.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  2. initca/testdata/ecdsa521.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  3. signer/local/testdata/ecdsa521.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
pem.certificate-request
RSA2048-bit Quantum-vulnerable Recorded traffic 3 places See details

RSA in the Go standard library

`rsa.GenerateKey()`, `rsa.SignPKCS1v15()`, `rsa.EncryptOAEP()` or an import of `crypto/rsa`.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-KEM-768 for encryption, ML-DSA-65 for signatures. Go 1.24 ships ML-KEM as `crypto/mlkem`.

  1. api/certadd/insert_test.go:58 test path privKey, err := rsa.GenerateKey(rand.Reader, 2048)
  2. api/revoke/revoke_test.go:129 test path privKey, err := rsa.GenerateKey(rand.Reader, 2048)
  3. certinfo/certinfo_test.go:110 test path key, err := rsa.GenerateKey(rand.Reader, 2048)
go.rsa · CWE-327
EC Quantum-vulnerable 2 places See details

X.509 certificate handling

`x509.CreateCertificate()` or a PKCS#1/PKCS#8/EC key parser. Certificates are the longest-lived cryptographic artefacts most systems own, and their validity periods often outrun the migration.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. An elliptic-curve key pair. The source does not say whether it signs or agrees a shared secret, and the curve alone cannot: the same curve serves both.

What to do. Shorten certificate lifetimes now so the eventual re-issue with a post-quantum key is routine rather than an incident.

  1. helpers/derhelpers/derhelpers.go:22 generalKey, err = x509.ParseECPrivateKey(keyDER)
  2. scan/crypto/tls/tls.go:293 if key, err := x509.ParseECPrivateKey(der); err == nil {
go.x509
ECDSA224-bitsecg/secp224r1 Quantum-vulnerable 2 places See details

ECDSA in the Go standard library

`ecdsa.GenerateKey()` or `ecdsa.Sign*()`. The curve is read from the `elliptic.P###()` argument.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 (FIPS 204).

  1. helpers/helpers_test.go:93 test path ecdsaPriv, _ := ecdsa.GenerateKey(elliptic.P224(), rand.Reader)
  2. scan/crypto/tls/generate_cert.go:94 priv, err = ecdsa.GenerateKey(elliptic.P224(), rand.Reader)
go.ecdsa · CWE-327
Ed25519255-bitother/Ed25519 Quantum-vulnerable 2 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. helpers/derhelpers/ed25519_test.go:15 test path -----BEGIN PRIVATE KEY-----
  2. helpers/testdata/private_ed25519_key.pem:1 test path -----BEGIN PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
Ed25519255-bitother/Ed25519 Quantum-vulnerable 2 places See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

  1. initca/testdata/ed25519.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
  2. signer/local/testdata/ed25519.csr:1 test path -----BEGIN CERTIFICATE REQUEST-----
pem.certificate-request
RSA3072-bit Quantum-vulnerable 2 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. bundler/testdata/cfssl-leaf-rsa3072.pem:1 test path -----BEGIN CERTIFICATE-----
  2. ubiquity/testdata/rsa3072sha2.pem:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
DSA Quantum-vulnerable 1 place See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. bundler/testdata/dsa2048.key:1 test path -----BEGIN PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
DSA Quantum-vulnerable 1 place See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. bundler/testdata/dsa2048.pem:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
ECDSA384-bitsecg/secp384r1 Quantum-vulnerable 1 place See details

ECDSA in the Go standard library

`ecdsa.GenerateKey()` or `ecdsa.Sign*()`. The curve is read from the `elliptic.P###()` argument.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 (FIPS 204).

  1. scan/crypto/tls/generate_cert.go:98 priv, err = ecdsa.GenerateKey(elliptic.P384(), rand.Reader)
go.ecdsa · CWE-327
ECDSA521-bitsecg/secp521r1 Quantum-vulnerable 1 place See details

ECDSA in the Go standard library

`ecdsa.GenerateKey()` or `ecdsa.Sign*()`. The curve is read from the `elliptic.P###()` argument.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 (FIPS 204).

  1. scan/crypto/tls/generate_cert.go:100 priv, err = ecdsa.GenerateKey(elliptic.P521(), rand.Reader)
go.ecdsa · CWE-327
Ed25519255-bitother/Ed25519 Quantum-vulnerable 1 place See details

Public key file

A PEM public-key block. The algorithm is read from the SubjectPublicKeyInfo.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Inventory only; a public key is not itself a secret.

