RSA Quantum-vulnerable Recorded traffic 4 places See details
Private key committed to the repository
A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.
A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.
What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.
-
src/test/resources/keys/pkcs1/test_key_pkcs1-1024.pem:1
test path
-----BEGIN RSA PRIVATE KEY----- -
src/test/resources/keys/pkcs1/test_key_pkcs1-2048.pem:1
test path
-----BEGIN RSA PRIVATE KEY----- -
src/test/resources/keys/pkcs1/test_key_pkcs1-4096.pem:1
test path
-----BEGIN RSA PRIVATE KEY----- -
src/test/resources/keys/pkcs1/test_key_pkcs1-512.pem:1
test path
-----BEGIN RSA PRIVATE KEY-----