Crypto-View

NixOS/nixpkgs

Readiness score
10 of 100
How this is calculated · previous scan 58
Cryptographic posture
Quantum-vulnerable 142 Reduced margin 27 Could not be determined 12 Quantum-safe 12
To address151
Key establishment40
Inventory only1
Total findings194
What was analysed
Branch master
Commit 6a18e3b76092b0dc1d92e4b709032a10848a3280 txm: add versionCheckHook (#560767)
Committed 2026-09-10 22:02 UTC
Scanned 2026-09-10 22:15 UTC 4 hours ago
Coverage 46482 files, 5 go, 4 java, 296 python, 49 javascript

Earlier scans of this repository

11 scans · score 56 → 10 · compare any two
11 scans · 56 → 10 (down 46). The filled point is the scan you are reading.
Scanned Commit Score To address
4 hours ago this scan 6a18e3b76092 master 10 151
5 hours ago 344b92fce990 master 58 31 Compare
21 hours ago 43a6c5d46f43 master 58 31 Compare
1 day ago 64b13628c177 master 58 31 Compare
1 day ago bac851da1b95 master 58 31 Compare
1 day ago a1e0b4ab0f2f master 58 31 Compare
1 day ago 425014edadcb master 58 31 Compare
3 days ago 39135594a8d6 master 56 31 Compare
3 days ago b58f9caee9c7 master 56 31 Compare
4 days ago 94aa2762715b master 56 31 Compare
8 days ago 3ed67ec0a4d3 master 56 31 Compare

Every repository in this history is re-scanned weekly.

List of cryptographic assets

Ed25519255-bitother/Ed25519 Quantum-vulnerable 28 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

  1. doc/styleguide.md:175 - Abbreviate keys like `ssh-ed25519 AAAAC3NzaC…`
  2. nixos/doc/manual/configuration/ssh.section.md:18 users.users.alice.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAB3NzaC1kc3MAAACBAPIkGWVEt4..." ];
  3. nixos/modules/profiles/keys/ssh_host_ed25519_key.pub:1 ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJBWcxb/Blaqt1auOtE+F8QUWrUotiC5qBJ+UuEWdVCb root@nixos
  4. nixos/modules/programs/ssh.nix:96 "ssh-ed25519"
  5. nixos/modules/programs/ssh.nix:108 "ssh-ed25519"
  6. nixos/modules/programs/ssh.nix:245 "myhost2.net".publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILIRuJ8p1Fi+m6WkHV0KWnRfpM1WxoW8XAS+XvsSKsTK";
  7. nixos/modules/programs/ssh.nix:269 github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
  8. nixos/modules/services/backup/borgbackup.md:60 ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID78zmOyA+5uPG4Ot0hfAy+sLDPU1L4AiIoRYEIVbbQ/ root@nixos
  9. nixos/modules/services/backup/borgbackup.md:69 "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID78zmOyA+5uPG4Ot0hfAy+sLDPU1L4AiIoRYEIVbbQ/ root@nixos"
  10. nixos/modules/services/misc/radicle.nix:209 install -D -m 644 /dev/stdin keys/radicle.pub <<<"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBgFMhajUng+Rjj/sCFXI9PzG8BQjru2n7JgUVF1Kbv5 snakeoil"
  11. nixos/modules/services/networking/ssh/sshd.nix:113 "ssh-ed25519 AAAAC3NzaCetcetera/etceteraJZMfk3QPfQ foo@bar"
  12. nixos/modules/system/boot/initrd-ssh.nix:109 "ssh-ed25519 AAAAC3NzaCetcetera/etceteraJZMfk3QPfQ foo@bar"
  13. nixos/tests/borgbackup.nix:27 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHHxQHThDpD9/AMWNqQer3Tg9gXMb2lTZMn0pelo8xyv root@client
  14. nixos/tests/borgbackup.nix:39 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFpxm7PUQsZB2Ejs8Xp0YVp8IOW+HylIRzhweORbRCMv root@client
  15. nixos/tests/btrbk-doas.nix:14 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHHxQHThDpD9/AMWNqQer3Tg9gXMb2lTZMn0pelo8xyv
  16. nixos/tests/btrbk.nix:14 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHHxQHThDpD9/AMWNqQer3Tg9gXMb2lTZMn0pelo8xyv
  17. nixos/tests/gitolite-fcgiwrap.nix:9 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO7urFhAA90BTpGuEHeWWTY3W/g9PBxXNxfWhfbrm4Le root@client
  18. nixos/tests/gitolite.nix:15 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO7urFhAA90BTpGuEHeWWTY3W/g9PBxXNxfWhfbrm4Le root@client
  19. nixos/tests/gitolite.nix:29 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFt5a8eH8BYZYjoQhzXGVKKHJe1pw1D0p7O2Vb9VTLzB alice@client
  20. nixos/tests/gitolite.nix:43 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJZNonUP1ePHLrvn0W9D2hdN6zWWZYFyJc+QR6pOKQEw bob@client
  21. nixos/tests/initrd-network-ssh/id_ed25519.pub:1 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBVxf7fZiqKDblHFEDxt6X9/rTjBXSn/re6b46S7/e9/ nixbld@localhost
  22. nixos/tests/initrd-network-ssh/ssh_host_ed25519_key.pub:1 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIM/0zPqqXF1CoDiiauBs6VWzFIY40Imy2Nb3Oqq5qOUg nixbld@localhost
  23. nixos/tests/sftpgo.nix:323 test path publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIE61C7pTXfnLG2u9So+ijNTKaSOg009UrquqNL3fpEu1";
  24. nixos/tests/ssh-audit.nix:43 test path "sk-ssh-ed25519-cert-v01@openssh.com"
  25. nixos/tests/ssh-audit.nix:44 test path "sk-ssh-ed25519@openssh.com"
  26. nixos/tests/ssh-audit.nix:45 test path "ssh-ed25519"
  27. nixos/tests/ssh-audit.nix:46 test path "ssh-ed25519-cert-v01@openssh.com"
  28. nixos/tests/ssh-keys.nix:34 test path snakeOilEd25519PublicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDPQXmEVMVLmeFRyafKMVWgPDkv8/uRBTwmcEDatZzMD snakeoil";
config.ssh-algorithms · CWE-757
Ed25519ed25519 Quantum-vulnerable 21 places See details

