Features¶
Protocol-independent¶
Algorithms¶
key encapsulation mechanism (KEM), including the post-quantum ones supported by the Open Quantum Safe project
Vulnerabilities¶
Parameters¶
Diffie-Hellman (finite field)
Elliptic curve (domain parameters, object identifiers and field sizes)
defined by standard
defined by research paper
parameter forms
short Weierstrass over prime, binary and extension fields, the binary one both in polynomial and in optimal normal basis representation
Montgomery
twisted Edwards over prime and extension fields
Registries¶
Stores¶
Trusted root CA certificate trust stores
Certificate Transparency (CT) Logs
Cloudflare
DigiCert
Google
Let’s Encrypt
Sectigo
TrustAsia
…
Protocol-dependent¶
Attributes¶
Internet Key Exchange (IKE)
-
Encryption Algorithm
Hash Algorithm
Authentication Method
Group Description
Life Type
Pseudorandom Function
Certificate Type
Identification Type
-
Encryption Algorithm
Pseudorandom Function
Integrity Algorithm
Diffie-Hellman Group
Extended Sequence Numbers
Certificate Type
Identification Type
Authentication Method
Hash Algorithm
Secure Socket Layer (SSL)
Transport Layer Security (TLS)
Secure Shell (SSH)
Domain Name System
Client Capabilities¶
Vulnerabilities¶
Transport Layer Security (TLS)