{
  "$schema": "https://cyclonedx.org/schema/bom-1.7.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "serialNumber": "urn:uuid:019c8f20-5a4d-7b11-8f20-123456789abc",
  "version": 1,
  "metadata": {
    "timestamp": "2026-09-14T00:00:00Z",
    "component": {
      "type": "application",
      "bom-ref": "cipherdiscovery:target:019c8f20-5a4d-7b11-8f20-123456789abc",
      "name": "tls.example.com:443",
      "version": "example",
      "description": "Synthetic public TLS endpoint used only for documentation. This component does not represent internal infrastructure or a complete organizational inventory.",
      "properties": [
        {
          "name": "cipherdiscovery:scan-id",
          "value": "019c8f20-5a4d-7b11-8f20-123456789abc"
        },
        {
          "name": "cipherdiscovery:source-kind",
          "value": "public_tls"
        }
      ]
    },
    "properties": [
      {
        "name": "cipherdiscovery:coverage:count:discovered",
        "value": "2"
      },
      {
        "name": "cipherdiscovery:coverage:count:inferred",
        "value": "0"
      },
      {
        "name": "cipherdiscovery:coverage:count:not_scanned",
        "value": "1"
      },
      {
        "name": "cipherdiscovery:coverage:count:scanned",
        "value": "1"
      },
      {
        "name": "cipherdiscovery:coverage:count:unknown",
        "value": "1"
      },
      {
        "name": "cipherdiscovery:coverage:item:coverage-internal",
        "value": "{\"scopeKind\":\"scope_boundary\",\"scopeKey\":\"internal_infrastructure\",\"label\":\"Internal infrastructure\",\"coverageState\":\"not_scanned\",\"outcome\":\"excluded\",\"assertionBasis\":\"scope_boundary\",\"reasonCode\":\"outside_public_tls_scope\",\"detail\":\"Internal infrastructure was not scanned.\",\"evidenceIds\":[]}"
      },
      {
        "name": "cipherdiscovery:coverage:item:coverage-public-tls",
        "value": "{\"scopeKind\":\"endpoint\",\"scopeKey\":\"tls.example.com:443\",\"label\":\"Public TLS endpoint\",\"coverageState\":\"scanned\",\"outcome\":\"observed\",\"assertionBasis\":\"direct_observation\",\"reasonCode\":\"tls_observed\",\"detail\":\"The explicitly submitted public TLS endpoint was inspected.\",\"evidenceIds\":[\"evidence-protocol\",\"evidence-certificate\"]}"
      },
      {
        "name": "cipherdiscovery:coverage:item:coverage-tls12",
        "value": "{\"scopeKind\":\"probe\",\"scopeKey\":\"192.0.2.10:TLS 1.2\",\"label\":\"TLS 1.2\",\"coverageState\":\"unknown\",\"outcome\":\"failed\",\"assertionBasis\":\"failure\",\"reasonCode\":\"tls_handshake_failed\",\"detail\":\"No authoritative observation.\",\"evidenceIds\":[]}"
      },
      {
        "name": "cipherdiscovery:exporter:version",
        "value": "1.0.0"
      },
      {
        "name": "cipherdiscovery:internal-infrastructure-scanned",
        "value": "false"
      },
      {
        "name": "cipherdiscovery:inventory-boundary",
        "value": "Not a Complete Cryptographic Inventory"
      },
      {
        "name": "cipherdiscovery:limitation:public_exposure_only",
        "value": "{\"title\":\"Public exposure only\",\"detail\":\"Not a complete cryptographic inventory.\"}"
      },
      {
        "name": "cipherdiscovery:report:schema-version",
        "value": "1.0.0"
      },
      {
        "name": "cipherdiscovery:report:type",
        "value": "Public Cryptographic Exposure"
      },
      {
        "name": "cipherdiscovery:ruleset:version",
        "value": "example"
      },
      {
        "name": "cipherdiscovery:scan:status",
        "value": "partial"
      },
      {
        "name": "cipherdiscovery:scanner:version",
        "value": "example"
      },
      {
        "name": "cipherdiscovery:standards-catalog:version",
        "value": "example"
      }
    ]
  },
  "components": [
    {
      "type": "cryptographic-asset",
