Commit 0f2d41

2025-02-12 13:37:02 Samuli Seppänen: Switch Downloads to a non-AI version
Downloads.md ..
@@ 1,741 1,846 @@
- # Downloads
-
- ## OpenVPN 2.6.13 -- Released 15 January 2025
+ ## OpenVPN 2.6.13 -- Released 15 January 2025
The OpenVPN community project team is proud to release OpenVPN 2.6.13. This is a bugfix release.
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.13/Changes.rst)
- ### Feature changes:
-
- - On non-windows clients (MacOS, Linux, Unix) send "release" string from `uname()` call as `IV_PLAT_VER` to server - while highly OS specific, this is still helpful to keep track of OS versions used on the client side ([#637](https://github.com/OpenVPN/openvpn/issues/637))
- - Windows: protect cached username, password, and token in client memory using the `CryptProtectMemory()` Windows API.
- - Windows: use new API to get dco-win driver version from driver (newly introduced non-exclusive control device) ([ovpn-dco-win#76](https://github.com/OpenVPN/ovpn-dco-win/issues/76))
- - Linux: pass `--timeout=0` argument to `systemd-ask-password`, to avoid default timeout of 90 seconds ("console prompting also has no timeout") ([#649](https://github.com/OpenVPN/openvpn/issues/649))
-
- ### Security fixes:
-
- - Improve server-side handling of clients sending usernames or passwords longer than `USER_PASS_LEN` - this would not result in a crash, buffer overflow, or other security issues, but the server would then misparse incoming IV variables and produce misleading error messages.
+ Feature changes:
+
+ * on non-windows clients (MacOS, Linux, Unix) send "release" string from
+ `uname()` call as `IV_PLAT_VER` to server - while highly OS specific this
+ is still helpful to keep track of OS versions used on the client side
+ (github [#637](https://github.com/OpenVPN/openvpn/issues/637))
+ * Windows: protect cached username, password and token in client memory
+ (using the `CryptProtectMemory()` windows API)
+ * Windows: use new API to get dco-win driver version from driver
+ (newly introduced non-exclusive control device) (github [ovpn-dco-win#76](https://github.com/OpenVPN/ovpn-dco-win/issues/76))
+ * Linux: pass `--timeout=0 argument` to `systemd-ask-password`, to avoid
+ default timeout of 90 seconds ("console prompting also has no timeout")
+ (github [#649](https://github.com/OpenVPN/openvpn/issues/649))
+
+ Security fixes:
+
+ * improve server-side handling of clients sending usernames or passwords
+ longer than `USER_PASS_LEN` - this would not result in a crash, buffer
+ overflow or other security issues, but the server would then misparse
+ incoming IV variables and produce misleading error messages.
+
+ Notable bug fixes:
+
+ * FreeBSD DCO: fix memory leaks in nvlist handling (github [#636](https://github.com/OpenVPN/openvpn/issues/636))
+ * purge proxy authentication credentials from memory after use
+ (if `--auth-nocache` is in use)
+
+ Windows MSI changes since 2.6.12:
+ * Built against OpenSSL 3.4.0
+ * Included openvpn-gui updated to 11.51.0.0
+ * Higher resolution eye icons (github [openvpn-gui#697](https://github.com/OpenVPN/openvpn-gui/issues/697))
+ * Support for concatenating OTP with password
+ * Optionally always prompt for OTP
+ * Fix tooltip positioning when the taskbar is at top (github [openvpn-gui#710](https://github.com/OpenVPN/openvpn-gui/issues/710))
- ### Notable bug fixes:
-
- - FreeBSD DCO: fix memory leaks in nvlist handling ([#636](https://github.com/OpenVPN/openvpn/issues/636))
- - Purge proxy authentication credentials from memory after use (if `--auth-nocache` is in use)
-
- ### Windows MSI changes since 2.6.12:
- - Built against OpenSSL 3.4.0
- - Included openvpn-gui updated to 11.51.0.0
- - Higher resolution eye icons ([openvpn-gui#697](https://github.com/OpenVPN/openvpn-gui/issues/697))
- - Support for concatenating OTP with password
- - Optionally always prompt for OTP
- - Fix tooltip positioning when the taskbar is at the top ([openvpn-gui#710](https://github.com/OpenVPN/openvpn-gui/issues/710))
-
- ### Debian/Ubuntu packages
Debian/Ubuntu packages in OpenvpnSoftwareRepos are now available for Ubuntu 24.10 (oracular).
- ### Downloads
- - **Windows 64-bit MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-amd64.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-amd64.msi)
- - **Windows ARM64 MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-arm64.msi)
- - **Windows 32-bit MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-x86.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-x86.msi)
- - **Source archive file:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.13.tar.gz.asc), [Download](https://swupdate.openvpn.org/community/releases/openvpn-2.6.13.tar.gz)
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-amd64.msi.asc)|[OpenVPN-2.6.13-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi.asc)|[OpenVPN-2.6.13-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-x86.msi.asc)|[OpenVPN-2.6.13-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.13.tar.gz.asc)|[openvpn-2.6.13.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.13.tar.gz)|
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
- ## OpenVPN 2.5.11 -- Released 18 July 2024The OpenVPN community project team is proud to release OpenVPN 2.5.11. This is a security fix release.
+ ## OpenVPN 2.5.11 -- Released 18 July 2024
+ The OpenVPN community project team is proud to release OpenVPN 2.5.11. This is a security fix release.
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.5.11/Changes.rst).
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.5.11/Changes.rst)
- **Security fixes:**
- - [CVE-2024-5594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5594): control channel: refuse control channel messages with nonprintable characters in them. Security scope: a malicious openvpn peer can send garbage to openvpn log, or cause high CPU load. (Reynir Björnsson)
- - (Backport of the security fix in 2.6.11 and the fix for the bugfix in 2.6.12)
+ Security fixes:
- In accordance with our [support policy](SupportedVersions), packages and installers are not provided for 2.5 anymore.
+ - [CVE-2024-5594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5594): control channel: refuse control channel messages with
+ nonprintable characters in them. Security scope: a malicious openvpn peer can send garbage to openvpn log, or cause high CPU load.
+ (Reynir Björnsson)
- **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.11.tar.gz.asc)
- - [openvpn-2.5.11.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.5.11.tar.gz)
+ (Backport of the security fix in 2.6.11 and the fix for the bugfix
+ in 2.6.12)
- ## OpenVPN 2.6.12 -- Released 18 July 2024
- The OpenVPN community project team is proud to release OpenVPN 2.6.12. This is a bugfix release.
+ In accordance with our [support policy](/SupportedVersions) packages and installers are not provided for 2.5 anymore.
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.12/Changes.rst).
+ | | | |
+ |-|-|-|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.11.tar.gz.asc)|[openvpn-2.5.11.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.5.11.tar.gz)|
- **Bug fixes:**
- - the fix for CVE-2024-5594 (refuse control channel messages with nonprintable characters) was too strict, breaking user configurations with AUTH_FAIL messages having trailing CR/NL characters. This often happens if the AUTH_FAIL reason is set by a script. Strip those before testing the command buffer ([#568](https://github.com/OpenVPN/openvpn/issues/568)). Also, add unit test.
- - Http-proxy: fix bug preventing proxy credentials caching (trac #1187)
- **Windows MSI changes since 2.6.11:**
- - Built against OpenSSL 3.3.1
- - Included openvpn-gui updated to 11.50.0.0
- - Update Italian language ([#696](https://github.com/OpenVPN/openvpn-gui/pull/696))
+ ## OpenVPN 2.6.12 -- Released 18 July 2024
+ The OpenVPN community project team is proud to release OpenVPN 2.6.12. This is a bugfix release.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.12/Changes.rst)
- **Windows 64-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-amd64.msi.asc)
- - [OpenVPN-2.6.12-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-amd64.msi)
+ Bug fixes:
- **Windows ARM64 MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi.asc)
- - [OpenVPN-2.6.12-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi)
+ * the fix for CVE-2024-5594 (refuse control channel messages with
+ nonprintable characters) was too strict, breaking user configurations
+ with AUTH_FAIL messages having trailing CR/NL characters. This often
+ happens if the AUTH_FAIL reason is set by a script. Strip those before
+ testing the command buffer (github [#568](https://github.com/OpenVPN/openvpn/issues/568)). Also, add unit test.
+ * Http-proxy: fix bug preventing proxy credentials caching (trac #1187)
- **Windows 32-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-x86.msi.asc)
- - [OpenVPN-2.6.12-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-x86.msi)
+ Windows MSI changes since 2.6.11:
+ * Built against OpenSSL 3.3.1
+ * Included openvpn-gui updated to 11.50.0.0
+ * Update Italian language (github [#696](https://github.com/OpenVPN/openvpn-gui/pull/696))
- **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.12.tar.gz.asc)
- - [openvpn-2.6.12.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.12.tar.gz)
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-amd64.msi.asc)|[OpenVPN-2.6.12-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi.asc)|[OpenVPN-2.6.12-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-x86.msi.asc)|[OpenVPN-2.6.12-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.12.tar.gz.asc)|[openvpn-2.6.12.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.12.tar.gz)|
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
- ## OpenVPN 2.6.11 -- Released 20 June 2024
+ ## OpenVPN 2.6.11 -- Released 20 June 2024
The OpenVPN community project team is proud to release OpenVPN 2.6.11. This is a bugfix release containing several security fixes.
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.11/Changes.rst).
-
- **Security fixes:**- [CVE-2024-4877](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4877): Windows: harden interactive service pipe.
- Security scope: a malicious process with "some" elevated privileges (!SeImpersonatePrivilege) could open the pipe a second time, tricking openvpn GUI into providing user credentials (tokens), getting full access to the account openvpn-gui.exe runs as.
- (Zeze with TeamT5)
- - [CVE-2024-5594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5594): control channel: refuse control channel messages with nonprintable characters in them. Security scope: a malicious openvpn peer can send garbage to openvpn log, or cause high CPU load. (Reynir Björnsson)
- - [CVE-2024-28882](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28882): only call schedule_exit() once (on a given peer). Security scope: an authenticated client can make the server "keep the session" even when the server has been told to disconnect this client (Reynir Björnsson)
-
- ### New features:
-
- - Windows Crypto-API: Implement Windows CA template match for searching certificates in windows crypto store.
