public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] Encryption Export
@ 2002-04-18  1:50 Ryan Phillips
  2002-04-18  2:06 ` Preston A. Elder
  0 siblings, 1 reply; 7+ messages in thread
From: Ryan Phillips @ 2002-04-18  1:50 UTC (permalink / raw
  To: gentoo-dev

[-- Attachment #1: Type: text/plain, Size: 2571 bytes --]

Hi guys,

  I'm currently helping the gentoo team work out some issues with export
controls of strong encryption software.  Currently, Gentoo is being
developed mostly in the United States, and downloaded all over the
world, thus the reason of this mail.

  Gentoo provides ebuilds, source archives, and binaries for openssl,
gpg, and many other high-encryption packages off of its own website and
mirrors.  I'm drafting a letter to the Bureau of Export Administration
right at the moment, but I need to propose a couple (very minor!)
changes to the portage system.

  There should be a USE variable named 'agree-to-crypto', (the name
doesn't matter).  The purpose is to verify the user has read the export
license, in this case:

------------------

PLEASE REMEMBER THAT EXPORT/IMPORT AND/OR USE OF STRONG CRYPTOGRAPHY
SOFTWARE, PROVIDING CRYPTOGRAPHY HOOKS OR EVEN JUST COMMUNICATING
TECHNICAL DETAILS ABOUT CRYPTOGRAPHY SOFTWARE IS ILLEGAL IN SOME PARTS
OF THE WORLD. SO, WHEN YOU IMPORT THIS PACKAGE TO YOUR COUNTRY, RE-
DISTRIBUTE IT FROM THERE OR EVEN JUST EMAIL TECHNICAL SUGGESTIONS OR
EVEN SOURCE PATCHES TO THE AUTHOR OR OTHER PEOPLE YOU ARE STRONGLY
ADVISED TO PAY CLOSE ATTENTION TO ANY EXPORT/IMPORT AND/OR USE LAWS
WHICH APPLY TO YOU. THE AUTHORS OF GENTOO ARE NOT LIABLE FOR ANY
VIOLATIONS YOU MAKE HERE. SO BE CAREFULLY YOURSELF, IT IS YOUR
RESPONSIBILITY.  

If you agree to this license, and would like to enable high-grade
encryption then place the variable 'agree-to-crypto' in your USE
variable in /etc/make.conf

----------------- 
Note: (Possible License, and could change)

If this variable is not set, then the ebuilds affected should resort to
building openssh/openssl/etc with export grade encryption.

In addition, I propose the RESTRICT variable for ebuilds.  This would
make source archives not be mirrored on the gentoo/ibiblio site, and
it's mirrors.  

Onto the subject of binary CDs.  There should probably be two sets of
binary CDs: one with high encryption, and one with export grade.  To
download the high encryption ISO, the website could ask the user if they
agreed to the export license, or under FTP the license could be stored
as a .message.  A more simpler solution is to take out openssl/openssh
altogether, since they are relatively small downloads.

I believe this is a wise course of action.  
Any comments? additions? subtractions?

Best regards,
Ryan Phillips
rphillips at gentoo.org

[Note: I am not a lawyer, and this should not be considered legal
advice.]


[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 524 bytes --]

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2002-04-18 18:13 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-04-18  1:50 [gentoo-dev] Encryption Export Ryan Phillips
2002-04-18  2:06 ` Preston A. Elder
2002-04-18  3:18   ` Ryan Phillips
2002-04-18  3:38     ` Ryan Phillips
2002-04-18  6:10       ` [gentoo-dev] " Paul
2002-04-18 18:05   ` [gentoo-dev] " Todd Wright
2002-04-18 18:13     ` Todd Wright

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox