Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

For http://www.apache.org/licenses/exports/ - see

Jira
serverASF JIRA
columnskey,summary,type,created,updated,due,assignee,reporter,priority,status,resolution
serverId5aa69414-a9e9-3523-82ec-879b028fb15b
keyTAVERNA-959

 

Also described in READMEs:

 

Jira
serverASF JIRA
columnskey,summary,type,created,updated,due,assignee,reporter,priority,status,resolution
serverId5aa69414-a9e9-3523-82ec-879b028fb15b
keyLEGAL-250

 

ECCN classification

To consider if Taverna code is classified, we follow Flowchart 1 from https://www.bis.doc.gov/index.php/policy-guidance/encryption/identifying-encryption-items, with the questions:

  • Is the item designed to use cryptography or does it contain cryptography?  (exempt if No)
  • Is the hardware or software specially designed for medical end use? (exempt if  Yes)
  • Is the product described by Note 4? (exempt if Yes)
  • Is the encryption functionality limited to intellectual property or copyright protection functions? (exempt if Yes)

If we get through this, then we are controlled under Category 5, part 2 and must consider flow chart 2 to determine if we can self-classify using https://www.bis.doc.gov/index.php/policy-guidance/encryption/registration.

  • Is the item publicly available encryption source code? (If yes, self-classify as ECCN 5D002)
  • Beta Test Software? (If yes, self-classify as ECCN 5200d)
  • Encryption using key length <= 56 symmetric, <= 512 assymmetric or <= 112 elliptic curve? (If yes, self-classify as ECCN 5x992 NLR)
  • Is the item described in Note for 5A002? (If yes, self-classify as 5x992)
  • Is the item limited to authentication only? (If yes, self-classify as 5x992)
  • Does the item meet the criteria for Mass Market?

So for each of our repositories:

incubator-taverna-maven-parent:

  • Is the item designed to use cryptography or does it contain cryptography?  No

    • Not controlled

incubator-taverna-language:

  • Is the item designed to use cryptography or does it contain cryptography?  Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4?  No
    • Set of function includes taverna-robundle and taverna-databundle, which primary function is to store information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

incubator-taverna-osgi:

  • Is the item designed to use cryptography or does it contain cryptography?  Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Set of function include taverna-download-impl, which primary function is to receive information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

incubator-taverna-engine:

incubator-taverna-commandline

  • Is the item designed to use cryptography or does it contain cryptography? Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is to execute workflows - however those workflows generally do Sending, receiving or storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-common-activities

incubator-taverna-server

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE), BouncyCastle crypto, Apache CXF and Apache Taverna Command Line
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Set of function includes Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-databundle-viewer

  • Is the item designed to use cryptography or does it contain cryptography? Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-mobile

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Android SDK https support, Dropbox Android SDK and Apache HttpComponent
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-plugin-bioinformatics

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-plugin-component

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-plugin-gis

  • Is the item designed to use cryptography or does it contain cryptography? No
    • Not controlled

incubator-taverna-workbench

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is to design workflows, but set of functions includes UI for the Credential Manager
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

incubator-taverna-workbench-common-activities

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager, HttpComponents and Taverna Common Activities WSS4j support.
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Set of function includes  Receiving information (for Service Discovery)
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

 

incubator-taverna-workbench-product

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Builds distribution that includes Apache WSS4J, Apache XML Security for Java, Apache HttpComponents and BouncyCastle crypto
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is to design and run workflows, but those workflows generally do Sending, receiving or storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

 

Not (yet) classified

https://github.com/apache/incubator-taverna-maven-parent (exempt)

The taverna-plugin-* and taverna-workbench-* repositories have been classified mainly because they depend on Taverna Engine. This might be reviewed, see LEGAL-250 about transitivity.

Encryption declaration XML

Added to https://svn.apache.org/repos/asf/infrastructure/site/trunk/content/licenses/exports/index.page/eccnmatrix.xml according to http://www.apache.org/dev/crypto.html

Note that there are two sections - development is for our multiple source code repositories as listed on http://taverna.incubator.apache.org/code/ - and all releases which cover anything under https://archive.apache.org/dist/incubator/taverna/ (however this would include releases of even potentially non-classified products like taverna-maven-parent or incubator-taverna-databundle-viewer). Taverna releases are separate per code repository - so this could alternatively be split into many separate <Version> declarations - but then we might have to reorganize the dist folders to avoid updating this XML for every release.

