メインコンテンツまでスキップ

PQCスキャナー入門

適用対象:
Windows 10+LinuxmacOS

前提条件​

前提条件

  • サポートされているオペレーティングシステム(Windows 10+、Linux、macOS)
  • エージェントスキャンおよび Windows 証明書ストアには管理者/root アクセス
  • スキャンターゲットへのネットワーク接続(ドメインスキャンには 443/TCP ポート)
  • 最小 4GB RAM(8GB を推奨)
  • 5GB の空きディスク容量

インストール​

Cockpit から配布されます(公開リリースではありません)

dke-scanner-agent のバイナリは GitHub にも公開 Docker レジストリにも公開されていません。各 Cockpit テナントは、Operations.Pki.Scanner.Agent.Download 権限で保護された、有効期限の短い署名付きダウンロードリンクを独自に提供します。

インストーラーを生成する

DuoKey Cockpit で Scanner Agents → Generate Installer に移動し、プラットフォーム(Windows x64、Linux x64/arm64、macOS x64/arm64)を選択します。署名付きダウンロードリンクと、1時間有効な使い捨ての登録トークンが返されます。

バイナリをダウンロードする

リンクからお使いのプラットフォーム用のバイナリをダウンロードします。Linux/macOS では実行可能にして $PATH に配置します: chmod +x dke-scanner-agent-* && sudo mv dke-scanner-agent-* /usr/local/bin/dke-scanner-agent。

Cockpit に登録する

enroll を一度実行してホストを登録し、~/.dke/agent.toml(Unix ではモード 0600)を作成します。

dke-scanner-agent enroll --server https://cockpit.example.com --token <bundle-token>
ヒント

シェル履歴やプロセス一覧に残らないよう、トークンは --token ではなく環境変数 DKE_AGENT_ENROLL_TOKEN で渡してください。Cockpit のリリースがバイナリのハッシュを公開している場合は --expected-sha256 <hex> を追加すると、一致しない場合は登録が拒否されます。

クイックスタート: 最初のスキャン​

利用可能なスキャンモード

filesystem証明書、キーストア、鍵を求めてディレクトリをスキャン
domainリモートの TLS/SSL エンドポイントを分析
agentシステム全体の完全な暗号インベントリ
sourcecodeコード内の暗号パターンの静的解析

1. ファイルシステムスキャン​

証明書、キーストア、秘密鍵を求めてディレクトリをスキャンします。

# Scan current directory (default: recursive, max-depth 10)
dke-scanner-agent filesystem

# Scan specific directory with output
dke-scanner-agent filesystem --path /etc/ssl/certs --output scan.json

# Scan with specific extensions and thread count
dke-scanner-agent filesystem \
--path /opt/app \
--extensions .pem,.crt,.p12,.jks \
--exclude node_modules,.git,target \
--threads 8 \
--format html \
--output report.html

# Include Windows Certificate Store scanning
dke-scanner-agent filesystem --scan-windows-certstore

2. ドメインスキャン​

リモートの TLS エンドポイントを分析し、証明書チェーンを抽出します。

# Basic domain scan
dke-scanner-agent domain --target example.com

# Custom port with timeout
dke-scanner-agent domain --target api.example.com --port 8443 --timeout 30

# With subdomain discovery (requires WhoisXML API key)
dke-scanner-agent domain \
--target example.com \
--discover-subdomains \
--subdomain-api-key $WHOISXML_API_KEY \
--max-subdomains 50

# Enable PQ key exchange detection (requires elevated privileges)
sudo dke-scanner-agent domain --target example.com --detect-pq-kex --interface eth0
注記

ドメインスキャナーは TLS 接続に Rustls を使用します。デフォルトでは、TLS 1.3 の鍵交換は X25519 であると想定されます。パケットキャプチャを伴う --detect-pq-kex を使用して、X25519MLKEM768 または Kyber768 の鍵交換を検出してください。

