It's most likely fine. Tor Project has to abide by DFARS (and I too when I was a Tor contractor) due to its DARPA funding and we all used Debian.
DFARS is literally 600+ pages of regulations, not really feasible for a small org to crawl over in detail. X Kunowski, Betty: > WARNING: This message is from an external source. Evaluate the message > carefully BEFORE clicking on links or opening attachments. > > Thank you I have already sent them a separate email asking this question and > am waiting for a response. > > Betty Kunowski > IT Asset Specialist - Software > ITS Planning & Operations > Ph. 858.525.6599 / Internal Ext. 802-6599 > ------------------------------------- > > "Together we will realize our Vision if we live our Mission and Values" > > GA's Software Policy: https://in.ga.com/PEC/policy/CP-1305.pdf > > Have you checked your Software Center lately?? Many applications are > available there for self-installation. > For faster response on IT issues, please contact the ITS Service Desk at Ext: > 4000 in GA or Ext: 3550 in ASI or email itshelpd...@ga.com > This message contains information that may be confidential and privileged. > Unless you are the addressee (or authorized to receive for the addressee), > you may not use, copy, print or disclose to anyone this message or any > information contained in this message. If you have received this e-mail in > error, please advise the sender by reply and delete the message. Thank you > > > -----Original Message----- > From: Moritz Muehlenhoff <j...@inutil.org> > Sent: Thursday, February 20, 2020 10:42 AM > To: Kunowski, Betty <betty.kunow...@ga.com> > Cc: secur...@debian.org > Subject: -EXT-Re: DFARS Compliance Question > > WARNING: This message is from an external source. Evaluate the message > carefully BEFORE clicking on links or opening attachments. > > On Thu, Feb 20, 2020 at 06:06:46PM +0000, Kunowski, Betty wrote: >> Hello. >> I have a group of users that have a need to put Debian Linux on some >> internal General Atomics computers for an apprenticeship program we are >> running with a local community college. >> I would like to know if it is DFARS compliant as we are a defense contractor >> and I could not find that answer within your FAQs. >> Please let me know. >> Thank you. > > I have no idea, but probably others know this better: Please send an email to > debian-project@lists.debian.org > > Cheers, > Moritz > -- GPG: ed25519/56034877E1F87C35 GPG: rsa4096/1318EFAC5FBBDBCE https://github.com/infinity0/pubkeys.git