New legal rquirement: import and export of encryption in France

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi everyone,


Background
----------

For many years, France has required organizations to obtain authorization from the French agency ANSSI to import or export cryptographic technology.


Why now?
--------

Apple now requires you to upload an authorization certificate from ANSSI before you can release new versions in the French App Store. Because of this new Apple requirement, LibreOffice, NeoOffice, and Collabora Office cannot distribute new versions in the French App Store.

Since I have to do an application for NeoOffice (I am still backporting security fixes from LibreOffice), I have volunteered to try and prepare LibreOffice's application to ANSSI. Hopefully, with only minor changes, I can use LibreOffice's application as a template for NeoOffice and Collabora Office.

The current "work in progress" version of the application is at:

https://nextcloud.documentfoundation.org/s/PrACjSQfTZ5cYcA/download?path=%2F&files=ANNEXE%20I_FR-EN.odt


What needs to be done?
----------------------

I have posted a "todo" file at:

https://nextcloud.documentfoundation.org/s/PrACjSQfTZ5cYcA?path=%2F&openfile=1236102

The file lists the tasks that I think need to be done, as well some notes and questions, in three groups:
- Not complete
- Needs review
- Complete


Where I need help
-----------------

1. I wrote answers to most of the text questions. Can anyone review and suggest edits for any of the items in the "Needs review" group in the "todo" file?

2. ANSSI wants several brochures/manuals/guides in PDF format. Can anyone find any good web pages or, even better, PDF documents for the "Section E" items in the "Not complete" group?

3. My next planned step was to look through the code in the libreoffice-7-5-0 branch and see if I can fill out the table in question B.3.4. Can anyone confirm that the following are the only cryptographic APIs that we use now and in the near future?:
- MS-CAPI (Windows only)
- NSS (all non-Windows platforms)
- OpenSSL
- OpenPGP


Thank you all for any help that you can provide. Regulatory filings are never fun but so far my limited contact with ANSSI has been very positive (I asked if they had a fillable PDF and they responded the same day).

Patrick



[Index of Archives]     [LARTC]     [Bugtraq]     [Yosemite Forum]     [Photo]

  Powered by Linux