SSH public key

An `ssh-rsa`, `ecdsa-sha2-*`, `ssh-ed25519` or `ssh-dss` key. `ssh-dss` is disabled by default in current OpenSSH and is reported as broken.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Replace `ssh-dss` now. For the rest, enable the `sntrup761x25519-sha512` key exchange, which protects recorded sessions even while host keys stay classical.

  1. nixos/doc/manual/configuration/ssh.section.md:18 users.users.alice.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAB3NzaC1kc3MAA
  2. nixos/modules/profiles/keys/ssh_host_ed25519_key.pub:1 ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJBWcxb/Blaqt1auOtE+F8QUWrUotiC5qBJ+UuEWdVCb
  3. nixos/modules/programs/ssh.nix:245 "myhost2.net".publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILIRuJ8p1Fi+m6WkH
  4. nixos/modules/programs/ssh.nix:269 github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okW
  5. nixos/modules/services/backup/borgbackup.md:60 ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID78zmOyA+5uPG4Ot0hfAy+sLDPU1L4AiIoRYEIVbbQ/
  6. nixos/modules/services/backup/borgbackup.md:69 "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID78zmOyA+5uPG4Ot0hfAy+sLDPU1L4AiIoRYEIVbbQ
  7. nixos/modules/services/misc/radicle.nix:209 install -D -m 644 /dev/stdin keys/radicle.pub <<<"ssh-ed25519 AAAAC3NzaC1lZDI1NT
  8. nixos/modules/services/networking/ssh/sshd.nix:113 "ssh-ed25519 AAAAC3NzaCetcetera/etceteraJZMfk3QPfQ foo@bar"
  9. nixos/modules/system/boot/initrd-ssh.nix:109 "ssh-ed25519 AAAAC3NzaCetcetera/etceteraJZMfk3QPfQ foo@bar"
  10. nixos/tests/borgbackup.nix:27 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHHxQHThDpD9/AMWNqQer3Tg9gXMb2lTZMn0pelo8xyv
  11. nixos/tests/borgbackup.nix:39 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFpxm7PUQsZB2Ejs8Xp0YVp8IOW+HylIRzhweORbRCMv
  12. nixos/tests/btrbk-doas.nix:14 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHHxQHThDpD9/AMWNqQer3Tg9gXMb2lTZMn0pelo8xyv
  13. nixos/tests/btrbk.nix:14 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHHxQHThDpD9/AMWNqQer3Tg9gXMb2lTZMn0pelo8xyv
  14. nixos/tests/gitolite-fcgiwrap.nix:9 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO7urFhAA90BTpGuEHeWWTY3W/g9PBxXNxfWhfbrm4Le
  15. nixos/tests/gitolite.nix:15 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO7urFhAA90BTpGuEHeWWTY3W/g9PBxXNxfWhfbrm4Le
  16. nixos/tests/gitolite.nix:29 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFt5a8eH8BYZYjoQhzXGVKKHJe1pw1D0p7O2Vb9VTLzB
  17. nixos/tests/gitolite.nix:43 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJZNonUP1ePHLrvn0W9D2hdN6zWWZYFyJc+QR6pOKQEw
  18. nixos/tests/initrd-network-ssh/id_ed25519.pub:1 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBVxf7fZiqKDblHFEDxt6X9/rTjBXSn/re6b46S7/e9/
  19. nixos/tests/initrd-network-ssh/ssh_host_ed25519_key.pub:1 test path ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIM/0zPqqXF1CoDiiauBs6VWzFIY40Imy2Nb3Oqq5qOUg
  20. nixos/tests/sftpgo.nix:323 test path publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIE61C7pTXfnLG2u9So+ijNTKaSOg009
  21. nixos/tests/ssh-keys.nix:34 test path snakeOilEd25519PublicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDPQXmEVMVLmeFRy
ssh.public-key · CWE-327
RSASSA-PKCS1v15 Quantum-vulnerable 11 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer. The v1.5 signature scheme of RFC 8017 section 8.2 has no classical break of its own; RSA-PSS is preferred for new work, but the quantum exposure is the same for both.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

