Re: Export restrictions / SSH session key
- From: "quebert" <isquereal@xxxxxxxx>
- Date: 23 May 2006 03:11:50 -0700
Richard E. Silverman schrieb:
As Nico said, ask a lawyer.
I have already contacted our lawyer in the company.
However, the hostkeys in SSH-2 are used only
for signing, not encryption, and I believe there are no restrictions on
signature algorithms.
For SSHv2 this is also my understanding.
But we would still like to use SSHv1 only, because DES is not
recommended in SSHv2.
From the Wassenaar Arrangement it is not possible for me to
interpret the following sentences:
crypto products of up to 512 bits, and all subgroup-based crypto- free for export are: all symmetric crypto products of up to 56 bits, all asymmetric
products (including
elliptic curve) of up to 112 bits;
export (the 64-bit limit was deleted on 1 December 2000, see- mass-market symmetric crypto software and hardware of up to 64 bits are free for
below);
DVDs) is relaxed;- the export of products that use encryption to protect intellectual property (such as
- export of all other crypto still requires a license.
The key point is:
Does the encryption of the session key with RSA (by default 768 bits) violate
this arrangement, or does this arrangement only affect the 'encryption' of the
data itself?
Kind Regards
Quebert
.
- Follow-Ups:
- Re: Export restrictions / SSH session key
- From: Unruh
- Re: Export restrictions / SSH session key
- References:
- Export restrictions / SSH session key
- From: quebert
- Re: Export restrictions / SSH session key
- From: Richard E. Silverman
- Export restrictions / SSH session key
- Prev by Date: write data into file
- Next by Date: Re: Distinguishing ssh-logins from sftp-logins
- Previous by thread: Re: Export restrictions / SSH session key
- Next by thread: Re: Export restrictions / SSH session key
- Index(es):