Commit 29409e
2025-09-11 09:55:10 novaflash: -/-| /dev/null .. Meetings/2025/2025-09-10.md | |
| @@ 0,0 1,81 @@ | |
| + | # Basic info |
| + | |
| + | * Time: Wednesday 3 September 2025 at 14:00 CEST (12:00 UTC) |
| + | * Place: #openvpn-meeting channel on !LiberaChat IRC network |
| + | |
| + | # Topics |
| + | |
| + | - **Updated: OpenVPN community meetup 2025** |
| + | https://community.openvpn.net/openvpn/wiki/CommunityMeetup2025 |
| + | When: 25 and 26 october (Saturday and Sunday), with travel days on the Friday before and Monday after. |
| + | Where: Naples, Italy. |
| + | Meeting room: https://www.hotelparadisonapoli.it/en/home-page.aspx |
| + | Hotel: Paradiso Napoli Hotel. |
| + | Beer: yes. |
| + | T-shirts: yes. |
| + | Invites were sent to openvpn-devel and some selected individuals. If we missed anyone please reach out. |
| + | Current status is we have asked Matt the designer to come up with a t-shirt design. |
| + | |
| + | - **Updated: Release 2.7** |
| + | OpenVPN 2.7 beta1 was released on 4th of September. |
| + | The intention is to follow up with OpenVPN 2.7 beta2 on 18th of September. |
| + | |
| + | - **forums situation** |
| + | minx offered to set up a new forum and help us migrate old data to it. |
| + | We have a new setup with flarum at a hidden location and we're trying to get the old forums data in there. |
| + | The tool for that called nitroporter had some difficulty, partially because the database is just so huge, but there is some progress. |
| + | Sad news; minx left openvpn inc. however, he does still want to try to get this working and is helping us still. |
| + | Once the migration is done, we can run some tests, and see if it meets our standards. Then we can plan a cutover date. |
| + | To the question where the instance should be hosted, community indicates it should be under the community AWS infrastructure. |
| + | To the question what authentication system should be used, community indicates it should just be the built-in system from the forum solution itself. |
| + | |
| + | - **wolfSSL license changed from gplv2 to gplv3** |
| + | The release notes of wolfSSL indicate the license changed to GPLv3. This basically makes wolfSSL incompatible in regards to licensing with OpenVPN. |
| + | An issue was opened on github and we received a response to give them some time to come up with a solution https://github.com/wolfSSL/wolfssl/issues/9143 |
| + | |
| + | - **t_server and t_client testing framework** |
| + | mattock reports progress on building automated testing environment for really old OpenVPN versions. |
| + | This covers tests for versions going back to 2.2. |
| + | |
| + | - **push_update / live route updates** |
| + | Client-side support for push_update is now merged. |
| + | For server-side support, company did QA on it with openvpn2 but found some missing features that are being added now. |
| + | Client-side support made it into alpha3. |
| + | |
| + | - **format code using clang formatting** |
| + | It seems prudent to do this before the real 2.7 release. |
| + | It was discussed and there's some additional work to be paid either on reviewer or submitter side. |
| + | Strategy will be; get all code into beta1, collect bugfixes, reformat everything, then beta2. |
| + | Collect more bugfixes and then do release 2.7.0 and branch it off into its own release branch. |
| + | |
| + | - **cve.mitre.org deprecation notice** |
| + | The MITRE CVE site we are linking to for all CVE record references has a deprecation notice. Instead cve.org is being advised as the site to use from now on. |
| + | novaflash made an internal company ticket to update links on the main site. |
| + | novaflash search/replaced all the CVE links on community wiki to the new address. |
| + | |
| + | ## Backlog |
| + | |
| + | - **build failures** |
| + | Changes in Gerrit do not automatically pick up fixes from master, so sometimes we see a lot of build failures even though those are fixed in master. |
| + | Some options were discussed, seems like the one preferred is to reject pushes that are behind. djpig will look into it. |
| + | |
| + | - **2.7 security audit** |
| + | ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code. |
| + | |
| + | - **Tunnelcrack progress (see TunnelCrack community wiki article)** |
| + | Status update on TunnelCrack mitigations: |
| + | The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this. |
| + | Windows, openvpn2: block-local merged to master, not to 2.6.x. openvpn3: in code review. |
| + | Linux, openvpn2: in progress. openvpn3: in progress. |
| + | macOS: to be determined. |
| + | iOS: to be determined. |
| + | Android: not vulnerable. |
| + | |
| + | - **donation collection** |
| + | From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations. |
| + | What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on. |
| + | There are some options to consider. There may be existing solutions that we want to consider. |
| + | PayPal seems overly expensive with all their fees. |
| + | Stripe could be worth considering for credit card processing. |
| + | GitHub Sponsors was mentioned as a possible solution, this is worth investigating. |
| + | Open Collective was also mentioned, that needs some investigating how that exactly would work for us. |