  1. helpers/derhelpers/ed25519_test.go:10 test path -----BEGIN PUBLIC KEY-----
pem.public-key
Ed25519255-bitother/Ed25519 Quantum-vulnerable 1 place See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. initca/testdata/5min-ed25519.pem:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
AES Reduced margin 5 places See details

AES block cipher

`aes.NewCipher(key)`. Not broken by a quantum computer; the key length is what matters.

This is the kind of encryption that quantum computers do not break.

What to do. Use a 32-byte key. No change of algorithm is required.

  1. scan/crypto/rsa/example_test.go:64 test path block, err := aes.NewCipher(key)
  2. scan/crypto/tls/cipher_suites.go:111 block, _ := aes.NewCipher(key)
  3. scan/crypto/tls/cipher_suites.go:160 aes, err := aes.NewCipher(key)
  4. scan/crypto/tls/ticket.go:148 block, err := aes.NewCipher(key.aesKey[:])
  5. scan/crypto/tls/ticket.go:193 block, err := aes.NewCipher(key.aesKey[:])
go.aes
unknown Could not be determined 23 places See details

X.509 certificate handling

`x509.CreateCertificate()` or a PKCS#1/PKCS#8/EC key parser. Certificates are the longest-lived cryptographic artefacts most systems own, and their validity periods often outrun the migration.

The algorithm could not be established from the source. Usually it is selected while the program runs, but it may equally be that the call gives no clue, or that it is decided somewhere this scan does not reach. Somebody has to check.

What to do. Shorten certificate lifetimes now so the eventual re-issue with a post-quantum key is routine rather than an incident.

