Commit 29aa5c

2025-10-13 15:21:27 uddr: 2.7_beta3 release
Downloads.md ..
@@ 1,16 1,16 @@
- ## OpenVPN 2.7_beta2 -- Released 25 September 2025
- The OpenVPN community project team is proud to release OpenVPN 2.7_beta2. This is the second Beta release for the feature release 2.7.0. As the Beta name implies this is an early release build, it is not intended for production use.
+ ## OpenVPN 2.7_beta3 -- Released 13 October 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.7_beta3. This is the third Beta release for the feature release 2.7.0. As the Beta name implies this is an early release build, it is not intended for production use.
- Feature changes since 2.7_beta1:
- * greatly improved event log handling for the Windows interactive service - this brings build system changes and a new openvpnservmsg.dll
+ Feature changes since 2.7_beta2:
+ * improvements on PUSH_UPDATE handling on the server side
+ * improve "recursive routing checks", prepare the way for a policy-based setup where "packets to VPN server" could end up in the tunnel without interfering with OpenVPN operations
+ * add support for "eoch" data format to DCO on Windows (needs dco-win driver 2.8.0+)
+ * clean up and remove outdated stuff from COPYING
- Important bug fixes since 2.7_beta1:
- * add proper input sanitation to DNS strings to prevent an attack coming from a trusted-but-malicous OpenVPN server ([CVE-2025-10680](https://www.cve.org/CVERecord?id=CVE-2025-10680), affects unixoid systems with `--dns-updown` scripts and windows using the built-in powershell call)
- * bugfixes when using multi-socket on windows (properly recognize that TCP server mode does not work with DCO, properly handle TCP multi-socket server setups without DCO)
- * bring back configuring of IPv4 broadcast addresses on Linux
- * repair "--dhcp-option DNS" setting in combination with DHCP (TAP) or "--up" scripts (Github: [OpenVPN/openvpn#839](https://github.com/OpenVPN/openvpn/issues/839), [OpenVPN/openvpn#840](https://github.com/OpenVPN/openvpn/issues/840))
+ Important bug fixes since 2.7_beta2:
+ * bugfixes reconnect and PUSH_UPDATE handling on the client side (notably handling of ifconfig/ifconfig-ipv6/redirect-gateway ipv6 if the server is not always pushing the same address families)
- For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_beta1...v2.7_beta2).
+ For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_beta2...v2.7_beta3).
Highlights of 2.7 include:
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
@@ 34,20 34,23 @@
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
* TLS 1.3 support with bleeding-edge mbedTLS versions
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
+ * Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
+ * "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
+ * COPYING: license details only relevant to our Windows installers havebeen updated and moved to the openvpn-build repo
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_beta2/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_beta3/Changes.rst)
- Windows MSI changes since 2.7_beta1:
- * Built against OpenSSL 3.5.3
+ Windows MSI changes since 2.7_beta2:
+ * Built against OpenSSL 3.6.0
* Included openvpn-gui updated to 11.56.0.0
- * Fix "Cannot open the System Tray Menu with Keyboard" (Github: [OpenVPN/openvpn-gui#763](https://github.com/OpenVPN/openvpn-gui/issues/763))
+ * Included win-dco driver updated to 2.8.0
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-amd64.msi.asc)|[OpenVPN-2.7_beta2-I006-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-arm64.msi.asc)|[OpenVPN-2.7_beta2-I006-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-x86.msi.asc)|[OpenVPN-2.7_beta2-I006-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_beta2.tar.gz.asc)|[openvpn-2.7_beta2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_beta2.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-amd64.msi.asc)|[OpenVPN-2.7_beta3-I007-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-arm64.msi.asc)|[OpenVPN-2.7_beta3-I007-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-x86.msi.asc)|[OpenVPN-2.7_beta3-I007-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_beta3.tar.gz.asc)|[openvpn-2.7_beta3.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_beta3.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9