Crypto-View

certbot/certbot

Readiness score
0 of 100
How this is calculated · previous scan 0
Cryptographic posture
Quantum-vulnerable 177 Already broken 37 Reduced margin 7 Quantum-safe 17
To address180
Key establishment80
Inventory only4
Total findings242
What was analysed
Branch main
Commit 485649333422392901e7ef891630f0129985df8e hooks: truncate the correct env var (#10779)
Committed 2026-09-09 20:35 UTC
Scanned 2026-09-10 22:12 UTC 4 hours ago
Coverage 785 files, 359 python

Earlier scans of this repository

13 scans · score 0 → 0 · compare any two
13 scans · 0 → 0 (unchanged). The filled point is the scan you are reading.
Scanned Commit Score To address
4 hours ago this scan 485649333422 main 0 180
5 hours ago 485649333422 main 0 168 Compare
19 hours ago e75e7378cd02 0 168 Compare
21 hours ago 485649333422 main 0 166 Compare
1 day ago 485649333422 main 0 166 Compare
1 day ago 485649333422 main 0 166 Compare
1 day ago 485649333422 main 0 166 Compare
1 day ago 485649333422 main 0 166 Compare
3 days ago 56ee04928d67 main 0 165 Compare
3 days ago 56ee04928d67 main 0 165 Compare
4 days ago 56ee04928d67 main 0 165 Compare
10 days ago 2b817be14620 main 0 165 Compare
11 days ago e75e7378cd02 0 165 Compare

Every repository in this history is re-scanned weekly.

List of cryptographic assets

RSA-1024512-bit Already broken 11 places See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

  1. acme/src/acme/_internal/tests/testdata/csr-100sans.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  2. acme/src/acme/_internal/tests/testdata/csr-6sans.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  3. acme/src/acme/_internal/tests/testdata/csr-idnsans.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  4. acme/src/acme/_internal/tests/testdata/csr-nosans.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  5. acme/src/acme/_internal/tests/testdata/csr-san.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  6. acme/src/acme/_internal/tests/testdata/csr.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  7. certbot/src/certbot/tests/testdata/csr-6sans_512.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  8. certbot/src/certbot/tests/testdata/csr-nonames_512.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  9. certbot/src/certbot/tests/testdata/csr-nosans_512.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  10. certbot/src/certbot/tests/testdata/csr-san_512.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
  11. certbot/src/certbot/tests/testdata/csr_512.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
pem.certificate-request
RC4 Already broken 8 places See details

TLS cipher suites pinned in configuration

An `ssl_ciphers`, `SSLCipherSuite` or `ssl-default-bind-ciphers` directive. Every suite available today uses a classical key exchange; a suite naming RC4, DES, 3DES, EXPORT or NULL is broken now.

This is already unsafe today, with no quantum computer involved. RC4 keystream biases break it classically; it is prohibited in TLS by RFC 7465.

What to do. Remove anything below TLS 1.2. The key exchange changes when the server software offers a hybrid group, not before.

  1. certbot-ci/src/certbot_integration_tests/assets/sample-config/options-ssl-apache.conf:7 test path SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-
  2. certbot-compatibility-test/nginx/nginx-roundtrip-testdata/guide-to-nginx-ssl-spdy-hsts/nginx.conf:104 test path ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA2
  3. certbot-compatibility-test/nginx/nginx-roundtrip-testdata/iredmail/iredadmin.conf:10 test path ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv3:+EXP;
  4. certbot-compatibility-test/nginx/nginx-roundtrip-testdata/iredmail/nginx.conf:41 test path ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP;
  5. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/passing/ipv6-1143b.conf:14 test path SSLCipherSuite "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH+aRSA+RC4 EECDH EDH +aRSA RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS"
  6. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/passing/ipv6-1143d.conf:14 test path SSLCipherSuite "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH+aRSA+RC4 EECDH EDH +aRSA RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS"
  7. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/passing/two-blocks-one-line-1693.conf:13 test path SSLCipherSuite "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EEC DH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH+aRSA+RC4 EECDH EDH+aRS A RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS !RC4"
  8. certbot/src/certbot/_internal/tests/plugins/apache/testdata/gentoo_apache/apache/apache2/vhosts.d/00_default_ssl_vhost.conf:34 test path SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SH
config.tls-ciphers · CWE-757
RSA-1024512-bit Already broken 8 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. acme/src/acme/_internal/tests/testdata/cert-100sans.pem:1 test path -----BEGIN CERTIFICATE-----
  2. acme/src/acme/_internal/tests/testdata/cert-idnsans.pem:1 test path -----BEGIN CERTIFICATE-----
  3. acme/src/acme/_internal/tests/testdata/cert-san.pem:1 test path -----BEGIN CERTIFICATE-----
  4. acme/src/acme/_internal/tests/testdata/cert.pem:1 test path -----BEGIN CERTIFICATE-----
  5. certbot/src/certbot/tests/testdata/cert-5sans_512.pem:1 test path -----BEGIN CERTIFICATE-----
  6. certbot/src/certbot/tests/testdata/cert-san_512.pem:1 test path -----BEGIN CERTIFICATE-----
  7. certbot/src/certbot/tests/testdata/cert_512.pem:1 test path -----BEGIN CERTIFICATE-----
  8. certbot/src/certbot/tests/testdata/cert_512_bad.pem:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
MD5 Already broken 6 places See details

TLS cipher suites pinned in configuration

An `ssl_ciphers`, `SSLCipherSuite` or `ssl-default-bind-ciphers` directive. Every suite available today uses a classical key exchange; a suite naming RC4, DES, 3DES, EXPORT or NULL is broken now.

