Skip to content

Protocol: Missing Post-Quantum Key Exchange

Identifier: issue_ssl_missing_post_quantum_key_exchange

Scanner(s) Support

GraphQL Scanner REST Scanner WebApp Scanner ASM Scanner

Description

A TLS service that negotiates only classical key exchange exposes every session it serves to harvest now, decrypt later: an attacker records the handshake today and derives the session key once a cryptographically relevant quantum computer can break elliptic-curve Diffie-Hellman. Key exchange is the part of TLS that cannot be fixed retroactively: rotating the certificate or upgrading the cipher later does not protect traffic that was already captured.

How we test: We open a TLS 1.3 handshake offering only the hybrid ML-KEM key exchange groups (X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024) and read back the group the server selected. A second handshake with the classical groups establishes that the endpoint speaks TLS at all, so an unreachable service is never reported as lacking post-quantum support.

References:

Configuration

Example

Example configuration:

---
security_tests:
  issue_ssl_missing_post_quantum_key_exchange:
    skip: false

Reference

skip

Type : boolean

Skip the test if true.