Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

For http://www.apache.org/licenses/exports/ - see

Jira
serverASF JIRA
columnskey,summary,type,created,updated,due,assignee,reporter,priority,status,resolution
serverId5aa69414-a9e9-3523-82ec-879b028fb15b
keyTAVERNA-959
Jira
serverASF JIRA
columnskey,summary,type,created,updated,due,assignee,reporter,priority,status,resolution
serverId5aa69414-a9e9-3523-82ec-879b028fb15b
keyLEGAL-250

 

ECCN classification

To consider if Taverna code is classified, we follow Flowchart 1 from https://www.bis.doc.gov/index.php/policy-guidance/encryption/identifying-encryption-items, with the questions:

  • Is the item designed to use cryptography or does it contain cryptography?  (exempt if No)
  • Is the hardware or software specially designed for medical end use? (exempt if  Yes)
  • Is the product described by Note 4? (exempt if Yes)
  • Is the encryption functionality limited to intellectual property or copyright protection functions? (exempt if Yes)

If we get through this, then we are controlled under Category 5, part 2 and must consider flow chart 2 to determine if we can self-classify using https://www.bis.doc.gov/index.php/policy-guidance/encryption/registration.

  • Is the item publicly available encryption source code? (If yes, self-classify as ECCN 5D002)
  • Beta Test Software? (If yes, self-classify as ECCN 5200d)
  • Encryption using key length <= 56 symmetric, <= 512 assymmetric or <= 112 elliptic curve? (If yes, self-classify as ECCN 5x992 NLR)
  • Is the item described in Note for 5A002? (If yes, self-classify as 5x992)
  • Is the item limited to authentication only? (If yes, self-classify as 5x992)
  • Does the item meet the criteria for Mass Market?

So for each of our repositories:

incubator-taverna-maven-parent:

  • Is the item designed to use cryptography or does it contain cryptography?  No

    • Not controlled

incubator-taverna-language:

  • Is the item designed to use cryptography or does it contain cryptography?  Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4?  No
    • Set of function includes taverna-robundle and taverna-databundle, which primary function is to store information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

incubator-taverna-osgi:

  • Is the item designed to use cryptography or does it contain cryptography?  Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Set of function include taverna-download-impl, which primary function is to receive information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

incubator-taverna-engine:

incubator-taverna-commandline

  • Is the item designed to use cryptography or does it contain cryptography? Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is to execute workflows - however those workflows generally do Sending, receiving or storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-common-activities

incubator-taverna-server

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE), BouncyCastle crypto, Apache CXF and Apache Taverna Command Line
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Set of function includes Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-databundle-viewer

  • Is the item designed to use cryptography or does it contain cryptography? Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-mobile

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Android SDK https support, Dropbox Android SDK and Apache HttpComponent
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-plugin-bioinformatics

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-plugin-component

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-plugin-gis

  • Is the item designed to use cryptography or does it contain cryptography? No
    • Not controlled

incubator-taverna-workbench

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is to design workflows, but set of functions includes UI for the Credential Manager
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

incubator-taverna-workbench-common-activities

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager, HttpComponents and Taverna Common Activities WSS4j support.
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Set of function includes  Receiving information (for Service Discovery)
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

 

incubator-taverna-workbench-product

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Builds distribution that includes Apache WSS4J, Apache XML Security for Java, Apache HttpComponents and BouncyCastle crypto
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is to design and run workflows, but those workflows generally do Sending, receiving or storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

 

Not (yet) classified

https://github.com/apache/incubator-taverna-maven-parent (exempt)

The taverna-plugin-* and taverna-workbench-* repositories have been classified mainly because they depend on Taverna Engine. This might be reviewed, see LEGAL-250 about transitivity.

Encryption declaration XML

Added to https://svn.apache.org/repos/asf/infrastructure/site/trunk/content/licenses/exports/index.page/eccnmatrix.xml according to http://www.apache.org/dev/crypto.html

Note that there are two sections - development is for our multiple source code repositories as listed on http://taverna.incubator.apache.org/code/ - and all releases which cover anything under https://archive.apache.org/dist/incubator/taverna/ (however this would include releases of even potentially non-classified products like taverna-maven-parent or incubator-taverna-databundle-viewer). Taverna releases are separate per code repository - so this could alternatively be split into many separate <Version> declarations - but then we might have to reorganize the dist folders to avoid updating this XML for every release.

