Commit 6f02e7

2025-01-29 06:40:08 Samuli Seppänen: Import meeting pages from Trac Signed-off-by: Samuli Seppänen <samuli.seppanen@gmail.com>
/dev/null .. meetings.md
@@ 0,0 1,5 @@
+ # Meetings
+
+ This is the parent page for all community meetings, excluding physical meetups.
+ The meetings are current held in IRC on [Libera.chat](https://libera.chat/) in
+ #openvpn-meeting channel at 14:00 CET/CEST.
/dev/null .. meetings/2010-04-22.md
@@ 0,0 1,14 @@
+ # Possible bugs/issues
+
+ - Several issues discussed first in [this email thread](http://thread.gmane.org/gmane.network.openvpn.devel/3446)
+ - (Windows) All error codes when using the InternetQueryOption API are lost. See also [Microsoft support](http://support.microsoft.com/kb/226473). OpenVPN 2.1 uses the "old" IE4 API.
+ - Enabling auto-proxy to work in configs that contain both UDP and TCP-based "<connection>" profiles?
+ - Similarly, there is a general problem with mixing TCP and UDP options (e.g., mssfix, nobind, fragment) as noted in this [SourceForge.net tracker item](http://sourceforge.net/tracker/index.php?func=detail&aid=2945147&group_id=48978&atid=454720)
+ - Unnecessary script-security warning? See attachment below.
+
+ # Other
+
+ - Roadmap
+ - Who will be responsible for creating and following the roadmap?
+ - How do we integrate organic development ("random" patches to ml) and planned development (roadmap)
+ - Bad TCP-over-TCP performance. What could be done to make it less bad? See [this thread](http://thread.gmane.org/gmane.network.openvpn.user/29601) and [Stephen Carville's response](http://sourceforge.net/mailarchive/forum.php?thread_name=l2s2428c0381004201943w2a0ee0a1hf4a2497d790416e6%40mail.gmail.com&forum_name=openvpn-users).
\ No newline at end of file
/dev/null .. meetings/2010-04-29.md
@@ 0,0 1,46 @@
+ # Possible bugs/issues
+
+ - Update on a few issues discussed first in [this email thread](http://thread.gmane.org/gmane.network.openvpn.devel/3446) and later in [this meeting](http://thread.gmane.org/gmane.network.openvpn.devel/3571).
+ - (Windows) All error codes when using the InternetQueryOption API are lost. See also [Microsoft Support](http://support.microsoft.com/kb/226473). Openvpn 2.1 uses the "old" IE4 API.
+ - Enabling auto-proxy to work in configs that contain both UDP and TCP-based "<connection>" profiles?
+ - In a similar vein, the following ticket is in the bug tracking system. There seems to be a general problem with mixing TCP and UDP options (e.g., mssfix, nobind, fragment) [SourceForge.net tracker item](http://sourceforge.net/tracker/index.php?func=detail&aid=2945147&group_id=48978&atid=454720)
+ - Using --inactive and --ping seems to defeat each other [Related Thread](http://thread.gmane.org/gmane.network.openvpn.devel/3556)
+
+ # Patch Queue
+
+ ## New / awaiting ACK
+
+ - [Avoid repetition of "this config may cache passwords in memory" (v2)](http://thread.gmane.org/gmane.network.openvpn.devel/3591)
+ - [Revamped the script-security warning logging (version 2)](http://thread.gmane.org/gmane.network.openvpn.devel/3587)
+ - [(PULL-REQUEST v3) VLAN-Tagging](http://thread.gmane.org/gmane.network.openvpn.devel/3489)
+ - This patch set is available via the 'feat_vlan_tagging' branch in openvpn-testing.git for review. It is not merged into allmerged at the moment. It needs an ACK to take that step. The branch will be rebuilt based on a better branch from Fabian Knittel in the near future - and before a merge into allmerged.
+
+ ## In progress - awaiting dazo
+
+ - "Unpackaged Windows binaries"
+ - [Discussion 1](http://thread.gmane.org/gmane.network.openvpn.devel/3589/focus=3593)
+ - [Discussion 2](http://thread.gmane.org/gmane.network.openvpn.devel/2566/focus=2581)
+ - [Discussion 3](http://thread.gmane.org/gmane.network.openvpn.devel/2566/focus=3147)
+
+ ## In progress / awaiting further feedback
+
+ - [MacOSX Keychain Certificate support](http://thread.gmane.org/gmane.network.openvpn.devel/3631)
+ - [MacOSX making .dmg/.pkg](http://thread.gmane.org/gmane.network.openvpn.devel/3589/focus=3613)
+ - [Solaris tun/tap support](http://thread.gmane.org/gmane.network.openvpn.devel/3660/focus=3667)
+ - Gert is supervising this patch and will merge it into his IPv6 payload tree, as he does several improvements to tun.c there.
