Introduction¶
What is CBOM Generator?¶
The Cryptography Bill of Materials (CBOM) Generator is a production-ready, high-performance C11 multithreaded application that inventories cryptographic assets on Linux systems to assess Post-Quantum Cryptography (PQC) readiness.
Key Capabilities¶
- Comprehensive Asset Discovery: Certificates, keys, packages, services, protocols, cipher suites
- Complete Dependency Graph: Tracks relationships between services, protocols, and algorithms
- PQC Readiness Assessment: Analyzes quantum vulnerability across your entire cryptographic infrastructure
- High Performance: Scans 12,000+ files/minute with parallel processing
- Privacy-by-Default: GDPR/CCPA compliant with configurable redaction
- Industry Standards: Outputs CycloneDX 1.6/1.7 format with CBOM extensions
Version: 1.9.0 | Platform: Linux (Ubuntu, RHEL, Debian)
Why Use CBOM Generator?¶
For Security Teams¶
- Inventory all cryptographic assets before quantum computers break current encryption
- Identify weak or deprecated algorithms that need immediate replacement
- Track certificate expiration and trust issues
- Map service dependencies on cryptographic components
For Compliance¶
- Generate machine-readable cryptographic inventories for audits (CyclneDX standard format)
- Track FIPS 140-2/3 certified implementations
- Document privacy controls and data redaction
- Provide SLSA provenance for build transparency
For Operations¶
- Discover all TLS/SSH configurations across infrastructure
- Identify services using deprecated protocols or cipher suites
- Plan migrations with PQC readiness scoring and recommendations
Yocto CBOM Sample¶
Click to expand: Full first 200 lines of yocto-cbom.json
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 | |
View the full Yocto CBOM on GitHub (pretty-printed, searchable)↗
License¶
crypto-tracer like all the tools in CipherIQ is dual-licensed:
- GPL 3.0 - Free for open-source use (copyleft applies when distributing)
- Commercial license - For proprietary integration without copyleft obligations
Quick Links¶
- Installation - Get started with building and installing
- Quick Start - Run your first scan
- CLI Reference - Complete command-line options
- Features - Deep-dive into capabilities
- Playbooks - Step-by-step migration guides
Copyright (c) 2025 Graziano Labs Corp.