 

Code Block
languagexml
  <Product>
    <Name>Apache Taverna</Name>
    <Version>
      <Names>development</Names>
      <ECCN>5D002</ECCN>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-language.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache HttpComponents</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-osgi.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache HttpComponents</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-engine.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE), BouncyCastle crypto, Apache Derby, Apache Taverna Language and Apache Taverna OSGi</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-common-activities.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE), Jetty, Apache WSS4J, Apache XML Security for Java, Apache HttpComponents and Apache Taverna Engine</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-commandline.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache WSS4J, Apache XML Security for Java, Apache HttpComponents, BouncyCastle crypto, Apache Taverna Engine and Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-server.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE), BouncyCastle crypto, Apache CXF and Apache Taverna Command Line</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE) and Apache Taverna Engine</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench-common-activities.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache Taverna Workbench and Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench-product.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Builds distribution that includes Apache WSS4J, Apache XML Security for Java, Apache HttpComponents and BouncyCastle crypto</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-plugin-component.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache HttpComponents, Apache Taverna Engine, Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-plugin-bioinformatics.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache Taverna Engine</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-plugin-gis.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache Taverna Engine, Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-mobile.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Android SDK https support, Dropbox Android SDK and Apache HttpComponent</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-databundle-viewer.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Ruby OpenSSL</Why>
      </ControlledSource>

      <ControlledSource href="http://bouncycastle.org/download/bcprov-jdk15on-154.tar.gz">
        <Manufacturer>Bouncy Castle</Manufacturer>
        <Why>General-purpose encryption library for Java 1.5</Why>
      </ControlledSource>
      <ControlledSource href="http://eclipse.org/jetty">
        <Manufacturer>The Eclipse Foundation</Manufacturer>
        <Why>SSL library for Jetty</Why>
      </ControlledSource>
      <ControlledSource href="http://www.oracle.com/technetwork/java/javase/downloads/index.html">
        <Manufacturer>Oracle</Manufacturer>
        <Why>general-purpose cryptography library (JCE) included with Java</Why>
      </ControlledSource>
      <ControlledSource href="http://www.apache.org/dist/santuario/java-library/">
        <Manufacturer>ASF</Manufacturer>
        <Why>General-purpose XML encryption and digital signature implementation</Why>
      </ControlledSource>
Code Block
languagexml
    <Product>
    <Name>Apache Taverna</Name>
    <Version>
      <Names>development</Names>
      <ECCN>5D002</ECCN>
      <ControlledSource href="httpshttp://git-wip-ussvn.apache.org/reposviewvc/asfsantuario/incubatorxml-taverna-language.gitsecurity-java/branches/1.5.x-fixes/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed<Why>Implements forXML useSignature withand ApacheEncryption HttpComponents<specs</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-uspeople.apache.org/reposdist/asf/incubator-taverna-osgi.gitcxf/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache HttpComponents< with the Apache XML Security Java API, WSS4J and BouncyCastle crypto</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-usarchive.apache.org/dist/reposxml/asfsecurity/incubator-taverna-engine.gitjava-library/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE), BouncyCastle crypto, Apache Taverna Language and Apache Taverna OSGi<<Why>General-purpose XML encryption and digital signature implementation</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-usarchive.apache.org/reposdist/db/asf/incubator-taverna-common-activities.gitderby/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed<Why>designed for use with Java Secure Socket Extension (JSSE), Apache WSS4J, Apache XML Security for Java, Apache HttpComponents and Apache Taverna Engine<the Java Cryptography Extension (JCE) API</Why>
      </ControlledSource>