  1. nixos/doc/manual/release-notes/rl-2111.section.md:65 - This breaks connections to old SSH daemons as ssh-rsa host keys and ssh-rsa public keys that were signed with SHA-1 are disabled by default now
  2. nixos/modules/programs/ssh.nix:97 "ssh-rsa"
  3. nixos/modules/programs/ssh.nix:109 "ssh-rsa"
  4. nixos/modules/programs/ssh.nix:267 github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsK
  5. nixos/modules/services/networking/ssh/sshd.nix:112 "ssh-rsa AAAAB3NzaC1yc2etc/etc/etcjwrsh8e596z6J0l7 example@host"
  6. nixos/modules/system/boot/initrd-ssh.nix:108 "ssh-rsa AAAAB3NzaC1yc2etc/etc/etcjwrsh8e596z6J0l7 example@host"
  7. nixos/modules/virtualisation/vagrant-guest.nix:14 install -m 0600 <(echo "ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEA6NF8iallvQVp22WDkTkyrtvp9eWW6A8YVr+kz4TjGYe7gHzIw+niNltGEFHzD8+v1I2YJ6oXevct1YeS0o9HZyN1Q9qgCgzUFtdOKLv6IedplqoPkcmF0aYet2PkEDo3MlTBckFXPITAMzF8dJSIFo9D8HfdOV0IAdx4O7PtixWKn5y2hMNG
  8. nixos/tests/ssh-audit.nix:39 test path "rsa-sha2-256"
  9. nixos/tests/ssh-audit.nix:40 test path "rsa-sha2-256-cert-v01@openssh.com"
  10. nixos/tests/ssh-audit.nix:41 test path "rsa-sha2-512"
  11. nixos/tests/ssh-audit.nix:42 test path "rsa-sha2-512-cert-v01@openssh.com"
config.ssh-algorithms · CWE-757
RSA Quantum-vulnerable Recorded traffic 9 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. nixos/tests/common/acme/server/acme.test.key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  2. nixos/tests/common/acme/server/ca.key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  3. nixos/tests/forgejo.nix:9 test path -----BEGIN PGP PRIVATE KEY BLOCK-----
  4. nixos/tests/gitea.nix:11 test path -----BEGIN PGP PRIVATE KEY BLOCK-----
  5. nixos/tests/nginx-proxyprotocol/_.test.nix.key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  6. nixos/tests/nginx-proxyprotocol/ca.key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  7. nixos/tests/tinc/snakeoil-keys.nix:13 test path -----BEGIN RSA PRIVATE KEY-----
  8. nixos/tests/tinc/snakeoil-keys.nix:65 test path -----BEGIN RSA PRIVATE KEY-----
  9. nixos/tests/tinc/snakeoil-keys.nix:117 test path -----BEGIN RSA PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
RSA2048-bit Quantum-vulnerable 8 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. nixos/tests/common/acme/server/acme.test.cert.pem:1 test path -----BEGIN CERTIFICATE-----
  2. nixos/tests/common/acme/server/ca.cert.pem:1 test path -----BEGIN CERTIFICATE-----
  3. nixos/tests/hitch/example.pem:1 test path -----BEGIN CERTIFICATE-----
  4. nixos/tests/nginx-proxyprotocol/_.test.nix.cert.pem:1 test path -----BEGIN CERTIFICATE-----
  5. nixos/tests/nginx-proxyprotocol/ca.cert.pem:1 test path -----BEGIN CERTIFICATE-----
  6. nixos/tests/rkvm/cert.pem:1 test path -----BEGIN CERTIFICATE-----
  7. nixos/tests/tpm-ek/ca.crt:1 test path -----BEGIN CERTIFICATE-----
  8. pkgs/by-name/dn/dn42-cacert/root-ca.crt:66 -----BEGIN CERTIFICATE-----
pem.certificate
ECDH Quantum-vulnerable Recorded traffic 7 places See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. nixos/modules/services/web-servers/nginx/default.nix:1054 "ECDHE-ECDSA-AES128-GCM-SHA256"
  2. nixos/modules/services/web-servers/nginx/default.nix:1055 "ECDHE-RSA-AES128-GCM-SHA256"
  3. nixos/modules/services/web-servers/nginx/default.nix:1056 "ECDHE-ECDSA-AES256-GCM-SHA384"
  4. nixos/modules/services/web-servers/nginx/default.nix:1057 "ECDHE-RSA-AES256-GCM-SHA384"
  5. nixos/modules/services/web-servers/nginx/default.nix:1058 "ECDHE-ECDSA-CHACHA20-POLY1305"
  6. nixos/modules/services/web-servers/nginx/default.nix:1059 "ECDHE-RSA-CHACHA20-POLY1305"
  7. nixos/tests/web-servers/h2o/tls-recommendations.nix:98 test path curl_max_tls1_2_intermediate_cipher ="curl -v --tlsv1.0 --tls-max 1.2 --ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256' 'https://${domain}:{port}/'"
config.cipher-suite · CWE-757
X25519255-bitother/Curve25519 Quantum-vulnerable Recorded traffic 7 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

