╔══════════════════════════════════════════════════════════════════╗ ║ QNSQY CRYPTOGRAPHY MIGRATION REPORT ║ ╚══════════════════════════════════════════════════════════════════╝ Scanned: ./demo-vault Total cryptographic files: 10 ═══ RISK SUMMARY ═══ 🔴 CRITICAL: 5 files 🟠 HIGH: 2 files 🟡 MEDIUM: 2 files 🟢 LOW: 0 files ✅ SAFE: 1 files ═══ CRITICAL RISK FILES (Quantum Vulnerable) ═══ 🔴 ./demo-vault/archives/ledger-2021.txt.gpg Type: GPG Encrypted Algorithms: RSA-2048, AES-256 → RSA-2048: Replace with ML-KEM-768/1024 for encryption or ML-DSA-65/87 for signatures 🔴 ./demo-vault/archives/patient-export-2019.csv.gpg Type: GPG Encrypted Algorithms: RSA-2048, AES-256 → RSA-2048: Replace with ML-KEM-768/1024 for encryption or ML-DSA-65/87 for signatures 🔴 ./demo-vault/certs/backup-identity.p12 Type: PKCS#12 Keystore Algorithms: RSA-2048, 3DES → RSA-2048: Replace with ML-KEM-768/1024 for encryption or ML-DSA-65/87 for signatures → 3DES: Replace with AES-256 or ChaCha20-Poly1305 🔴 ./demo-vault/certs/api-gateway-ecdsa.key Type: PKCS#8 Private Key Algorithms: RSA-2048 → RSA-2048: Replace with ML-KEM-768/1024 for encryption or ML-DSA-65/87 for signatures 🔴 ./demo-vault/certs/legacy-server-rsa2048.key Type: PKCS#8 Private Key Algorithms: RSA-2048 → RSA-2048: Replace with ML-KEM-768/1024 for encryption or ML-DSA-65/87 for signatures ═══ HIGH RISK FILES ═══ 🟠 ./demo-vault/ssh/id_ed25519.pub Algorithms: Ed25519 🟠 ./demo-vault/ssh/id_ed25519 Algorithms: Ed25519 ═══ ALGORITHMS DETECTED ═══ • 3DES • AES-256 • Ed25519 • ML-KEM-768 • RSA-2048 • Unknown (PEM format) ═══ MIGRATION RECOMMENDATIONS ═══ 1. IMMEDIATE: Replace RSA/ECDSA keys with ML-DSA-65/87 2. IMMEDIATE: Replace ECDH with ML-KEM-768 or hybrid X25519+ML-KEM 3. PRIORITY: Re-encrypt GPG/PGP files with QNSQY (post-quantum) 4. CONSIDER: Upgrade AES-128 to AES-256 for Grover resistance