oss-sec mailing list archives

Release of pqcscan


From: "Vincent Berg" <gvb () tleilax io>
Date: Thu, 10 Jul 2025 08:11:19 +0200

After reading oss-security for years I finally felt I may have something to contribute. I want share the public release 
of pqcscan.

What is it? It is a dedicated scanner to test SSH and TLS services for their support of Post-Quantum Cryptographic 
algorithms. It's released under 2-clause BSD license so it seems it would fit here just fine.

Why? Given the push of big players in the industry (Cloudflare, Google etc) on PQC support, as well as upcoming 
regulatory requirements (see [2]), it seemed to me a good idea to try and improve tooling on this.

I'm sure there's tons of space for other options as well (specific filter options to tlsscan, nmap nse scripts etc), 
but wanted to throw my hat in the ring and hopefully get some useful feedback, feature requests or bugs of people.

A bit more context on it and some scan results of the top 10k domains can be found at [1].  The code and binary 
releases can be found at [2].

Thanks for your attention to this matter,
Vincent

[1] https://www.anvilsecure.com/blog/scanning-for-post-quantum-cryptographic-support.html
[2] https://github.com/anvilsecure/pqcscan


Current thread: