Glossary
Definitions of key terms used in the BigFix Quantum Risk Analyzer documentation.
| Term | Definition |
|---|---|
| Archive Manager | A BigFix capability that uploads files from endpoints to the Root Server. QRA uses it only for the Elasticsearch-forwarding and CBOM scan options. |
| BigFix Analysis | A collection of Relevance property expressions activated against BigFix Clients to aggregate endpoint data in Web Reports. QRA provides five Analyses (see Activating the QRA Analyses and Configuring DataBridge). |
| BigFix Task | An admin-initiated action that stays relevant after running, enabling re-use on a schedule. QRA uses Tasks, not Fixlets. |
| CBOM | Cryptographic Bill of Materials - complete inventory of cryptographic implementations on a system. |
certscanner |
The cross-platform scanner binary. Windows amd64, Linux x64, macOS
amd64/arm64. Delivered by the Scan Tool Task as platform-specific
packages named
cryptographic-analyzer-<platform>-<arch>-<version>. |
| DataBridge | Optional service on the BigFix Root Server that transfers forwarded scan output from the Upload Manager buffer to Elasticsearch. Only the Root Server needs Elasticsearch network access. |
| Endpoint Scan | Standard QRA scan type (the Scan Endpoint
action) covering active network connections, running processes, and
memory-loaded libraries. The -fullscan flag activates:
cipherscan, scanmemory, scanfilesystem, scanoutlookarchives,
detect-vpn-clients, detect-ipsec. |
| Filesystem Scan | Optional, separate QRA scan that searches local disk for certificates, keystores, and private keys. Detects PQC algorithms (ML-DSA, ML-KEM, SLH-DSA). Must be deliberately initiated. |
| Harvest Now, Decrypt Later | Adversarial strategy: collect encrypted data now, decrypt once quantum computers mature. Key PQC urgency driver. |
| ML-DSA / ML-KEM / SLH-DSA | NIST-standardized PQC algorithms: ML-DSA (Dilithium - signatures), ML-KEM (Kyber - key encapsulation), SLH-DSA (SPHINCS+ - hash-based signatures). Detected by the filesystem scan. |
| PQC | Post-Quantum Cryptography - algorithms designed to be secure against quantum computing attacks. |
QRA_License |
BigFix Client setting required for the scan Task to become relevant on endpoints. Scanning is not available until this setting exists. |
| Quantum Readiness Score | A 0-100 score across Hardware (40 pts), OS (30 pts), Crypto Libraries (25 pts), and Network (5 pts) with sub-categories in each. Thresholds differ for workstations and servers. A 32-bit architecture results in automatic score 0. |
| Scan Health Report | BigFix Web Report showing when each endpoint last ran the scanner and whether it succeeded. |