Post quantum cryptography
Recipe ID
io.moderne.cryptography.PostQuantumCryptographyArtifact
io.moderne.recipe:rewrite-cryptographyThis recipe searches for instances in code that may be impacted by post quantum cryptography. Applications may need to support larger key sizes, different algorithms, or use crypto agility to handle the migration. The recipe includes detection of hardcoded values that affect behavior in a post-quantum world, programmatic configuration that may prevent algorithm changes, and general cryptographic usage patterns that should be reviewed.
Usage
This recipe has no required configuration options. You’ll need the Moderne CLI configured before running the command below.
mod run . --recipe io.moderne.cryptography.PostQuantumCryptographyIf the recipe isn’t available locally, install it with:
mod config recipes jar install io.moderne.recipe:rewrite-cryptography:0.14.10Definition
This recipe runs the following recipes in order.
- Find hardcoded algorithm choices
io.moderne.cryptography.FindHardcodedAlgorithmChoice - Find hardcoded certificates
io.moderne.cryptography.FindHardcodedCertificate - Find hardcoded cipher suite choices
io.moderne.cryptography.FindHardcodedCiphersuiteChoice - Find hardcoded cryptographic key lengths
io.moderne.cryptography.FindHardcodedKeyLength - Find hardcoded private keys
io.moderne.cryptography.FindHardcodedPrivateKey - Find hardcoded SSL/TLS protocol choices
io.moderne.cryptography.FindHardcodedProtocolChoice - Find hardcoded cryptographic provider names
io.moderne.cryptography.FindHardcodedProviderName - Find programmatic security provider editing
io.moderne.cryptography.FindProgrammaticProviderEditing - Find SSLContext.setDefault() usage
io.moderne.cryptography.FindSSLContextSetDefault - Find direct SSL configuration editing
io.moderne.cryptography.FindDirectSSLConfigurationEditing - Find
Security.setProperty(..)calls for certain propertiesio.moderne.cryptography.FindSecuritySetProperties - Report as security issues
io.moderne.devcenter.ReportAsSecurityIssues
Data tables
Structured output this recipe can produce.
- Taint flowRecords taint flows from sources to sinks with their taint types.
org.openrewrite.analysis.java.taint.table.TaintFlowTable - Insecure `Security.setProperty(..)` uses.An itemization of the properties used in such calls
io.moderne.cryptography.table.InsecureSetProperties - Security issuesSecurity issues in the repository.
io.moderne.devcenter.table.SecurityIssues - Source files that had resultsSource files that were modified by the recipe run.
org.openrewrite.table.SourcesFileResults - Source files that had search resultsSearch results that were found during the recipe run.
org.openrewrite.table.SearchResults - Source files that errored on a recipeThe details of all errors produced by a recipe run.
org.openrewrite.table.SourcesFileErrors - Recipe performanceStatistics used in analyzing the performance of recipes.
org.openrewrite.table.RecipeRunStats