Re: Request dev help: Info for required crypto export declaration

2011-09-22 Thread Michael Stahl
[this mail has managed to hide in a draft folder for weeks...] On 01.09.2011 23:01, Robert Burrell Donkin wrote: On Thu, Sep 1, 2011 at 9:35 PM, Dennis E. Hamilton dennis.hamil...@acm.org wrote: Technically, this was to have been resolved before the code was put up on SVN. We need to audit

RE: Request dev help: Info for required crypto export declaration

2011-09-22 Thread Dennis E. Hamilton
: Michael Stahl [mailto:m...@openoffice.org] Sent: Thursday, September 22, 2011 09:18 To: ooo-dev@incubator.apache.org Subject: Re: Request dev help: Info for required crypto export declaration [this mail has managed to hide in a draft folder for weeks...] On 01.09.2011 23:01, Robert Burrell Donkin

Re: Request dev help: Info for required crypto export declaration

2011-09-02 Thread Robert Burrell Donkin
On Fri, Sep 2, 2011 at 4:11 AM, Joe Schaefer joe_schae...@yahoo.com wrote: Off-topic.  Please drop this line of inquiry and return to the Subject of this thread, which is about determining required info for the crypto export declaration. Which is collecting a list of sources [1] :-) OOo uses

RE: Request dev help: Info for required crypto export declaration

2011-09-02 Thread Dennis E. Hamilton
-dev@incubator.apache.org Subject: Re: Request dev help: Info for required crypto export declaration Starting fresh. The more I look into this the more I'm starting to think that the Apache export control instructions [1] are leading us in the wrong direction. From what I've been able to determine

Re: Request dev help: Info for required crypto export declaration

2011-09-02 Thread Rob Weir
-dev@incubator.apache.org Subject: Re: Request dev help: Info for required crypto export declaration Starting fresh.  The more I look into this the more I'm starting to think that the Apache export control instructions [1] are leading us in the wrong direction. From what I've been able

RE: Request dev help: Info for required crypto export declaration

2011-09-02 Thread Dennis E. Hamilton
, September 02, 2011 08:01 To: ooo-dev@incubator.apache.org Subject: Re: Request dev help: Info for required crypto export declaration Starting fresh. The more I look into this the more I'm starting to think that the Apache export control instructions [1] are leading us in the wrong direction

RE: Request dev help: Info for required crypto export declaration

2011-09-02 Thread Dennis E. Hamilton
for the list of places to identify in the code. - Dennis -Original Message- From: Dennis E. Hamilton [mailto:dennis.hamil...@acm.org] Sent: Thursday, September 01, 2011 13:12 To: ooo-dev@incubator.apache.org Subject: RE: Request dev help: Info for required crypto export declaration I'm

Re: Request dev help: Info for required crypto export declaration

2011-09-02 Thread Rob Weir
: Friday, September 02, 2011 08:26 To: ooo-dev@incubator.apache.org Subject: Re: Request dev help: Info for required crypto export declaration On Fri, Sep 2, 2011 at 11:12 AM, Dennis E. Hamilton dennis.hamil...@acm.org wrote: We're already behind the 8-ball on having not done this when

Re: Request dev help: Info for required crypto export declaration

2011-09-02 Thread Donald Whytock
On Fri, Sep 2, 2011 at 11:25 AM, Rob Weir robw...@apache.org wrote: I'd rather not file false information with the government.  Of course, you are welcome to do so, if you think the need is urgent. Can I cite that in my next indictment? Don

Re: Request dev help: Info for required crypto export declaration

2011-09-02 Thread Rob Weir
On Fri, Sep 2, 2011 at 2:00 PM, Donald Whytock dwhyt...@gmail.com wrote: On Fri, Sep 2, 2011 at 11:25 AM, Rob Weir robw...@apache.org wrote: I'd rather not file false information with the government.  Of course, you are welcome to do so, if you think the need is urgent. Can I cite that in my

