From: ADVAX::"kannan@sejour.lkg.dec.com" " " 5-JUN-1991 15:57:53.96 To: arisia::everhart CC: kannan@sejour.lkg.dec.com Subj: new SPX kit ready Received: by ADVAX.DECnet (utk-mail11 v1.5) ; Wed, 5 Jun 91 15:55:07 EDT Received: from mcnc by ge-dab.GE.COM (5.61/GE-DAB 1.15) with UUCP id AA07132 for ; Wed, 5 Jun 91 14:30:45 -0400 From: kannan@sejour.lkg.dec.com Received: from uucp-gw-1.pa.dec.com by mcnc.mcnc.org (5.59/MCNC/3-21-91) id AA05837; Wed, 5 Jun 91 14:18:01 -0400 for arisia.dnet.ge.com!everhart Received: by uucp-gw-1.pa.dec.com; id AA00985; Wed, 5 Jun 91 08:26:59 -0700 Received: by sejour.lkg.dec.com (5.57/Ultrix4.0) id AA02565; Wed, 5 Jun 91 09:34:55 -0400 Message-Id: <9106051334.AA02565@sejour.lkg.dec.com> To: arisia::everhart Cc: kannan@sejour.lkg.dec.com Subject: new SPX kit ready Date: Wed, 05 Jun 91 09:34:54 EDT Glenn, Thank you for you patience! I enjoyed talking with you at DECUS. Since returning from DECUS, I've been updating the SPX distribution kit. A new SPX version v2.1 is publically available (in source code) on the Internet. SPX is distributed via anonymous FTP from crl.dec.com (address 192.58.206.2). The following files can be obtained in the /pub/DEC/SPX directory. SPX.v2.1-beta.tar.Z - SPX sources (without crypto algorithm sources) SPX.v2.1-doc.tar.Z - SPX documentation SPX-README - SPX README notes kit-verifier.tar.Z - sources for kit verifier program SPX-FORMS - forms to obtain crypto algorithms Since SPX contains the DES and RSA algorithm, the SPX source code is being distributed in two pieces. Anyone can get the public-domain kit without the crypto algorithm sources from crl.dec.com. Note that SPX is essentially useless with the crypto piece. I've attached the necessary form for you to fill in order to get the crypto software. SPX v2.1 is being distributed with the following major caveats: o This software is supplied "as is" with no warranty of any kind, expressed or implied, for any purpose, including any warranty of fitness or merchantibility. DIGITAL assumes no responsibility for the use or reliability of this software, nor promises to provide any form of support for it on any basis. o Distribution of this software is authorized only if no profit or remuneration of any kind is received in exchange for such distribution. o This software produces public key authentication certificates bearing an expiration date established by DIGITAL and RSA Data Security, Inc. It may cease to generate certificates after the expiration date. Any modification of this software that changes or defeats the expiration date or its effect is unauthorized. SPX has been ported to IBM RT/PC, Sun, Vax, and Mips platforms. We are in having SPX ported to other platforms and additional applications. The distribution kit contains the Berkeley r-tools, specifically rlogin and rcp, modified to use strong authentication. Also, Digital has been working with MIT/Project Athena to develop a Generic Security Services Application Program Interface (GSS API) so that applications can be written without being tied to a specific authentication mechanism. Once an application is written, it can be linked with a Kerberos or SPX library during compile-time. Recently, we complete discussions refining this interface with MIT. SPX v2.1 will be providing a subset of the GSSAPI and it provides the modified Berkeley r-tools as an example of how to write portable applications. If you have difficulty getting the SPX kit or documentation, please let me know. -kannan ==================== SPX-FORMS ================= +---------------------------+ TM | | | | | | | | | d | i | g | i | t | a | l | M E M O R A N D U M | | | | | | | | +---------------------------+ Date: 21 February 1991 To: Requester From: Bruce Chase Loc.M/S: LTN1-1/G08 Phone: (508) 486-6011 E-Mail: chase@ultra.enet.dec.com SUBJECT: Request for SPX crypto algorithm source code Please provide the following information in order to be granted SPX crypto algorithm source code: Your full name: ________________________________ Nationality: ________________________________ Affiliation: ________________________________ Department: ________________________________ Address: ________________________________ ________________________________ ________________________________ ________________________________ Phone number: _(_____)________________________ E-Mail address: ________________________________ Following information is desired regarding your computing environment to assist us in supporting SPX. Number of networked systems: ________ Hardware platforms: ________________________________ ________________________________ Operating Systems: ________________________________ ________________________________ Network protocols: ________________________________ ________________________________ What network authentication service is presently being used? ________________________________ Please reply to this request by inserting the appropriate information. You may fax a hardcopy (with original to follow later by mail) of this request to the following address: SPX Distribution, Attn. Bruce Chase Digital Equipment Corporation 295 Foster Street, LTN1-1/G08 Littleton, MA 01460 Fax: (508) 486-6014 A confirmation or rejection letter will be mailed back to you. If you have been confirmed, you will be mailed a shell archive file with the SPX crypto sources. The information in the SPX crypto algorithm source code is subject to U.S. export restrictions under the U.S. Department of State's International Traffic in Arms Regulations (22 CFR Subchapter M). Access to the SPX crypto algorithm source code will be granted to you under the condition that you agree not to disclose information found in the crypto sources to people who are not authorized access to the information. Also, SPX uses a patented RSA algorithm which is copyrighted in the source distribution. Access to SPX sources will be granted to you under the condition that you agree not to tamper with either the RSA algorithm or certification authority functions. By sending you the SPX crypto algorithm source code, Digital Equipment Corporation is not authorizing the Requestor to use the RSA algorithm in SPX beyond the indended use in the software. Print name: ________________________________ Signature: ________________________________ Date: ________________________________ +---------------------------+ TM | | | | | | | | | d | i | g | i | t | a | l | M E M O R A N D U M | | | | | | | | +---------------------------+ Date: 21 February 1991 To: Requester From: Bruce Chase Loc.M/S: LTN1-1/G08 Phone: (508) 486-6011 E-Mail: chase@ultra.enet.dec.com SUBJECT: Request for SPX crypto algorithm binary code Please provide the following information in order to be granted SPX crypto algorithm binary code: STATEMENT OF ASSURANCE "I hereby agree that I, ..............................., will not knowingly export, directly or indirectly, any U.S.-origin technical data acquired from Digital Equipment Corporation, or any direct product of such data, to any unauthorized destination [see note below], as defined under U.S. laws and regulations." Signature: .............................. Date: .............. Name in block capitals: ...................................... NOTE: If Digital knows or has reason to believe that the recipient of Digital restricted technical data plans to export or reexport the data or their direct product to South Africa, the following language should be included in the assurance: "or to or for use by the following entities in the Republic of South Africa: police or military entities, or entities enforcing apartheid." Following information is desired regarding your computing environment to assist us in supporting SPX. Number of networked systems: ________ Hardware platforms: ________________________________ ________________________________ Operating Systems: ________________________________ ________________________________ Network protocols: ________________________________ ________________________________ What network authentication service is presently being used? ________________________________ Please reply to this request by inserting the appropriate information. You may fax a hardcopy (with original to follow later by mail) of this request to the following address: SPX Distribution, Attn. Bruce Chase Digital Equipment Corporation 295 Foster Street, LTN1-1/G08 Littleton, MA 01460 Fax: (508) 486-6014