Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Problematic RSA-MD licensed files #448

Open
bgermann opened this issue Nov 17, 2024 · 0 comments · May be fixed by #449 or #450
Open

Problematic RSA-MD licensed files #448

bgermann opened this issue Nov 17, 2024 · 0 comments · May be fixed by #449 or #450

Comments

@bgermann
Copy link

bgermann commented Nov 17, 2024

libetpan contains md5.c and md5.h from Cyrus SASL. They are licensed under RSA-MD, which contains an advertisement clause and is therefore incompatible with GNU GPL. Major libetpan users are licensed under GPL, e.g. Claws Mail. The incompatibility makes distributing binaries that are covered by both licenses problematic.

Please consider replacing the files. If you want to stick with the Cyrus SASL HMAC-MD5 implementation, please consider importing a later (relicensed) version that uses OpenSSL as MD5 backend. I do not see HMAC-MD5 being used. APOP is the only user of regular MD5 calculations, so it should be possible to replace the MD5 entirely with some other implementation, e.g. the Openwall one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
1 participant