Any US export restrictions on use of 256 bit AES SSL & TLS certificates?

Peter Tomlinson ukcrypto at chiark.greenend.org.uk
Wed, 25 Mar 2009 17:36:03 +0000


A client has asked for advice on the use of 256 bit AES SSL and TLS 
certificates. They want to know if the USA has placed any restrictions 
on using AES like this in export markets, or even if the US govt has to 
be notified when they are deployed.

The application is on a commercial web site operated by a UK company, 
and very probably hosted here as well. The company concerned hosts 
datasets for their clients, and the datasets contain basic personal data 
collected by those clients. They want to offer stronger security for 
on-line database access.

A web search turned up nothing definitive, but did turn up several 
organisations offering these certificates, including at least one 
domiciled in the UK.

Peter