RE: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Pedro F. Giffuni
...@acm.org Subject: RE: Request dev help: Info for required crypto export declaration To: ooo-dev@incubator.apache.org Date: Thursday, September 1, 2011, 12:00 AM It is simplified and it isn't.  But we are doing it out of order. Here is the page that I couldn't remember the location of: http

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Rob Weir
the java based Bouncy Castle: http://www.bouncycastle.org/ cheers, Pedro. --- On Thu, 9/1/11, Dennis E. Hamilton dennis.hamil...@acm.org wrote: From: Dennis E. Hamilton dennis.hamil...@acm.org Subject: RE: Request dev help: Info for required crypto export declaration To: ooo-dev

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Danese Cooper
On Wed, Aug 31, 2011 at 9:30 AM, Rob Weir r...@robweir.com wrote: On Wed, Aug 31, 2011 at 12:29 PM, Dennis E. Hamilton dennis.hamil...@acm.org wrote: snip 1) Was something similar every done for OpenOffice.org? Most software companies are aware of this US export regulation and do

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Rob Weir
On Thu, Sep 1, 2011 at 11:51 AM, Danese Cooper dan...@gmail.com wrote: On Wed, Aug 31, 2011 at 9:30 AM, Rob Weir r...@robweir.com wrote: On Wed, Aug 31, 2011 at 12:29 PM, Dennis E. Hamilton dennis.hamil...@acm.org wrote: snip 1) Was something similar every done for OpenOffice.org?  

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Robert Burrell Donkin
On Thu, Sep 1, 2011 at 7:38 PM, Dennis E. Hamilton dennis.hamil...@acm.org wrote: Please just do it this way: http://www.apache.org/dev/crypto.html ASF is very clear on what is required for *its* releases and this page appears to be comprehensive. The Apache rules break down into reporting

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Rob Weir
Subject: Re: Request dev help: Info for required crypto export declaration On Thu, Sep 1, 2011 at 11:51 AM, Danese Cooper dan...@gmail.com wrote: On Wed, Aug 31, 2011 at 9:30 AM, Rob Weir r...@robweir.com wrote: On Wed, Aug 31, 2011 at 12:29 PM, Dennis E. Hamilton dennis.hamil...@acm.org

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Rob Weir
On Thu, Sep 1, 2011 at 2:51 PM, Robert Burrell Donkin robertburrelldon...@gmail.com wrote: On Thu, Sep 1, 2011 at 7:38 PM, Dennis E. Hamilton dennis.hamil...@acm.org wrote: Please just do it this way: http://www.apache.org/dev/crypto.html ASF is very clear on what is required for *its*

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Robert Burrell Donkin
On Thu, Sep 1, 2011 at 8:00 PM, Rob Weir r...@robweir.com wrote: On Thu, Sep 1, 2011 at 2:51 PM, Robert Burrell Donkin robertburrelldon...@gmail.com wrote: On Thu, Sep 1, 2011 at 7:38 PM, Dennis E. Hamilton dennis.hamil...@acm.org wrote: Please just do it this way:

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Donald Whytock
On Thu, Sep 1, 2011 at 3:00 PM, Rob Weir r...@robweir.com wrote: On Thu, Sep 1, 2011 at 2:51 PM, Robert Burrell Donkin robertburrelldon...@gmail.com wrote: Following the instructions[3], step 1 is to work out whether OOo has any unusual cryptography beyond ECCN 5D002, which is: blockquote

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Robert Burrell Donkin
On Thu, Sep 1, 2011 at 8:18 PM, Donald Whytock dwhyt...@gmail.com wrote: On Thu, Sep 1, 2011 at 3:00 PM, Rob Weir r...@robweir.com wrote: On Thu, Sep 1, 2011 at 2:51 PM, Robert Burrell Donkin robertburrelldon...@gmail.com wrote: Following the instructions[3], step 1 is to work out whether OOo

