For http://www.apache.org/licenses/exports/ - see TAVERNA-959 - Getting issue details... STATUS LEGAL-250 - Getting issue details... STATUS

 

ECCN classification

To consider if Taverna code is classified, we follow Flowchart 1 from https://www.bis.doc.gov/index.php/policy-guidance/encryption/identifying-encryption-items, with the questions:

  • Is the item designed to use cryptography or does it contain cryptography?  (exempt if No)
  • Is the hardware or software specially designed for medical end use? (exempt if  Yes)
  • Is the product described by Note 4? (exempt if Yes)
  • Is the encryption functionality limited to intellectual property or copyright protection functions? (exempt if Yes)

If we get through this, then we are controlled under Category 5, part 2 and must consider flow chart 2 to determine if we can self-classify using https://www.bis.doc.gov/index.php/policy-guidance/encryption/registration.

  • Is the item publicly available encryption source code? (If yes, self-classify as ECCN 5D002)
  • Beta Test Software? (If yes, self-classify as ECCN 5200d)
  • Encryption using key length <= 56 symmetric, <= 512 assymmetric or <= 112 elliptic curve? (If yes, self-classify as ECCN 5x992 NLR)
  • Is the item described in Note for 5A002? (If yes, self-classify as 5x992)
  • Is the item limited to authentication only? (If yes, self-classify as 5x992)
  • Does the item meet the criteria for Mass Market?

So for each of our repositories:

incubator-taverna-maven-parent:

  • Is the item designed to use cryptography or does it contain cryptography?  No

    • Not controlled

incubator-taverna-language:

  • Is the item designed to use cryptography or does it contain cryptography?  Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4?  No
    • Set of function includes taverna-robundle and taverna-databundle, which primary function is to store information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

incubator-taverna-osgi:

  • Is the item designed to use cryptography or does it contain cryptography?  Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Set of function include taverna-download-impl, which primary function is to receive information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

incubator-taverna-engine:

incubator-taverna-commandline

  • Is the item designed to use cryptography or does it contain cryptography? Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is to execute workflows - however those workflows generally do Sending, receiving or storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-common-activities

incubator-taverna-server

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE), BouncyCastle crypto, Apache CXF and Apache Taverna Command Line
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Set of function includes Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-databundle-viewer

  • Is the item designed to use cryptography or does it contain cryptography? Yes
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-mobile

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Android SDK https support, Dropbox Android SDK and Apache HttpComponent
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-plugin-bioinformatics

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is Sending, receiving and storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-plugin-component

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No

  • Is the item publicly available encryption source code? Yes

    • ECCN 5D002

incubator-taverna-plugin-gis

  • Is the item designed to use cryptography or does it contain cryptography? No
    • Not controlled

incubator-taverna-workbench

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is to design workflows, but set of functions includes UI for the Credential Manager
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

incubator-taverna-workbench-common-activities

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Designed for use with Taverna Engine's Credential Manager, HttpComponents and Taverna Common Activities WSS4j support.
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Set of function includes  Receiving information (for Service Discovery)
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

 

incubator-taverna-workbench-product

  • Is the item designed to use cryptography or does it contain cryptography? Yes
    • Builds distribution that includes Apache WSS4J, Apache XML Security for Java, Apache HttpComponents and BouncyCastle crypto
  • Is the hardware or software specially designed for medical end use? No
  • Is the product described by Note 4? No
    • Primary function is to design and run workflows, but those workflows generally do Sending, receiving or storing information
  • Is the encryption functionality limited to intellectual property or copyright protection functions? No
  • Is the item publicly available encryption source code? Yes
    • ECCN 5D002

 

Not (yet) classified

https://github.com/apache/incubator-taverna-maven-parent (exempt)

The taverna-plugin-* and taverna-workbench-* repositories have been classified mainly because they depend on Taverna Engine. This might be reviewed, see LEGAL-250 about transitivity.

Encryption declaration XML

Added to https://svn.apache.org/repos/asf/infrastructure/site/trunk/content/licenses/exports/index.page/eccnmatrix.xml according to http://www.apache.org/dev/crypto.html

Note that there are two sections - development is for our multiple source code repositories as listed on http://taverna.incubator.apache.org/code/ - and all releases which cover anything under https://archive.apache.org/dist/incubator/taverna/ (however this would include releases of even potentially non-classified products like taverna-maven-parent or incubator-taverna-databundle-viewer). Taverna releases are separate per code repository - so this could alternatively be split into many separate <Version> declarations - but then we might have to reorganize the dist folders to avoid updating this XML for every release.