+
+ ## Awaiting testing before ACK
+
+ - [--passtos feature](http://thread.gmane.org/gmane.network.openvpn.devel/3165/focus=3306)
+ - The VLAN patches are based on some of these changes as well, might be able to combine this testing with VLAN?
+
+ # Other
+
+ - Community site Trac configuration
+ - Plugins, editable/protected pages etc.
+ - Roadmap
+ - Who will be responsible for creating and following the roadmap?
+ - How do we integrate organic development ("random" patches to ml) and planned development (roadmap)
+ - Bad TCP-over-TCP performance. What could be done to make it less bad? See [this thread](http://thread.gmane.org/gmane.network.openvpn.user/29601) and [Stephen Carville's response](http://sourceforge.net/mailarchive/forum.php?thread_name=l2s2428c0381004201943w2a0ee0a1hf4a2497d790416e6%40mail.gmail.com&forum_name=openvpn-users).
+ - Coding style guidelines
+ - Several begins to touch this issue. Which coding style guidelines do we have? How do we enforce it? For patches the most critical one is to decide whether to use tabs or spaces.
\ No newline at end of file
/dev/null .. meetings/2010-05-06.md
@@ 0,0 1,8 @@
+ # Agenda
+
+ - James will present his views regarding OpenVPN 3.0
+
+ # Open questions
+
+ - Who will be responsible for creating and following the roadmap?
+ - How do we integrate organic development ("random" patches to ml) and planned development (roadmap)?
\ No newline at end of file
/dev/null .. meetings/2010-05-13.md
@@ 0,0 1,8 @@
+ # RoadMap
+ * Spend 10-15 minutes discussing the [roadmap document](wiki:RoadMap), focusing on OpenVPN 3.0
+
+ # Possible bugs/issues
+ * [Compiler warnings with OpenSSL 1.0.0-beta4](http://thread.gmane.org/gmane.network.openvpn.devel/3091)
+
+ # Other
+ * Will the OpenVPN community support OpenVPN AS? How? Where?
\ No newline at end of file
/dev/null .. meetings/2010-05-20.md
@@ 0,0 1,62 @@
+ # Development/testing issues
+
+ ## [Beaker test framework](https://fedorahosted.org/beaker)
+
+ Should we start configuring a dedicated testing framework for OpenVPN? This idea will be presented by _mattock_.
+
+ - **Rationale**
+ - Would allow testing that OpenVPN works on a large number of predefined platforms and configurations.
+ - Replaces part of the manual testing effort by testing the external behavior of the application automatically.
+ - Would allow spotting bugs early.
+
+ - **Implementation ideas**
+ - Beaker could perhaps be made to simulate poor connections for testing purposes. If not, there are plenty of tools and services available for this purpose (see full chatlog).
+
+ - **Limitations**
+ - Only tests for external behavior of the application.
+ - Does not replace human testing for those classes of problems which are difficult/impossible to test programmatically.
+
+ ## Continuous integration server
+
+ Should we build a continuous integration (CI) / automated release management server? This idea will be presented by _mattock_.
+
+ - **Rationale**
+ - Would allow spotting build problems early on by building "allmerged" and reporting developers of build problems.
+ - Would reduce developer frustration.
+ - Would allow automated packaging of OpenVPN-testing for various platforms and publishing those on a web server.
+ - The above would translate to increased use of OpenVPN-testing, leading to earlier bug reports and would thus make the release process (new code -> acceptance to testing -> acceptance to stable -> release) faster.
+ - Could also allow centralized automated searching of code problems.
+
+ - **Implementation ideas**
+ - Developers could be notified of problems using email.
+ - The OpenVPN project has a license to [Coverity](http://www.coverity.com/) service. As this service has an API, Coverity code analysis could be integrated into the CI server.
+
+ - **Limitations**
+ - Does not replace human testing.
+ - Only tests the build process (and possibly code problems).
+
+ ## Developer bounties
+
+ Should we have a bounty system for writing missing features? Similar systems are in use by several other projects, e.g. freeswitch, pfSense, and Funambol. This idea will be presented by _ecrist_.
+
+ - **Rationale**
+ - Would allow users to prioritize feature additions through compensation.
+ - Would help achieve greater interest of developers in users' requests and needs.
