[Openstack-security] Cryptographic Export Controls and OpenStack

Bryan D. Payne bdpayne at acm.org
Wed Apr 16 17:28:15 UTC 2014


I'm not aware of a list of the specific changes, but this seems quite
related to the work that Nathan has started played with... discussed on his
blog here:

https://blog-nkinder.rhcloud.com/?p=51

Cheers,
-bryan



On Tue, Apr 15, 2014 at 1:38 AM, Clark, Robert Graham
<robert.clark at hp.com>wrote:

> Does anyone have a documented run-down of changes that must be made to
> OpenStack configurations to allow them to comply with EAR requirements?
> http://www.bis.doc.gov/index.php/policy-guidance/encryption
>
> It seems like something we should consider putting into the security
> guide. I realise that most of the time it’s just “don’t use your own
> libraries, call to others, make algorithms configurable” etc but it’s a
> question I’m seeing more and more, the security guide’s compliance section
> looks like a great place to have something about EAR.
>
> -Rob
>
> _______________________________________________
> Openstack-security mailing list
> Openstack-security at lists.openstack.org
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-security
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-security/attachments/20140416/6bbb85e8/attachment.html>


More information about the Openstack-security mailing list