 

Code Block
languagexml
  <Product>
    <Name>Apache Taverna</Name>
    <Version>
      <Names>development</Names>
      <ECCN>5D002</ECCN>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-language.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache HttpComponents</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-osgi.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache HttpComponents</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-engine.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE), BouncyCastle crypto, Apache Derby, Apache Taverna Language and Apache Taverna OSGi</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-common-activities.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE), Jetty, Apache WSS4J, Apache XML Security for Java, Apache HttpComponents and Apache Taverna Engine</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-commandline.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache WSS4J, Apache XML Security for Java, Apache HttpComponents, BouncyCastle crypto, Apache Taverna Engine and Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-server.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE), BouncyCastle crypto, Apache CXF and Apache Taverna Command Line</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE) and Apache Taverna Engine</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench-common-activities.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache Taverna Workbench and Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench-product.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Builds distribution that includes Apache WSS4J, Apache XML Security for Java, Apache HttpComponents and BouncyCastle crypto</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-plugin-component.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache HttpComponents, Apache Taverna Engine, Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-plugin-bioinformatics.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache Taverna Engine</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-plugin-gis.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache Taverna Engine, Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-mobile.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Android SDK https support, Dropbox Android SDK and Apache HttpComponent</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-databundle-viewer.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Ruby OpenSSL</Why>
      </ControlledSource>

      <ControlledSource href="http://bouncycastle.org/download/bcprov-jdk15on-154.tar.gz">
        <Manufacturer>Bouncy Castle</Manufacturer>
        <Why>General-purpose encryption library for Java 1.5</Why>
      </ControlledSource>
      <ControlledSource href="http://eclipse.org/jetty">
        <Manufacturer>The Eclipse Foundation</Manufacturer>
        <Why>SSL library for Jetty</Why>
      </ControlledSource>
Code Block
languagexml
   <Product>
    <Name>Apache Taverna</Name>
    <Version>
      <Names>development</Names>
      <ECCN>5D002</ECCN>
      <ControlledSource href="httpshttp://git-wip-us.apache.org/repos/asf/incubator-taverna-language.gitwww.oracle.com/technetwork/java/javase/downloads/index.html">
        <Manufacturer>ASF<<Manufacturer>Oracle</Manufacturer>
        <Why>Designed for use<Why>general-purpose cryptography library (JCE) included with Apache HttpComponents<Java</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-uswww.apache.org/reposdist/asfsantuario/incubator-taverna-osgi.gitjava-library/">
        <Manufacturer>ASF</Manufacturer>
        <Why>General-purpose <Why>DesignedXML forencryption useand withdigital Apachesignature HttpComponents<implementation</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-ussvn.apache.org/repos/asf/incubator-taverna-engine.gitviewvc/santuario/xml-security-java/branches/1.5.x-fixes/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed<Why>Implements for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE), BouncyCastle crypto, Apache Derby, Apache Taverna Language and Apache Taverna OSGi<XML Signature and Encryption specs</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-uspeople.apache.org/reposdist/asf/incubator-taverna-common-activities.gitcxf/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE), Apache WSS4J, the Apache XML Security forJava JavaAPI, ApacheWSS4J HttpComponents and ApacheBouncyCastle Taverna Engine<crypto</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-usarchive.apache.org/reposdist/xml/asfsecurity/incubator-taverna-commandline.gitjava-library/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache WSS4J, Apache XML Security for Java, Apache HttpComponents, BouncyCastle crypto, Apache Taverna OSGi, Apache Taverna Engine and Apache Taverna Common Activities<<Why>General-purpose XML encryption and digital signature implementation</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-usarchive.apache.org/reposdist/db/asf/incubator-taverna-server.gitderby/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed<Why>designed for use with Java Secure Socket Extension (JSSE), the Java Cryptography Extension (JCE), BouncyCastle crypto, Apache CXF and Apache Taverna Command Line< API</Why>
      </ControlledSource>