This is already unsafe today, with no quantum computer involved. Practical chosen-prefix collisions exist; MD5 has no remaining security as a digest.

What to do. Remove anything below TLS 1.2. The key exchange changes when the server software offers a hybrid group, not before.

config.tls-ciphers · CWE-757
MD5 Already broken 2 places See details

Broken hash function

`hashlib.md5()` or `hashlib.sha1()`. Both have practical collisions. Where the call is annotated `usedforsecurity=False` the finding is recorded as inventory instead.

This is already unsafe today, with no quantum computer involved. Practical chosen-prefix collisions exist; MD5 has no remaining security as a digest.

What to do. SHA-256, or SHA-384 for long-lived signatures.

  1. certbot/src/certbot/_internal/account.py:70 hasher = hashlib.md5()
  2. certbot/src/certbot/_internal/account.py:75 hasher = hashlib.new('md5', **cast(Mapping[str, Any], {"usedforsecurity": False}))
py.hashlib.weak · CWE-328
RSA-10241024-bit Already broken 1 place See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. acme/src/acme/_internal/tests/testdata/rsa1024_cert.pem:1 test path -----BEGIN CERTIFICATE-----
pem.certificate
RSAES-PKCS1v15 Already broken Recorded traffic Renamed import 1 place See details

PKCS#1 v1.5 padding

`padding.PKCS1v15()`. For encryption this is vulnerable to Bleichenbacher-style padding oracles today; for signatures it is acceptable but the key is still RSA.

This is already unsafe today, with no quantum computer involved. PKCS#1 v1.5 encryption padding is vulnerable to Bleichenbacher oracles today, and the underlying RSA is broken by Shor.

What to do. For encryption, OAEP immediately and ML-KEM-768 as the destination.

  1. certbot/src/certbot/crypto_util.py:373 signature, payload, PKCS1v15(), signature_hash_algorithm
py.cryptography.pkcs1v15 · CWE-327
RSA2048-bit Quantum-vulnerable 29 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

  1. acme/src/acme/_internal/tests/testdata/cert-ipsans.pem:1 test path -----BEGIN CERTIFICATE-----
  2. acme/src/acme/_internal/tests/testdata/cert-ipv6sans.pem:1 test path -----BEGIN CERTIFICATE-----
  3. acme/src/acme/_internal/tests/testdata/critical-san.pem:1 test path -----BEGIN CERTIFICATE-----
  4. acme/src/acme/_internal/tests/testdata/rsa2048_cert.pem:1 test path -----BEGIN CERTIFICATE-----
  5. certbot-ci/src/certbot_integration_tests/assets/sample-config/archive/a.encryption-example.com/cert1.pem:1 test path -----BEGIN CERTIFICATE-----
  6. certbot-ci/src/certbot_integration_tests/assets/sample-config/archive/a.encryption-example.com/chain1.pem:1 test path -----BEGIN CERTIFICATE-----
  7. certbot-ci/src/certbot_integration_tests/assets/sample-config/archive/a.encryption-example.com/fullchain1.pem:1 test path -----BEGIN CERTIFICATE-----
  8. certbot-ci/src/certbot_integration_tests/assets/sample-config/archive/a.encryption-example.com/fullchain1.pem:30 test path -----BEGIN CERTIFICATE-----
  9. certbot-ci/src/certbot_integration_tests/assets/sample-config/archive/b.encryption-example.com/cert1.pem:1 test path -----BEGIN CERTIFICATE-----
  10. certbot-ci/src/certbot_integration_tests/assets/sample-config/archive/b.encryption-example.com/chain1.pem:1 test path -----BEGIN CERTIFICATE-----
  11. certbot-ci/src/certbot_integration_tests/assets/sample-config/archive/b.encryption-example.com/fullchain1.pem:1 test path -----BEGIN CERTIFICATE-----
  12. certbot-ci/src/certbot_integration_tests/assets/sample-config/archive/b.encryption-example.com/fullchain1.pem:30 test path -----BEGIN CERTIFICATE-----
  13. certbot-ci/src/certbot_integration_tests/assets/sample-config/archive/c.encryption-example.com/chain.pem:1 test path -----BEGIN CERTIFICATE-----
  14. certbot-ci/src/certbot_integration_tests/assets/sample-config/archive/c.encryption-example.com/fullchain.pem:19 test path -----BEGIN CERTIFICATE-----
  15. certbot-compatibility-test/src/certbot_compatibility_test/testdata/empty_cert.pem:1 test path -----BEGIN CERTIFICATE-----
  16. certbot/src/certbot/tests/testdata/cert_2048.pem:1 test path -----BEGIN CERTIFICATE-----
  17. certbot/src/certbot/tests/testdata/cert_fullchain_2048.pem:1 test path -----BEGIN CERTIFICATE-----
  18. certbot/src/certbot/tests/testdata/cert_fullchain_2048.pem:21 test path -----BEGIN CERTIFICATE-----
  19. certbot/src/certbot/tests/testdata/cert_intermediate_1.pem:1 test path -----BEGIN CERTIFICATE-----
  20. certbot/src/certbot/tests/testdata/cert_intermediate_2.pem:1 test path -----BEGIN CERTIFICATE-----
  21. certbot/src/certbot/tests/testdata/cert_leaf.pem:1 test path -----BEGIN CERTIFICATE-----
  22. certbot/src/certbot/tests/testdata/ocsp_certificate.pem:1 test path -----BEGIN CERTIFICATE-----
  23. certbot/src/certbot/tests/testdata/ocsp_responder_certificate.pem:1 test path -----BEGIN CERTIFICATE-----
  24. certbot/src/certbot/tests/testdata/sample-archive-ec/chain1.pem:1 test path -----BEGIN CERTIFICATE-----
  25. certbot/src/certbot/tests/testdata/sample-archive-ec/fullchain1.pem:19 test path -----BEGIN CERTIFICATE-----
  26. certbot/src/certbot/tests/testdata/sample-archive/cert1.pem:1 test path -----BEGIN CERTIFICATE-----
  27. certbot/src/certbot/tests/testdata/sample-archive/chain1.pem:1 test path -----BEGIN CERTIFICATE-----
  28. certbot/src/certbot/tests/testdata/sample-archive/fullchain1.pem:1 test path -----BEGIN CERTIFICATE-----
  29. certbot/src/certbot/tests/testdata/sample-archive/fullchain1.pem:29 test path -----BEGIN CERTIFICATE-----
pem.certificate
RSA Quantum-vulnerable Recorded traffic Renamed import 22 places See details