- - Support pre-created DCO interface on FreeBSD (OpenVPN would fail to set ifmode p2p/subnet otherwise)
-
- ### Bug fixes:
-
- - Fix connect timeout when using SOCKS proxies (trac #328, github [#267](https://github.com/OpenVPN/openvpn/issues/267))
- - Work around LibreSSL crashing on OpenBSD 7.5 when enumerating ciphers (LibreSSL bug, already fixed upstream, but not backported to OpenBSD 7.5, see also [LibreSSL/OpenBSD#150](https://github.com/libressl/openbsd/issues/150))
- - Add bracket in fingerprint message and do not warn about missing verification (github [#516](https://github.com/OpenVPN/openvpn/issues/516))
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.11/Changes.rst)
+
+ Security fixes:
+
+ * [CVE-2024-4877](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4877): Windows: harden interactive service pipe.
+ Security scope: a malicious process with "some" elevated privileges
+ (!SeImpersonatePrivilege) could open the pipe a second time, tricking
+ openvn GUI into providing user credentials (tokens), getting full
+ access to the account openvpn-gui.exe runs as.
+ (Zeze with TeamT5)
+ * [CVE-2024-5594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5594): control channel: refuse control channel messages with
+ nonprintable characters in them. Security scope: a malicious openvpn
+ peer can send garbage to openvpn log, or cause high CPU load.
+ (Reynir Björnsson)
+ * [CVE-2024-28882](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28882): only call schedule_exit() once (on a given peer).
+ Security scope: an authenticated client can make the server "keep the
+ session" even when the server has been told to disconnect this client
+ (Reynir Björnsson)
+
+
+ New features:
+
+ * Windows Crypto-API: Implement Windows CA template match for searching
+ certificates in windows crypto store.
+ * Support pre-created DCO interface on FreeBSD (OpenVPN would fail to
+ set ifmode p2p/subnet otherwise)
+
+ Bug fixes:
+
+ * Fix connect timeout when using SOCKS proxies (trac #328, github [#267](https://github.com/OpenVPN/openvpn/issues/267))
+ * Work around LibreSSL crashing on OpenBSD 7.5 when enumerating ciphers
+ (LibreSSL bug, already fixed upstream, but not backported to OpenBSD 7.5,
+ see also [LibreSSL/OpenBSD#150](https://github.com/libressl/openbsd/issues/150))
+ * Add bracket in fingerprint message and do not warn about missing
+ verification (github [#516](https://github.com/OpenVPN/openvpn/issues/516))
+
+ Documentation:
+
+ * Remove "experimental" denotation for --fast-io
+ * Correctly document ifconfig_* variables passed to scripts
+ * Documentation: make section levels consistent
+ * Samples: Update sample configurations (remove compression & old cipher settings, add more informative comments)
+
+ Windows MSI changes since 2.6.10:
+ * For the Windows-specific security fixes see above
+ * Built against OpenSSL 3.3.1
+ * Included openvpn-gui updated to 11.49.0.0
+ * Contains part of the fix for [CVE-2024-4877](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4877)
+
+ Note: Windows MSI was updated to I002 on June 26th. Changes in I002:
+ * Group names are localized in some localizations, so we have to use SIDs. (Github: [#671](https://github.com/OpenVPN/openvpn-build/issues/671))
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-amd64.msi.asc)|[OpenVPN-2.6.11-I002-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-arm64.msi.asc)|[OpenVPN-2.6.11-I002-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-x86.msi.asc)|[OpenVPN-2.6.11-I002-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.11.tar.gz.asc)|[openvpn-2.6.11.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.11.tar.gz)|
- ### Documentation:
-
- - Remove "experimental" denotation for --fast-io
- - Correctly document ifconfig_* variables passed to scripts
- - Documentation: make section levels consistent
- - Samples: Update sample configurations (remove compression & old cipher settings, add more informative comments)
-
- ### Windows MSI changes since 2.6.10:
- - For the Windows-specific security fixes see above
- - Built against OpenSSL 3.3.1
- - Included openvpn-gui updated to 11.49.0.0
- - Contains part of the fix for [CVE-2024-4877](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4877)
-
- **Note:** Windows MSI was updated to I002 on June 26th. Changes in I002:
- - Group names are localized in some localizations, so we have to use SIDs. (Github: [#671](https://github.com/OpenVPN/openvpn-build/issues/671))
-
- **Windows 64-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-amd64.msi.asc)
- - [OpenVPN-2.6.11-I002-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-amd64.msi)## OpenVPN Releases and Downloads
-
- ### Windows MSI Installers
- - **Windows ARM64 MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-arm64.msi.asc)
- - [Download OpenVPN-2.6.11-I002-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-arm64.msi)
- - **Windows 32-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-x86.msi.asc)
- - [Download OpenVPN-2.6.11-I002-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-x86.msi)
- - **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.11.tar.gz.asc)
- - [Download openvpn-2.6.11.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.11.tar.gz)
-
- For Community-maintained packages for Linux distributions, see OpenvpnSoftwareRepos.
+ For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
- ### OpenVPN 2.5.10 -- Released 21 March 2024
+ ## OpenVPN 2.5.10 -- Released 21 March 2024
The OpenVPN community project team is proud to release OpenVPN 2.5.10. This is a bugfix release containing several security fixes specific to the Windows platform.
- For details, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.5.10/Changes.rst).
-
- **Security fixes:**
- - [CVE-2024-27459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27459): Windows: fix a possible stack overflow in the interactive service component.
- - [CVE-2024-24974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24974): Windows: disallow access to the interactive service pipe from remote computers.
- - [CVE-2024-27903](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27903): Windows: disallow loading of plugins from untrusted installation paths.
- - [CVE-2024-1305](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow.
-
- **Windows MSI Installers:**
- - **Windows 64-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-amd64.msi.asc)
- - [Download OpenVPN-2.5.10-I601-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-amd64.msi)
- - **Windows ARM64 MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-arm64.msi.asc)
- - [Download OpenVPN-2.5.10-I601-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-arm64.msi)
- - **Windows 32-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-x86.msi.asc)
- - [Download OpenVPN-2.5.10-I601-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-x86.msi)
- - **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.10.tar.gz.asc)
- - [Download openvpn-2.5.10.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.5.10.tar.gz)
-
- ### OpenVPN 2.6.10 -- Released 20 March 2024
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.5.10/Changes.rst)
+
+ Note that OpenVPN 2.5.x is in "Old Stable Support" status (see SupportedVersions). This usually means that we do not provide updated Windows Installers anymore, even for security fixes. Since this release fixes several issues specific to the Windows platform we decided to provide installers anyway. This does not change the support status of 2.5.x branch. We might not provide security updates for issues found in the future. We recommend that everyone switch to the 2.6.x versions of installers as soon as possible.
+
+ Security fixes:
+
+ * [CVE-2024-27459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27459): Windows: fix a possible stack overflow in the
+ interactive service component which might lead to a local privilege
+ escalation.
+ Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
+ * [CVE-2024-24974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24974): Windows: disallow access to the interactive service
+ pipe from remote computers.
+ Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
+ * [CVE-2024-27903](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27903): Windows: disallow loading of plugins from untrusted
+ installation paths, which could be used to attack `openvpn.exe` via
+ a malicious plugin. Plugins can now only be loaded from the OpenVPN
+ install directory, the Windows system directory, and possibly from
+ a directory specified by `HKLM\SOFTWARE\OpenVPN\plugin_dir`.
+ Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
+ * [CVE-2024-1305](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket.
+ Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
+
+ Windows MSI changes since 2.5.10:
+ * For the Windows-specific security fixes see above
+ * Built against OpenSSL 1.1.1w
+ * Note that OpenSSL 1.1.1 is not supported anymore, so this might not address all known issues in OpenSSL 1.1.1. If that concerns you, please switch to OpenVPN 2.6.x
+ * Included tap6-windows driver updated to 9.27.0
+ * Security fix, see above
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-amd64.msi.asc)|[OpenVPN-2.5.10-I601-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-arm64.msi.asc)|[OpenVPN-2.5.10-I601-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-x86.msi.asc)|[OpenVPN-2.5.10-I601-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.10.tar.gz.asc)|[openvpn-2.5.10.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.5.10.tar.gz)|
+
+ ## OpenVPN 2.6.10 -- Released 20 March 2024
The OpenVPN community project team is proud to release OpenVPN 2.6.10. This is a bugfix release containing several security fixes specific to the Windows platform.
- For details, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.10/Changes.rst).- [CVE-2024-27459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27459): Windows: fix a possible stack overflow in the interactive service component which might lead to a local privilege escalation.
- Reported by: Vladimir Tokarev <vtokarev@microsoft.com>
- - [CVE-2024-24974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24974): Windows: disallow access to the interactive service pipe from remote computers.
- Reported by: Vladimir Tokarev <vtokarev@microsoft.com>
- - [CVE-2024-27903](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27903): Windows: disallow loading of plugins from untrusted installation paths, which could be used to attack `openvpn.exe` via a malicious plugin. Plugins can now only be loaded from the OpenVPN install directory, the Windows system directory, and possibly from a directory specified by `HKLM\SOFTWARE\OpenVPN\plugin_dir`.
- Reported by: Vladimir Tokarev <vtokarev@microsoft.com>
- - [CVE-2024-1305](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket.
- Reported by: Vladimir Tokarev <vtokarev@microsoft.com>
-
- **New features:**
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.10/Changes.rst)
- - `t_client.sh` can now run pre-tests and skip a test block if needed (e.g. skip NTLM proxy tests if SSL library does not support MD4)
+ Security fixes:
- **User visible changes:**
+ * [CVE-2024-27459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27459): Windows: fix a possible stack overflow in the
+ interactive service component which might lead to a local privilege
+ escalation.
+ Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
+ * [CVE-2024-24974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24974): Windows: disallow access to the interactive service
+ pipe from remote computers.
+ Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
+ * [CVE-2024-27903](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27903): Windows: disallow loading of plugins from untrusted
+ installation paths, which could be used to attack `openvpn.exe` via
+ a malicious plugin. Plugins can now only be loaded from the OpenVPN
+ install directory, the Windows system directory, and possibly from
+ a directory specified by `HKLM\SOFTWARE\OpenVPN\plugin_dir`.
+ Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
+ * [CVE-2024-1305](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket.
+ Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
- - Update copyright notices to 2024
+ New features:
- **Bug fixes:**
+ * `t_client.sh` can now run pre-tests and skip a test block if needed
+ (e.g. skip NTLM proxy tests if SSL library does not support MD4)
- - Windows: if the win-dco driver is used (default) and the GUI requests use of a proxy server, the connection would fail. Disable DCO in this case. ([#522](https://github.com/OpenVPN/openvpn/issues/522))
- - Compression: minor bugfix in checking option consistency vs. compiled-in algorithm support
- - systemd unit files: remove obsolete syslog.target
+ User visible changes:
- **Documentation:**
+ * Update copyright notices to 2024
- - Remove license warnings about mbedTLS linking (README.mbedtls)
- - Update documentation references in systemd unit files
- - Sample config files: remove obsolete tls-*.conf files
- - Document that auth-user-pass may be inlined
+ Bug fixes:
- **Windows MSI changes since 2.6.9:**
- - For the Windows-specific security fixes see above
- - Built against OpenSSL 3.2.1
- - Included tap6-windows driver updated to 9.27.0
- - Security fix, see above
- - Included ovpn-dco-win driver updated to 1.0.1
- - Ensure we don't pass too large key size to CryptoNG. We do not consider this a security issue since the CryptoNG API handles this gracefully either way.
- - Included openvpn-gui updated to 11.48.0.0
- - Position tray tooltip above the taskbar### Tray Icon Tips
- - Combine the title and message in the tray icon tooltip text.
- - Use a custom tooltip window for the tray icon.
+ * Windows: if the win-dco driver is used (default) and the GUI requests
+ use of a proxy server, the connection would fail. Disable DCO in
+ this case. (Github: [#522](https://github.com/OpenVPN/openvpn/issues/522))
+ * Compression: minor bugfix in checking option consistency vs. compiled-in
+ algorithm support
+ * systemd unit files: remove obsolete syslog.target
- ### Windows MSI Updates
- #### Update I002 (April 15th)
- - **Updated**: ovpn-dco-win to v1.1.1
- - Improves reconnect behavior after hibernate/standby. ([Issue #64](https://github.com/OpenVPN/ovpn-dco-win/issues/64))
+ Documentation:
- #### Update I003 (May 23rd)
- - **Updated**: ovpn-dco-win to v1.2.1
- - Fix bug check in timer management routines. ([Issue #70](https://github.com/OpenVPN/ovpn-dco-win/issues/70))
+ * remove license warnings about mbedTLS linking (README.mbedtls)
+ * update documentation references in systemd unit files
+ * sample config files: remove obsolete tls-*.conf files
+ * document that auth-user-pass may be inlined
- ### MSI Installers
- - **Windows 64-bit**: [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-amd64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-amd64.msi.asc)
- - **Windows ARM64**: [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-arm64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-arm64.msi.asc)
- - **Windows 32-bit**: [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-x86.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-x86.msi.asc)
- - **Source Archive**: [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6.10.tar.gz) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.10.tar.gz.asc)
+ Windows MSI changes since 2.6.9:
+ * For the Windows-specific security fixes see above
+ * Built against OpenSSL 3.2.1
+ * Included tap6-windows driver updated to 9.27.0
+ * Security fix, see above
+ * Included ovpn-dco-win driver updated to 1.0.1
+ * Ensure we don't pass too large key size to CryptoNG. We do not consider this a security issue since the CryptoNG API handles this gracefully either way.
+ * Included openvpn-gui updated to 11.48.0.0
+ * Position tray tooltip above the taskbar
+ * Combine title and message in tray icon tip text
+ * Use a custom tooltip window for the tray icon
- ### Community-maintained Linux Packages
- For details on Linux distribution packages, see OpenvpnSoftwareRepos.
+ Note: Windows MSI was updated to I002 on April 15th. Changes in I002:
- ### OpenVPN 2.6.9 Release (12 February 2024)
- The OpenVPN community project team is pleased to announce the release of OpenVPN 2.6.9, a bugfix release that includes a crucial security fix for the Windows installer.
+ * Update include ovpn-dco-win to v1.1.1
+ * Improves reconnect behavior after hibernate/standby. (Github: [#64](https://github.com/OpenVPN/ovpn-dco-win/issues/64))
- **Security Fixes:**
- - **Windows Installer**: Fixed a vulnerability ([CVE-2023-7235](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7235)) where installing to a non-default directory could lead to local privilege escalation.
+ Note: Windows MSI was updated to I003 on May 23rd. Changes in I003:
- **New Features:**
- - Support for building with mbedTLS 3.x.x.
- - New `--force-tls-key-material-export` option.
- - Windows: Updated pkcs11-helper to 1.30.
- - Improved logging for SSL alerts.
+ * Update include ovpn-dco-win to v1.2.1
+ * Fix bug check in timer management routines. (Github: [#70](https://github.com/OpenVPN/ovpn-dco-win/issues/70))
- **User Visible Changes:**
- - License change completed; all code now under a new license (GPLv2 with a linking exception for Apache2 licensed code). See [COPYING](https://github.com/OpenVPN/openvpn/blob/release/2.6/COPYING) for details.
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-amd64.msi.asc)|[OpenVPN-2.6.10-I003-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-arm64.msi.asc)|[OpenVPN-2.6.10-I003-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-x86.msi.asc)|[OpenVPN-2.6.10-I003-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.10.tar.gz.asc)|[openvpn-2.6.10.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.10.tar.gz)|
- For more details on this release, see the [Change Log](https://github.com/OpenVPN/openvpn/blob/v2.6.9/Changes.rst).Original code has been assessed for feature compatibility by various developers through a review of both the old and new code alongside documentation. There *should* not be any user-visible changes.
-
- - IPv6 route addition and deletion are now logged at the same level (3) as IPv4. Previously, IPv6 was always logged at `--verb 1`.
- - Enhanced handling of TLS 1.0 PRF failures in the underlying SSL library, such as on some FIPS builds. These issues are now reported at startup, and clients prior to version 2.6.0 that cannot use TLS EKM to generate key material are rejected by the server. Additionally, error messages have been improved to clarify the specific failure.
-
- ### Notable Bug Fixes:
-
- - **FreeBSD:** For servers handling multiple clients, reporting of peer traffic statistics would fail due to insufficient buffer space. ([#487](https://github.com/OpenVPN/openvpn/issues/487))
-
- ### Windows MSI Changes Since 2.6.8:
- - Security fix (detailed above).
- - Built against OpenSSL 3.2.0.
- - Included openvpn-gui updated to version 11.47.0.0:
- - **Windows GUI:** The tray icon is always updated on state changes. ([#669](https://github.com/OpenVPN/openvpn-gui/issues/669)) This is particularly important for persistent connection profiles where the "connecting" state might not display.
-
- **Download Links:**
- - **Windows 64-bit MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-amd64.msi.asc) | [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-amd64.msi)
- - **Windows ARM64 MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-arm64.msi.asc) | [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-arm64.msi)
- - **Windows 32-bit MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-x86.msi.asc) | [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-x86.msi)
- - **Source archive file:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.9.tar.gz.asc) | [Download](https://swupdate.openvpn.org/community/releases/openvpn-2.6.9.tar.gz)
-
- For Community-maintained packages for Linux distributions, see OpenvpnSoftwareRepos.
+ For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
- ## OpenVPN 2.6.8 -- Released 17 November 2023
- The OpenVPN community project team proudly announces the release of OpenVPN 2.6.8. This update focuses on fixing a few regressions found in the 2.6.7 release.
+ ## OpenVPN 2.6.9 -- Released 12 February 2024
+ The OpenVPN community project team is proud to release OpenVPN 2.6.9. This is a bugfix release containing one security fix for the Windows installer.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.9/Changes.rst)
+
+ Security fixes:
+
+ * Windows Installer: fix [CVE-2023-7235](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7235) where installing to a non-default
+ directory could lead to a local privilege escalation. Reported by Will Dormann.
+
+ New features:
+
+ * Add support for building with mbedTLS 3.x.x
+ * New option `--force-tls-key-material-export` to only accept clients
+ that can do TLS keying material export to generate session keys
+ (mostly an internal option to better deal with TLS 1.0 PRF failures).
+ * Windows: bump vcpkg-ports/pkcs11-helper to 1.30
+ * Log incoming SSL alerts in easier to understand form and move logging
+ from `--verb 8` to `--verb 3`.
+ * protocol_dump(): add support for printing `--tls-crypt` packets
+
+ User visible changes:
+
+ * License change is now complete, and all code has been re-licensed
+ under the new license (still GPLv2, but with new linking exception
+ for Apache2 licensed code). See [COPYING](https://github.com/OpenVPN/openvpn/blob/release/2.6/COPYING) for details.
+
+ Code that could not be re-licensed has been removed or rewritten.
+ * The original code for the `--tls-export-cert` feature has been removed
+ (due to the re-licensing effort) and rewritten without looking at the
+ original code. Feature-compatibility has been tested by other developers,
+ looking at both old and new code and documentation, so there *should*
+ not be a user-visible change here.
+ * IPv6 route addition/deletion are now logged on the same level (3) as
+ for IPv4. Previously IPv6 was always logged at `--verb 1`.
+ * Better handling of TLS 1.0 PRF failures in the underlying SSL library
+ (e.g. on some FIPS builds) - this is now reported on startup, and
+ clients before 2.6.0 that can not use TLS EKM to generate key material
+ are rejected by the server. Also, error messages are improved to see
+ what exactly failed.