  1. nixos/modules/programs/ssh.nix:279 "curve25519-sha256@libssh.org"
  2. nixos/modules/services/networking/ssh/sshd.nix:593 "curve25519-sha256"
  3. nixos/modules/services/networking/ssh/sshd.nix:594 "curve25519-sha256@libssh.org"
  4. nixos/modules/services/networking/ssh/sshd.nix:605 "curve25519-sha256"
  5. nixos/modules/services/networking/ssh/sshd.nix:606 "curve25519-sha256@libssh.org"
  6. nixos/tests/ssh-audit.nix:49 test path "curve25519-sha256"
  7. nixos/tests/ssh-audit.nix:50 test path "curve25519-sha256@libssh.org"
config.ssh-algorithms · CWE-757
DH Quantum-vulnerable Recorded traffic 6 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

  1. nixos/modules/programs/ssh.nix:280 "diffie-hellman-group-exchange-sha256"
  2. nixos/modules/services/networking/ssh/sshd.nix:595 "diffie-hellman-group-exchange-sha256"
  3. nixos/modules/services/networking/ssh/sshd.nix:607 "diffie-hellman-group-exchange-sha256"
  4. nixos/tests/ssh-audit.nix:51 test path "diffie-hellman-group-exchange-sha256"
  5. nixos/tests/ssh-audit.nix:52 test path "diffie-hellman-group16-sha512"
  6. nixos/tests/ssh-audit.nix:53 test path "diffie-hellman-group18-sha512"
config.ssh-algorithms · CWE-757
ECDH Quantum-vulnerable Recorded traffic 6 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

