Bug#423379: OpenSSL license violation

classic Classic list List threaded Threaded
3 messages Options
Reply | Threaded
Open this post in threaded view
|

Bug#423379: OpenSSL license violation

Hendrik Weimer
Package: kmymoney2
Version: 0.8.6-1
Severity: serious

According to the copyright file kmymoney2 is being distributed under
GPLv2. However, it depends on libgwenhywfar, which in turns is linked
against OpenSSL. While libgwenhywfar contains an OpenSSL exception,
kmymoney2 does not.

So, please obtain an OpenSSL exception from upstream, fix bug #340573,
or upload a version not linking against libgwenhywfar.

Hendrik


--
To UNSUBSCRIBE, email to [hidden email]
with a subject of "unsubscribe". Trouble? Contact [hidden email]

Reply | Threaded
Open this post in threaded view
|

Bug#423379: marked as forwarded (OpenSSL license violation)

Debian Bug Tracking System
Your message dated Mon, 21 May 2007 19:11:57 +0100
with message-id <[hidden email]>
has caused the Debian Bug report #423379,
regarding OpenSSL license violation
to be marked as having been forwarded to the upstream software
author(s) [hidden email].

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)


kmymoney2-developer,

In the Debian/GNU Linux binary package of kmymoney we are currently linking
to OpenSSL (via libgwenhywfar) which isn't actually allowed under the GPL
unless the kmymoney team provide an exemption.

http://www.openssl.org/support/faq.html#LEGAL2

e.g. "This program is released under the GPL with the additional exemption that
compiling, linking, and/or using OpenSSL is allowed."

If the kmymoney team are unable/ unwilling to provide an exception we will stop
distributing kmymoney linked to openssl, by building kmymoney without
libgwenhywfar support whilst libgwenhywfar links against openssl.

http://bugs.debian.org/423379
http://bugs.debian.org/340573

Could I ask you to maintain the Cc: on any response so they are
filed into the Debian bug tracking system.

Thanks,
Mark


----------  Forwarded Message  ----------

Subject: [Pkg-kde-extras] Bug#423379: OpenSSL license violation
Date: Fri, 11 May 2007
From: Hendrik Weimer <[hidden email]>
To: [hidden email]

Package: kmymoney2
Version: 0.8.6-1
Severity: serious

According to the copyright file kmymoney2 is being distributed under
GPLv2. However, it depends on libgwenhywfar, which in turns is linked
against OpenSSL. While libgwenhywfar contains an OpenSSL exception,
kmymoney2 does not.

So, please obtain an OpenSSL exception from upstream, fix bug #340573,
or upload a version not linking against libgwenhywfar.

Hendrik


_______________________________________________
pkg-kde-extras mailing list
[hidden email]
http://lists.alioth.debian.org/mailman/listinfo/pkg-kde-extras

-------------------------------------------------------

attachment0 (196 bytes) Download Attachment
Reply | Threaded
Open this post in threaded view
|

Bug#423379: marked as done (OpenSSL license violation)

Debian Bug Tracking System
In reply to this post by Hendrik Weimer
Your message dated Mon, 23 Jul 2007 06:17:03 +0000
with message-id <[hidden email]>
and subject line Bug#423379: fixed in kmymoney2 0.8.7-1
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)


Package: kmymoney2
Version: 0.8.6-1
Severity: serious

According to the copyright file kmymoney2 is being distributed under
GPLv2. However, it depends on libgwenhywfar, which in turns is linked
against OpenSSL. While libgwenhywfar contains an OpenSSL exception,
kmymoney2 does not.

So, please obtain an OpenSSL exception from upstream, fix bug #340573,
or upload a version not linking against libgwenhywfar.

Hendrik


Source: kmymoney2
Source-Version: 0.8.7-1

We believe that the bug you reported is fixed in the latest version of
kmymoney2, which is due to be installed in the Debian FTP archive:

kmymoney2_0.8.7-1.diff.gz
  to pool/main/k/kmymoney2/kmymoney2_0.8.7-1.diff.gz
kmymoney2_0.8.7-1.dsc
  to pool/main/k/kmymoney2/kmymoney2_0.8.7-1.dsc
kmymoney2_0.8.7-1_i386.deb
  to pool/main/k/kmymoney2/kmymoney2_0.8.7-1_i386.deb
kmymoney2_0.8.7.orig.tar.gz
  to pool/main/k/kmymoney2/kmymoney2_0.8.7.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [hidden email],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Mark Purcell <[hidden email]> (supplier of updated kmymoney2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [hidden email])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sun, 22 Jul 2007 22:27:48 +0100
Source: kmymoney2
Binary: kmymoney2
Architecture: source i386
Version: 0.8.7-1
Distribution: unstable
Urgency: low
Maintainer: Debian KDE Extras Team <[hidden email]>
Changed-By: Mark Purcell <[hidden email]>
Description:
 kmymoney2  - personal finance manager for KDE
Closes: 403939 423379 427122
Changes:
 kmymoney2 (0.8.7-1) unstable; urgency=low
 .
   * New upstream release
     - Upstream changlog: Fixed #1723325 (Cannot quit the program)
       - Cannot exit KMyMoney2 (Closes: #403939)
     - Upstream changlog: Use dash as standard separator if no short date
       - Date field separator displayed as letter a (Closes: #427122)
   * Remove Build-Depends: libaqbanking16-dev, refer to NEWS.debian
     - OpenSSL license violation (Closes: #423379)
   * Document lack of online banking in NEWS.Debian
Files:
 20144b6649c6822ab255b6b905555f74 734 kde optional kmymoney2_0.8.7-1.dsc
 bf9957833242659c58f95bbfcd182681 8172461 kde optional kmymoney2_0.8.7.orig.tar.gz
 85d5a2d8fdfa34f47ab3dd4939827466 6065 kde optional kmymoney2_0.8.7-1.diff.gz
 5887e4f4806ae73c6dd683d001ad9573 7270708 kde optional kmymoney2_0.8.7-1_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGpEQmoCzanz0IthIRAmg6AJ9941dSazXiC864G3peaShVuhRbhgCgnIDD
JWLz5tLjCb3+YY7hbAxWJas=
=RKVr
-----END PGP SIGNATURE-----