+
+ Notable bug fixes:
+
+ * FreeBSD: for servers with multiple clients, reporting of peer traffic
+ statistics would fail due to insufficient buffer space (Github: [#487](https://github.com/OpenVPN/openvpn/issues/487))
+
+ Windows MSI changes since 2.6.8:
+ * Security fix, see above
+ * Built against OpenSSL 3.2.0
+ * Included openvpn-gui updated to 11.47.0.0
+ * Windows GUI: always update tray icon on state change (Github: [#669](https://github.com/OpenVPN/openvpn-gui/issues/669))
+ (for persistent connection profiles, "connecting" state would not show)
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-amd64.msi.asc)|[OpenVPN-2.6.9-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-arm64.msi.asc)|[OpenVPN-2.6.9-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-x86.msi.asc)|[OpenVPN-2.6.9-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.9.tar.gz.asc)|[openvpn-2.6.9.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.9.tar.gz)|
- For details, see the [Changes documentation](https://github.com/OpenVPN/openvpn/blob/v2.6.8/Changes.rst).
+ For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
- ### User Visible Changes:
- - **Windows:** A warning is now printed if pushed options require DHCP (e.g., DOMAIN-SEARCH) and the current driver does not utilize DHCP (e.g., wintun, dco).
+ ## OpenVPN 2.6.8 -- Released 17 November 2023
+ The OpenVPN community project team is proud to release OpenVPN 2.6.8. This is a small bugfix release fixing a few regressions in 2.6.7 release.
- ### Bug Fixes:
- - **SIGSEGV Crash:** Do not check key_state buffers that are in S_UNDEF state. ([#449](https://github.com/OpenVPN/openvpn/issues/449)) The new sanity check function introduced in 2.6.7 could sometimes attempt to use a NULL pointer after an unsuccessful TLS handshake.
- - **Windows:** The `--dns` option did not function when the tap-windows6 driver was in use because the internal flag for "apply DNS option to DHCP server" wasn't set. ([#447](https://github.com/OpenVPN/openvpn/issues/447))
- - **Windows:** Fixed status/log file permissions, a regression caused by the switch to the CMake build system. ([#454](https://github.com/OpenVPN/openvpn/issues/454), [Trac #1430](https://community.openvpn.net/openvpn/ticket/1430))**Windows:** fix `--chdir` failures, also caused by error in CMake build system ([#448](https://github.com/OpenVPN/openvpn/issues/448))
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.8/Changes.rst)
- **Windows MSI changes since 2.6.7:**
- - Included openvpn-gui updated to 11.46.0.0
+ User visible changes:
- **Download Links:**
+ * Windows: print warning if pushed options require DHCP (e.g. DOMAIN-SEARCH)
+ and driver in use does not use DHCP (wintun, dco).
- - **Windows 64-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-amd64.msi.asc)
- - [OpenVPN-2.6.8-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-amd64.msi)
+ Bug fixes:
- - **Windows ARM64 MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-arm64.msi.asc)
- - [OpenVPN-2.6.8-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-arm64.msi)
+ * SIGSEGV crash: Do not check key_state buffers that are in S_UNDEF state
+ (Github [#449](https://github.com/OpenVPN/openvpn/issues/449)) - the new sanity check function introduced in 2.6.7
+ sometimes tried to use a NULL pointer after an unsuccessful TLS handshake
+ * Windows: `--dns` option did not work when tap-windows6 driver was used,
+ because internal flag for "apply DNS option to DHCP server" wasn't set
+ (Github [#447](https://github.com/OpenVPN/openvpn/issues/447))
+ * Windows: fix status/log file permissions, caused by regression after
+ changing to CMake build system (Github: [#454](https://github.com/OpenVPN/openvpn/issues/454), Trac: [#1430](https://community.openvpn.net/openvpn/ticket/1430))
+ * Windows: fix `--chdir` failures, also caused by error in CMake build system
+ (Github [#448](https://github.com/OpenVPN/openvpn/issues/448))
- - **Windows 32-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-x86.msi.asc)
- - [OpenVPN-2.6.8-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-x86.msi)
+ Windows MSI changes since 2.6.7:
+ * Included openvpn-gui updated to 11.46.0.0
- - **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.8.tar.gz.asc)
- - [openvpn-2.6.8.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.8.tar.gz)
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-amd64.msi.asc)|[OpenVPN-2.6.8-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-arm64.msi.asc)|[OpenVPN-2.6.8-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-x86.msi.asc)|[OpenVPN-2.6.8-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.8.tar.gz.asc)|[openvpn-2.6.8.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.8.tar.gz)|
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
- ---
-
- ## OpenVPN 2.6.7 -- Released 09 November 2023
-
+ ## OpenVPN 2.6.7 -- Released 09 November 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.7. This is a bugfix release containing security fixes.
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.7/Changes.rst)
- **Security Fixes:**
-
- - [CVE-2023-46850](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46850): OpenVPN versions between 2.6.0 and 2.6.6 incorrectly use a send buffer after it has been free()d in some circumstances, causing some free()d memory to be sent to the peer. All configurations using TLS (e.g. not using --secret) are affected by this issue. (found while tracking down [CVE-2023-46849](https://github.com/OpenVPN/openvpn/issues/400), [#417](https://github.com/OpenVPN/openvpn/issues/417))
- - [CVE-2023-46849](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46849): OpenVPN versions between 2.6.0 and 2.6.6 incorrectly restore `--fragment` configuration in some circumstances, leading to a division by zero when `--fragment` is used. On platforms where division by zero is fatal, this will cause an OpenVPN crash.
-
- **User visible changes:**
-
- - DCO: warn if DATA_V1 packets are sent by the other side - this a hard incompatibility between a 2.6.x client connecting to a 2.4.0-2.4.4 server, and the only fix is to use `--disable-dco`.
- - Remove OpenSSL Engine method for loading a key. This had to be removed because the original author did not agree to relicensing the code with the new linking exception added. This was a somewhat obsolete feature anyway as it only worked with OpenSSL 1.x, which is end-of-support.
- - Add warning if p2p NCP client connects to a p2mp server - this is a combination that used to work without cipher negotiation (pre 2.6 on both ends), but would fail in non-obvious ways with 2.6 to 2.6.
- - Add warning to `--show-groups` that not all supported groups are listed (this is due to the internal enumeration in OpenSSL being a bit weird, omitting X448 and X25519 curves).
- - `--dns`: remove support for `exclude-domains` argument (this was a new 2.6 option, with no backend support implemented yet on any platform, and it turns out that no platform supported it at all - so remove option again)
- - Warn user if INFO control message too long, do not forward to management client (safeguard against protocol-violating server implementations)
-
- **New features:**
-
- - DCO-WIN: get and log driver version (for easier debugging).
- - Print "peer temporary key details" in TLS handshake.## Changelog
+ Security Fixes:
+
+ * [CVE-2023-46850](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46850) OpenVPN versions between 2.6.0 and 2.6.6 incorrectly use a send buffer after it has been free()d in some circumstances, causing some free()d memory to be sent to the peer. All configurations using TLS (e.g. not using --secret) are affected by this issue. (found while tracking down CVE-2023-46849 / Github [#400](https://github.com/OpenVPN/openvpn/issues/400), [#417](https://github.com/OpenVPN/openvpn/issues/417))
+ * [CVE-2023-46849](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46849) OpenVPN versions between 2.6.0 and 2.6.6 incorrectly restore `--fragment` configuration in some circumstances, leading to a division by zero when `--fragment` is used. On platforms where division by zero is fatal, this will cause an OpenVPN crash.
+ (Github [#400](https://github.com/OpenVPN/openvpn/issues/400), [#417](https://github.com/OpenVPN/openvpn/issues/417)).
+
+ User visible changes:
+
+ * DCO: warn if DATA_V1 packets are sent by the other side - this a hard
+ incompatibility between a 2.6.x client connecting to a 2.4.0-2.4.4 server,
+ and the only fix is to use `--disable-dco`.
+ * Remove OpenSSL Engine method for loading a key. This had to be removed
+ because the original author did not agree to relicensing the code with
+ the new linking exception added. This was a somewhat obsolete feature
+ anyway as it only worked with OpenSSL 1.x, which is end-of-support.
+ * add warning if p2p NCP client connects to a p2mp server - this is a
+ combination that used to work without cipher negotiation (pre 2.6 on
+ both ends), but would fail in non-obvious ways with 2.6 to 2.6.
+ * add warning to `--show-groups` that not all supported groups are listed
+ (this is due the internal enumeration in OpenSSL being a bit weird,
+ omitting X448 and X25519 curves).
+ * `--dns`: remove support for `exclude-domains` argument
+ (this was a new 2.6 option, with no backend support implemented yet
+ on any platform, and it turns out that no platform supported it at all -
+ so remove option again)
+ * warn user if INFO control message too long, do not forward to management
+ client (safeguard against protocol-violating server implementations)
+
+ New features:
+
+ * DCO-WIN: get and log driver version (for easier debugging).
+ * print "peer temporary key details" in TLS handshake
+ * log OpenSSL errors on failure to set certificate, for example if the
+ algorithms used are in acceptable to OpenSSL (misleading message would
+ be printed in cryptoapi / pkcs11 scenarios)
+ * add CMake build system for MinGW and MSVC builds
+ * remove old MSVC build system
+ * improve cmocka unit test building for Windows
+
+ Windows MSI changes since 2.6.6:
+ * Included openvpn-gui updated to 11.45.0.0
+ * Add clarity for error on missing management parameter.
+ See GH [#657](https://github.com/OpenVPN/openvpn-gui/issues/657)
+ * Improve "OpenVPN GUI" tooltip handling
+ See GH [#649](https://github.com/OpenVPN/openvpn-gui/issues/649)
+ * MSIs now use OpenSSL 3.1.4
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-amd64.msi.asc)|[OpenVPN-2.6.7-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-arm64.msi.asc)|[OpenVPN-2.6.7-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-x86.msi.asc)|[OpenVPN-2.6.7-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.7.tar.gz.asc)|[openvpn-2.6.7.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.7.tar.gz)|
- ### General Changes
- - Log OpenSSL errors on failure to set certificate, especially when the algorithms used are unacceptable to OpenSSL (Note: misleading messages may appear in cryptoapi/pkcs11 scenarios).