RSA key generated with pyca/cryptography

`rsa.generate_private_key()`. The `key_size` argument is read where it is a literal and reported on the finding; it does not change the classification, because Shor is polynomial in the modulus size.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-KEM-768 for encryption and ML-DSA-65 for signatures.

  1. acme/src/acme/crypto_util.py:81 rsa.RSAPrivateKey,
  2. certbot-ci/src/certbot_integration_tests/certbot_tests/assertions.py:8 test path from cryptography.hazmat.primitives.asymmetric.rsa import RSAPrivateKey
  3. certbot-ci/src/certbot_integration_tests/certbot_tests/assertions.py:49 test path assert isinstance(key, RSAPrivateKey)
  4. certbot-ci/src/certbot_integration_tests/utils/misc.py:216 test path key: Union[rsa.RSAPrivateKey, ec.EllipticCurvePrivateKey]
  5. certbot-ci/src/certbot_integration_tests/utils/pebble_ocsp_server.py:17 test path from cryptography.hazmat.primitives.asymmetric.rsa import RSAPrivateKey
  6. certbot-ci/src/certbot_integration_tests/utils/pebble_ocsp_server.py:33 test path Union[RSAPrivateKey, EllipticCurvePrivateKey],
  7. certbot/src/certbot/_internal/client.py:199 rsa_key = generate_private_key(
  8. certbot/src/certbot/_internal/renewal.py:754 if isinstance(key, rsa.RSAPrivateKey):
  9. certbot/src/certbot/_internal/storage.py:20 from cryptography.hazmat.primitives.asymmetric.rsa import RSAPrivateKey
  10. certbot/src/certbot/_internal/storage.py:1095 def _private_key(self) -> Union[RSAPrivateKey, EllipticCurvePrivateKey]:
  11. certbot/src/certbot/_internal/storage.py:1102 return cast(Union[RSAPrivateKey, EllipticCurvePrivateKey], key)
  12. certbot/src/certbot/_internal/storage.py:1111 if isinstance(key, RSAPrivateKey):
  13. certbot/src/certbot/_internal/storage.py:1122 if isinstance(key, RSAPrivateKey):
  14. certbot/src/certbot/crypto_util.py:35 from cryptography.hazmat.primitives.asymmetric.rsa import RSAPublicKey
  15. certbot/src/certbot/crypto_util.py:259 key: Union[rsa.RSAPrivateKey, ec.EllipticCurvePrivateKey]
  16. certbot/src/certbot/crypto_util.py:264 key = rsa.generate_private_key(public_exponent=65537, key_size=bits)
  17. certbot/src/certbot/crypto_util.py:357 MLKEM1024PublicKey, RSAPublicKey,
  18. certbot/src/certbot/crypto_util.py:363 :param RSAPublicKey/EllipticCurvePublicKey public_key: the public_key to check signature
  19. certbot/src/certbot/crypto_util.py:371 if isinstance(public_key, RSAPublicKey):
  20. certbot/src/certbot/tests/util.py:27 test path from cryptography.hazmat.primitives.asymmetric.rsa import RSAPrivateKey
  21. certbot/src/certbot/tests/util.py:122 test path def load_rsa_private_key_pem(*names: str) -> RSAPrivateKey:
  22. certbot/src/certbot/tests/util.py:128 test path assert isinstance(key, RSAPrivateKey)
py.cryptography.rsa · CWE-327
TLS Quantum-vulnerable Recorded traffic 16 places See details

TLS versions pinned in configuration

An `ssl_protocols` or `SSLProtocol` directive. SSLv3, TLS 1.0 and TLS 1.1 are withdrawn.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Every TLS cipher suite in general use negotiates a classical key exchange, so a recorded session is decryptable once that exchange falls.