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Rob Weir
So in general OpenOffice supports encryption and digital signatures and https/SSL. So we have support for standard algorithms, from one-way hashes like SHA-1, to block encryption like Blowfish and AES-256, to public key cryptography per the W3C's XML Digital Signatures. We also support legacy

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Rob Weir
Subject: Re: Request dev help: Info for required crypto export declaration On Thu, Sep 1, 2011 at 8:00 PM, Rob Weir r...@robweir.com wrote: On Thu, Sep 1, 2011 at 2:51 PM, Robert Burrell Donkin robertburrelldon...@gmail.com wrote: On Thu, Sep 1, 2011 at 7:38 PM, Dennis E. Hamilton dennis.hamil

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Robert Burrell Donkin
On Thu, Sep 1, 2011 at 8:40 PM, Donald Whytock dwhyt...@gmail.com wrote: On Thu, Sep 1, 2011 at 3:25 PM, Robert Burrell Donkin robertburrelldon...@gmail.com wrote: EAR 740.13(e) should be on

RE: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Dennis E. Hamilton
that OpenOffice.org deals with SSL certifications, but I guess I should be prepared for anything. - Dennis -Original Message- From: Rob Weir [mailto:robw...@apache.org] Sent: Thursday, September 01, 2011 12:32 To: ooo-dev@incubator.apache.org Subject: Re: Request dev help: Info for required

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Robert Burrell Donkin
On Thu, Sep 1, 2011 at 8:59 PM, Dennis E. Hamilton dennis.hamil...@acm.org wrote: Let me see if I can help ground this. Currently, digest algorithms are used for a variety of things.  The common case is SHA1.  These are not themselves a concern, as I understand it, since their function is

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Robert Burrell Donkin
On Thu, Sep 1, 2011 at 9:03 PM, Rob Weir r...@robweir.com wrote: On Thu, Sep 1, 2011 at 3:59 PM, Dennis E. Hamilton dennis.hamil...@acm.org wrote: Let me see if I can help ground this. Remember, the export could be of code, not just the binaries.  So if we have code that does asymmetrical

RE: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Dennis E. Hamilton
, September 01, 2011 12:14 To: ooo-dev@incubator.apache.org Subject: Re: Request dev help: Info for required crypto export declaration On Thu, Sep 1, 2011 at 8:00 PM, Rob Weir r...@robweir.com wrote: On Thu, Sep 1, 2011 at 2:51 PM, Robert Burrell Donkin robertburrelldon...@gmail.com wrote

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Rob Weir
: Re: Request dev help: Info for required crypto export declaration So in general OpenOffice supports encryption and digital signatures and https/SSL.  So we have support for standard algorithms, from one-way hashes like SHA-1, to block encryption like Blowfish and AES-256,  to public key

RE: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Dennis E. Hamilton
[mailto:robertburrelldon...@gmail.com] Sent: Thursday, September 01, 2011 13:13 To: ooo-dev@incubator.apache.org; dennis.hamil...@acm.org Subject: Re: Request dev help: Info for required crypto export declaration [ ... ] So far, looks like OOo most likely has strong crypto but it's all fairly standard

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Robert Burrell Donkin
On Thu, Sep 1, 2011 at 9:35 PM, Dennis E. Hamilton dennis.hamil...@acm.org wrote: Technically, this was to have been resolved before the code was put up on SVN.  We need to audit specifically for this rather quickly, and including the places that Rob also identified (import-export filters and

RE: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Dennis E. Hamilton
appropriately. -Original Message- From: Robert Burrell Donkin [mailto:robertburrelldon...@gmail.com] Sent: Thursday, September 01, 2011 14:01 To: ooo-dev@incubator.apache.org Subject: Re: Request dev help: Info for required crypto export declaration On Thu, Sep 1, 2011 at 9:35 PM, Dennis E

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Rob Weir
dev help: Info for required crypto export declaration On Thu, Sep 1, 2011 at 9:35 PM, Dennis E. Hamilton dennis.hamil...@acm.org wrote: Technically, this was to have been resolved before the code was put up on SVN.  We need to audit specifically for this rather quickly, and including

