CycloneDX / CycloneDX/specification

[Defect]: Variant pattern for PBES2 must have {prfFunction} instead of {kdf}

Open
#905 0 comments 0 reactions 0 assignees View on GitHub
cap: cryptography-registry defect
Dominant language
XSLT
Stars
547
Forks
93
Avg merge
7h 11m
Merged PRs (30d)
37

Description

## Describe the defect

As per [RFC8018](https://datatracker.ietf.org/doc/html/rfc8018#section-6.2) PBES2 combines a password-based key derivation function, which shall be PBKDF2 for this version of PKCS #5, with an underlying encryption scheme. Therefore, the variable {prfFunction} which is one of the parameters for the underlying PBKDF2 must be an element of the variant pattern instead of {kdf}.

Refer https://docs.oracle.com/en/java/javase/25/docs/specs/security/standard-names.html#cipher-algorithms for example of PBES2 usage.

## Additional context

The issue is data-quality / naming defect in the Cryptography Registry and can be fixed without changing schema behavior or introducing new algorithms.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.