New legal rquirement: import and export of encryption in France

Patrick Luby plubius at neooffice.org
Tue Feb 21 22:17:41 UTC 2023


Hi everyone,


Background
----------

For many years, France has required organizations to obtain 
authorization from the French agency ANSSI to import or export 
cryptographic technology.


Why now?
--------

Apple now requires you to upload an authorization certificate from ANSSI 
before you can release new versions in the French App Store. Because of 
this new Apple requirement, LibreOffice, NeoOffice, and Collabora Office 
cannot distribute new versions in the French App Store.

Since I have to do an application for NeoOffice (I am still backporting 
security fixes from LibreOffice), I have volunteered to try and prepare 
LibreOffice's application to ANSSI. Hopefully, with only minor changes, 
I can use LibreOffice's application as a template for NeoOffice and 
Collabora Office.

The current "work in progress" version of the application is at:

https://nextcloud.documentfoundation.org/s/PrACjSQfTZ5cYcA/download?path=%2F&files=ANNEXE%20I_FR-EN.odt


What needs to be done?
----------------------

I have posted a "todo" file at:

https://nextcloud.documentfoundation.org/s/PrACjSQfTZ5cYcA?path=%2F&openfile=1236102

The file lists the tasks that I think need to be done, as well some 
notes and questions, in three groups:
- Not complete
- Needs review
- Complete


Where I need help
-----------------

1. I wrote answers to most of the text questions. Can anyone review and 
suggest edits for any of the items in the "Needs review" group in the 
"todo" file?

2. ANSSI wants several brochures/manuals/guides in PDF format. Can 
anyone find any good web pages or, even better, PDF documents for the 
"Section E" items in the "Not complete" group?

3. My next planned step was to look through the code in the 
libreoffice-7-5-0 branch and see if I can fill out the table in question 
B.3.4. Can anyone confirm that the following are the only cryptographic 
APIs that we use now and in the near future?:
- MS-CAPI (Windows only)
- NSS (all non-Windows platforms)
- OpenSSL
- OpenPGP


Thank you all for any help that you can provide. Regulatory filings are 
never fun but so far my limited contact with ANSSI has been very 
positive (I asked if they had a fillable PDF and they responded the same 
day).

Patrick


More information about the LibreOffice mailing list