adoptium / adoptium/infrastructure
Post Quantum Cryptography review
- Dominant language
- Python
- Stars
- 96
- Forks
- 106
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 12
Description
Possible Epic. After going through the secure development training on post quantum cryptography (qpc), I think it would be a good idea to do a review on some of the 'classic' ways in which we are using cryptographic encryption in this organisation/repo and decide if these methods need to be updated to those that are 'quantum safe'.
Areas where we use cryptographic encryption methods:
- Temurin signing gpg key
- JSF signing of the SBOM
- ssh keys of the infra team
- ECDSA public host keys
(will add more to the list after a review)
Contributor guide
Research direction
Start by reviewing the listed cryptographic uses: the Temurin signing GPG key, JSF SBOM signing, infrastructure-team SSH keys, and ECDSA public host keys. Expand the inventory as needed, assess whether each method is quantum safe, and document which methods should be updated and why.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cryptography
- Domain
- cryptography, infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100