  1. nixos/modules/services/networking/ssh/sshd.nix:585 KexAlgorithms = lib.mkOption {
  2. nixos/modules/services/networking/ssh/sshd.nix:654 Ciphers = lib.mkOption {
  3. nixos/modules/system/boot/initrd-ssh.nix:188 KexAlgorithms ${concatStringsSep "," sshdCfg.settings.KexAlgorithms}
  4. nixos/modules/system/boot/initrd-ssh.nix:191 Ciphers ${concatStringsSep "," sshdCfg.settings.Ciphers}
  5. nixos/tests/openssh.nix:222 test path Ciphers = null;
  6. nixos/tests/openssh.nix:223 test path KexAlgorithms = null;
config.ssh-algorithms · CWE-757
ECDSA384-bitsecg/secp384r1 Quantum-vulnerable 6 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. nixos/tests/ente/acme.test.cert.pem:1 test path -----BEGIN CERTIFICATE-----
  2. nixos/tests/ente/ca.cert.pem:1 test path -----BEGIN CERTIFICATE-----
  3. nixos/tests/redlib/ca.cert.pem:1 test path -----BEGIN CERTIFICATE-----
  4. nixos/tests/redlib/www.reddit.com.cert.pem:1 test path -----BEGIN CERTIFICATE-----
  5. pkgs/by-name/ca/cacert/package.nix:187 -----BEGIN CERTIFICATE-----
  6. pkgs/by-name/ca/cacert/test-cert-file.crt:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
ECDSA384-bitsecg/secp384r1 Quantum-vulnerable 4 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. nixos/tests/ente/acme.test.key.pem:1 test path -----BEGIN PRIVATE KEY-----
  2. nixos/tests/ente/ca.key.pem:1 test path -----BEGIN PRIVATE KEY-----
  3. nixos/tests/redlib/ca.key.pem:1 test path -----BEGIN PRIVATE KEY-----
  4. nixos/tests/redlib/www.reddit.com.key.pem:1 test path -----BEGIN PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
RSA Quantum-vulnerable 4 places See details

SSH public key

An `ssh-rsa`, `ecdsa-sha2-*`, `ssh-ed25519` or `ssh-dss` key. `ssh-dss` is disabled by default in current OpenSSH and is reported as broken.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Replace `ssh-dss` now. For the rest, enable the `sntrup761x25519-sha512` key exchange, which protects recorded sessions even while host keys stay classical.

  1. nixos/modules/programs/ssh.nix:267 github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+V
  2. nixos/modules/services/networking/ssh/sshd.nix:112 "ssh-rsa AAAAB3NzaC1yc2etc/etc/etcjwrsh8e596z6J0l7 example@host"
  3. nixos/modules/system/boot/initrd-ssh.nix:108 "ssh-rsa AAAAB3NzaC1yc2etc/etc/etcjwrsh8e596z6J0l7 example@host"
  4. nixos/modules/virtualisation/vagrant-guest.nix:14 install -m 0600 <(echo "ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEA6NF8iallvQVp22WDkTky
ssh.public-key · CWE-327
RSASSA-PKCS1v15 Quantum-vulnerable 4 places See details

JOSE algorithm declared in configuration

An `alg` value in JSON or YAML. `none` is reported as a critical defect; HS* is an HMAC and is not quantum-vulnerable; RS*, PS*, ES* and EdDSA are.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer. The v1.5 signature scheme of RFC 8017 section 8.2 has no classical break of its own; RSA-PSS is preferred for new work, but the quantum exposure is the same for both.

What to do. No standardised post-quantum JOSE algorithm exists yet. Keep token lifetimes short.

  1. nixos/tests/pomerium.nix:105 test path "id_token_signing_alg_values_supported": ["RS256"]
  2. nixos/tests/web-apps/lasuite-docs.nix:45 test path OIDC_RP_SIGN_ALGO = "RS256";
  3. nixos/tests/web-apps/lasuite-drive.nix:46 test path OIDC_RP_SIGN_ALGO = "RS256";
  4. nixos/tests/web-apps/lasuite-meet.nix:42 test path OIDC_RP_SIGN_ALGO = "RS256";
jose.algorithm · CWE-327
DSA Quantum-vulnerable 3 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

  1. nixos/doc/manual/administration/imperative-containers.section.md:24 users.users.root.openssh.authorizedKeys.keys = ["ssh-dss AAAAB3N…"];
  2. nixos/doc/manual/configuration/user-mgmt.chapter.md:18 openssh.authorizedKeys.keys = [ "ssh-dss AAAAB3Nza... alice@foobar" ];
  3. nixos/modules/services/misc/nix-ssh-serve.nix:41 example = [ "ssh-dss AAAAB3NzaC1k... alice@example.org" ];
config.ssh-algorithms · CWE-757
ECDSA Quantum-vulnerable 3 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

