Enable hybrid TLS key exchange
Recipe ID
io.moderne.cryptography.pqc.EnableHybridTlsKeyExchangeArtifactio.moderne.recipe:rewrite-cryptographyPrepends an ML-KEM hybrid key-exchange group to explicitly configured named-group lists in Java and .properties sources, and reports the sites that cannot be rewritten safely. Code that configures no named groups is deliberately left alone: on JDK 27 and BouncyCastle 1.81 the provider default already offers a hybrid group, so inserting a literal list there would freeze today's defaults forever.
Composite recipeProprietary
Usage
This recipe has no required configuration options. You’ll need the Moderne CLI configured before running the command below.
mod run . --recipe io.moderne.cryptography.pqc.EnableHybridTlsKeyExchangeIf the recipe isn’t available locally, install it with:
mod config recipes jar install io.moderne.recipe:rewrite-cryptography:RELEASEDefinition
This recipe runs the following recipes in order.
- Offer a hybrid ML-KEM key exchange group first
io.moderne.cryptography.pqc.AddHybridTlsNamedGroup - Offer a hybrid ML-KEM key exchange group first in properties files
io.moderne.cryptography.pqc.AddHybridTlsNamedGroupToProperties - Find TLS key exchange sites that cannot be made hybrid automatically
io.moderne.cryptography.pqc.FindMissingHybridTlsNamedGroups
Data tables
Structured output this recipe can produce.
- Hybrid TLS key exchange enforcementNamed-group configuration rewritten to offer an ML-KEM hybrid group first, and sites flagged as needing manual review because the value is not statically resolvable or the transformation would need a BouncyCastle upgrade to compile. `-D` flags outside the scanned repository are invisible, so an unchanged repository is not evidence of a hybrid-ready runtime.
io.moderne.cryptography.pqc.table.HybridKexEnforcementTable - Source files that had resultsSource files that were modified by the recipe run.
org.openrewrite.table.SourcesFileResults - Source files that had search resultsSearch results that were found during the recipe run.
org.openrewrite.table.SearchResults - Source files that errored on a recipeThe details of all errors produced by a recipe run.
org.openrewrite.table.SourcesFileErrors - Recipe performanceStatistics used in analyzing the performance of recipes.
org.openrewrite.table.RecipeRunStats