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Norbert Thiebaud
On Thu, Sep 1, 2011 at 11:15 AM, Rob Weir r...@robweir.com wrote: Looks like LO discussed it briefly [4], but dismissed it under the misapprehension that since they are not in the US, the regulation is irrelevant. I'm confused, how is that a 'misapprehension' exactly ? Are you concerned

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Rob Weir
On Thu, Sep 1, 2011 at 9:38 PM, Norbert Thiebaud nthieb...@gmail.com wrote: On Thu, Sep 1, 2011 at 11:15 AM, Rob Weir r...@robweir.com wrote: Looks like LO discussed it briefly [4], but dismissed it under the misapprehension that since they are not in the US, the regulation is irrelevant.

RE: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Dennis E. Hamilton
: Info for required crypto export declaration On Thu, Sep 1, 2011 at 11:15 AM, Rob Weir r...@robweir.com wrote: Looks like LO discussed it briefly [4], but dismissed it under the misapprehension that since they are not in the US, the regulation is irrelevant. I'm confused, how

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Rob Weir
...@gmail.com] Sent: Thursday, September 01, 2011 18:38 To: ooo-dev@incubator.apache.org Subject: Re: Request dev help: Info for required crypto export declaration On Thu, Sep 1, 2011 at 11:15 AM, Rob Weir r...@robweir.com wrote: Looks like LO discussed it briefly [4], but dismissed it under

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Norbert Thiebaud
On Thu, Sep 1, 2011 at 8:57 PM, Rob Weir robw...@apache.org wrote: On Thu, Sep 1, 2011 at 9:38 PM, Norbert Thiebaud nthieb...@gmail.com wrote: On Thu, Sep 1, 2011 at 11:15 AM, Rob Weir r...@robweir.com wrote: Looks like LO discussed it briefly [4], but dismissed it under the misapprehension

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Rob Weir
On Thu, Sep 1, 2011 at 10:55 PM, Norbert Thiebaud nthieb...@gmail.com wrote: On Thu, Sep 1, 2011 at 8:57 PM, Rob Weir robw...@apache.org wrote: On Thu, Sep 1, 2011 at 9:38 PM, Norbert Thiebaud nthieb...@gmail.com wrote: On Thu, Sep 1, 2011 at 11:15 AM, Rob Weir r...@robweir.com wrote: Looks

Re: Request dev help: Info for required crypto export declaration

2011-09-01 Thread Joe Schaefer
, 2011 11:07 PM Subject: Re: Request dev help: Info for required crypto export declaration On Thu, Sep 1, 2011 at 10:55 PM, Norbert Thiebaud nthieb...@gmail.com wrote: On Thu, Sep 1, 2011 at 8:57 PM, Rob Weir robw...@apache.org wrote: On Thu, Sep 1, 2011 at 9:38 PM, Norbert Thiebaud nthieb

Re: Request dev help: Info for required crypto export declaration

2011-08-31 Thread Mathias Bauer
Moin, please take my answers with a decent grain of salt, I'm not an expert for that area, Matthias Hütsch and Malte Timmermann certainly could answer that better, but I don't know if they are currently contributing to this list. Hopefully my remarks can help to look at the right places. Am

RE: Request dev help: Info for required crypto export declaration

2011-08-31 Thread Dennis E. Hamilton
: Info for required crypto export declaration Moin, please take my answers with a decent grain of salt, I'm not an expert for that area, Matthias Hütsch and Malte Timmermann certainly could answer that better, but I don't know if they are currently contributing to this list. Hopefully my remarks

Re: Request dev help: Info for required crypto export declaration

2011-08-31 Thread Rob Weir
. -Rob -Original Message- From: Mathias Bauer [mailto:mathias_ba...@gmx.net] Sent: Wednesday, August 31, 2011 07:00 To: ooo-dev@incubator.apache.org Subject: Re: Request dev help: Info for required crypto export declaration Moin, please take my answers with a decent grain of salt