  1. nixos/modules/programs/ssh.nix:205 example = "ecdsa-sha2-nistp521 AAAAE2VjZHN...UEPg==";
  2. nixos/modules/programs/ssh.nix:268 github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
  3. nixos/tests/ssh-keys.nix:15 test path "ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHA"
config.ssh-algorithms · CWE-757
RSA2048-bit Quantum-vulnerable Recorded traffic 3 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. nixos/tests/hitch/example.pem:26 test path -----BEGIN PRIVATE KEY-----
  2. nixos/tests/rkvm/key.pem:1 test path -----BEGIN PRIVATE KEY-----
  3. pkgs/by-name/li/libcamera/ipa-priv-key.pem:1 -----BEGIN PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
RSA Quantum-vulnerable 3 places See details

Public key file

A PEM public-key block. The algorithm is read from the SubjectPublicKeyInfo.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Inventory only; a public key is not itself a secret.

  1. nixos/tests/tinc/snakeoil-keys.nix:43 test path -----BEGIN RSA PUBLIC KEY-----
  2. nixos/tests/tinc/snakeoil-keys.nix:95 test path -----BEGIN RSA PUBLIC KEY-----
  3. nixos/tests/tinc/snakeoil-keys.nix:147 test path -----BEGIN RSA PUBLIC KEY-----
pem.public-key
ECDSAsecp256r1 Quantum-vulnerable 2 places See details

SSH public key

An `ssh-rsa`, `ecdsa-sha2-*`, `ssh-ed25519` or `ssh-dss` key. `ssh-dss` is disabled by default in current OpenSSH and is reported as broken.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Replace `ssh-dss` now. For the rest, enable the `sntrup761x25519-sha512` key exchange, which protects recorded sessions even while host keys stay classical.

  1. nixos/modules/programs/ssh.nix:268 github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAA
  2. nixos/tests/ssh-keys.nix:15 test path "ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHA"
ssh.public-key · CWE-327
Ed25519255-bitother/Ed25519 Quantum-vulnerable 2 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. nixos/tests/yggdrasil.nix:4 test path -----BEGIN PRIVATE KEY-----
  2. nixos/tests/yggdrasil.nix:9 test path -----BEGIN PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
ECDSA Quantum-vulnerable 1 place See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. nixos/tests/ssh-keys.nix:7 test path -----BEGIN EC PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
RSA4096-bit Quantum-vulnerable 1 place See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. pkgs/by-name/gn/gnutls/dummy.crt:2 -----BEGIN CERTIFICATE-----
pem.certificate
TLS Quantum-vulnerable Recorded traffic 1 place See details

TLS cipher suites pinned in configuration

An `ssl_ciphers`, `SSLCipherSuite` or `ssl-default-bind-ciphers` directive. Every suite available today uses a classical key exchange; a suite naming RC4, DES, 3DES, EXPORT or NULL is broken now.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Every TLS cipher suite in general use negotiates a classical key exchange, so a recorded session is decryptable once that exchange falls.

What to do. Remove anything below TLS 1.2. The key exchange changes when the server software offers a hybrid group, not before.

config.tls-ciphers · CWE-757
TLS Quantum-vulnerable Recorded traffic 1 place See details

TLS versions pinned in configuration

An `ssl_protocols` or `SSLProtocol` directive. SSLv3, TLS 1.0 and TLS 1.1 are withdrawn.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Every TLS cipher suite in general use negotiates a classical key exchange, so a recorded session is decryptable once that exchange falls.

What to do. TLS 1.2 as the floor, TLS 1.3 preferred.

  1. nixos/tests/certmgr.nix:155 test path ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
config.tls-protocols · CWE-757
SHA-256 Reduced margin 13 places See details

Hash function in use

`hashlib.sha256()` and friends. The digest is read from the call, so SHA-384 and above are inventory while the broken ones are reported separately.

A quantum computer weakens this but does not break it. Increasing the key or digest size restores the margin. Pre-image resistance falls to about 128 bits of quantum work. Adequate for most uses; SHA-384 restores the full margin where a signature must last decades.

What to do. SHA-256 as the floor, SHA-384 where the digest protects something long-lived.

