There are still things ongoing in regards to the security audit but no new major findings so far.
-
Still have items to review and go through, but this is ongoing.
-
-
## Backlog
-
-
- **t_server and t_client testing framework**
-
mattock asked where to put the t_server stack as it is currently on ordex's open source fund funded AWS account but funds might dry up there.
-
Discussed option to move it to OpenVPN Inc. funded AWS community account. Will explore this option.
-
Needs to be picked up by either djpig or uddr.
-
-
- **Tunnelcrack progress (see TunnelCrack community wiki article)**
-
Status update on TunnelCrack mitigations:
-
The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
-
Windows, openvpn2: block-local merged to master, not to 2.6.x. openvpn3: in code review.
-
Linux, openvpn2: in progress. openvpn3: in progress.
-
macOS: to be determined.
-
iOS: to be determined.
-
Android: not vulnerable.
+
Still have items to review and go through, but this is ongoing.