3. エージェントスキャン​

システム全体の包括的な暗号インベントリ。

# Full system scan (requires elevated privileges)
sudo dke-scanner-agent agent

# Skip process scanning for faster results
sudo dke-scanner-agent agent --no-process-scan

# Save results
sudo dke-scanner-agent agent --output system-scan.json --format json

4. ソースコードスキャン​

150 以上の検出ルールを用いて、8 言語にわたるソースコード内の暗号使用パターンを静的解析します。

# Scan local directory
dke-scanner-agent sourcecode --path /path/to/code

# Scan GitHub repository
dke-scanner-agent sourcecode \
--github-repo owner/repo \
--github-token $GITHUB_TOKEN \
--branch main

# Scan GitLab project
dke-scanner-agent sourcecode \
--gitlab-project group/project \
--gitlab-token $GITLAB_TOKEN

# Scan Azure DevOps repository
dke-scanner-agent sourcecode \
--azdo-org myorg \
--azdo-project myproject \
--azdo-repo myrepo \
--azdo-token $AZDO_TOKEN

5. CI/CD モード​

SARIF 出力と重大度による失敗しきい値を用いて、スキャンを CI/CD パイプラインに統合します。

# Scan with SARIF output for GitHub/GitLab security tabs
dke-scanner-agent ci --source-path . --format sarif --output results.sarif

# Fail build on high severity findings
dke-scanner-agent ci --source-path ./src --fail-on high --output ci-scan.json

# Fail only on critical
dke-scanner-agent ci --fail-on critical

スキャン後のワークフロー​

CBOM の生成​

検出結果を CycloneDX 1.7 暗号部品表(Cryptographic Bill of Materials)としてエクスポートします。

# Run scan first
dke-scanner-agent filesystem --path /app --output scan.json

# Generate CBOM
dke-scanner-agent cbom \
--input scan.json \
--app-name "Payment Gateway" \
--app-version "2.5.1" \
--output payment-gateway-cbom.json

コンプライアンスの確認​

dke-scanner-agent compliance \
--scan-results scan.json \
--frameworks "NIST-800-131A,PCI-DSS-4.0,HIPAA,SOC2" \
--organization "Acme Corp" \
--format all \
--output compliance-reports/

ServiceNow への公開​

dke-scanner-agent servicenow \
--instance $SERVICENOW_INSTANCE \
--token $SERVICENOW_TOKEN \
--input scan.json \
--auto-incidents true

Web ダッシュボードの起動​

# Start on default port 3000
dke-scanner-agent serve

# Custom port
dke-scanner-agent serve --port 8080

結果の理解​

リスク重大度レベル​

重大度スコア範囲優先度対応
Critical9.0-10.0P0即時対応 - RSA <2048、DSA、3DES、RC4
High7.0-8.9P13 か月以内 - RSA-2048、ECDSA、EdDSA
Medium5.0-6.9P26 か月以内 - RSA-3072
Low3.0-4.9P312 か月以内 - RSA-4096
Info0-2.9P4監視 - PQC アルゴリズム(ML-KEM、ML-DSA、SLH-DSA)

スキャン結果の構造​

設定​

# Git provider tokens (for source code scanning)
export GITHUB_TOKEN="ghp_xxxxxxxxxxxx"
export GITLAB_TOKEN="glpat-xxxxxxxxxxxx"
export AZDO_TOKEN="xxxxxxxxxxxx"

# ServiceNow credentials
export SERVICENOW_INSTANCE="https://dev12345.service-now.com"
export SERVICENOW_USER="api_user"
export SERVICENOW_PASSWORD="secret"
export SERVICENOW_TOKEN="oauth-token" # Alternative to user/password

# Subdomain discovery
export WHOISXML_API_KEY="your-api-key"

# Logging verbosity
export RUST_LOG=info # debug, info, warn, error, trace

# Web dashboard authentication (optional)
export PQC_AUTH_MODE=none # none | oidc | api_key | both
export PQC_PORT=3000

トラブルシューティング​

ヒント

包括的なインフラストラクチャ評価を実行する前に、まず単一の filesystem または domain スキャンから始めて、出力形式に慣れてください。