Glossary

Definitions of key terms used in the BigFix Quantum Risk Analyzer documentation.

Table 1. Glossary
Term Definition
Archive Manager A BigFix capability that uploads files from endpoints to the Root Server. QRA uses it only for the Elasticsearch-forwarding and CBOM scan options.
BigFix Analysis A collection of Relevance property expressions activated against BigFix Clients to aggregate endpoint data in Web Reports. QRA provides five Analyses (see Activating the QRA Analyses and Configuring DataBridge).
BigFix Task An admin-initiated action that stays relevant after running, enabling re-use on a schedule. QRA uses Tasks, not Fixlets.
CBOM Cryptographic Bill of Materials - complete inventory of cryptographic implementations on a system.
certscanner The cross-platform scanner binary. Windows amd64, Linux x64, macOS amd64/arm64. Delivered by the Scan Tool Task as platform-specific packages named cryptographic-analyzer-<platform>-<arch>-<version>.
DataBridge Optional service on the BigFix Root Server that transfers forwarded scan output from the Upload Manager buffer to Elasticsearch. Only the Root Server needs Elasticsearch network access.
Endpoint Scan Standard QRA scan type (the Scan Endpoint action) covering active network connections, running processes, and memory-loaded libraries. The -fullscan flag activates: cipherscan, scanmemory, scanfilesystem, scanoutlookarchives, detect-vpn-clients, detect-ipsec.
Filesystem Scan Optional, separate QRA scan that searches local disk for certificates, keystores, and private keys. Detects PQC algorithms (ML-DSA, ML-KEM, SLH-DSA). Must be deliberately initiated.
Harvest Now, Decrypt Later Adversarial strategy: collect encrypted data now, decrypt once quantum computers mature. Key PQC urgency driver.
ML-DSA / ML-KEM / SLH-DSA NIST-standardized PQC algorithms: ML-DSA (Dilithium - signatures), ML-KEM (Kyber - key encapsulation), SLH-DSA (SPHINCS+ - hash-based signatures). Detected by the filesystem scan.
PQC Post-Quantum Cryptography - algorithms designed to be secure against quantum computing attacks.
QRA_License BigFix Client setting required for the scan Task to become relevant on endpoints. Scanning is not available until this setting exists.
Quantum Readiness Score A 0-100 score across Hardware (40 pts), OS (30 pts), Crypto Libraries (25 pts), and Network (5 pts) with sub-categories in each. Thresholds differ for workstations and servers. A 32-bit architecture results in automatic score 0.
Scan Health Report BigFix Web Report showing when each endpoint last ran the scanner and whether it succeeded.