- - Implement CMake build system for MinGW and MSVC builds.
- - Remove old MSVC build system.
- - Enhance cmocka unit test building for Windows.
-
- ### Windows MSI Updates Since 2.6.6
- - Included openvpn-gui updated to 11.45.0.0:
- - Add clarity for error on missing management parameter. [See GH #657](https://github.com/OpenVPN/openvpn-gui/issues/657)
- - Improve "OpenVPN GUI" tooltip handling. [See GH #649](https://github.com/OpenVPN/openvpn-gui/issues/649)
- - MSIs now use OpenSSL 3.1.4
-
- ### MSI Download Links
- - **Windows 64-bit MSI installer**: [OpenVPN-2.6.7-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-amd64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-amd64.msi.asc)
- - **Windows ARM64 MSI installer**: [OpenVPN-2.6.7-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-arm64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-arm64.msi.asc)
- - **Windows 32-bit MSI installer**: [OpenVPN-2.6.7-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-x86.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-x86.msi.asc)
- - **Source archive file**: [openvpn-2.6.7.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.7.tar.gz) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.7.tar.gz.asc)
-
- For community-maintained packages for Linux distributions, see OpenvpnSoftwareRepos.
+ For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
- ## OpenVPN 2.6.6 -- Released 15 August 2023
- The OpenVPN community project team is proud to release OpenVPN 2.6.6, a small bugfix release.
+ ## OpenVPN 2.6.6 -- Released 15 August 2023
+ The OpenVPN community project team is proud to release OpenVPN 2.6.6. This is a small bugfix release.
- For details, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.6/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.6/Changes.rst)
- ### User Visible Changes:
- - OCC exit messages are now more visibly logged. [See GH #391](https://github.com/OpenVPN/openvpn/issues/391).
- - OpenSSL error messages now log more details (e.g., which .so was tried and why it failed). [See GH #361](https://github.com/OpenVPN/openvpn/issues/361).
- - Print a more user-friendly message when tls-crypt-v2 client auth fails.
- - Packaging now includes all documentation in the source tarball.
+ User visible changes:
- ### New Features:
- - Set WINS server via interactive service - supports "dhcp-option WINS 192.0.2.1" for DCO + wintun interfaces where no DHCP server is used. [See GH #373](https://github.com/OpenVPN/openvpn/issues/373).
+ * OCC exit messages are now logged more visibly
+ See GH [#391](https://github.com/OpenVPN/openvpn/issues/391).
+ * OpenSSL error messages are now logged with more details (for example,
+ when loading a provider fails, which .so was tried, and why did it fail)
+ See GH [#361](https://github.com/OpenVPN/openvpn/issues/361).
+ * print a more user-friendly message when tls-crypt-v2 client auth fails
+ * packaging now includes all documentation in the source tarball
- ### Windows MSI Updates Since 2.6.5:
- - Included openvpn-gui updated to 11.44.0.0.
- - MSIs now use OpenSSL 3.1.2.
+ New features:
- ### MSI Download Links for 2.6.6
- - **Windows 64-bit MSI installer**: [OpenVPN-2.6.6-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-amd64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-amd64.msi.asc)
- - **Windows ARM64 MSI installer**: [OpenVPN-2.6.6-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-arm64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-arm64.msi.asc)### Downloads
+ * set WINS server via interactive service - this adds support for
+ "dhcp-option WINS 192.0.2.1" for DCO + wintun interfaces where no
+ DHCP server is used.
+ See GH [#373](https://github.com/OpenVPN/openvpn/issues/373).
- **Windows 32-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-x86.msi.asc)
- - [OpenVPN-2.6.6-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-x86.msi)
+ Windows MSI changes since 2.6.5:
+ * Included openvpn-gui updated to 11.44.0.0
+ * MSIs now use OpenSSL 3.1.2
- **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.6.tar.gz.asc)
- - [openvpn-2.6.6.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.6.tar.gz)
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-amd64.msi.asc)|[OpenVPN-2.6.6-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-arm64.msi.asc)|[OpenVPN-2.6.6-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-x86.msi.asc)|[OpenVPN-2.6.6-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.6.tar.gz.asc)|[openvpn-2.6.6.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.6.tar.gz)|
- For Community-maintained packages for Linux distributions see [OpenvpnSoftwareRepos](https://github.com/OpenVPN/openvpn-software-repos)
+ For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
- ### OpenVPN 2.6.5 -- Released 13 June 2023
+ ## OpenVPN 2.6.5 -- Released 13 June 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.5. This is a small bugfix release.
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.5/Changes.rst)
- **User visible changes:**
-
- - **tapctl (windows):** generate driver-specific names. See [GH #337](https://github.com/OpenVPN/openvpn/issues/337).
- - **interactive service (windows):** do not force target desktop for openvpn.exe. See [openvpn-gui#626](https://github.com/OpenVPN/openvpn-gui/issues/626)
-
- **Windows MSI changes since 2.6.4:**
- - MSIs now use OpenSSL 3.1.1
+ User visible changes:
- Debian/Ubuntu packages in [OpenvpnSoftwareRepos](https://github.com/OpenVPN/openvpn-software-repos) are now available for arm64.
+ * tapctl (windows): generate driver-specific names (if using tapctl to
+ create additional tap/wintun/dco devices, and not using --name).
+ See GH [#337](https://github.com/OpenVPN/openvpn/issues/337).
+ * interactive service (windows): do not force target desktop for
+ openvpn.exe - this has no impact for normal use, but enables running
+ of OpenVPN in a scripted way when no user is logged on (for example,
+ via task scheduler).
+ See GH [openvpn-gui#626](https://github.com/OpenVPN/openvpn-gui/issues/626)
- **Windows 64-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-amd64.msi.asc)
- - [OpenVPN-2.6.5-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-amd64.msi)
+ Windows MSI changes since 2.6.4:
+ * MSIs now use OpenSSL 3.1.1
- **Windows ARM64 MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-arm64.msi.asc)
- - [OpenVPN-2.6.5-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-arm64.msi)
+ Debian/Ubuntu packages in OpenvpnSoftwareRepos are now available for arm64.
- **Windows 32-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-x86.msi.asc)
- - [OpenVPN-2.6.5-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-x86.msi)
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-amd64.msi.asc)|[OpenVPN-2.6.5-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-arm64.msi.asc)|[OpenVPN-2.6.5-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-x86.msi.asc)|[OpenVPN-2.6.5-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.5.tar.gz.asc)|[openvpn-2.6.5.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.5.tar.gz)|
- **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.5.tar.gz.asc)
- - [openvpn-2.6.5.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.5.tar.gz)
-
- For Community-maintained packages for Linux distributions see [OpenvpnSoftwareRepos](https://github.com/OpenVPN/openvpn-software-repos)
+ For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
- ### OpenVPN 2.6.4 -- Released 11 May 2023
+ ## OpenVPN 2.6.4 -- Released 11 May 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.4. This is a small bugfix release.
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.4/Changes.rst)
- **Note:**
- - **License amendment:** all **new** commits fall under a modified license that explicitly permits linking with Apache2 libraries (mbedTLS, OpenSSL). See COPYING for details. Existing code will fall under the new license as soon as all contributors have agreed to the change - work ongoing.
-
- **Feature changes:**
- - **DCO:** support kernel-triggered key rotation (avoid IV reuse after 2^32 packets). This is the userland side, accepting a message from kernel, and initiating a TLS renegotiation. As of 2.6.4 release, only implemented in FreeBSD kernel.## Windows MSI Changes Since 2.6.3
-
- - Rebuilt included tap-windows driver with the correct version of the old Windows 7 driver, removing a warning about unsigned driver on Windows 7 installation. See [openvpn-build#365](https://github.com/OpenVPN/openvpn-build/issues/365).
-
- ### Downloads
-
- - **Windows 64-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-amd64.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-amd64.msi)
-
- - **Windows ARM64 MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-arm64.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-arm64.msi)
-
- - **Windows 32-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-x86.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-x86.msi)
-
- - **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.4.tar.gz.asc)
- - [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6.4.tar.gz)
+ Note:
+ * **License amendment**: all **new** commits fall under a modified license that
+ explicitly permits linking with Apache2 libraries (mbedTLS, OpenSSL) -
+ see COPYING for details. Existing code will fall under the new license
+ as soon as all contributors have agreed to the change - work ongoing.
+
+ Feature changes:
+ * DCO: support kernel-triggered key rotation (avoid IV reuse after 2^32^
+ packets). This is the userland side, accepting a message from kernel,
+ and initiating a TLS renegotiation. As of 2.6.4 release, only implemented in
+ FreeBSD kernel.
+
+ Windows MSI changes since 2.6.3:
+ * Rebuilt included tap-windows driver with the correct version of the old Windows 7 driver, removing a warning about unsigned driver on Windows 7 installation.
+ See GH [openvpn-build#365](https://github.com/OpenVPN/openvpn-build/issues/365).
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-amd64.msi.asc)|[OpenVPN-2.6.4-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-arm64.msi.asc)|[OpenVPN-2.6.4-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-x86.msi.asc)|[OpenVPN-2.6.4-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.4.tar.gz.asc)|[openvpn-2.6.4.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.4.tar.gz)|
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
- ## OpenVPN 2.6.3 -- Released 13 April 2023
-
+ ## OpenVPN 2.6.3 -- Released 13 April 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.3. This is a small bugfix release.
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.3/Changes.rst)
- ### Feature Changes
-
- - Windows: support setting DNS domain in configurations without GUI and DHCP (typically wintun or windco drivers), see [openvpn#306](https://github.com/OpenVPN/openvpn/issues/306).
-
- ### Windows MSI Changes Since 2.6.2
-
- - Several Windows-specific issues fixed:
- - Ensure interactive service stays enabled after silent reinstall, see [openvpn-build#348](https://github.com/OpenVPN/openvpn-build/issues/348), [openvpn-build#349](https://github.com/OpenVPN/openvpn-build/issues/349), and [openvpn-build#351](https://github.com/OpenVPN/openvpn-build/issues/351).