What to do. TLS 1.2 as the floor, TLS 1.3 preferred.

  1. certbot-ci/src/certbot_integration_tests/assets/sample-config/options-ssl-apache.conf:6 test path SSLProtocol all -SSLv2 -SSLv3
  2. certbot-compatibility-test/nginx/nginx-roundtrip-testdata/guide-to-nginx-ssl-spdy-hsts/nginx.conf:47 test path
  3. certbot-compatibility-test/nginx/nginx-roundtrip-testdata/imapproxyexample/nginx.conf:15 test path ssl_protocols TLSv1 SSLv3;
  4. certbot-compatibility-test/nginx/nginx-roundtrip-testdata/iredmail/iredadmin.conf:9 test path ssl_protocols SSLv3 TLSv1;
  5. certbot-compatibility-test/nginx/nginx-roundtrip-testdata/iredmail/nginx.conf:40 test path ssl_protocols SSLv2 SSLv3 TLSv1;
  6. certbot/src/certbot/_internal/plugins/apache/tls_configs/current-options-ssl-apache.conf:10 SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
  7. certbot/src/certbot/_internal/plugins/apache/tls_configs/old-options-ssl-apache.conf:14 SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
  8. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/failing/missing-double-quote-1724.conf:7 test path
  9. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/failing/multivhost-1093b.conf:172 test path SSLProtocol All -SSLv2 -SSLv3
  10. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/failing/multivhost-1093b.conf:466 test path SSLProtocol All -SSLv2 -SSLv3
  11. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/passing/ipv6-1143b.conf:13 test path SSLProtocol all -SSLv2 -SSLv3
  12. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/passing/ipv6-1143d.conf:13 test path SSLProtocol all -SSLv2 -SSLv3
  13. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/passing/missing-quote-1724.conf:7 test path
  14. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/passing/two-blocks-one-line-1693.conf:11 test path SSLProtocol all -SSLv2 -SSLv3
  15. certbot/src/certbot/_internal/tests/plugins/apache/testdata/centos7_apache/apache/httpd/conf.d/ssl.conf:75 test path SSLProtocol all -SSLv2
  16. certbot/src/certbot/_internal/tests/plugins/apache/testdata/gentoo_apache/apache/apache2/vhosts.d/00_default_ssl_vhost.conf:27 test path SSLProtocol ALL -SSLv2 -SSLv3
config.tls-protocols · CWE-757
ECDH Quantum-vulnerable Recorded traffic 10 places See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. certbot-ci/src/certbot_integration_tests/assets/sample-config/options-ssl-apache.conf:7 test path SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-
  2. certbot-compatibility-test/nginx/nginx-roundtrip-testdata/guide-to-nginx-ssl-spdy-hsts/nginx.conf:104 test path ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA2
  3. certbot/CHANGELOG.md:1588 * Remove ECDHE-RSA-AES128-SHA from NGINX ciphers list now that Windows 2008 R2 and Windows 7 are EOLed
  4. certbot/src/certbot/_internal/plugins/apache/tls_configs/current-options-ssl-apache.conf:12 SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-G
  5. certbot/src/certbot/_internal/plugins/apache/tls_configs/old-options-ssl-apache.conf:15 SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-G
  6. certbot/src/certbot/_internal/plugins/nginx/tls_configs/options-ssl-nginx-old.conf:17 ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384";
  7. certbot/src/certbot/_internal/plugins/nginx/tls_configs/options-ssl-nginx-tls12-only.conf:18 ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384";
  8. certbot/src/certbot/_internal/plugins/nginx/tls_configs/options-ssl-nginx-tls13-session-tix-on.conf:17 ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384";
  9. certbot/src/certbot/_internal/plugins/nginx/tls_configs/options-ssl-nginx.conf:14 ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384";
  10. certbot/src/certbot/_internal/tests/plugins/apache/testdata/gentoo_apache/apache/apache2/vhosts.d/00_default_ssl_vhost.conf:34 test path SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SH
config.cipher-suite · CWE-757
RSA2048-bit Quantum-vulnerable Recorded traffic 9 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

pem.private-key · CWE-321, CWE-327
TLS Quantum-vulnerable Recorded traffic 8 places See details

TLS cipher suites pinned in configuration

An `ssl_ciphers`, `SSLCipherSuite` or `ssl-default-bind-ciphers` directive. Every suite available today uses a classical key exchange; a suite naming RC4, DES, 3DES, EXPORT or NULL is broken now.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Every TLS cipher suite in general use negotiates a classical key exchange, so a recorded session is decryptable once that exchange falls.

What to do. Remove anything below TLS 1.2. The key exchange changes when the server software offers a hybrid group, not before.