      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench.gitwww.dropbox.com/developers-v1/core/sdks/android">
        <Manufacturer>ASF<<Manufacturer>Dropbox</Manufacturer>
        <Why>Designed<Why>designed for use with Java Secure Socket Extension (JSSE)Android SDK, Apacheadds Tavernaa Engine<SecureSSLSocketFactory</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench-common-activities.gitandroid.googlesource.com/">
        <Manufacturer>ASF<<Manufacturer>Google</Manufacturer>
        <Why>Designed for use with Apache Taverna Workbench and Apache Taverna Common Activities<<Why>includes encryption code adapted from OpenSSL, BouncyCastle, BoringSSL</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench-product.gitgithub.com/ruby/openssl">
        <Manufacturer>ASF<<Manufacturer>Ruby Programming Language</Manufacturer>
        <Why>Designed<Why>designed for use with Apache Taverna Workbench Common Activities<OpenSSL</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-us.apachewww.openssl.org/repos/asf/incubator-taverna-plugin-component.gitsource/">
        <Manufacturer>The OpenSSL <Manufacturer>ASF<Project</Manufacturer>
        <Why>Publicly available SSL encryption library</Why>
      </ControlledSource>
  <Why>Designed for use with Apache HttpComponents, Apache Taverna Engine, Apache Taverna Common Activities</Why>  </Version>
    <Version>
      <Names>all releases</Names>
      <<ECCN>5D002</ControlledSource>ECCN>
      <ControlledSource href="https://git-wip-usarchive.apache.org/reposdist/asfincubator/incubator-taverna-plugin-bioinformatics.gittaverna/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache CXF, Apache WSS4J, Apache XML Security for Java, Apache HttpComponents, Apache Derby, BouncyCastle crypto, Jetty, Java Secure Socket <Why>Designed for use with Apache Taverna Engine<Extension (JSSE), Java Cryptography Extension (JCE)</Why>
      </ControlledSource>
      <ControlledSource href="httpshttp://git-wip-us.apache.bouncycastle.org/reposdownload/asf/incubatorbcprov-taverna-plugin-gis.gitjdk15on-154.tar.gz">
        <Manufacturer>ASF<<Manufacturer>Bouncy Castle</Manufacturer>
        <Why>Designed for use with Apache Taverna Engine, Apache Taverna Common Activities< <Why>General-purpose encryption library for Java 1.5</Why>
      </ControlledSource>