 

  <Product>
    <Name>Apache Taverna</Name>
    <Version>
      <Names>development</Names>
      <ECCN>5D002</ECCN>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-language.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache HttpComponents</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-osgi.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache HttpComponents</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-engine.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE), BouncyCastle crypto, Apache Derby, Apache Taverna Language and Apache Taverna OSGi</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-common-activities.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE), Jetty, Apache WSS4J, Apache XML Security for Java, Apache HttpComponents and Apache Taverna Engine</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-commandline.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache WSS4J, Apache XML Security for Java, Apache HttpComponents, BouncyCastle crypto, Apache Taverna Engine and Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-server.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE), BouncyCastle crypto, Apache CXF and Apache Taverna Command Line</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Java Secure Socket Extension (JSSE) and Apache Taverna Engine</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench-common-activities.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache Taverna Workbench and Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-workbench-product.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Builds distribution that includes Apache WSS4J, Apache XML Security for Java, Apache HttpComponents and BouncyCastle crypto</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-plugin-component.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache HttpComponents, Apache Taverna Engine, Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-plugin-bioinformatics.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache Taverna Engine</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-plugin-gis.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache Taverna Engine, Apache Taverna Common Activities</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-mobile.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Android SDK https support, Dropbox Android SDK and Apache HttpComponent</Why>
      </ControlledSource>
      <ControlledSource href="https://git-wip-us.apache.org/repos/asf/incubator-taverna-databundle-viewer.git">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Ruby OpenSSL</Why>
      </ControlledSource>

      <ControlledSource href="http://bouncycastle.org/download/bcprov-jdk15on-154.tar.gz">
        <Manufacturer>Bouncy Castle</Manufacturer>
        <Why>General-purpose encryption library for Java 1.5</Why>
      </ControlledSource>
      <ControlledSource href="http://eclipse.org/jetty">
        <Manufacturer>The Eclipse Foundation</Manufacturer>
        <Why>SSL library for Jetty</Why>
      </ControlledSource>
      <ControlledSource href="http://www.oracle.com/technetwork/java/javase/downloads/index.html">
        <Manufacturer>Oracle</Manufacturer>
        <Why>general-purpose cryptography library (JCE) included with Java</Why>
      </ControlledSource>
      <ControlledSource href="http://www.apache.org/dist/santuario/java-library/">
        <Manufacturer>ASF</Manufacturer>
        <Why>General-purpose XML encryption and digital signature implementation</Why>
      </ControlledSource>
      <ControlledSource href="http://svn.apache.org/viewvc/santuario/xml-security-java/branches/1.5.x-fixes/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Implements XML Signature and Encryption specs</Why>
      </ControlledSource>
      <ControlledSource href="http://people.apache.org/dist/cxf/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with the Apache XML Security Java API, WSS4J and BouncyCastle crypto</Why>
      </ControlledSource>
      <ControlledSource href="http://archive.apache.org/dist/xml/security/java-library/">
        <Manufacturer>ASF</Manufacturer>
        <Why>General-purpose XML encryption and digital signature implementation</Why>
      </ControlledSource>
      <ControlledSource href="http://archive.apache.org/dist/db/derby/">
        <Manufacturer>ASF</Manufacturer>
        <Why>designed for use with the Java Cryptography Extension (JCE) API</Why>
      </ControlledSource>

