{"id":25352,"date":"2024-08-14T23:46:16","date_gmt":"2024-08-14T21:46:16","guid":{"rendered":"https:\/\/daniel.haxx.se\/blog\/?p=25352"},"modified":"2024-10-19T23:59:44","modified_gmt":"2024-10-19T21:59:44","slug":"so-the-department-of-energy-emailed-me","status":"publish","type":"post","link":"https:\/\/daniel.haxx.se\/blog\/2024\/08\/14\/so-the-department-of-energy-emailed-me\/","title":{"rendered":"So the Department of Energy emailed me"},"content":{"rendered":"\n<p>I received an email today.  What follows is a slightly edited version (for brevity).<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">From: DOE Attestation &lt;doe.attestation@hq.doe.gov&gt;<br>Subject: [ACTION REQUIRED] U.S. Department of Energy Secure Software Development Attestation Submission Request<br><br>OMB Control No. 1670-0052<br>Expires: 03\/31\/2027<br><br>Hello Haxx<br><br>** The following communication contains important DOE Secure Software Development Attestation Submission instructions. Please read this communication in its entirety. **<br><br>The U.S. Department of Energy (DOE) has identified your company's software as affected by this request. The list of impacted software products and versions can be found below.<br><br>DOE Request:<br><br>In support of the Office of Management and Budget (OMB) requirement to collect attestations per M-22-18, please complete the U.S. Department of Energy Secure Software Development Attestation Form (DOE Common Form). If you are unable to attest to all secure software development framework (SSDF) practices, please be sure to attach your Plan of Action and Milestones (POA&amp;M). The software listed below has been identified as being associated with your company and requires DOE to collect an attestation for the software.<br><br>Product Name   Version Number<br><br>libcurl        8.3<br><br>The U.S. Department of Energy Secure Software Development Attestation Form (DOE Common Form) can be found at DOE F 205.2 Secure Software Development Attestation Form. The DOE Common Form identifies the minimum secure software development requirements a Software Producer must meet, and attest to meeting, before software subject to the requirements of M-22-18 as updated by M-23-16, may be used by Federal agencies. This form is used by Software Producers to attest that the software they produce is developed in conformity with specified secure software development practices and standards.<br><br>Regards,<br><br>DOE OCIO C-SCRM Team<\/pre>\n\n\n\n<p>Don&#8217;t you just love the personal touch in the signature in the end? <\/p>\n\n\n\n<p>I could add that I have never been in contact with them before. I did not know they use libcurl before this email. I do not know what they use it for.<\/p>\n\n\n\n<p>I find it amusing they insist this is &#8220;required&#8221; .<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">My response<\/h2>\n\n\n\n<p>I am not impossible and I will not deny them this information. So I pressed reply and immediately sent an answer back.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">Hello Department of Energy,<br><br>I cannot find that you are an existing customer of ours, so we cannot fulfill this request.<br><br>libcurl is a product we work on. It is open source and licensed under an MIT-like license in which the distribution and use conditions are clearly stated.<br><br>If you contact support@wolfssl.com we can remedy this oversight and can then arrange for all the paperwork and attestations you need.<br><br>Thanks,<br><br>\/ Daniel<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Related<\/h2>\n\n\n\n<p><a href=\"https:\/\/daniel.haxx.se\/email\/\">Other emails<\/a> I have received. <a href=\"https:\/\/daniel.haxx.se\/blog\/2020\/12\/17\/curl-supports-nasa\/\" data-type=\"post\" data-id=\"15315\">NASA emailed me<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Discussion<\/h2>\n\n\n\n<p>On <a href=\"https:\/\/news.ycombinator.com\/item?id=41252331\">hacker news<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I received an email today. What follows is a slightly edited version (for brevity). From: DOE Attestation &lt;doe.attestation@hq.doe.gov&gt;Subject: [ACTION REQUIRED] U.S. Department of Energy Secure Software Development Attestation Submission RequestOMB Control No. 1670-0052Expires: 03\/31\/2027Hello Haxx** The following communication contains important DOE Secure Software Development Attestation Submission instructions. Please read this communication in its entirety. **The &hellip; <a href=\"https:\/\/daniel.haxx.se\/blog\/2024\/08\/14\/so-the-department-of-energy-emailed-me\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">So the Department of Energy emailed me<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":5,"featured_media":12258,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[33,507],"class_list":["post-25352","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-curl","tag-curl-and-libcurl","tag-email"],"_links":{"self":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/25352","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/comments?post=25352"}],"version-history":[{"count":8,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/25352\/revisions"}],"predecessor-version":[{"id":25693,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/25352\/revisions\/25693"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/media\/12258"}],"wp:attachment":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/media?parent=25352"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/categories?post=25352"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/tags?post=25352"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}