      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-commandline.gitwww.dropbox.com/developers-v1/core/sdks/android">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache WSS4J, Apache XML Security for Java, Apache HttpComponents, BouncyCastle crypto, Apache Taverna OSGi, Apache Taverna Engine and Apache Taverna Common Activities<<Manufacturer>Dropbox</Manufacturer>
        <Why>designed for use with Android SDK, adds a SecureSSLSocketFactory</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-server.git">
        <Manufacturer>ASF</Manufacturer>android.googlesource.com/">
        <Why>Designed<Manufacturer>Google</Manufacturer>
  for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE)<Why>includes encryption code adapted from OpenSSL, BouncyCastle crypto, Apache CXF and Apache Taverna Command Line<BoringSSL</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench.gitgithub.com/ruby/openssl">
        <Manufacturer>Ruby <Manufacturer>ASF<Programming Language</Manufacturer>
        <Why>Designed<Why>designed for use with Java Secure Socket Extension (JSSE), Apache Taverna Engine<OpenSSL</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-us.apachewww.openssl.org/repos/asf/incubator-taverna-workbench-common-activities.git">
source/">
        <Manufacturer>The OpenSSL Project</Manufacturer>
        <Why>Publicly available SSL encryption <Manufacturer>ASF<library</Manufacturer>Why>
      </ControlledSource>
    <Why>Designed</Version>
 for use with Apache<Version>
 Taverna Workbench and Apache Taverna Common<Names>all Activities<releases</Why>Names>
      <<ECCN>5D002</ControlledSource>ECCN>
      <ControlledSource href="https://git-wip-usarchive.apache.org/reposdist/asfincubator/incubator-taverna-workbench-product.gittaverna/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache Taverna Workbench Common Activities< Apache CXF, Apache WSS4J, Apache XML Security for Java, Apache HttpComponents, Apache Derby, BouncyCastle crypto, Jetty, Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE)</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-us.apachebouncycastle.org/reposdownload/asf/incubatorbcprov-taverna-plugin-component.gitjdk15on-154.tar.gz">
        <Manufacturer>Bouncy <Manufacturer>ASF<Castle</Manufacturer>
        <Why>Designed<Why>General-purpose forencryption uselibrary withfor Apache HttpComponents, Apache Taverna Engine, Apache Taverna Common Activities<Java 1.5</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-us.apacheeclipse.org/repos/asf/incubator-taverna-plugin-bioinformatics.gitjetty">
        <Manufacturer>The <Manufacturer>ASF<Eclipse Foundation</Manufacturer>
        <Why>SSL <Why>Designedlibrary for use with Apache Taverna Engine<Jetty</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-us.apache.org/repos/asf/incubator-taverna-plugin-gis.gitwww.oracle.com/technetwork/java/javase/downloads/index.html">
        <Manufacturer>ASF<<Manufacturer>Oracle</Manufacturer>
        <Why>Designed<Why>general-purpose forcryptography uselibrary with(JCE) Apacheincluded Taverna Engine, Apache Taverna Common Activities<with Java</Why>
      </ControlledSource>

