JavaScript is not currently enabled, but is required for full CodeSonar manual search and browse functionality.
If you are viewing this file in your hub's Web GUI, enable JavaScript in your browser: you will also need it for GUI functionality.
If you opened this file directly from disk, your browser may be directly suppressing JavaScript functionality: certain browsers perform this suppression on local files (but not files delivered by web servers) for security reasons.
| CodeSonar® 27.0w | AdaCore Inc |
A function uses a cryptographic operation, but is missing a prerequisite step for that operation.
| Class Name | Missing Required Cryptographic Step (Java) | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Significance | security | |||||||||
| Mnemonic | JAVA.CRYPTO.MRCS | |||||||||
| Categories |
|
|||||||||
| Availability | Available for Java and Kotlin. | |||||||||
| Enabling | Checks for this warning class are enabled by
default. To disable them, add the following WARNING_FILTER rule to the
project configuration file.
WARNING_FILTER += discard class="Missing Required Cryptographic Step (Java)" |
import java.security.MessageDigest;
import java.security.NoSuchAlgorithmException;
import javax.crypto.KeyGenerator;
import javax.crypto.SecretKey;
public class MissingCryptoStep {
// Generating a key without first calling init() falls back to a
// provider-chosen default key size, which may be weaker than intended
// and may differ between cryptographic providers.
SecretKey weakKey() throws NoSuchAlgorithmException {
KeyGenerator keyGenerator = KeyGenerator.getInstance("AES");
return keyGenerator.generateKey(); // 'Missing Required Cryptographic Step (Java)' warning issued here
}
// Calling init() with an explicit key size selects the key strength
// deterministically before generateKey().
SecretKey strongKey() throws NoSuchAlgorithmException {
KeyGenerator keyGenerator = KeyGenerator.getInstance("AES");
keyGenerator.init(256);
return keyGenerator.generateKey(); // ok: key size fixed by init()
}
// Calling digest() without first supplying data with update() hashes an
// empty input, so the result reflects none of the intended message.
byte[] emptyHash() throws NoSuchAlgorithmException {
MessageDigest messageDigest = MessageDigest.getInstance("SHA-512");
return messageDigest.digest(); // 'Missing Required Cryptographic Step (Java)' warning issued here
}
// Feeding the message with update() before digest() hashes the data.
byte[] hashOf(byte[] data) throws NoSuchAlgorithmException {
MessageDigest messageDigest = MessageDigest.getInstance("SHA-512");
messageDigest.update(data);
return messageDigest.digest(); // ok: data supplied via update()
}
}
To reproduce this example, analyze it with the following configuration:
JAVA_ANALYSIS_ENTRY_POINTS_MODE = ALL_METHODS
Add the missing cryptographic step.
The following configuration file parameters affect checks for this warning class.
To report problems with this documentation, please visit https://support.adacore.com/csm.