  1. maintainers/scripts/kde/generate-sources.py:121 hasher = hashlib.sha256()
  2. nixos/modules/system/boot/loader/systemd-boot/systemd-boot-builder.py:192 combined_hash = hashlib.sha256(combined.encode("utf-8")).hexdigest()
  3. nixos/modules/system/boot/loader/systemd-boot/systemd-boot-builder.py:204 contents_hash = hashlib.sha256(contents).hexdigest()
  4. nixos/modules/system/boot/loader/systemd-boot/systemd-boot-builder.py:213 if hashlib.sha256(Path(e.path).read_bytes()).hexdigest() != contents_hash:
  5. nixos/modules/virtualisation/nspawn-container/run-nspawn/src/run_nspawn/__init__.py:132 hashed = hashlib.sha256(host_intf_name.encode()).hexdigest()[:6]
  6. nixos/tests/google-oslogin/server.py:25 test path return hashlib.sha256(decoded_key).hexdigest()
  7. nixos/tests/google-oslogin/server.py:30 test path return str(int(hashlib.sha256(username.encode()).hexdigest(), 16))[0:21]
  8. pkgs/build-support/docker/stream_layered_image.py:118 self._digest = hashlib.sha256()
  9. pkgs/build-support/docker/stream_layered_image.py:415 image_json_checksum = hashlib.sha256(image_json).hexdigest()
  10. pkgs/build-support/rust/fetch-cargo-vendor-util.py:50 sha256_hash = hashlib.sha256()
  11. pkgs/by-name/nd/ndi-6/update.py:64 sha256 = hashlib.sha256(tarball).hexdigest()
  12. pkgs/by-name/nd/ndi/update.py:64 sha256 = hashlib.sha256(tarball).hexdigest()
  13. pkgs/games/papermc/update.py:128 sha256_hash = hashlib.sha256()
py.hashlib
SHA3-256 Reduced margin 1 place See details

Hash function in use

`hashlib.sha256()` and friends. The digest is read from the call, so SHA-384 and above are inventory while the broken ones are reported separately.

A quantum computer weakens this but does not break it. Increasing the key or digest size restores the margin. Grover's algorithm halves the effective strength; the parameter, not the design, is the problem.

What to do. SHA-256 as the floor, SHA-384 where the digest protects something long-lived.

  1. pkgs/by-name/ni/nixos-render-docs/src/nixos_render_docs/manual.py:300 content_hash = hashlib.sha3_256(content).hexdigest()
py.hashlib
unknown Could not be determined 9 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. nixos/tests/borgbackup.nix:18 test path -----BEGIN OPENSSH PRIVATE KEY-----
  2. nixos/tests/borgbackup.nix:30 test path -----BEGIN OPENSSH PRIVATE KEY-----
  3. nixos/tests/btrbk-doas.nix:5 test path -----BEGIN OPENSSH PRIVATE KEY-----
  4. nixos/tests/btrbk.nix:5 test path -----BEGIN OPENSSH PRIVATE KEY-----
  5. nixos/tests/gitolite.nix:5 test path -----BEGIN OPENSSH PRIVATE KEY-----
  6. nixos/tests/gitolite.nix:19 test path -----BEGIN OPENSSH PRIVATE KEY-----
  7. nixos/tests/gitolite.nix:33 test path -----BEGIN OPENSSH PRIVATE KEY-----
  8. nixos/tests/sftpgo.nix:120 test path -----BEGIN OPENSSH PRIVATE KEY-----
  9. nixos/tests/ssh-keys.nix:25 test path -----BEGIN OPENSSH PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
unknown Could not be determined 1 place See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. nixos/modules/security/ca.nix:60 -----BEGIN CERTIFICATE-----
pem.certificate
unknown Could not be determined 1 place See details

Cryptographic library in the dependency manifest

A dependency known to implement classical asymmetric cryptography. Its presence is inventory, not a finding about this codebase: the library may never be called with a quantum-vulnerable algorithm.

The project depends on a cryptography library. Listed so the inventory is complete; it is not by itself a problem.

What to do. Check the version. Several of these libraries have shipped ML-KEM and ML-DSA support since 2024, so the migration may need an upgrade rather than a replacement.

  1. pkgs/by-name/pa/pam_ussh/go.mod:7 golang.org/x/crypto v0.0.0-20220313003712-b769efc7c000
dep.crypto-library
ML-KEM-768 Quantum-safe 7 places See details

SSH algorithms pinned in configuration

A `KexAlgorithms`, `HostKeyAlgorithms` or `Ciphers` directive in an SSH configuration. `KexAlgorithms` is the line that decides whether recorded sessions stay confidential.

No known quantum attack changes how strong this is. No known quantum algorithm changes the security margin.

What to do. Put `sntrup761x25519-sha512@openssh.com` first in `KexAlgorithms`. It is a hybrid, so it is no weaker than the classical exchange it replaces.