      "bom-ref": "cipherdiscovery:asset:asset-certificate",
      "name": "Leaf certificate — tls.example.com",
      "cryptoProperties": {
        "assetType": "certificate",
        "certificateProperties": {
          "subjectName": "CN=tls.example.com",
          "issuerName": "CN=Synthetic Documentation CA",
          "notValidBefore": "2026-09-13T00:00:00Z",
          "notValidAfter": "2026-10-14T00:00:00Z",
          "certificateFormat": "X.509",
          "fingerprint": {
            "alg": "SHA-256",
            "content": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
          }
        }
      },
      "properties": [
        {
          "name": "cipherdiscovery:assertion-status",
          "value": "discovered"
        },
        {
          "name": "cipherdiscovery:certificate:key-size-bits",
          "value": "2048"
        },
        {
          "name": "cipherdiscovery:certificate:presented-role",
          "value": "leaf"
        },
        {
          "name": "cipherdiscovery:certificate:public-key-algorithm",
          "value": "RSA"
        },
        {
          "name": "cipherdiscovery:certificate:signature-algorithm",
          "value": "SHA256-RSA"
        },
        {
          "name": "cipherdiscovery:confidence",
          "value": "high"
        },
        {
          "name": "cipherdiscovery:evidence-ids",
          "value": "evidence-certificate"
        },
        {
          "name": "cipherdiscovery:pqc-migration-relevance",
          "value": "review_required"
        },
        {
          "name": "cipherdiscovery:risk-assessment-ids",
          "value": "risk-certificate"
        },
        {
          "name": "cipherdiscovery:risk-rules",
          "value": "pqc_public_key_classification@example"
        },
        {
          "name": "cipherdiscovery:source-asset-id",
          "value": "asset-certificate"
        },
        {
          "name": "cipherdiscovery:source-identity-kind",
          "value": "x509_sha256"
        },
        {
          "name": "cipherdiscovery:source-identity-value",
          "value": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
        }
      ]
    },
    {
      "type": "cryptographic-asset",
      "bom-ref": "cipherdiscovery:asset:asset-protocol",
      "name": "TLS 1.3 / TLS_AES_128_GCM_SHA256",
      "cryptoProperties": {
        "assetType": "protocol",
        "protocolProperties": {
          "type": "tls",
          "version": "1.3",
          "cipherSuites": [
            {
              "name": "TLS_AES_128_GCM_SHA256"
            }
          ]
        }
      },
      "properties": [
        {
          "name": "cipherdiscovery:assertion-status",
          "value": "discovered"
        },
        {
          "name": "cipherdiscovery:confidence",
          "value": "high"
        },
        {
          "name": "cipherdiscovery:evidence-ids",
          "value": "evidence-protocol"
        },
        {
          "name": "cipherdiscovery:pqc-migration-relevance",
          "value": "monitor_or_confirm"
        },
        {
          "name": "cipherdiscovery:risk-assessment-ids",
          "value": "risk-protocol"
        },
        {
          "name": "cipherdiscovery:risk-rules",
          "value": "tls_parameters_context@example"
        },
        {
          "name": "cipherdiscovery:source-asset-id",
          "value": "asset-protocol"
        },
        {
          "name": "cipherdiscovery:source-identity-kind",
          "value": "context_sha256"
        },
        {
          "name": "cipherdiscovery:source-identity-value",
          "value": "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "cipherdiscovery:target:019c8f20-5a4d-7b11-8f20-123456789abc",
      "dependsOn": [
        "cipherdiscovery:asset:asset-certificate",
        "cipherdiscovery:asset:asset-protocol"
      ]
    }
  ]
}