- - Repair querying install path info for easyrsa-start.bat on some Windows language versions, see [openvpn-build#352](https://github.com/OpenVPN/openvpn-build/issues/352).
- - MSIs are now built against OpenSSL 3.1.0.
- - Update included openvpn-gui to 11.41.0.0
- - This update removes the ability to change the password of a private key from the GUI. This was a niche feature which caused a direct dependency of GUI on OpenSSL. Use openssl.exe directly if you need to edit a private key.
-
- ### Note: Windows MSI was updated to I002 on April 26th
-
- - The GPG subkey for creating the .asc files for the downloads has been updated. You might need to re-download or update the GPG key if verifying the signatures.
- - Fix the encoding of some documentation/sample files included in the installer. See [openvpn-build#358](https://github.com/OpenVPN/openvpn-build/issues/358)
- - Update include tap-windows6 driver to 9.25.0
- - Fixes a problem with sending small non-IP packets (e.g., PPPoE) over the VPN connection. See [tap-windows6#158](https://github.com/OpenVPN/tap-windows6/issues/158)
- - Fixes occasional TCP performance degradation on Windows Server 2022 See [tap-windows6#147](https://github.com/OpenVPN/tap-windows6/pull/147)
- - Note: The new driver is only used on Windows 10 and newer. We can't rebuild drivers for Windows 7/8 since Microsoft doesn't support the signing mechanism anymore. We include the previous driver version to still allow installation on Windows 7/8.
- - Update included openvpn-gui to 11.42.0.0
- - Fixes a problem with passphrase prompt was sometimes not displayed. See [openvpn-gui#619](https://github.com/OpenVPN/openvpn-gui/issues/619)
- - Adds "Password Reveal" feature which allows you to see passwords while entering them.
-
- ### Note: Windows MSI was updated to I003 on April 27th
-
- - Update include tap-windows6 driver to 9.26.0
- - Revert fix for occasional TCP performance degradation on Windows Server 2022 (GH [tap-windows6#147](https://github.com/OpenVPN/tap-windows6/pull/147)) since users reported BSODs in some (undetermined) scenarios.
-
- ### Downloads for OpenVPN 2.6.3
-
- - **Windows 64-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-amd64.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-amd64.msi)
-
- - **Windows ARM64 MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-arm64.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-arm64.msi)
-
- - **Windows 32-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-x86.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-x86.msi)
-
- - **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.3.tar.gz.asc)
- - [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6.3.tar.gz)
-
- ## OpenVPN 2.6.2 -- Released 24 March 2023
-
- The OpenVPN community project team is proud to release OpenVPN 2.6.2. This is mostly a bugfix release with some improvements.For details, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.2/Changes.rst).
-
- ### Feature Changes:
- - Implement byte counter statistics for DCO Linux (p2mp server and client).
- - Implement byte counter statistics for DCO Windows (client only).
- - `--dns server <n> address ...` now permits up to 8 v4 or v6 addresses.
+ Feature changes:
+ * Windows: support setting DNS domain in configurations without GUI and DHCP (typically wintun or windco drivers), see GH [openvpn#306](https://github.com/OpenVPN/openvpn/issues/306).
+
+ Windows MSI changes since 2.6.2:
+ * Several Windows-specific issues fixed:
+ * ensure interactive service stays enabled after silent reinstall, see GH [openvpn-build#348](https://github.com/OpenVPN/openvpn-build/issues/348), [openvpn-build#349](https://github.com/OpenVPN/openvpn-build/issues/349) and [openvpn-build#351](https://github.com/OpenVPN/openvpn-build/issues/351)
+ * repair querying install path info for easyrsa-start.bat on some Windows language versions, see GH [openvpn-build#352](https://github.com/OpenVPN/openvpn-build/issues/352).
+ * MSIs are now built against OpenSSL 3.1.0.
+ * Update included openvpn-gui to 11.41.0.0
+ * This update removes the ability to change the password of a private key from the GUI. This was a niche feature which caused a direct dependency of
+ GUI on OpenSSL. Use openssl.exe directly if you need to edit a private key.
+
+ Note: Windows MSI was updated to I002 on April 26th. Changes in I002:
+ * The GPG subkey for creating the .asc files for the downloads has been updated. You might need to re-download or update the GPG key if verifying the signatures.
+ * Fix the encoding of some documentation/sample files included in the installer. See GH [openvpn-build#358](https://github.com/OpenVPN/openvpn-build/issues/358)
+ * Update include tap-windows6 driver to 9.25.0
+ * Fixes a problem with sending small non-IP packets (e.g. PPPoE) over the VPN connection. See GH [tap-windows6#158](https://github.com/OpenVPN/tap-windows6/issues/158)
+ * Fixes occasional TCP performance degradation on Windows Server 2022 See GH [tap-windows6#147](https://github.com/OpenVPN/tap-windows6/pull/147)
+ * Note: The new driver is only used on Windows 10 and newer. We can't rebuild drivers for Windows 7/8 since Microsoft doesn't support the signing mechanism anymore. We include the previous driver version to still allow installation on Windows 7/8.
+ * Update included openvpn-gui to 11.42.0.0
+ * Fixes a problem with passphrase prompt was sometimes not displayed. See GH [openvpn-gui#619](https://github.com/OpenVPN/openvpn-gui/issues/619)
+ * Adds "Password Reveal" feature which allows you to see passwords while entering them.
+
+ Note: Windows MSI was updated to I003 on April 27th. Changes in I003:
+ * Update include tap-windows6 driver to 9.26.0
+ * Revert fix for occasional TCP performance degradation on Windows Server 2022 (GH [tap-windows6#147](https://github.com/OpenVPN/tap-windows6/pull/147)) since users reported BSODs in some (undetermined) scenarios.
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-amd64.msi.asc)|[OpenVPN-2.6.3-I003-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-arm64.msi.asc)|[OpenVPN-2.6.3-I003-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-x86.msi.asc)|[OpenVPN-2.6.3-I003-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.3.tar.gz.asc)|[openvpn-2.6.3.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.3.tar.gz)|
+
+ ## OpenVPN 2.6.2 -- Released 24 March 2023
+ The OpenVPN community project team is proud to release OpenVPN 2.6.2. This is mostly a bugfix release with some improvements.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.2/Changes.rst)
+
+ Feature changes:
+ * implement byte counter statistics for DCO Linux (p2mp server and client)
+ * implement byte counter statistics for DCO Windows (client only)
+ * `--dns server <n> address ...` now permits up to 8 v4 or v6 addresses
**Important note for Linux DCO users**:
- - New control packets flow for data channel offloading on Linux:
- Version 2.6.2+ changes the way OpenVPN control packets are handled on Linux when DCO is active, fixing the lockups observed with versions 2.6.0/2.6.1 under high client connect/disconnect activity.
- This is an **INCOMPATIBLE** change, and therefore an ovpn-dco kernel module older than v0.2.20230323 (commit ID 726fdfe0fa21) will not work anymore and must be upgraded. The kernel module was renamed to "ovpn-dco-v2.ko" to highlight this change and ensure that users and userspace software could easily understand which version is loaded. Attempting to use the old ovpn-dco with 2.6.2+ will lead to disabling DCO at runtime.
-
- ### Windows MSI Changes since 2.6.1:
- - Update included OpenVPN-GUI to 11.39.0.0.
-
- **Windows 64-bit MSI installer**:
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-amd64.msi.asc)
- - [OpenVPN-2.6.2-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-amd64.msi)
-
- **Windows ARM64 MSI installer**:
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-arm64.msi.asc)
- - [OpenVPN-2.6.2-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-arm64.msi)
-
- **Windows 32-bit MSI installer**:
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-x86.msi.asc)
- - [OpenVPN-2.6.2-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-x86.msi)
-
- **Source archive file**:
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.2.tar.gz.asc)
- - [openvpn-2.6.2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.2.tar.gz)
-
- ## OpenVPN 2.6.1 -- Released 8 March 2023
- The OpenVPN community project team is proud to release OpenVPN 2.6.1. This release is mostly focused on bugfixes with some improvements.
-
- For details, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.1/Changes.rst).
-
- ### Feature Changes:
- - **Dynamic TLS Crypt**:
- When both peers are OpenVPN 2.6.1+, OpenVPN will dynamically create a tls-crypt key that is used for renegotiation. This ensures that only the previously authenticated peer can trigger renegotiation and complete renegotiations.
- - **CryptoAPI (Windows)**: support issuer name as a selector. Certificate selection string can now specify a partial issuer name string as `--cryptoapicert ISSUER:<string>`, where `<string>` is matched as a substring of the issuer (CA) name in the certificate.
-
- **Note**: The `configure` script now enables DCO build by default on FreeBSD and Linux. On Linux, this introduces a new default dependency for libnl-genl (for Linux distributions that are too old to have a suitable version of the library, use `configure --disable-dco`).## Windows MSI Changes Since 2.6.0:
- - Update included ovpn-dco-win driver to 0.9.2
-
- ### Download Links:
- - **Windows 64-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-amd64.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-amd64.msi)
- - **Windows ARM64 MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-arm64.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-arm64.msi)
- - **Windows 32-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-x86.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-x86.msi)
- - **Source archive file**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.1.tar.gz.asc), [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6.1.tar.gz)
-
- ## OpenVPN 2.5.9 -- Released 15 February 2023
+ * New control packets flow for data channel offloading on Linux:
+ 2.6.2+ changes the way OpenVPN control packets are handled on
+ Linux when DCO is active, fixing the lockups observed with 2.6.0/2.6.1
+ under high client connect/disconnect activity.
+ This is an **INCOMPATIBLE** change and therefore an ovpn-dco kernel
+ module older than v0.2.20230323 (commit ID 726fdfe0fa21) will not
+ work anymore and must be upgraded. The kernel module was renamed to
+ "ovpn-dco-v2.ko" in order to highlight this change and ensure that
+ users and userspace software could easily understand which version
+ is loaded. Attempting to use the old ovpn-dco with 2.6.2+ will
+ lead to disabling DCO at runtime.
