adoptium / adoptium/infrastructure

Post Quantum Cryptography review

Open
#4,113 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
96
Forks
106
Avg merge
1d 16h
Merged PRs (30d)
12

Description

Possible Epic. After going through the secure development training on post quantum cryptography (qpc), I think it would be a good idea to do a review on some of the 'classic' ways in which we are using cryptographic encryption in this organisation/repo and decide if these methods need to be updated to those that are 'quantum safe'.

Areas where we use cryptographic encryption methods:

- Temurin signing gpg key
- JSF signing of the SBOM
- ssh keys of the infra team
- ECDSA public host keys

(will add more to the list after a review)

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the listed cryptographic uses: the Temurin signing GPG key, JSF SBOM signing, infrastructure-team SSH keys, and ECDSA public host keys. Expand the inventory as needed, assess whether each method is quantum safe, and document which methods should be updated and why.

Written by the indexing model from the issue text.

Assessment

Tech stack
cryptography
Domain
cryptography, infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.