Important Notice:
OpenSSL and Export Control Regulations: Guidance Note
Current versions of software provided by LDRA make use of an open source module called OpenSSL. The function of this module is to allow customers to make secure communications with remote computer systems including remote websites. OpenSSL uses cryptography and in a number of countries there may be restrictions on its use.
The purpose of this note is to provide some guidance to enable customers to be aware of their position in the various jurisdictions in which they operate and to enable them to discuss any issues with their lawyers and local regulators. LDRA is a software company and is not qualified to offer detailed and specific legal advice, nor would it be feasible to do so in the many territories in which their software products are likely to be used. Moreover regulations in individual jurisdictions are liable to constant change. However LDRA is able to provide this factual information which we hope will assist. We stress however, the need for LDRA customers to obtain independent advice and, if necessary, further authorisation for their specific use.
This note has been written to include explanations for the benefit of advisers and regulators.
1. LDRA provide software quality tools that automate code analysis for a variety of engineering purposes including safety-critical and secure-critical applications. Their products automate software verification, requirements traceability and standards compliance. Among the sectors currently served are aerospace, defence, energy, automotive, rail transport, and medical. Further information is available on the LDRA website: www.ldra.com
2. As with most software products, LDRA’s software developers have made use of modules containing specific functions which have been written by others, as there is no point in “reinventing the wheel”. In addition, many of these additional and external modules have been very fully tested by others and hence may be considered reliable. LDRA customers will find that all acknowledgements and, if necessary, licensing fees have already been paid and incorporated into the LDRA products they use.
3. One such module is called OpenSSL which is a widely available, ‘open source’ product, which means that it is free to get and use for both commercial and non-commercial purposes. It provides a variety of security functions and in particular, functions for authentication and confidentiality. Authentication is necessary so that a remote computer system has confidence that someone using it is properly authorised to be admitted and so that the user has confidence that they are dealing with the remote site they believe it to be, as opposed to a fraudulent version. A further benefit provided by OpenSSL, is protection against eavesdropping while communications are taking place across the open Internet. To provide a little more detail: SSL stands for ‘secure sockets layer’ and is a family of protocols incorporated into websites and also into remote computer systems using a version of FTP (file transport protocol). OpenSSL also deals with a protocol called TLS (transport layer security). Further information about OpenSSL is available at its website https://www.openssl.org. The website also explains the governance of the OpenSSL community.
4. Websites and remote sites that have implemented SSL and similar protocols will decline admission to computers that lack the appropriate functions.
5. The primary use of OpenSSL by most of LDRA customers is the simple authentication function. Customers may need additional or updated information from remote websites and other computers. A number of customers also operate from multiple locations each with their own computer systems and need to communicate with them securely.
6. OpenSSL uses cryptography and in many countries there are restrictions on their use and in particular, their export. The following are a number of the chief criteria that tend to be considered by local regulatory authorities. OpenSSL include the following statement on their website:
“Please remember that export/import and/or use of strong cryptography software, providing cryptography hooks, or even just communicating technical details about cryptography software is illegal in some parts of the world. So when you import this package to your country, re-distribute it from there or even just email technical suggestions or even source patches to the authors or other people you are strongly advised to pay close attention to any laws or regulations which apply to you. The authors of OpenSSL are not liable for any violations you make here. So be careful, it is your responsibility.”
7. Most countries provide formal procedures to be followed to apply to export encryption products and which should be used unless there is an obvious exemption.
8. For the avoidance of doubt, it should be assumed that “exporting” may include using a cryptographic product for the purpose of communicating with a computer outside the home jurisdiction.
9. LDRA customers operating in more than one jurisdiction may find that although their primary purchase has been properly licensed or falls within an exemption their use of OpenSSL in another jurisdiction may attract the requirement to obtain a licence within that jurisdiction also.
10. There may be an absolute bar to exporting to certain countries, usually on political grounds. Examples include nation states listed under ITAR, the International Traffic in Arms Regulations run by the US Department of State and EAR, the Export Administration Regulations run by the US Department of Commerce. The main UK guidance is at: https://www.gov.uk/guidance/current-arms-embargoes-and-other-restrictions. A note on EU provisions can be found at: http://trade.ec.europa.eu/doclib/docs/2016/october/tradoc_155052.pdf. At the time this note is being compiled the US/ITAR embargoed countries are: Afghanistan, Belarus, Central African Republic, Cuba, Cyprus, Eritrea, Fiji, Iran, Iraq, Cote d’Ivoire, Lebanon, Libya, North Korea, Syria, Vietnam, Myanmar, China, Haiti, Liberia, Rwanda, Somalia, Sri Lanka, Republic of the Sudan (Northern Sudan), Yemen, Zimbabwe, Venezuela, Democratic Republic of the Congo.
11. A number of countries including the United States, the United Kingdom and the European Union provide exemptions for “mass market” or “retail” products. Typical criteria include that the cryptographic products:
• can be easily acquired by the general public,
• require little or no support to install, and
• cryptographic functionality cannot be easily changed by the user.
12. As OpenSSL is an open source product, ‘widely available’, is installed by LDRA ‘without the need for customer involvement’ / is mostly installed by the customer without much LDRA involvement and ‘cannot be easily changed by the user’ it is thus a good candidate for the “mass market” exemption.
13. Also some countries provide exemptions for cryptographic products with a limited key length. The key length used in LDRA’s implementation by default is 2048.
14. However a routine use envisaged by software developers would be for updated information to extend the existing capacity of a LDRA product to provide software quality assurance and standards compliance. These particular LDRA customers dealing in products regarded as “sensitive” may need to obtain a licence.
15. Although a licence or exemption may be obtained for the use of OpenSSL, restrictions may nevertheless apply to the type of material or traffic that is being communicated from one computer to another. LDRA is not in a position to give advice to its customers on this matter.
16. In view of the above, LDRA strongly advise customers to obtain independent advice and, if necessary, further authorisation for their specific use.
Any updates to this Guidance Note will be posted on this page so it is the licensee’s obligation to check for updates there and on the relevant official websites.
Email: info@ldra.com
EMEA: +44 (0)151 649 9300
USA: +1 (855) 855 5372
INDIA: +91 80 4080 8707