+
+ Windows MSI changes since 2.6.1:
+ * Update included openvpn-gui to 11.39.0.0
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-amd64.msi.asc)|[OpenVPN-2.6.2-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-arm64.msi.asc)|[OpenVPN-2.6.2-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-x86.msi.asc)|[OpenVPN-2.6.2-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.2.tar.gz.asc)|[openvpn-2.6.2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.2.tar.gz)|
+
+ ## OpenVPN 2.6.1 -- Released 8 March 2023
+ The OpenVPN community project team is proud to release OpenVPN 2.6.1. This is mostly a bugfix release with some improvements.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.1/Changes.rst)
+
+ Feature changes:
+ * Dynamic TLS Crypt:
+ When both peers are OpenVPN 2.6.1+, OpenVPN will dynamically create
+ a tls-crypt key that is used for renegotiation. This ensure that only the
+ previously authenticated peer can do trigger renegotiation and complete
+ renegotiations.
+ * CryptoAPI (Windows): support issuer name as a selector.
+ Certificate selection string can now specify a partial
+ issuer name string as "--cryptoapicert ISSUER:<string>" where
+ <string> is matched as a substring of the issuer (CA) name in
+ the certificate.
+
+ Note: configure now enables DCO build by default on FreeBSD and Linux. On Linux
+ this brings in a new default dependency for libnl-genl (for Linux distributions
+ that are too old to have a suitable version of the library, use "configure --disable-dco")
+
+ Windows MSI changes since 2.6.0:
+ * Update included ovpn-dco-win driver to 0.9.2
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-amd64.msi.asc)|[OpenVPN-2.6.1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-arm64.msi.asc)|[OpenVPN-2.6.1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-x86.msi.asc)|[OpenVPN-2.6.1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.1.tar.gz.asc)|[openvpn-2.6.1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.1.tar.gz)|
+
+ ## OpenVPN 2.5.9 -- Released 15 February 2023
The OpenVPN community project team is proud to release OpenVPN 2.5.9. This is a small bugfix release.
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.5.9/Changes.rst)
- ### Windows MSI Changes Since 2.5.8:
- - Build against OpenSSL 1.1.1t which contains several security fixes.
+ Windows MSI changes since 2.5.8:
+ * Build against OpenSSL 1.1.1t which contains several security fixes.
- #### Download Links:
- - **Windows 64-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-amd64.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-amd64.msi)
- - **Windows ARM64 MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-arm64.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-arm64.msi)
- - **Windows 32-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-x86.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-x86.msi)
- - **Source archive file**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.9.tar.gz.asc), [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.5.9.tar.gz)
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-amd64.msi.asc)|[OpenVPN-2.5.9-I601-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-arm64.msi.asc)|[OpenVPN-2.5.9-I601-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-x86.msi.asc)|[OpenVPN-2.5.9-I601-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.9.tar.gz.asc)|[openvpn-2.5.9.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.5.9.tar.gz)|
- ## OpenVPN 2.6.0 -- Released 25 January 2023
+ ## OpenVPN 2.6.0 -- Released 25 January 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.0. This is a release with some major new features.
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.0/Changes.rst)
- ### Changes Since RC2:
- - Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.0/Changes.rst)
-
- ### Windows MSI Changes Since RC2:
- - Included openvpn-gui updated to 11.37.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.37.0.0/CHANGES.rst).
- - DCO driver is now included as an installer module (msm) so that other products (like OpenVPN Connect) can share the DCO installation.
-
- #### Note:
- - MSI was updated to I003 on January 26th: Fixes installation on Windows 7 and a broken tray icon menu with single profile.
- - MSI was updated to I004 on February 6th: Update included ovpn-dco-win driver to 0.9.0, fixing an issue that breaks Windows boot on some machines. See [Issue #24](https://github.com/OpenVPN/ovpn-dco-win/issues/24).
- - MSI was updated to I005 on February 15th: Update included ovpn-dco-win driver to 0.9.1, fixing potential crash on machines using "legacy standby" and incompatibility with Citrix DNE Lightweight Filter. Built against OpenSSL 3.0.8.# OpenVPN 2.6.0 Features and Improvements
-
- ## Key Updates
- - **Data Channel Offload (DCO)** kernel acceleration support for Windows, Linux, and FreeBSD.
- - **OpenSSL 3** support, now the default on Windows.
- - Improved handling of **tunnel MTU**, including support for pushable MTU.
- - **Outdated cryptographic algorithms** disabled by default, with options to override if necessary.
- - Reworked **TLS handshake**, enhancing security against replay-packet state exhaustion attacks.
- - Introduced `--peer-fingerprint` mode for simpler certificate setup and verification.
- - **Pre-Logon Access Provider support** added to OpenVPN GUI for Windows.
- - Enhanced **protocol negotiation** for faster connection setup.
- - Updated **easy-rsa3** bundled with the Windows installer.
-
- ### Windows Default Settings
- On Windows, DCO is enabled by default for client connections unless the configuration specifies settings that are not DCO compatible, such as compression.
-
- ### Linux Requirements
- For Linux, DCO support necessitates an additional kernel module, available from our [OpenvpnSoftwareRepos software repositories for Linux](https://github.com/OpenVPN/openvpn), and for the OpenVPN3 Linux client.
-
- ## Download Links
-
- - **Windows 64-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-amd64.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-amd64.msi)
-
- - **Windows ARM64 MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-arm64.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-arm64.msi)
-
- - **Windows 32-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-x86.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-x86.msi)
-
- - **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.0.tar.gz.asc)
- - [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6.0.tar.gz)
-
- ## OpenVPN 2.6_rc2 - Released 12 January 2023
- The OpenVPN community project team is proud to present OpenVPN 2.6_rc2. This beta release features major new features and updates. For a stable version, download from the [stable release](https://openvpn.net/community-downloads).
-
- For more details, see the [Changes Document](https://github.com/OpenVPN/openvpn/blob/v2.6_rc2/Changes.rst).
-
- ### Changes Since RC1:
- - Added a rate limiter for incoming "initial handshake packets", set to 100 packets per 10 seconds by default.
- - `CONNECTED,ROUTE_ERROR` status reported to management GUI if connection succeeds but not all routes can be installed (specific to Windows and Linux/Netlink).
- - Various bug fixes detailed in the [Changes Document](https://github.com/OpenVPN/openvpn/blob/v2.6_rc2/Changes.rst).
-
- ### MSI and Debian Package Updates Since RC1:
- - **Windows MSI:** Includes updated openvpn-gui to 11.35.0.0 with new features and fixes for upgrade issues.
- - **Debian Packages:** Now available for Debian bookworm.
-
- These enhancements and additions aim to further secure and streamline OpenVPN usage across various platforms.## Changelog for OpenVPN Releases
-
- ### OpenVPN 2.6_rc2 - Recent Changes
-
- - Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
- - Improved protocol negotiation, leading to faster connection setup.
- - Updated easy-rsa3 bundled with the installer on Windows.
-
- **Note:** On Windows, DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, which is available from our [software repositories for Linux](OpenvpnSoftwareRepos), and is also available for OpenVPN3 Linux client.
-
- #### Download Links for Windows
-
- - **Windows 64-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-amd64.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-amd64.msi)
- - **Windows ARM64 MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-arm64.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-arm64.msi)
- - **Windows 32-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-x86.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-x86.msi)
- - **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc2.tar.gz.asc)
- - [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc2.tar.gz)
-
- ### OpenVPN 2.6_rc1 - Released 28 December 2022
-
- The OpenVPN community project team is proud to announce the release of OpenVPN 2.6_rc1. This version includes several new features and is currently in beta. For those needing a stable release, the [stable version](https://openvpn.net/community-downloads) is also available.
-
- For detailed changes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_rc1/Changes.rst).
-
- #### Highlights:
-
- - Officially deprecated NTLMv1 proxy auth method in 2.6, to be removed in 2.7.
- - Support for an unlimited number of connection entries and remote entries.
- - New management commands to enumerate and list remote entries.
- - Various bug fixes detailed in the [change log](https://github.com/OpenVPN/openvpn/blob/v2.6_rc1/Changes.rst).
-
- #### Windows MSI Updates:
-
- - OpenVPN GUI updated to 11.34.0.0, with connections active on exit/logout now automatically restarted in the next session.
- - Windows installers are now built with Visual Studio 17 2022 (previously Visual Studio 16 2019).
-
- #### Download Links for Windows
-
- - **Windows 64-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-amd64.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-amd64.msi)
- - **Windows ARM64 MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-arm64.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-arm64.msi)
- - **Windows 32-bit MSI installer**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-x86.msi.asc)
- - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-x86.msi)
- - **Source archive file**
- - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc1.tar.gz.asc)
- - [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc1.tar.gz)
-
- ### OpenVPN 2.6_beta2 - Released 15 December 2022
-
- The OpenVPN community project team is pleased to release OpenVPN 2.6_beta2, featuring major new features and still in the beta testing phase. For those requiring a stable version, the [stable release](https://openvpn.net/community-downloads) is recommended.For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_beta2/Changes.rst)
-
- ### Changes since Beta 1:
-
- - Transport statistics (bytes in/out) for DCO environments. Currently only for Windows clients and FreeBSD servers. Other platforms will be fixed in the next release.
- - Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_beta2/Changes.rst)
-
- ### Windows MSI changes since Beta 1:
- - Included openvpn-gui updated to 11.33.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.33.0.0/CHANGES.rst).
- - Update included pkcs11-helper so it can load pkcs11 providers from outside of its own install directory.
- - Add legacy provider for included OpenSSL so that the workarounds documented for old ciphers work on Windows.
-
- ### New features and improvements in 2.6.0 compared to 2.5.8:
-
- - Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
- - OpenSSL 3 support, which is now the default on Windows.
- - Improved handling of tunnel MTU, including support for pushable MTU.
- - Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
- - Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
- - Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
- - Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
- - Improved protocol negotiation, leading to faster connection setup.
- - Updated easy-rsa3 bundled with the installer on Windows.
+ Changes since RC2:
- On Windows, DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, available from our [software repositories for Linux](OpenvpnSoftwareRepos), and is also available for OpenVPN3 Linux client.
+ * Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.0/Changes.rst)
+
+ Windows MSI changes since RC2:
+ * Included openvpn-gui updated to 11.37.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.37.0.0/CHANGES.rst).
+ * DCO driver is now included as a installer module (msm) so that other products (like OpenVPN Connect) can share the DCO installation.
- ### Installers:
- - **Windows 64-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-amd64.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-amd64.msi)
- - **Windows ARM64 MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-arm64.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-arm64.msi)
- - **Windows 32-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-x86.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-x86.msi)
- - **Source archive file**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta2.tar.gz.asc), [Download](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta2.tar.gz)
+ Note: Windows MSI was updated to I003 on January 26th. Changes in I003:
+ * Fix installation on Windows 7
+ * Fix broken tray icon menu with single profile (regression in openvpn-gui 11.36.0)
+
+ Note: Windows MSI was updated to I004 on February 6th. Changes in I004:
+ * Update included ovpn-dco-win driver to 0.9.0. Fixes an issue that breaks Windows boot on some machines. See [OpenVPN/ovpn-dco-win#24](https://github.com/OpenVPN/ovpn-dco-win/issues/24).
+ * Update included easy-rsa to 3.1.2
+
+ Note: Windows MSI was updated to I005 on February 15th. Changes in I005:
+ * Update included ovpn-dco-win driver to 0.9.1.
+ * Fixes an potential crash on machines that use "legacy standby" (S3). See [OpenVPN/ovpn-dco-win#36](https://github.com/OpenVPN/ovpn-dco-win/issues/36).
+ * Fixes an incompatibility of DCO driver with Citrix DNE Lightweight Filter. See [OpenVPN/ovpn-dco-win#31](https://github.com/OpenVPN/ovpn-dco-win/issues/31).
+ * Built against OpenSSL 3.0.8 which includes several security fixes.
+
+ New features and improvements in 2.6.0 compared to 2.5.8:
+
+ * Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
+ * OpenSSL 3 support, which is now the default on Windows.
+ * Improved handling of tunnel MTU, including support for pushable MTU.
+ * Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
+ * Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
+ * Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
+ * Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
+ * Improved protocol negotiation, leading to faster connection setup.
+ * Updated easy-rsa3 bundled with the installer on Windows.
- ---
+ On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-amd64.msi.asc)|[OpenVPN-2.6.0-I005-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-arm64.msi.asc)|[OpenVPN-2.6.0-I005-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-x86.msi.asc)|[OpenVPN-2.6.0-I005-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.0.tar.gz.asc)|[openvpn-2.6.0.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.0.tar.gz)|
+
+ ## OpenVPN 2.6_rc2 -- Released 12 January 2023
+ The OpenVPN community project team is proud to release OpenVPN 2.6_rc2. This is a release with some major new features and currently in beta (you can also download the [stable release](https://openvpn.net/community-downloads) should you require it).
- ### OpenVPN 2.6_beta1 -- Released 2 December 2022
- The OpenVPN community project team is proud to release OpenVPN 2.6_beta1. This is a release with some major new features and currently in beta. You may find the [stable release](https://openvpn.net/community-downloads) should you require it.
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_rc2/Changes.rst)
+
+ Changes since RC1:
+
+ * add rate limiter for incoming "initial handshake packets", enabled by
+ default with a limit of 100 packets per 10 seconds. This change makes
+ OpenVPN servers uninteresting as an UDP reflection DDoS engine.
+ * report `CONNECTED,ROUTE_ERROR` to management GUI if connection to
+ server succeeds but not all routes can be installed (Windows and
+ !Linux/Netlink only, so far)
+ * Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_rc2/Changes.rst)
+
+ Windows MSI changes since RC1:
+ * Included openvpn-gui updated to 11.35.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.35.0.0/CHANGES.rst).
+ * New feature: Support the `CONNECTED,ROUTE_ERROR` management message (see above)
+ * Fix some issues related to upgrading:
+ * "Run on logon" option not preserved when updating from 2.5 to 2.6
+ * Fix check for running service when upgrading from old NSIS installations
+
+ Debian packages changes since RC1:
+ * Packages for Debian bookworm are now available.
+
+ New features and improvements in 2.6.0 compared to 2.5.8:
+
+ * Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
+ * OpenSSL 3 support, which is now the default on Windows.
+ * Improved handling of tunnel MTU, including support for pushable MTU.
+ * Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
+ * Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
+ * Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
+ * Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
+ * Improved protocol negotiation, leading to faster connection setup.
+ * Updated easy-rsa3 bundled with the installer on Windows.
+
+ On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-amd64.msi.asc)|[OpenVPN-2.6_rc2-I002-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-arm64.msi.asc)|[OpenVPN-2.6_rc2-I002-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-x86.msi.asc)|[OpenVPN-2.6_rc2-I002-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc2.tar.gz.asc)|[openvpn-2.6_rc2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc2.tar.gz)|
+
+ ## OpenVPN 2.6_rc1 -- Released 28 December 2022
+ The OpenVPN community project team is proud to release OpenVPN 2.6_rc1. This is a release with some major new features and currently in beta (you can also download the [stable release](https://openvpn.net/community-downloads) should you require it).
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_rc1/Changes.rst)
+
+ Changes since Beta 2:
+
+ * Officially deprecate NTLMv1 proxy auth method in 2.6. Will be removed in 2.7.
+ * Support unlimited number of connection entries and remote entries.
+ * New management commands to enumerate and list remote entries.
+ * Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_rc1/Changes.rst)
+
+ Windows MSI changes since Beta 2:
+ * Included openvpn-gui updated to 11.34.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.34.0.0/CHANGES.rst).
+ * New feature: Connections active on exit/logout are now automatically restarted in the next session of the GUI
+ * Windows installers are now built with Visual Studio 17 2022 (previously built with VS 16 2019)
+
+ New features and improvements in 2.6.0 compared to 2.5.8:
+
+ * Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
+ * OpenSSL 3 support, which is now the default on Windows.
+ * Improved handling of tunnel MTU, including support for pushable MTU.
+ * Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
+ * Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
+ * Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
+ * Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
+ * Improved protocol negotiation, leading to faster connection setup.
+ * Updated easy-rsa3 bundled with the installer on Windows.
+
+ On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-amd64.msi.asc)|[OpenVPN-2.6_rc1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-arm64.msi.asc)|[OpenVPN-2.6_rc1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-x86.msi.asc)|[OpenVPN-2.6_rc1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc1.tar.gz.asc)|[openvpn-2.6_rc1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc1.tar.gz)|
+
+ ## OpenVPN 2.6_beta2 -- Released 15 December 2022
+ The OpenVPN community project team is proud to release OpenVPN 2.6_beta2. This is a release with some major new features and currently in beta (you can also download the [stable release](https://openvpn.net/community-downloads) should you require it).
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_beta2/Changes.rst)
+
+ Changes since Beta 1:
+
+ * Transport statistics (bytes in/out) for DCO environments. Currently only for Windows clients and FreeBSD servers. Other platforms will be fixed in next release.
+ * Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_beta2/Changes.rst)
+
+ Windows MSI changes since Beta 1:
+ * Included openvpn-gui updated to 11.33.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.33.0.0/CHANGES.rst).
+ * Update included pkcs11-helper so it can load pkcs11 providers from outside of its own install directory.
+ * Add legacy provider for included OpenSSL so that the workarounds documented for old ciphers work on Windows.
+
+ New features and improvements in 2.6.0 compared to 2.5.8:
+
+ * Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
+ * OpenSSL 3 support, which is now the default on Windows.
+ * Improved handling of tunnel MTU, including support for pushable MTU.
+ * Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
+ * Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
+ * Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
+ * Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
+ * Improved protocol negotiation, leading to faster connection setup.
+ * Updated easy-rsa3 bundled with the installer on Windows.
+
+ On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-amd64.msi.asc)|[OpenVPN-2.6_beta2-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-arm64.msi.asc)|[OpenVPN-2.6_beta2-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-x86.msi.asc)|[OpenVPN-2.6_beta2-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta2.tar.gz.asc)|[openvpn-2.6_beta2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta2.tar.gz)|
+
+ ## OpenVPN 2.6_beta1 -- Released 2 December 2022
+ The OpenVPN community project team is proud to release OpenVPN 2.6_beta1. This is a release with some major new features and currently in beta (you may find [stable release](https://openvpn.net/community-downloads) should you require it).
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_beta1/Changes.rst)
- This release includes numerous new features and improvements similar to those listed for Beta 2.| Description | GnuPG Signature | Download Link |
- |-------------|-----------------|---------------|
- | **Windows 64-bit MSI installer** | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-amd64.msi.asc) | [OpenVPN-2.6_beta1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-amd64.msi) |
- | **Windows ARM64 MSI installer** | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-arm64.msi.asc) | [OpenVPN-2.6_beta1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-arm64.msi) |
- | **Windows 32-bit MSI installer** | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-x86.msi.asc) | [OpenVPN-2.6_beta1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-x86.msi) |
- | **Source archive file** | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta1.tar.gz.asc) | [openvpn-2.6_beta1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta1.tar.gz) |
+ There were a number of new features and improvements:
+
+ * Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
+ * OpenSSL 3 support, which is now the default on Windows.
+ * Improved handling of tunnel MTU, including support for pushable MTU.
+ * Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
+ * Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
+ * Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
+ * Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
+ * Improved protocol negotiation, leading to faster connection setup.
+ * Updated easy-rsa3 bundled with the installer on Windows.
+
+ On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-amd64.msi.asc)|[OpenVPN-2.6_beta1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-arm64.msi.asc)|[OpenVPN-2.6_beta1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-x86.msi.asc)|[OpenVPN-2.6_beta1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta1.tar.gz.asc)|[openvpn-2.6_beta1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta1.tar.gz)|
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9