  1. certbot/src/certbot/_internal/plugins/apache/tls_configs/current-options-ssl-apache.conf:12 SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-G
  2. certbot/src/certbot/_internal/plugins/apache/tls_configs/old-options-ssl-apache.conf:15 SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-G
  3. certbot/src/certbot/_internal/plugins/nginx/tls_configs/options-ssl-nginx-old.conf:16
  4. certbot/src/certbot/_internal/plugins/nginx/tls_configs/options-ssl-nginx-tls12-only.conf:17
  5. certbot/src/certbot/_internal/plugins/nginx/tls_configs/options-ssl-nginx-tls13-session-tix-on.conf:16
  6. certbot/src/certbot/_internal/plugins/nginx/tls_configs/options-ssl-nginx.conf:13
  7. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/failing/missing-double-quote-1724.conf:9 test path SSLCipherSuite "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRS$
  8. certbot/src/certbot/_internal/tests/plugins/apache/apache-conf-files/passing/missing-quote-1724.conf:9 test path SSLCipherSuite "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRS$
config.tls-ciphers · CWE-757
RSA2048-bit Quantum-vulnerable 7 places See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

pem.certificate-request
ECDSA256-bitsecg/secp256r1 Quantum-vulnerable 6 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

pem.certificate
ECDSA256-bitsecg/secp256r1 Quantum-vulnerable 6 places See details

Elliptic-curve key generated with pyca/cryptography

`ec.generate_private_key()`. The curve is read from the argument and normalised onto the CycloneDX 1.7 curve registry.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 for signatures. If the key feeds ECDH, treat it as key establishment and prioritise it above signatures.

  1. acme/src/acme/_internal/tests/client_test.py:652 test path key = ec.generate_private_key(ec.SECP256R1())
  2. certbot/src/certbot/_internal/tests/renewal_test.py:24 test path key = ec.generate_private_key(ec.SECP256R1())
  3. certbot/src/certbot/_internal/tests/san_test.py:70 test path key = ec.generate_private_key(ec.SECP256R1())
  4. certbot/src/certbot/_internal/tests/san_test.py:89 test path key = ec.generate_private_key(ec.SECP256R1())
  5. certbot/src/certbot/_internal/tests/san_test.py:113 test path key = ec.generate_private_key(ec.SECP256R1())
  6. certbot/src/certbot/_internal/tests/san_test.py:134 test path key = ec.generate_private_key(ec.SECP256R1())
py.cryptography.ec · CWE-327
RSA2048-bit Quantum-vulnerable Recorded traffic From a constant 5 places See details

RSA key generated with pyca/cryptography

`rsa.generate_private_key()`. The `key_size` argument is read where it is a literal and reported on the finding; it does not change the classification, because Shor is polynomial in the modulus size.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-KEM-768 for encryption and ML-DSA-65 for signatures.

  1. acme/examples/http01_example.py:72 test path pkey = rsa.generate_private_key(public_exponent=65537, key_size=CERT_PKEY_BITS)
  2. acme/examples/http01_example.py:161 test path key=rsa.generate_private_key(public_exponent=65537,
  3. acme/src/acme/_internal/tests/crypto_util_test.py:120 test path self.privkey = rsa.generate_private_key(public_exponent=65537, key_size=2048)
  4. acme/src/acme/_internal/tests/crypto_util_test.py:206 test path privkey = rsa.generate_private_key(public_exponent=65537, key_size=2048)
  5. certbot-ci/src/certbot_integration_tests/utils/misc.py:218 test path key = rsa.generate_private_key(public_exponent=65537, key_size=2048)
py.cryptography.rsa · CWE-327
RSA Quantum-vulnerable Recorded traffic 5 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. acme/src/acme/_internal/tests/testdata/rsa1024_key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  2. acme/src/acme/_internal/tests/testdata/rsa256_key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  3. acme/src/acme/_internal/tests/testdata/rsa4096_key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  4. acme/src/acme/_internal/tests/testdata/rsa512_key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
  5. certbot/src/certbot/tests/testdata/rsa512_key.pem:1 test path -----BEGIN RSA PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
ECDSA Quantum-vulnerable 4 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. certbot/src/certbot/tests/testdata/ec_prime256v1_key.pem:4 test path -----BEGIN EC PRIVATE KEY-----
  2. certbot/src/certbot/tests/testdata/ec_secp384r1_key.pem:4 test path -----BEGIN EC PRIVATE KEY-----
  3. certbot/src/certbot/tests/testdata/ec_secp521r1_key.pem:4 test path -----BEGIN EC PRIVATE KEY-----
  4. certbot/src/certbot/tests/testdata/nistp256_key.pem:1 test path -----BEGIN EC PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
RSA4096-bit Quantum-vulnerable 3 places See details

X.509 certificate

A PEM certificate. The subject public-key algorithm and key size are read from the SubjectPublicKeyInfo structure, and the not-after date is reported so certificates that outlive the migration window are visible.

This is a digital identity document. Its expiry date matters: one valid for many years locks in today's algorithms for that long.

What to do. Shorten certificate lifetimes so re-issuing with a post-quantum key is routine.

pem.certificate
ECDSA256-bitsecg/secp256r1 Quantum-vulnerable 2 places See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

pem.private-key · CWE-321, CWE-327
DH Quantum-vulnerable Recorded traffic 1 place See details

TLS cipher suite named in source

A cipher suite written into the code rather than into a configuration file - `TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256`, or the OpenSSL spelling `ECDHE-RSA-AES128-GCM-SHA256`. The key exchange is reported, and the bulk cipher separately when it is one of the broken ones.