  1. api/certadd/insert_test.go:99 test path issuerBytes, err := x509.CreateCertificate(rand.Reader, &issuerTemplate, &issuerTemplate, &privKey.PublicKey, privKey)
  2. api/certadd/insert_test.go:115 test path responderBytes, err := x509.CreateCertificate(rand.Reader, &responderTemplate, &responderTemplate, &privKey.PublicKey, privKey)
  3. api/certadd/insert_test.go:129 test path derBytes, err := x509.CreateCertificate(rand.Reader, &template, issuer, &privKey.PublicKey, privKey)
  4. api/revoke/revoke_test.go:150 test path issuerBytes, err := x509.CreateCertificate(rand.Reader, &issuerTemplate, &issuerTemplate, &privKey.PublicKey, privKey)
  5. api/revoke/revoke_test.go:171 test path revokedBytes, err := x509.CreateCertificate(rand.Reader, &revokedTemplate, issuer, &privKey.PublicKey, privKey)
  6. api/revoke/revoke_test.go:196 test path responderBytes, err := x509.CreateCertificate(rand.Reader, &responderTemplate, &responderTemplate, &privKey.PublicKey, privKey)
  7. bundler/bundle_from_remote_test.go:251 test path leafDER, err := x509.CreateCertificate(rand.Reader, template, issuer, &leafKey.PublicKey, issuerKey)
  8. certdb/ocspstapling/ocspstapling_test.go:151 test path der, err := x509.CreateCertificate(rand.Reader, &template, issuer, privKey.Public(), privKey)
  9. certinfo/certinfo_test.go:128 test path certificate, err := x509.CreateCertificate(rand.Reader, cert, cert, &key.PublicKey, key)
  10. csr/csr.go:408 return x509.CreateCertificateRequest(rand.Reader, req, priv)
  11. csr/csr.go:463 csr, err = x509.CreateCertificateRequest(rand.Reader, &tpl, priv)
  12. helpers/derhelpers/derhelpers.go:18 generalKey, err := x509.ParsePKCS8PrivateKey(keyDER)
  13. helpers/derhelpers/derhelpers.go:20 generalKey, err = x509.ParsePKCS1PrivateKey(keyDER)
  14. initca/initca.go:256 cert, err = x509.CreateCertificate(rand.Reader, copy, copy, priv.Public(), priv)
  15. scan/crypto/tls/generate_cert.go:155 derBytes, err := x509.CreateCertificate(rand.Reader, &template, &template, publicKey(priv), priv)
  16. scan/crypto/tls/tls.go:282 if key, err := x509.ParsePKCS1PrivateKey(der); err == nil {
  17. scan/crypto/tls/tls.go:285 if key, err := x509.ParsePKCS8PrivateKey(der); err == nil {
  18. selfsign/selfsign.go:139 cert, err := x509.CreateCertificate(rand.Reader, template, template, pub, priv)
  19. signer/local/local.go:169 prelintBytes, err := x509.CreateCertificate(rand.Reader, &template, s.ca, template.PublicKey, s.lintPriv)
  20. signer/local/local.go:210 derBytes, err := x509.CreateCertificate(rand.Reader, template, s.ca, template.PublicKey, s.priv)
  21. signer/local/local_test.go:1519 test path issuerDer, _ := x509.CreateCertificate(rand.Reader, jankyTemplate, jankyTemplate, k.Public(), k)
  22. signer/local/local_test.go:1655 test path csrDER, err := x509.CreateCertificateRequest(rand.Reader, tmpl, key)
  23. transport/kp/key_provider.go:403 return x509.CreateCertificateRequest(rand.Reader, tpl, sp.internal.priv)
go.x509
unknown Could not be determined 9 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. api/testdata/broken.pem:1 test path -----BEGIN CERTIFICATE-----
  2. bundler/bundle_from_pem_test.go:132 test path -----BEGIN CERTIFICATE-----
  3. bundler/bundle_from_pem_test.go:163 test path -----BEGIN CERTIFICATE-----
  4. bundler/bundle_from_pem_test.go:253 test path -----BEGIN CERTIFICATE-----
  5. helpers/testdata/emptycert.pem:1 test path -----BEGIN CERTIFICATE-----
  6. helpers/testdata/messed_up_bundle.pem:1 test path -----BEGIN CERTIFICATE-----
  7. helpers/testdata/messedupcert.pem:1 test path -----BEGIN CERTIFICATE-----
  8. ocsp/testdata/server_broken.crt:1 test path -----BEGIN CERTIFICATE-----
  9. testdata/garbage.crt:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
SEED Could not be determined 5 places See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. scan/crypto/tls/cfsslscan_common.go:222 0x0096: {Name: "TLS_RSA_WITH_SEED_CBC_SHA", ShortName: "SEED-SHA"},
  2. scan/crypto/tls/cfsslscan_common.go:223 0x0097: {Name: "TLS_DH_DSS_WITH_SEED_CBC_SHA", ShortName: "DH-DSS-SEED-SHA"},
  3. scan/crypto/tls/cfsslscan_common.go:224 0x0098: {Name: "TLS_DH_RSA_WITH_SEED_CBC_SHA", ShortName: "DH-RSA-SEED-SHA"},
  4. scan/crypto/tls/cfsslscan_common.go:225 0x0099: {Name: "TLS_DHE_DSS_WITH_SEED_CBC_SHA", ShortName: "DHE-DSS-SEED-SHA", ForwardSecret: true},
  5. scan/crypto/tls/cfsslscan_common.go:226 0x009A: {Name: "TLS_DHE_RSA_WITH_SEED_CBC_SHA", ShortName: "DHE-RSA-SEED-SHA", ForwardSecret: true},
config.cipher-suite · CWE-757
IDEA Could not be determined 1 place See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. scan/crypto/tls/cfsslscan_common.go:135 0x0007: {Name: "TLS_RSA_WITH_IDEA_CBC_SHA", ShortName: "IDEA-CBC-SHA"},
config.cipher-suite · CWE-757
RC2 Could not be determined 1 place See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. scan/crypto/tls/cfsslscan_common.go:134 0x0006: {Name: "TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5", ShortName: "EXP-RC2-CBC-MD5"},
config.cipher-suite · CWE-757
unknown Could not be determined 1 place See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

  1. helpers/testdata/test.bad.csr.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
pem.certificate-request
unknown Could not be determined 1 place See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. scan/crypto/tls/tls_test.go:45 test path -----BEGIN PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
unknown Could not be determined 1 place See details

Cryptographic library in the dependency manifest

A dependency known to implement classical asymmetric cryptography. Its presence is inventory, not a finding about this codebase: the library may never be called with a quantum-vulnerable algorithm.

The project depends on a cryptography library. Listed so the inventory is complete; it is not by itself a problem.

What to do. Check the version. Several of these libraries have shipped ML-KEM and ML-DSA support since 2024, so the migration may need an upgrade rather than a replacement.

  1. go.mod:19 golang.org/x/crypto v0.21.0
dep.crypto-library
CSPRNG Quantum-safe 7 places See details

Random number generation

`crypto/rand`. Recorded so the inventory names its randomness source. `math/rand` reaching key material would be a present-day defect, and is a different thing entirely.

This is where the software gets its random numbers. Quantum computers do not weaken it.

What to do. No action.

