Severity: serious
Package: cyrus-sasl2-mit
Version: 2.1.19.dfsg1-1
User: debian-release@lists.debian.org
Usertags: nonfree-doc rfc

Hi!

Based on the package names, I suspect cyrus-sasl2-mit share the same
source package as the cyrus-sasl2 package, and that the problem below
might get fixed automatically when cyrus-sasl2-mit is updated to use
the latest cyrus-sasl2 sources (see #365183), but as far as I can
tell, it isn't guaranteed that this will happen automatically, hence
this report.

This source package contains the following files from the
IETF under non-free license terms:

cyrus-sasl-2.1.19.dfsg1/java/doc/draft-weltman-java-sasl-02.txt
cyrus-sasl-2.1.19.dfsg1/doc/draft-ietf-sasl-rfc2831bis-02.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc2195.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc3174.txt
cyrus-sasl-2.1.19.dfsg1/doc/draft-newman-sasl-c-api-01.txt
cyrus-sasl-2.1.19.dfsg1/doc/draft-ietf-sasl-saslprep-04.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc1939.txt
cyrus-sasl-2.1.19.dfsg1/doc/draft-ietf-sasl-rfc2222bis-03.txt
cyrus-sasl-2.1.19.dfsg1/doc/draft-ietf-sasl-crammd5-01.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc2243.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc2444.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc2831.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc2222.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc2289.txt
cyrus-sasl-2.1.19.dfsg1/doc/draft-ietf-sasl-plain-03.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc2595.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc2945.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc1321.txt
cyrus-sasl-2.1.19.dfsg1/doc/draft-ietf-sasl-anon-02.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc2104.txt
cyrus-sasl-2.1.19.dfsg1/doc/draft-burdis-cat-srp-sasl-08.txt
cyrus-sasl-2.1.19.dfsg1/doc/draft-ietf-sasl-gssapi-00.txt
cyrus-sasl-2.1.19.dfsg1/doc/draft-murchison-sasl-login-00.txt
cyrus-sasl-2.1.19.dfsg1/doc/rfc2245.txt

The license on RFC/I-Ds is not DFSG-free, see:
 * http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=199810
 * http://release.debian.org/removing-non-free-documentation
 * http://wiki.debian.org/NonFreeIETFDocuments

The etch release policy says binary and source packages must each be free:
 * http://release.debian.org/etch_rc_policy.txt

The severity is serious, because this violates the Debian policy:
 * http://www.debian.org/doc/debian-policy/ch-archive.html#s-dfsg

There are (at least) three ways to fix this problem.  In order of
preference:

1. Ask the author of the RFC to re-license the RFC under a free
   license.  A template for this e-mail request can be found at
   http://wiki.debian.org/NonFreeIETFDocuments

2. Remove the non-free material from the source, e.g., by re-packaging
   the upstream archive and adding a 'dfsg' version name to it.

3. Move the package to non-free.

General discussions are kindly requested to take place on debian-legal
or debian-devel in the thread with Subject: "Non-free IETF RFC/I-Ds in
source packages".

Thanks,
Simon


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to