  1. nixos/modules/services/networking/ssh/sshd.nix:590 "mlkem768x25519-sha256"
  2. nixos/modules/services/networking/ssh/sshd.nix:591 "sntrup761x25519-sha512"
  3. nixos/modules/services/networking/ssh/sshd.nix:592 "sntrup761x25519-sha512@openssh.com"
  4. nixos/modules/services/networking/ssh/sshd.nix:602 "mlkem768x25519-sha256"
  5. nixos/modules/services/networking/ssh/sshd.nix:603 "sntrup761x25519-sha512"
  6. nixos/modules/services/networking/ssh/sshd.nix:604 "sntrup761x25519-sha512@openssh.com"
  7. nixos/tests/ssh-audit.nix:54 test path "sntrup761x25519-sha512@openssh.com"
config.ssh-algorithms · CWE-757
BLAKE2 Quantum-safe 2 places See details

Hash function in use

`hashlib.sha256()` and friends. The digest is read from the call, so SHA-384 and above are inventory while the broken ones are reported separately.

No known quantum attack changes how strong this is. No known quantum algorithm changes the security margin.

What to do. SHA-256 as the floor, SHA-384 where the digest protects something long-lived.

py.hashlib
CSPRNG Quantum-safe Renamed import 1 place See details

Random number generation

`secrets.token_bytes()`, `os.urandom()` or `ssl.RAND_bytes()`. Recorded so the inventory names its randomness source.

This is where the software gets its random numbers. Quantum computers do not weaken it.

What to do. No action. `random.random()` is a separate, present-day defect if it reaches key material.

  1. pkgs/by-name/pu/pulumi/plugins/pulumi-python/smoke-test/__main__.py:10 test path return CreateResult(b2a_hex(urandom(16)), outs={})
py.rng
ML-DSA-44 Quantum-safe 1 place See details

JOSE algorithm declared in configuration

An `alg` value in JSON or YAML. `none` is reported as a critical defect; HS* is an HMAC and is not quantum-vulnerable; RS*, PS*, ES* and EdDSA are.

No known quantum attack changes how strong this is. No known quantum algorithm changes the security margin.

What to do. No standardised post-quantum JOSE algorithm exists yet. Keep token lifetimes short.

jose.algorithm · CWE-327
SHA-512 Quantum-safe 1 place See details

Hash function in use

`hashlib.sha256()` and friends. The digest is read from the call, so SHA-384 and above are inventory while the broken ones are reported separately.

No known quantum attack changes how strong this is. No known quantum algorithm changes the security margin.

What to do. SHA-256 as the floor, SHA-384 where the digest protects something long-lived.

  1. pkgs/by-name/se/session-desktop/generate_pnpm_patch.py:25 integrity = base64.b64encode(hashlib.sha512(data).digest()).decode()
py.hashlib

Cryptographic assets

Algorithm Assessment What it means Occurrences
Ed25519 Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 51
RSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 28
SHA-256 Reduced margin Pre-image resistance falls to about 128 bits of quantum work. Adequate for most uses; SHA-384 restores the full margin where a signature must last decades. 26
ECDSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 16
RSASSA-PKCS1v15 Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. The v1.5 signature scheme of RFC 8017 section 8.2 has no classical break of its own; RSA-PSS is preferred for new work, but the quantum exposure is the same for both. 15
ECDH Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 13
unknown Could not be determined The algorithm could not be established from the source - chosen at runtime, or decided somewhere this scan does not reach. 12
X25519 Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 7
ML-KEM-768 Quantum-safe No known quantum algorithm changes the security margin. 7
DH Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 6
DSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 3
TLS Quantum-vulnerable Every TLS cipher suite in general use negotiates a classical key exchange, so a recorded session is decryptable once that exchange falls. 3
BLAKE2 Quantum-safe No known quantum algorithm changes the security margin. 2
CSPRNG Quantum-safe A cryptographically secure random number generator provided by the platform. Not weakened by a quantum computer. 1
SHA-512 Quantum-safe No known quantum algorithm changes the security margin. 1
SHA3-256 Reduced margin Grover's algorithm halves the effective strength; the parameter, not the design, is the problem. 1
ML-DSA-44 Quantum-safe No known quantum algorithm changes the security margin. 1

Imported cryptographic libraries

Library Files
ssl the TLS client and server 1
hashlib the standard digests, including the broken ones 13
node:crypto the Node crypto module 2