Commit 17e8ad
2025-05-12 12:52:17 Samuli Seppänen: -/-| /dev/null .. Meetings/2025-05-07.md | |
| @@ 0,0 1,146 @@ | |
| + | # Basic info |
| + | |
| + | * Time: Wednesday 7 May 2025 at 14:00 CEST (12:00 UTC) |
| + | * Place: #openvpn-meeting channel on !LiberaChat IRC network |
| + | |
| + | # Topics |
| + | |
| + | ## Current topics |
| + | |
| + | * **Updated: security mailing list**\ |
| + | ''Contact page was updated (probably by accident) before it was approved.''\ |
| + | ''There are several items that community would like to see addressed before it gets updated.'' |
| + | |
| + | * **Updated: community.openvpn.net wiki**\ |
| + | ''On May 12 around 14:30 CET the community wiki will be switched to otterwiki.'' |
| + | |
| + | * **Updated: Release 2.7**\ |
| + | ''Current estimates are to have all major code items in by May 1st and then a release on July 1st.''\ |
| + | ''Because DCO kernel upstreaming was completed, a backport of that code was made. It will become the new DCO module and is incompatible with the old one.''\ |
| + | ''OpenVPN master which will become 2.7 now has the userspace code to support the new DCO code, so when 2.7 goes out, so will the new DCO module.'\ |
| + | ''An application was submitted to OTF for a security audit of DCO-WIN.''\ |
| + | ''For the security audit on 2.7 we need to make some 2.7-alpha version.''\ |
| + | ''Regarding the arm64 openssl issue that we encountered, according to microsoft, this was a bug in MSVC build tools and the new (preview) version has it fixed.'' |
| + | |
| + | * **New: OpenVPN GUI improvements**\ |
| + | ''With OpenVPN 2.7 it will be possible to support server with DCO, whereas before it had to tap/wintun.''\ |
| + | ''We already wanted to remove wintun, so we'll implement a logic to autodetect if we can remap wintun to DCO otherwise TAP.''\ |
| + | ''Additionally OpenVPN GUI will add ability to add new adapters as needed, if more than one connection is active at a time.'' |
| + | |
| + | * **new --dns option support**\ |
| + | ''https://gerrit.openvpn.net/q/topic:%22dns+option%22''\ |
| + | ''Implementation for unix-like has needed approvals but needs to go in. Windows implementation is done and in.''\ |
| + | ''Currently work is being done on expanding the test framework to test the new DNS options - server-side of that is done, client side needs to comply.'' |
| + | |
| + | * **forums situation**\ |
| + | ''Situation in a nutshell; old forums got flooded with spam. attempt was made to make new forums to fix it. this was aborted. now we're in limbo.''\ |
| + | ''We now have someone from OpenVPN Inc to help us fix it up, so we'll let him try.'' |
| + | |
| + | * **push_update / live route updates**\ |
| + | ''Client-side support looks to be relatively straight-forward.''\ |
| + | ''Server-side support patch is up and requires review and is a bit more involved.'' |
| + | |
| + | --- |
| + | |
| + | == Backlog == |
| + | |
| + | * **data format v3 / epoch data keys**\ |
| + | ''Implementation in user space in OpenVPN2 and OpenVPN3 are both done now.''\ |
| + | ''Developing support for epoch data keys in DCO Linux is on hold until upstreaming to Linux kernel is done.''\ |
| + | ''Developing support for epoch data keys in DCO Windows is unblocked - to be picked up by lev when he is able.'' |
| + | |
| + | |
| + | |
| + | * **t_server_null improvements**\ |
| + | ''ovpnlwip seems to work fine on all linux platforms, based on buildbot tests.''\ |
| + | ''This is in cron2's backlog to review.'' |
| + | |
| + | * **community downloads hard to find on main website**\ |
| + | ''Three suggestions that will be passed on to company:''\ |
| + | ''1. rename community to open source, there is a consensus in the meeting that community could be anything and open source is specific to openvpn open source software.''\ |
| + | ''2. open source community would prefer to see open source downloads back on the 'second line' main menu.''\ |
| + | ''3. it was suggested to add a call to action like "looking for open source downloads?" at the bottom of the page.'' |
| + | |
| + | * **OpenVPN SEO**\ |
| + | ''There is a request from OpenVPN whether we could exclude build.openvpn.net and gerrit.openvpn.net from search engines to not muddle search''\ |
| + | ''results for openvpn with developer-only resources. We will need more information about the actual problem they see before doing something like that.'' |