  1. api/certadd/insert_test.go:64 test path serialNumber, err = rand.Int(rand.Reader, serialNumberRange)
  2. api/revoke/revoke_test.go:136 test path issuerSerial, err := rand.Int(rand.Reader, serialNumberRange)
  3. scan/crypto/md5/md5_test.go:113 test path rand.Read(buf)
  4. scan/crypto/rsa/rsa.go:237 primes[i], err = rand.Prime(random, todo/(nprimes-i))
  5. scan/crypto/sha1/sha1_test.go:98 test path rand.Read(buf)
  6. scan/crypto/tls/generate_cert.go:123 serialNumber, err := rand.Int(rand.Reader, serialNumberLimit)
  7. selfsign/selfsign.go:113 serialNumber, err := rand.Int(rand.Reader, new(big.Int).SetInt64(math.MaxInt64))
go.rng
HMAC Quantum-safe 4 places See details

Keyed hash in use

`hmac.New()`. Not broken by Shor and only marginally affected by Grover.

This is a fingerprint proving a message was not altered. Quantum computers do not break it.

What to do. No action, unless the digest is MD5 or SHA-1.

  1. auth/auth.go:74 h := hmac.New(sha256.New, p.key)
  2. scan/crypto/tls/cipher_suites.go:128 return tls10MAC{hmac.New(sha1.New, key)}
  3. scan/crypto/tls/prf.go:27 h := hmac.New(hash, secret)
  4. scan/crypto/tls/ticket.go:154 mac := hmac.New(sha256.New, key.hmacKey[:])
go.hmac

Cryptographic assets

Algorithm Assessment What it means Occurrences
RSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 685
ECDH Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 192
ECDSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 140
unknown Could not be determined The algorithm could not be established from the source - chosen at runtime, or decided somewhere this scan does not reach. 118
RSA-1024 Already broken A modulus of 1024 bits or less is below the NIST SP 800-57 floor and is within reach of classical factorisation. Shor is not the nearest problem here. 112
DH Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 104
RSAES-PKCS1v15 Already broken PKCS#1 v1.5 encryption padding is vulnerable to Bleichenbacher oracles today, and the underlying RSA is broken by Shor. 90
TLS Quantum-vulnerable Every TLS cipher suite in general use negotiates a classical key exchange, so a recorded session is decryptable once that exchange falls. 41
RC4 Already broken RC4 keystream biases break it classically; it is prohibited in TLS by RFC 7465. 37
SHA-1 Already broken SHAttered and subsequent work produced practical collisions; NIST withdrew SHA-1 in 2030 guidance and it is already unacceptable for signatures. 31
CSPRNG Quantum-safe A cryptographically secure random number generator provided by the platform. Not weakened by a quantum computer. 31
Ed25519 Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 30
3DES Already broken Triple DES is withdrawn by NIST and limited by its 64-bit block, independent of quantum. 22
NULL Already broken A NULL cipher provides no confidentiality at all: the session is authenticated and then sent in the clear. No quantum computer is needed to read it. 18
MD5 Already broken Practical chosen-prefix collisions exist; MD5 has no remaining security as a digest. 14
AES Reduced margin Grover's algorithm halves the effective strength; the parameter, not the design, is the problem. The key size was not visible at this call site, so the weaker case is assumed. 12
SHA-256 Reduced margin Pre-image resistance falls to about 128 bits of quantum work. Adequate for most uses; SHA-384 restores the full margin where a signature must last decades. 9
DES Already broken A 56-bit key is brute-forced classically in hours. 8
HMAC Quantum-safe A keyed MAC is not affected by Shor and only marginally by Grover. 8
EC Quantum-vulnerable An elliptic-curve key pair. The source does not say whether it signs or agrees a shared secret, and the curve alone cannot: the same curve serves both. 2
DSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 2
SHA-512 Quantum-safe No known quantum algorithm changes the security margin. 2

Imported cryptographic libraries

Library Files
crypto/sha1 the SHA-1 digest, which has practical collisions 11
crypto/md5 the MD5 digest, which has practical collisions 5
crypto/des DES and Triple DES, both withdrawn 1
crypto/rc4 RC4, prohibited in TLS by RFC 7465 1
crypto/ecdsa elliptic-curve signatures 24
crypto/rsa RSA key generation, signing and OAEP encryption 27
crypto/tls the TLS client and server 15
crypto/ed25519 Edwards-curve signatures 14
crypto/sha256 the SHA-2 digests 9
crypto/aes the AES block cipher 4
crypto/x509 certificate and key parsing 77
crypto/rand the platform random source 24
crypto/hmac keyed message authentication 4
crypto/sha512 the SHA-2 digests 2