      <ControlledSource href="http://www.apache.org/dist/santuario/java-library/">
        <Manufacturer>ASF</Manufacturer>
        <Why>General-purpose XML encryption and digital signature implementation</Why>
      </ControlledSource>
      <ControlledSource href="http://svn.apache.org/viewvc/santuario/xml-security-java/branches/1.5.x-fixes/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Implements XML Signature and Encryption specs</Why>
      </ControlledSource>
      <ControlledSource href="http://bouncycastlepeople.apache.org/dist/download/bcprov-jdk15on-154.tar.gzcxf/">
        <Manufacturer>Bouncy Castle<<Manufacturer>ASF</Manufacturer>
        <Why>General-purpose encryption library for Java 1.5<
        <Why>Designed for use with the Apache XML Security Java API, WSS4J and BouncyCastle crypto</Why>
      </ControlledSource>
      <ControlledSource href="http://peoplearchive.apache.org/dist/cxf/xml/security/java-library/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with the Apache XML Security Java API, WSS4J and BouncyCastle crypto<<Why>General-purpose XML encryption and digital signature implementation</Why>
      </ControlledSource>
      <ControlledSource href="http://archive.apache.org/dist/xml/security/java-librarydb/derby/">
        <Manufacturer>ASF</Manufacturer>
        <Why>General-purpose XML encryption and digital signature implementation<<Why>designed for use with the Java Cryptography Extension (JCE) API</Why>
      </ControlledSource>
      <ControlledSource href="httphttps://www.oracledropbox.com/technetworkdevelopers-v1/javacore/javase/downloads/index.html">
        <Manufacturer>Oracle</Manufacturer>sdks/android">
        <Manufacturer>Dropbox</Manufacturer>
        <Why>designed for use with Android SDK, adds a SecureSSLSocketFactory</Why>
      </ControlledSource>
  <Why>general-purpose cryptography library (JCE) included with Java</Why>
<ControlledSource href="https://android.googlesource.com/">
        <<Manufacturer>Google</ControlledSource>Manufacturer>
    </Version>
    <Version>
<Why>includes encryption code adapted from OpenSSL, <Names>allBouncyCastle, releases<BoringSSL</Names>Why>
      <ECCN>5D002<</ECCN>ControlledSource>
      <ControlledSource href="https://archivegithub.apache.orgcom/dist/incubator/taverna/ruby/openssl">
        <Manufacturer>Ruby <Manufacturer>ASF<Programming Language</Manufacturer>
        <Why>Designed for use with Apache CXF, Apache WSS4J, Apache XML Security for Java, Apache HttpComponents, BouncyCastle crypto, Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE)<<Why>designed for use with OpenSSL</Why>
      </ControlledSource>
      <ControlledSource href="http://www.apacheopenssl.org/dist/santuario/java-library/">source/">
        <Manufacturer>The OpenSSL Project</Manufacturer>
        <Why>Publicly available SSL encryption library</Why>
        <Manufacturer>ASF<</Manufacturer>ControlledSource>
    </Version>
    <Why>General-purpose XML encryption and digital signature implementation</Why>
</Product>

 

Draft registration email

This would formally have to be sent by the Incubator PMC chair:

Code Block
languagetext
   TO: crypt AT bis.doc.gov, 
       </ControlledSource>
enc AT nsa.gov, 
   <ControlledSource href="http://svn.apache.org/viewvc/santuario/xml-security-java/branches/1.5.x-fixes/">
   web_site AT bis.doc.gov
   <Manufacturer>ASF</Manufacturer>
    CC: {applicable project list}, 
    <Why>Implements XML Signature and Encryption specs</Why>{legal-archive AT a.o}

   SUBJ: TSU  </ControlledSource>
 NOTIFICATION - Encryption

SUBMISSION TYPE:     <ControlledSource href="http://bouncycastle.org/download/bcprov-jdk15on-154.tar.gz">
     TSU

SUBMITTED BY:    <Manufacturer>Bouncy Castle</Manufacturer>
    Ted    <Why>General-purpose encryption library for Java 1.5</Why>
Dunning

SUBMITTED FOR:        Apache   </ControlledSource>
  Software Foundation

POINT OF CONTACT:    <ControlledSource href="http://people.apache.org/dist/cxf/">
     Secretary, Apache Software Foundation

FAX:    <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with the Apache XML Security Java API, WSS4J and BouncyCastle crypto</Why>
      </ControlledSource>
      <ControlledSource href="http://archive.apache.org/dist/xml/security/java-library/">
   +1-919-573-9199
				
MANUFACTURER(S):   
    
The Apache Software Foundation
Bouncy Castle
The Eclipse Foundation
Oracle
Dropbox
Google
Ruby Programming Language
The OpenSSL Project

PRODUCT NAME/MODEL #: Apache Taverna

ECCN:      <Manufacturer>ASF</Manufacturer>
        <Why>General-purpose XML encryption and digital signature implementation</Why>
 5D002

NOTIFICATION:      </ControlledSource>
      <ControlledSource href="http://www.oracle.com/technetwork/java/javase/downloads/index.html">
        <Manufacturer>Oracle</Manufacturer>
        <Why>general-purpose cryptography library (JCE) included with Java</Why>
      </ControlledSource>
    </Version>
  </Product>

   http://www.apache.org/licenses/exports/

 

README updates

Also described in READMEs: