Hi everyone,
Background
----------
For many years, France has required organizations to obtain
authorization from the French agency ANSSI to import or export
cryptographic technology.
Why now?
--------
Apple now requires you to upload an authorization certificate from ANSSI
before you can release new versions in the French App Store. Because of
this new Apple requirement, LibreOffice, NeoOffice, and Collabora Office
cannot distribute new versions in the French App Store.
Since I have to do an application for NeoOffice (I am still backporting
security fixes from LibreOffice), I have volunteered to try and prepare
LibreOffice's application to ANSSI. Hopefully, with only minor changes,
I can use LibreOffice's application as a template for NeoOffice and
Collabora Office.
The current "work in progress" version of the application is at:
https://nextcloud.documentfoundation.org/s/PrACjSQfTZ5cYcA/download?path=%2F&files=ANNEXE%20I_FR-EN.odt
What needs to be done?
----------------------
I have posted a "todo" file at:
https://nextcloud.documentfoundation.org/s/PrACjSQfTZ5cYcA?path=%2F&openfile=1236102
The file lists the tasks that I think need to be done, as well some
notes and questions, in three groups:
- Not complete
- Needs review
- Complete
Where I need help
-----------------
1. I wrote answers to most of the text questions. Can anyone review and
suggest edits for any of the items in the "Needs review" group in the
"todo" file?
2. ANSSI wants several brochures/manuals/guides in PDF format. Can
anyone find any good web pages or, even better, PDF documents for the
"Section E" items in the "Not complete" group?
3. My next planned step was to look through the code in the
libreoffice-7-5-0 branch and see if I can fill out the table in question
B.3.4. Can anyone confirm that the following are the only cryptographic
APIs that we use now and in the near future?:
- MS-CAPI (Windows only)
- NSS (all non-Windows platforms)
- OpenSSL
- OpenPGP
Thank you all for any help that you can provide. Regulatory filings are
never fun but so far my limited contact with ANSSI has been very
positive (I asked if they had a fillable PDF and they responded the same
day).
Patrick