This code names the exact cryptography its TLS connections may use. Because the list is in the program rather than in a settings file, changing it needs a new release - which is the thing that makes a migration slow.

What to do. A hardcoded suite list ships with the binary and cannot be changed without a release, so move it to configuration first. The key exchange changes when the TLS library offers a hybrid group, not before.

  1. certbot/CHANGELOG.md:187 * Added `DHE-RSA-CHACHA20-POLY1305` to `SSLCipherSuite` list for better
config.cipher-suite · CWE-757
DH Quantum-vulnerable 1 place See details

Public key file

A PEM public-key block. The algorithm is read from the SubjectPublicKeyInfo.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Inventory only; a public key is not itself a secret.

  1. certbot/src/certbot/ssl-dhparams.pem:1 -----BEGIN DH PARAMETERS-----
pem.public-key
DSA Quantum-vulnerable 1 place See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. acme/src/acme/_internal/tests/testdata/dsa512_key.pem:7 test path -----BEGIN DSA PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
ECDSA384-bitsecg/secp384r1 Quantum-vulnerable 1 place See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

pem.private-key · CWE-321, CWE-327
ECDSA384-bitsecg/secp384r1 Quantum-vulnerable 1 place See details

Elliptic-curve key generated with pyca/cryptography

`ec.generate_private_key()`. The curve is read from the argument and normalised onto the CycloneDX 1.7 curve registry.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 for signatures. If the key feeds ECDH, treat it as key establishment and prioritise it above signatures.

  1. certbot-ci/src/certbot_integration_tests/utils/misc.py:220 test path key = ec.generate_private_key(ec.SECP384R1())
py.cryptography.ec · CWE-327
ECDSA Quantum-vulnerable 1 place See details

Elliptic-curve key generated with pyca/cryptography

`ec.generate_private_key()`. The curve is read from the argument and normalised onto the CycloneDX 1.7 curve registry.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. ML-DSA-65 for signatures. If the key feeds ECDH, treat it as key establishment and prioritise it above signatures.

  1. certbot/src/certbot/crypto_util.py:274 key = ec.generate_private_key(
py.cryptography.ec · CWE-327
ECDSA256-bitsecg/secp256r1 Quantum-vulnerable 1 place See details

Certificate signing request

A PKCS#10 certificate signing request. The public key it carries is read from the CertificationRequestInfo, so the algorithm and size are reported even though nothing has been issued yet.

This is an application for a digital identity document, not the document itself. It names the key that will be certified, so it shows what is about to be committed to.

What to do. Decide the key algorithm before the request is signed - a request is the last point at which changing it costs nothing.

  1. certbot/src/certbot/tests/testdata/csr-nosans_nistp256.pem:1 test path -----BEGIN CERTIFICATE REQUEST-----
pem.certificate-request
RSA4096-bit Quantum-vulnerable Recorded traffic 1 place See details

Private key committed to the repository

A PEM private-key block. The header names the algorithm where the format is the legacy one; for PKCS#8 the algorithm OID is read out of the DER. A private key in version control is a present-day incident before it is a quantum question.

A secret key is stored in this repository's files. Anyone who can read the repository can use it. This needs attention today, regardless of quantum computers.

What to do. Revoke and rotate the key, then keep key material out of the repository. Record the algorithm in the inventory.

  1. certbot-ci/src/certbot_integration_tests/assets/key.pem:1 test path -----BEGIN PRIVATE KEY-----
pem.private-key · CWE-321, CWE-327
RSA Quantum-vulnerable Recorded traffic 1 place See details

Public key declared as a JSON Web Key

A `kty` field, with the curve read from the sibling `crv` where the family needs one. A JWKS document declares a key without naming an algorithm anywhere, so it is invisible to a scan that only looks for `alg`.

This file publishes the public keys other systems use to check this system's signatures. Everyone who trusts these keys has to accept the new kind of key before the old ones can be retired.

What to do. A published JWKS is what relying parties trust. It has to accept a post-quantum key type before the keys behind it can change, so put it early in the migration order.

  1. certbot-ci/src/certbot_integration_tests/assets/sample-config/accounts/acme-staging.api.letsencrypt.org/directory/48d6b9e8d767eccf7e4d877d6ffa81e3/private_key.json:1 test path {"e": "AQAB", "d": "W410Wny96RO4qJ207KGQ3RSn0KAwqb93JBMHWU1yS9H3fN_2eCpFYdMLNFI9t1__nW1okeUioEfvMN_YW-G9krw97kVdZ63MfbeJCf35Onc8VZhAnk_3V8MtS26Of8ml0tTYhlQ65nuzhvHbY7aP-Uk260oDN-AbCCVhu5G4CQiMY6sdtCc8YkB6gK7SK874oWU7ogvAIPtNtEI-AXDUBYNAfoh3
jose.jwk · CWE-327
RSASSA-PKCS1v15 Quantum-vulnerable 1 place See details

JOSE algorithm declared in configuration

An `alg` value in JSON or YAML. `none` is reported as a critical defect; HS* is an HMAC and is not quantum-vulnerable; RS*, PS*, ES* and EdDSA are.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer. The v1.5 signature scheme of RFC 8017 section 8.2 has no classical break of its own; RSA-PSS is preferred for new work, but the quantum exposure is the same for both.