      <ControlledSource href="https://www.dropbox.com/developers-v1/core/sdks/android">
        <Manufacturer>Dropbox</Manufacturer>
        <Why>designed for use with Android SDK, adds a SecureSSLSocketFactory</Why>
      </ControlledSource>
      <ControlledSource href="https://android.googlesource.com/">
        <Manufacturer>Google</Manufacturer>
        <Why>includes encryption code adapted from OpenSSL, BouncyCastle, BoringSSL</Why>
      </ControlledSource>
      <ControlledSource href="https://github.com/ruby/openssl">
        <Manufacturer>Ruby Programming Language</Manufacturer>
        <Why>designed for use with OpenSSL</Why>
      </ControlledSource>
      <ControlledSource href="http://www.openssl.org/source/">
        <Manufacturer>The OpenSSL Project</Manufacturer>
        <Why>Publicly available SSL encryption library</Why>
      </ControlledSource>
    </Version>
    <Version>
      <Names>all releases</Names>
      <ECCN>5D002</ECCN>
      <ControlledSource href="https://archive.apache.org/dist/incubator/taverna/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with Apache CXF, Apache WSS4J, Apache XML Security for Java, Apache HttpComponents, Apache Derby, BouncyCastle crypto, Jetty, Java Secure Socket Extension (JSSE), Java Cryptography Extension (JCE)</Why>
      </ControlledSource>
      <ControlledSource href="http://bouncycastle.org/download/bcprov-jdk15on-154.tar.gz">
        <Manufacturer>Bouncy Castle</Manufacturer>
        <Why>General-purpose encryption library for Java 1.5</Why>
      </ControlledSource>
      <ControlledSource href="http://eclipse.org/jetty">
        <Manufacturer>The Eclipse Foundation</Manufacturer>
        <Why>SSL library for Jetty</Why>
      </ControlledSource>
      <ControlledSource href="http://www.oracle.com/technetwork/java/javase/downloads/index.html">
        <Manufacturer>Oracle</Manufacturer>
        <Why>general-purpose cryptography library (JCE) included with Java</Why>
      </ControlledSource>
      <ControlledSource href="http://www.apache.org/dist/santuario/java-library/">
        <Manufacturer>ASF</Manufacturer>
        <Why>General-purpose XML encryption and digital signature implementation</Why>
      </ControlledSource>
      <ControlledSource href="http://svn.apache.org/viewvc/santuario/xml-security-java/branches/1.5.x-fixes/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Implements XML Signature and Encryption specs</Why>
      </ControlledSource>
      <ControlledSource href="http://people.apache.org/dist/cxf/">
        <Manufacturer>ASF</Manufacturer>
        <Why>Designed for use with the Apache XML Security Java API, WSS4J and BouncyCastle crypto</Why>
      </ControlledSource>
      <ControlledSource href="http://archive.apache.org/dist/xml/security/java-library/">
        <Manufacturer>ASF</Manufacturer>
        <Why>General-purpose XML encryption and digital signature implementation</Why>
      </ControlledSource>
      <ControlledSource href="http://archive.apache.org/dist/db/derby/">
        <Manufacturer>ASF</Manufacturer>
        <Why>designed for use with the Java Cryptography Extension (JCE) API</Why>
      </ControlledSource>
      <ControlledSource href="https://www.dropbox.com/developers-v1/core/sdks/android">
        <Manufacturer>Dropbox</Manufacturer>
        <Why>designed for use with Android SDK, adds a SecureSSLSocketFactory</Why>
      </ControlledSource>
      <ControlledSource href="https://android.googlesource.com/">
        <Manufacturer>Google</Manufacturer>
        <Why>includes encryption code adapted from OpenSSL, BouncyCastle, BoringSSL</Why>
      </ControlledSource>
      <ControlledSource href="https://github.com/ruby/openssl">
        <Manufacturer>Ruby Programming Language</Manufacturer>
        <Why>designed for use with OpenSSL</Why>
      </ControlledSource>
      <ControlledSource href="http://www.openssl.org/source/">
        <Manufacturer>The OpenSSL Project</Manufacturer>
        <Why>Publicly available SSL encryption library</Why>
      </ControlledSource>
    </Version>
  </Product>

 

Draft registration email

This would formally have to be sent by the Incubator PMC chair:

   TO: crypt AT bis.doc.gov, 
       enc AT nsa.gov, 
       web_site AT bis.doc.gov
   CC: {applicable project list}, 
       {legal-archive AT a.o}

   SUBJ: TSU NOTIFICATION - Encryption

SUBMISSION TYPE:      TSU

SUBMITTED BY:         Ted Dunning

SUBMITTED FOR:        Apache Software Foundation

POINT OF CONTACT:     Secretary, Apache Software Foundation

FAX:                  +1-919-573-9199
				
MANUFACTURER(S):   
    
The Apache Software Foundation
Bouncy Castle
The Eclipse Foundation
Oracle
Dropbox
Google
Ruby Programming Language
The OpenSSL Project

PRODUCT NAME/MODEL #: Apache Taverna

ECCN:                 5D002

NOTIFICATION:         http://www.apache.org/licenses/exports/

 

README updates

Also described in READMEs:

 

 

  • No labels