A recent note by Sameer alluded to the following. The EAR issued on
30-dec-96 transferred crypto from US Dept of State to Commerce.
It loosened some requirements, but added this (chilling) addition
to the list of items controlled:
(c) Technical assistance by U.S. persons with respect to
encryption commodities or software as described in 744.9 of theEAR.
Now, there are various ways to consider this; Sameer is paying for a lawyer
to perform one analysis. Thanks. In anticipation of this, I encourage
the openssl-core folks to interpret this in the same way the US has
interpreted export: only the crypto algorithms, per se. That means,
e.g., US persons should check with a lawyer before postings diffs to
some of the files within the crypto/rc[245] and crypto/rsa directories.
In other words, the "with respect to" phrase is very important. Cryptography
is controlled. Frameworks, data manipulation routines, etc., are not.
Technical assistance follows the same rule.
Depending on how concerned the openssl folks wish to be, they can limit the
scope of US persons' contributions to keeping them out of probably 12 files.
Should Sameer's lawyer say otherwise, I'd encourage another opinion (perhaps
pray to John Gilmore to fund a review).
Hope this is useful.
/r$
______________________________________________________________________
OpenSSL Project http://www.openssl.org
Development Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]