[Defect]: Variant pattern for PBES2 must have {prfFunction} instead of {kdf}
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 75/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- cryptography
- Domain
- cryptography
Research direction
Start in the Cryptography Registry and locate the PBES2 variant pattern. Check the PBES2 parameters against RFC 8018 and the linked Java standard-names example, then confirm the pattern uses {prfFunction} rather than {kdf} without changing schema behavior or adding algorithms.
Written by the indexing model from the issue text.
Description
Describe the defect
As per RFC8018 PBES2 combines a password-based key derivation function, which shall be PBKDF2 for this version of PKCS #5, with an underlying encryption scheme. Therefore, the variable {prfFunction} which is one of the parameters for the underlying PBKDF2 must be an element of the variant pattern instead of {kdf}.
Refer https://docs.oracle.com/en/java/javase/25/docs/specs/security/standard-names.html#cipher-algorithms for example of PBES2 usage.
Additional context
The issue is data-quality / naming defect in the Cryptography Registry and can be fixed without changing schema behavior or introducing new algorithms.
- Dominant language
- XSLT
- Stars
- 555
- Forks
- 93
- Avg merge
- 9h 55m
- Merged PRs (30d)
- 21
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from CycloneDX/specification
-
Response vs ResponceOpen
Difficulty 1/5 Under an hour Newbie friendliness 68/100
CycloneDX/specification#1121 · 1 comment ·
Maintainers usually reply within 1 day
-
defect documentation
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
CycloneDX/specification#1115 ·
Maintainers usually reply within 1 day
-
cap: cryptography-registry
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
CycloneDX/specification#1098 ·
Maintainers usually reply within 1 day
-
defect
Difficulty 1/5 Under an hour Newbie friendliness 91/100
CycloneDX/specification#1045 · 2 comments ·
Maintainers usually reply within 1 day
-
CDX 2.0 documentation ready for review
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
CycloneDX/specification#1035 ·
Maintainers usually reply within 1 day
All issues in CycloneDX/specification
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 84/100
dusk-network/plonk#988 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
freedomofpress/securedrop-protocol#408 ·
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Documentation help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
golang/go#81933 · 2 comments ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 2 days