What to do. No standardised post-quantum JOSE algorithm exists yet. Keep token lifetimes short.

  1. acme/src/acme/_internal/tests/jose_test.py:32 test path _test_it('', 'RS512')
jose.algorithm · CWE-327
X25519255-bitother/Curve25519 Quantum-vulnerable Recorded traffic 1 place See details

X25519 key agreement

`X25519PrivateKey.generate()`. X25519 is the best classical key exchange available and is still a discrete-logarithm problem, so Shor solves it.

A quantum computer of sufficient size breaks this completely. It has to be replaced, not tuned. Broken by Shor's algorithm on a cryptographically relevant quantum computer.

What to do. Hybrid X25519+ML-KEM-768 keeps this exact code as the classical half.

  1. acme/src/acme/_internal/tests/crypto_util_test.py:264 test path privkey = x25519.X25519PrivateKey.generate()
py.cryptography.x25519 · CWE-327
SHA-256 Reduced margin Renamed import 3 places See details

Hash function in use

`hashlib.sha256()` and friends. The digest is read from the call, so SHA-384 and above are inventory while the broken ones are reported separately.

A quantum computer weakens this but does not break it. Increasing the key or digest size restores the margin. Pre-image resistance falls to about 128 bits of quantum work. Adequate for most uses; SHA-384 restores the full margin where a signature must last decades.

What to do. SHA-256 as the floor, SHA-384 where the digest protects something long-lived.

  1. acme/src/acme/challenges.py:265 return jose.b64encode(hashlib.sha256(self.key_authorization(
  2. certbot/src/certbot/crypto_util.py:563 sha256 = hashlib.sha256()
  3. tests/modification-check.py:30 test path hash_object = hashlib.sha256()
py.hashlib
unknown Could not be determined 4 places See details

Cryptographic library in the dependency manifest

A dependency known to implement classical asymmetric cryptography. Its presence is inventory, not a finding about this codebase: the library may never be called with a quantum-vulnerable algorithm.

The project depends on a cryptography library. Listed so the inventory is complete; it is not by itself a problem.

What to do. Check the version. Several of these libraries have shipped ML-KEM and ML-DSA support since 2024, so the migration may need an upgrade rather than a replacement.

  1. acme/pyproject.toml:29 "cryptography>=47.0.0",
  2. certbot-ci/pyproject.toml:29 "cryptography",
  3. certbot/setup.py:32 'cryptography>=47.0.0',
  4. tools/requirements.txt:35 cryptography==50.0.0 ; python_version >= "3.10" and python_version < "4.0"
dep.crypto-library
HMAC Quantum-safe Renamed import 10 places See details

JOSE algorithm declared in configuration

An `alg` value in JSON or YAML. `none` is reported as a critical defect; HS* is an HMAC and is not quantum-vulnerable; RS*, PS*, ES* and EdDSA are.

No known quantum attack changes how strong this is. A keyed MAC is not affected by Shor and only marginally by Grover.

What to do. No standardised post-quantum JOSE algorithm exists yet. Keep token lifetimes short.

  1. acme/src/acme/_internal/tests/jose_test.py:43 test path ('jwa', 'HS256',),
  2. acme/src/acme/_internal/tests/messages_test.py:221 test path self.hmac_alg = "HS256"
  3. acme/src/acme/_internal/tests/messages_test.py:249 test path self.key, self.kid, self.hmac_key, self.dir, "HS256"
  4. acme/src/acme/_internal/tests/messages_test.py:257 test path assert protected_default['alg'] == 'HS256'
  5. acme/src/acme/_internal/tests/messages_test.py:297 test path hmac_alg = "HS256"
  6. acme/src/acme/messages.py:303 directory: Directory, hmac_alg: str = "HS256") -> dict[str, Any]:
  7. acme/src/acme/messages.py:311 "HS256": jose.jwa.HS256,
  8. acme/src/acme/messages.py:312 "HS384": jose.jwa.HS384,
  9. acme/src/acme/messages.py:313 "HS512": jose.jwa.HS512,
  10. certbot/src/certbot/_internal/constants.py:85 eab_hmac_alg="HS256",
jose.algorithm · CWE-327
CSPRNG Quantum-safe 2 places See details

Random number generation

`secrets.token_bytes()`, `os.urandom()` or `ssl.RAND_bytes()`. Recorded so the inventory names its randomness source.

This is where the software gets its random numbers. Quantum computers do not weaken it.

What to do. No action. `random.random()` is a separate, present-day defect if it reaches key material.

  1. certbot-compatibility-test/src/certbot_compatibility_test/test_driver.py:112 test path token=os.urandom(int(challenges.HTTP01.TOKEN_SIZE)))
  2. certbot/src/certbot/_internal/plugins/apache/apache_util.py:119 return binascii.hexlify(os.urandom(16)).decode("utf-8")
py.rng
ML-DSA-44 Quantum-safe 1 place See details

Post-quantum algorithm in use

`cryptography.hazmat.primitives.asymmetric.mlkem` and its ML-DSA and SLH-DSA siblings, or a call into liboqs, `pqcrypto` or `kyber`/`dilithium` bindings. The class names carry the parameter set - `MLKEM768PrivateKey` is ML-KEM-768 - so the finding names the concrete algorithm rather than the family. Recorded so the inventory shows completed migration work.