| + | |
| + | * **TLS-exporter in mbedtls**\ |
| + | ''Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls.''\ |
| + | ''maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work.''\ |
| + | |
| + | * **snapshot releases via Chocolatey software**\ |
| + | ''mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.''\ |
| + | ''Seems like the maintainer is amenable to helping us achieve that goal.'' |
| + | |
| + | * **OpenVPN community meetup 2025**\ |
| + | ''https://community.openvpn.net/openvpn/wiki/CommunityMeetup2025''\ |
| + | ''When: september/october ish, a poll for checking availibity is here: https://nuudel.digitalcourage.de/NROHeFlkfaYnoNGC ''\ |
| + | ''Where: Napoli, Italy.''\ |
| + | ''Meeting room: tbd.''\ |
| + | ''Hotel: tbd.''\ |
| + | ''Beer: yes.''\ |
| + | ''T-shirts: yes.'' |
| + | |
| + | * **2.7 security audit**\ |
| + | ''ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code. |
| + | |
| + | * **forums topics**\ |
| + | ''novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.'' |
| + | |
| + | * **Tunnelcrack progress (see TunnelCrack community wiki article)\ |
| + | ''Status update on TunnelCrack mitigations:''\ |
| + | ''The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.''\ |
| + | ''Windows, openvpn2: block-local merged to master, not to 2.6.x. openvpn3: in code review.''\ |
| + | ''Linux, openvpn2: in progress. openvpn3: in progress.''\ |
| + | ''macOS: to be determined.''\ |
| + | ''iOS: to be determined.''\ |
| + | ''Android: not vulnerable.'' |
| + | |
| + | * **run tests of 2.x against openvpn3? how?**\ |
| + | ''There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.''\ |
| + | ''This is in the openvpn3 repository.'' |
| + | |
| + | * **donation collection**\ |
| + | ''From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.''\ |
| + | ''What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.''\ |
| + | ''There are some options to consider. There may be existing solutions that we want to consider.''\ |
| + | ''PayPal seems overly expensive with all their fees.''\ |
| + | ''Stripe could be worth considering for credit card processing.''\ |
| + | ''GitHub Sponsors was mentioned as a possible solution, this is worth investigating.''\ |
| + | ''Open Collective was also mentioned, that needs some investigating how that exactly would work for us.'' |
| + | |
| + | * **Community AWS account governance**\ |
| + | ''Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization''\ |
| + | ''With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.''\ |
| + | ''Requires further discussion whether that is something we want.'' |
| + | |
| + | * **website release process**\ |
| + | ''Waiting for faster way to update community downloads and security advisories on main site.''\ |
| + | ''Again postponed due to issues. Now planned for this week. We'll see.'' |
| + | |
| + | * **Status of SBOM**\ |
| + | ''There was a discussion between MaxF and djpig and others.''\ |
| + | ''For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.''\ |
| + | ''The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.'' |
| + | |
| + | * **Static-key mini how-to is outdated.**\ |
| + | ''This page is outdated badly: https://openvpn.net/community-resources/static-key-mini-howto/ ''\ |
| + | ''company will send this to tech writer to redo based on https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst info\ |
| + | and also retain a link to that github doc.\ |
| + | having a simple guide online will help adoption'' |
| + | |
| + | * **OpenVPN 2.6 performance results.**\ |
| + | ''tests should cover: gre, ipsec, userland, dco''\ |
| + | ''linux, freebsd, windows''\ |
| + | ''requires time to be dedicated to doing this, when time available will do it'' |
| + | |
| + | * **What's going on with new taskbar icons?**\ |
| + | ''matt provided icons in https://github.com/OpenVPN/openvpn-gui/issues/595 ''\ |
| + | ''last update: will be picked up by selva when he has time'' |
| + | |
| + | * **software code signing topic**\ |
| + | ''company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.''\ |
| + | ''in future we could possibly switch community to that same key. saves having to maintain 2 different keys.''\ |
| + | ''depends on how hard/easy it is to access company key signing thingee from community infrastructure.''\ |
| + | ''also no high priority at the moment, we have a working solution now.'' |
