Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [open-regulatory-compliance] More edge cases

(Warning: I've not yet read the latest version of the CRA from cover to cover, I may have missed some context or specific provision.)

Dirk-Willem van Gulik via open-regulatory-compliance kirjoitti 4.7.2024 klo 14.30:
7) If BigCo produces "BigCo Web Server for Java that is based on Apache
Tomcat" then clearly they will be subject to the CRA for that product.
Are all your questions assuming the customer is never on the hook? Is that because BigCo only sells their product to consumers for personal purposes or what? Say the customer is an ISP or domain hoster which sells web hosting on the side, aren't they supposed to be responsible for their webserver software? And if they ask BigCo to configure it for them, does it really matter whether BigCo delivers the binaries or just uses a public distribution?

At $dayjob-1 we had a vendor which sold us a giant monolith web service shipped for RHEL only, with tomcat and a bunch of dependencies vendored in. They required specific OS versions, configured all the dependencies, delivered everything in giant tarballs. Surely they're responsible for the tomcat upgrades as part of the overall product. I sure hope that doesn't change if they decide to stop vendoring the dependencies and, say, install a pinned version from the RHEL repos.

Best,
	Federico


Back to the top