This is already a quantum-safe algorithm.

What to do. None. Confirm the parameter set matches the required NIST category.

py.pqc
ML-DSA-65 Quantum-safe 1 place See details

Post-quantum algorithm in use

`cryptography.hazmat.primitives.asymmetric.mlkem` and its ML-DSA and SLH-DSA siblings, or a call into liboqs, `pqcrypto` or `kyber`/`dilithium` bindings. The class names carry the parameter set - `MLKEM768PrivateKey` is ML-KEM-768 - so the finding names the concrete algorithm rather than the family. Recorded so the inventory shows completed migration work.

This is already a quantum-safe algorithm.

What to do. None. Confirm the parameter set matches the required NIST category.

py.pqc
ML-DSA-87 Quantum-safe 1 place See details

Post-quantum algorithm in use

`cryptography.hazmat.primitives.asymmetric.mlkem` and its ML-DSA and SLH-DSA siblings, or a call into liboqs, `pqcrypto` or `kyber`/`dilithium` bindings. The class names carry the parameter set - `MLKEM768PrivateKey` is ML-KEM-768 - so the finding names the concrete algorithm rather than the family. Recorded so the inventory shows completed migration work.

This is already a quantum-safe algorithm.

What to do. None. Confirm the parameter set matches the required NIST category.

py.pqc
ML-KEM-1024 Quantum-safe 1 place See details

Post-quantum algorithm in use

`cryptography.hazmat.primitives.asymmetric.mlkem` and its ML-DSA and SLH-DSA siblings, or a call into liboqs, `pqcrypto` or `kyber`/`dilithium` bindings. The class names carry the parameter set - `MLKEM768PrivateKey` is ML-KEM-768 - so the finding names the concrete algorithm rather than the family. Recorded so the inventory shows completed migration work.

This is already a quantum-safe algorithm.

What to do. None. Confirm the parameter set matches the required NIST category.

  1. certbot/src/certbot/crypto_util.py:33 from cryptography.hazmat.primitives.asymmetric.mlkem import MLKEM768PublicKey, MLKEM1024PublicKey
py.pqc
ML-KEM-768 Quantum-safe 1 place See details

Post-quantum algorithm in use

`cryptography.hazmat.primitives.asymmetric.mlkem` and its ML-DSA and SLH-DSA siblings, or a call into liboqs, `pqcrypto` or `kyber`/`dilithium` bindings. The class names carry the parameter set - `MLKEM768PrivateKey` is ML-KEM-768 - so the finding names the concrete algorithm rather than the family. Recorded so the inventory shows completed migration work.

This is already a quantum-safe algorithm.

What to do. None. Confirm the parameter set matches the required NIST category.

  1. certbot/src/certbot/crypto_util.py:33 from cryptography.hazmat.primitives.asymmetric.mlkem import MLKEM768PublicKey, MLKEM1024PublicKey
py.pqc

Cryptographic assets

Algorithm Assessment What it means Occurrences
RSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 115
TLS Quantum-vulnerable Every TLS cipher suite in general use negotiates a classical key exchange, so a recorded session is decryptable once that exchange falls. 25
ECDSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 22
RSA-1024 Already broken A modulus of 1024 bits or less is below the NIST SP 800-57 floor and is within reach of classical factorisation. Shor is not the nearest problem here. 20
ECDH Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 10
HMAC Quantum-safe A keyed MAC is not affected by Shor and only marginally by Grover. 10
MD5 Already broken Practical chosen-prefix collisions exist; MD5 has no remaining security as a digest. 8
RC4 Already broken RC4 keystream biases break it classically; it is prohibited in TLS by RFC 7465. 8
SHA-256 Reduced margin Pre-image resistance falls to about 128 bits of quantum work. Adequate for most uses; SHA-384 restores the full margin where a signature must last decades. 7
DH Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 2
CSPRNG Quantum-safe A cryptographically secure random number generator provided by the platform. Not weakened by a quantum computer. 2
DSA Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 1
X25519 Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. 1
ML-DSA-44 Quantum-safe No known quantum algorithm changes the security margin. 1
ML-DSA-65 Quantum-safe No known quantum algorithm changes the security margin. 1
ML-DSA-87 Quantum-safe No known quantum algorithm changes the security margin. 1
ML-KEM-768 Quantum-safe No known quantum algorithm changes the security margin. 1
ML-KEM-1024 Quantum-safe No known quantum algorithm changes the security margin. 1
RSAES-PKCS1v15 Already broken PKCS#1 v1.5 encryption padding is vulnerable to Bleichenbacher oracles today, and the underlying RSA is broken by Shor. 1
RSASSA-PKCS1v15 Quantum-vulnerable Broken by Shor's algorithm on a cryptographically relevant quantum computer. The v1.5 signature scheme of RFC 8017 section 8.2 has no classical break of its own; RSA-PSS is preferred for new work, but the quantum exposure is the same for both. 1

Imported cryptographic libraries

Library Files
cryptography pyca/cryptography 30
ssl the TLS client and server 1
hashlib the standard digests, including the broken ones 4