JavaScript is not currently enabled, but is required for full CodeSonar manual search and browse functionality.

If you are viewing this file in your hub's Web GUI, enable JavaScript in your browser: you will also need it for GUI functionality.

If you opened this file directly from disk, your browser may be directly suppressing JavaScript functionality: certain browsers perform this suppression on local files (but not files delivered by web servers) for security reasons.

CodeSonar® 27.0w AdaCore Inc
Java


JAVA.CRYPTO.MRCS : Missing Required Cryptographic Step (Java)

Summary

A function uses a cryptographic operation, but is missing a prerequisite step for that operation.

Properties

Class Name Missing Required Cryptographic Step (Java)
Significance security
Mnemonic JAVA.CRYPTO.MRCS
Categories
CWE CWE:325 Missing Cryptographic Step
OWASP-2021 OWASP-2021:A2 Cryptographic Failures
OWASP-2025 OWASP-2025:A04 Cryptographic Failures
Availability Available for Java and Kotlin.
Enabling Checks for this warning class are enabled by default. To disable them, add the following WARNING_FILTER rule to the project configuration file.
WARNING_FILTER += discard class="Missing Required Cryptographic Step (Java)"

Example

import java.security.MessageDigest;
import java.security.NoSuchAlgorithmException;

import javax.crypto.KeyGenerator;
import javax.crypto.SecretKey;

public class MissingCryptoStep {

    // Generating a key without first calling init() falls back to a
    // provider-chosen default key size, which may be weaker than intended
    // and may differ between cryptographic providers.
    SecretKey weakKey() throws NoSuchAlgorithmException {
        KeyGenerator keyGenerator = KeyGenerator.getInstance("AES");
        return keyGenerator.generateKey();   // 'Missing Required Cryptographic Step (Java)' warning issued here
    }

    // Calling init() with an explicit key size selects the key strength
    // deterministically before generateKey().
    SecretKey strongKey() throws NoSuchAlgorithmException {
        KeyGenerator keyGenerator = KeyGenerator.getInstance("AES");
        keyGenerator.init(256);
        return keyGenerator.generateKey();   // ok: key size fixed by init()
    }

    // Calling digest() without first supplying data with update() hashes an
    // empty input, so the result reflects none of the intended message.
    byte[] emptyHash() throws NoSuchAlgorithmException {
        MessageDigest messageDigest = MessageDigest.getInstance("SHA-512");
        return messageDigest.digest();       // 'Missing Required Cryptographic Step (Java)' warning issued here
    }

    // Feeding the message with update() before digest() hashes the data.
    byte[] hashOf(byte[] data) throws NoSuchAlgorithmException {
        MessageDigest messageDigest = MessageDigest.getInstance("SHA-512");
        messageDigest.update(data);
        return messageDigest.digest();       // ok: data supplied via update()
    }
}

To reproduce this example, analyze it with the following configuration:

JAVA_ANALYSIS_ENTRY_POINTS_MODE = ALL_METHODS

Resolution

Add the missing cryptographic step.

Relevant Configuration File Parameters

The following configuration file parameters affect checks for this warning class.

 

To report problems with this documentation, please visit https://support.adacore.com/csm.