Commit 21a0aa

2026-03-31 15:00:25 flichtenheld: 2.7.1
Downloads.md ..
@@ 1,52 1,64 @@
- ## OpenVPN 2.7.0 -- Released 11 February 2026
- The OpenVPN community project team is proud to release OpenVPN 2.7.0.
- This is the new stable version of OpenVPN with some major new features.
-
- This release has only minor changes relative to the last release candidate release 2.7_rc6.
- For a list of these changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc6...v2.7.0).
-
- Highlights of 2.7 include:
- * Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- * Improved Client support for DNS options
- * Client implementations for Linux/BSD/macOS, included with the default install
- * New client implementation for Windows, adding support for features like split DNS and DNSSEC
- * Architectural improvements on Windows
- * The `block-local` flag is now enforced with WFP filters
- * Windows network adapters are now generated on demand
- * Windows automatic service now runs as an unpriviledged user
- * Support for server mode in win-dco driver
- * Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- * Improved data channel
- * Enforcement of AES-GCM usage limit
- * Epoch data keys and packet format
- * Support for new upstream DCO Linux kernel module
- * This release supports the new `ovpn` DCO Linux kernel module which is available in current upstream Linux kernel releases. Backports of the new module to older kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
- * Client-side support for new `PUSH_UPDATE` control-channel message
- * This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- * PUSH_UPDATE server support (minimal)
- * New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
- * TLS 1.3 support with bleeding-edge mbedTLS versions
- * Support for mbedTLS version 4
- * Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
- * Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
- * "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
- * COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
-
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.0/Changes.rst)
-
- Note: Windows MSI was updated to I017 on February 19th. Changes in I017:
- * msi: use Wix Util:EventSource to register OpenVPNService event source instead of PowerShell. GH: [openvpn-build #1230](https://github.com/OpenVPN/openvpn-build/issues/1230)
- * Included dco-win driver updated to 2.8.2
- * [CVE-2026-2738](https://www.cve.org/CVERecord?id=CVE-2026-2738): Fix TX buffer overflow in epoch AEAD encryption. GH: [ovpn-dco-win #130](https://github.com/OpenVPN/ovpn-dco-win/issues/130)
+ ## OpenVPN 2.7.1 -- Released 31 March 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.7.1. This is a bug fix release.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.1/Changes.rst)
+
+ New features:
+
+ - Add a new `username-only` flag argument to `--auth-user-pass` which
+ will now make OpenVPN only query for username and send a dummy password
+ to the server. This is only useful if auth schemes are used on the
+ server side that will do some sort of external challenge base on username,
+ and not password authentication. See discussion in
+ GH [OpenVPN/openvpn#501](https://github.com/OpenVPN/openvpn/issues/501)
+ (starting Jan 30, 2024).
+ - Increase default sizing of internal hash maps to `4 * --max-clients`.
+ The default used to be `256` with a `--max-clients` default of
+ 1024 - this is bad for performance, while the memory savings are
+ minimal. On a very memory constrained system, reduce `--max-clients`.
+
+ User-visible Changes:
+
+ - When compiled with the AWS-LC SSL library, using `--tls-cert-profile`
+ will now print a run-time warning - the library does not support it,
+ so it would silently do nothing.
+ - Systemd unit files: change LimitNPROC to TasksMax and increase limit
+ (GH: [OpenVPN/openvpn#929](https://github.com/OpenVPN/openvpn/issues/929))
+ - Documentation improvements.
+ - port-share: log incoming connections at `verb 3`, not on `error`
+ level anymore (GH: [OpenVPN/openvpn#976](https://github.com/OpenVPN/openvpn/issues/976)).
+
+ Bugfixes:
+
+ - Fix usage of `--lport` inside a `<connection>` block - this got
+ broken with the multi-socket patchset (GH: [OpenVPN/openvpn#995](https://github.com/OpenVPN/openvpn/issues/995))
+ - Do not try to run auto-pam unit test when cross-compiling.
+ - Do not break private-key passphrases of length >= 64
+ (GH: [OpenVPN/openvpn#993](https://github.com/OpenVPN/openvpn/issues/993))
+ - Fix obscure ASSERT() crash on TCP connects with TAP and no ip config.
+ - Make DCO work on FreeBSD systems that have no IPv4 support in kernel
+ (FreeBSD PR 286263)
+ - Make DCO work on Linux on big endian systems (namely, MIPS and PowerPC)
+ (GH: [OpenVPN/ovpn-dco#96](https://github.com/OpenVPN/ovpn-dco/issues/96))
+ - Fixup responses to management interface ``version`` command (for >= 4)
+ - Make `--enable-async-push` work on FreeBSD 15 (which has native
+ inotify support, and consequently no libinotify.pc anymore)
+ - Adjust some code parts to new "const" handling on string function
+ returns (ISO C23, as implemented by glibc 2.43 and newer).
+
+ Windows MSI changes since 2.7.1:
+ * Make sure that included openvpnserv2.exe is signed (GH: [OpenVPN/openvpn-build#1293](https://github.com/OpenVPN/openvpn-build/issues/1293))
+ * Included openvpn-gui updated to 11.62.0.0
+ * Translation updates
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-amd64.msi.asc)|[OpenVPN-2.7.0-I017-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-arm64.msi.asc)|[OpenVPN-2.7.0-I017-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-x86.msi.asc)|[OpenVPN-2.7.0-I017-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.0.tar.gz.asc)|[openvpn-2.7.0.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.0.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-amd64.msi.asc)|[OpenVPN-2.7.1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-arm64.msi.asc)|[OpenVPN-2.7.1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-x86.msi.asc)|[OpenVPN-2.7.1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.1.tar.gz.asc)|[openvpn-2.7.1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.1.tar.gz)|
- For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
+ For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
## OpenVPN 2.6.19 -- Released 4 February 2026
The OpenVPN community project team is proud to release OpenVPN 2.6.19. This is a bugfix release.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9