      <ControlledSource href="http://wwweclipse.apache.org/dist/santuario/java-library/jetty">
        <Manufacturer>The Eclipse <Manufacturer>ASF<Foundation</Manufacturer>
        <Why>General-purpose<Why>SSL XMLlibrary encryption and digital signature implementation<for Jetty</Why>
      </ControlledSource>
      <ControlledSource href="http://svnwww.apacheoracle.orgcom/viewvctechnetwork/santuario/xml-security-java/branches/1.5.x-fixes/java/javase/downloads/index.html">
        <Manufacturer>ASF<<Manufacturer>Oracle</Manufacturer>
        <Why>general-purpose <Why>Implementscryptography XMLlibrary Signature(JCE) andincluded Encryptionwith specs<Java</Why>
      </ControlledSource>
      <ControlledSource href="http://bouncycastlewww.apache.org/downloaddist/santuario/bcprov-jdk15on-154.tar.gzjava-library/">
        <Manufacturer>Bouncy Castle<<Manufacturer>ASF</Manufacturer>
        <Why>General-purpose XML encryption libraryand fordigital Javasignature 1.5<implementation</Why>
      </ControlledSource>
      <ControlledSource href="http://peoplesvn.apache.org/dist/cxfviewvc/santuario/xml-security-java/branches/1.5.x-fixes/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with the Apache <Why>Implements XML Security Java API, WSS4J Signature and BouncyCastleEncryption crypto<specs</Why>
      </ControlledSource>
      <ControlledSource href="http://archivepeople.apache.org/dist/xml/security/java-library/cxf/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with the Apache XML Security <Why>General-purpose XML encryptionJava API, WSS4J and digitalBouncyCastle signature implementation<crypto</Why>
      </ControlledSource>
      <ControlledSource href="http://archive.apache.org/dist/db/derbyxml/security/java-library/">
        <Manufacturer>ASF</Manufacturer>
        <Why>designed<Why>General-purpose forXML useencryption withand thedigital Java Cryptography Extension (JCE) API<signature implementation</Why>
      </ControlledSource>
      <ControlledSource href="http://wwwarchive.oracleapache.comorg/technetworkdist/java/javase/downloads/index.htmldb/derby/">
        <Manufacturer>Oracle<<Manufacturer>ASF</Manufacturer>
        <Why>general-purpose cryptography library<Why>designed for use with the Java Cryptography Extension (JCE) included with Java<API</Why>
      </ControlledSource>
    </Version>
    <Version>
      <Names>all releases</Names>
      <ECCN>5D002</ECCN>
      <ControlledSource href="https://archivewww.apachedropbox.orgcom/distdevelopers-v1/incubatorcore/tavernasdks/android">
        <Manufacturer>ASF<<Manufacturer>Dropbox</Manufacturer>
        <Why>Designed<Why>designed for use with ApacheAndroid CXFSDK, Apache WSS4J, Apache XML Security for Java, Apache HttpComponents, Apache Derby, BouncyCastle crypto, Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE)<adds a SecureSSLSocketFactory</Why>
      </ControlledSource>
      <ControlledSource href="httphttps://wwwandroid.apache.org/dist/santuario/java-library/googlesource.com/">
        <Manufacturer>ASF<<Manufacturer>Google</Manufacturer>
        <Why>includes <Why>General-purposeencryption XMLcode encryptionadapted andfrom digitalOpenSSL, signatureBouncyCastle, implementation<BoringSSL</Why>
      </ControlledSource>
      <ControlledSource href="httphttps://svn.apache.org/viewvc/santuario/xml-security-java/branches/1.5.x-fixes/github.com/ruby/openssl">
        <Manufacturer>Ruby <Manufacturer>ASF<Programming Language</Manufacturer>
        <Why>Implements<Why>designed XMLfor Signatureuse andwith Encryption specs<OpenSSL</Why>
      </ControlledSource>
      <ControlledSource href="http://bouncycastlewww.openssl.org/download/bcprov-jdk15on-154.tar.gz">
   source/">
        <Manufacturer>The OpenSSL Project</Manufacturer>
        <Why>Publicly available SSL encryption library</Why>
     <Manufacturer>Bouncy Castle<</Manufacturer>ControlledSource>
    </Version>
    <Why>General-purpose encryption library for Java 1.5</Why>
</Product>

 

Draft registration email

This would formally have to be sent by the Incubator PMC chair:

Code Block
languagetext
   TO: crypt AT bis.doc.gov, 
       </ControlledSource>
enc AT nsa.gov, 
       web_site <ControlledSource href="http://people.apache.org/dist/cxf/">AT bis.doc.gov
   CC: {applicable project list}, 
  <Manufacturer>ASF</Manufacturer>
     {legal-archive AT a.o}

 <Why>Designed for useSUBJ: withTSU theNOTIFICATION Apache XML Security Java API, WSS4J and BouncyCastle crypto</Why>
- Encryption

SUBMISSION TYPE:      TSU

SUBMITTED BY:      </ControlledSource>
   Ted Dunning

SUBMITTED FOR: <ControlledSource href="http://archive.apache.org/dist/xml/security/java-library/">
      Apache Software <Manufacturer>ASF</Manufacturer>Foundation

POINT OF CONTACT:     Secretary, Apache <Why>General-purpose XML encryption and digital signature implementation</Why>
Software Foundation

FAX:           </ControlledSource>
      <ControlledSource href="http://archive.apache.org/dist/db/derby/">
        <Manufacturer>ASF</Manufacturer>
        <Why>designed for use with the Java Cryptography Extension (JCE) API</Why>
 +1-919-573-9199
				
MANUFACTURER(S):   
    
The Apache Software Foundation
Bouncy Castle
The Eclipse Foundation
Oracle
Dropbox
Google
Ruby Programming Language
The OpenSSL Project

PRODUCT NAME/MODEL #: Apache Taverna

ECCN:                 </ControlledSource>
5D002

NOTIFICATION:        <ControlledSource href="httphttp://www.apache.org/licenses/exports/

 

README updates

Also described in READMEs:

...

...