Skip to content

Commit 63bfed5

Browse files
committed
more PKCS removal cleanup
1 parent f7fd4f4 commit 63bfed5

2 files changed

Lines changed: 0 additions & 15 deletions

File tree

checks/scoring.py

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -196,11 +196,6 @@
196196
WEB_TLS_OCSP_STAPLING_BAD = NO_POINTS
197197
WEB_TLS_OCSP_STAPLING_WORST_STATUS = STATUS_NOTICE
198198

199-
TLS_KEX_RSA_PKCS_GOOD = FULL_WEIGHT_POINTS
200-
TLS_KEX_RSA_PKCS_OK = FULL_WEIGHT_POINTS
201-
TLS_KEX_RSA_PKCS_BAD = NO_POINTS
202-
TLS_KEX_RSA_PKCS_WORST_STATUS = STATUS_NOTICE
203-
204199
WEB_TLS_KEX_HASH_FUNC_GOOD = FULL_WEIGHT_POINTS
205200
WEB_TLS_KEX_HASH_FUNC_OK = FULL_WEIGHT_POINTS
206201
WEB_TLS_KEX_HASH_FUNC_BAD = NO_POINTS

checks/tasks/tls/tls_constants.py

Lines changed: 0 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -132,16 +132,6 @@
132132
(OpenSslDigestNidEnum.SHA224, OpenSslEvpPkeyEnum.RSA),
133133
(OpenSslDigestNidEnum.SHA224, OpenSslEvpPkeyEnum.DSA),
134134
]
135-
# NCSC 3.3.2.1: RSA PKCS must not be used.
136-
# Failing these algs means the server has no RSA or RSA in PSS only, either is fine.
137-
SIGNATURE_ALGORITHMS_RSA_PKCS = [
138-
# (OpenSslDigestNidEnum.MD5, OpenSslEvpPkeyEnum.RSA),
139-
(OpenSslDigestNidEnum.SHA1, OpenSslEvpPkeyEnum.RSA),
140-
(OpenSslDigestNidEnum.SHA224, OpenSslEvpPkeyEnum.RSA),
141-
(OpenSslDigestNidEnum.SHA512, OpenSslEvpPkeyEnum.RSA),
142-
(OpenSslDigestNidEnum.SHA384, OpenSslEvpPkeyEnum.RSA),
143-
(OpenSslDigestNidEnum.SHA256, OpenSslEvpPkeyEnum.RSA),
144-
]
145135

146136
# Mail servers with an increased connection limit,
147137
# matched by substring matching on their hostname.

0 commit comments

Comments
 (0)