+
+ - **Implementation ideas**
+ - Bounty funds would be set up and maintained by a non-developer (ecrist?) and held. This assures payment upon completion and assures the feature is completed before bounty is paid.
+ - Multiple users could fund a bounty for intensive feature additions which may warrant higher payouts.
+ - Developers set up accounts and 'claim' tasks.
+ - After a specific timeout, a task becomes available to another user, unless progress can be shown.
+ - Payment could be divided into multiple phases to motivate developers to maintain the code they've written. For example:
+ - 50% payout for a commit to the main tree.
+ - 25% upon release in production (provided bugs are fixed/etc).
+ - 25% 6 months after release (provided bugs are fixed/etc).
+ - The above would also guarantee the quality of the code.
+ - Handling monetary transactions:
+ - Could be handled through an external foundation/organization (e.g., [SPI](http://www.spi-inc.org/projects)).
+ - We could establish our own foundation for this purpose.
+ - Licensing and copyright:
+ - Developer would have to use the BSD license for the bounty features.
+ - This would allow the project to relicense the code under GPLv2 (while mentioning the original author).
+ - This would allow both developer (payee) and payer to use the code any way they wish.
\ No newline at end of file
/dev/null .. meetings/2010-05-27.md
@@ 0,0 1,26 @@
+ # Development Process
+
+ ## Background
+ - The first phase of the development process (work done in "testing") is handled properly.
+ - The last phase of the development process, official releases, are handled by James, but the process/requirements for a release are not documented.
+ - Right now, "testing" is effectively a fork of James' "stable" SVN tree.
+ - There is no roadmap for the next 2.x release.
+
+ ## Which Tree to Base Releases On?
+
+ ### Option 1: Basing Releases on James' "Stable" Tree
+ - There's no process to move code from "testing" (git) to "stable" (svn).
+ - The release process is not documented.
+
+ ### Option 2: Basing Releases on David's "Testing" Tree
+ - Currently, James makes his modifications to his SVN tree and David pulls his changes to "testing". In this regard, James' SVN tree is no different from any other external tree.
+ - Only David's "allmerged" branch contains all code (James', external trees, etc.).
+ - The "testing" tree should get the widest testing, especially after we start releasing testing snapshots and linking to them from openvpn.net.
+
+ ## How to Verify Stability of the "Testing" Code (for Moving to "Stable" or Prior to a Release?)
+ - Publishing or linking to "testing" releases on openvpn.net is essential to get wider use for "testing".
+
+ # Other
+
+ ## Bridging Issues
+ - From [OpenVPN FAQ on Bridging](http://openvpn.net/index.php/open-source/faq.html#bridge1): "Another bridge disadvantage should be that layer2 is insecure by design, opening your layer2 exposes to ARP poisoning and the like."
\ No newline at end of file
/dev/null .. meetings/2010-06-03.md
@@ 0,0 1,19 @@
+ # Potential bugs
+
+ - [Openvpn-devel openvpn-2.1.0-r1: easy-rsa tools creates broken client CERTs unusable for TLS](http://thread.gmane.org/gmane.network.openvpn.devel/3703)
+ - Dynamic iroute behaviour:
+ - Do we want this feature and if yes, should it also be a configurable runtime option and not just compile time config option?
+ - [Discussion 1](http://thread.gmane.org/gmane.network.openvpn.devel/3691)
+ - [Discussion 2](http://thread.gmane.org/gmane.network.openvpn.devel/3722)
+ - [Not using --push on server makes client sending PUSH_REQUEST continuously](https://community.openvpn.net/openvpn/ticket/13)
+ - [Handling of subnets grammar in Packet filter file](http://thread.gmane.org/gmane.network.openvpn.devel/3721)
+ - [Proposed fix](https://community.openvpn.net/openvpn/ticket/14)
+
+ # Next release (2.2)
+
+ - What features should include in it?
+
+ # Other
+
+ - From reg9009: State/instance synchronization between OpenVPN instances (transparent failover option)
+ - Needs additional clarifications
\ No newline at end of file
/dev/null .. meetings/2010-06-10.md
@@ 0,0 1,13 @@
+ # Potential bugs
+
+ - [Not using --push on server makes client sending PUSH_REQUEST continuously](https://community.openvpn.net/openvpn/ticket/13)
+
+ # Patches
+
+ - [Handle non standard subnets in PF grammar](https://community.openvpn.net/openvpn/ticket/14)
+ - [Enabling Accounting/Stats for plugins](https://community.openvpn.net/openvpn/ticket/15)
+ - This could be useful for instance for radius based plugins
+
+ # Next release (2.2)
+
+ - What features should include in it?
\ No newline at end of file
/dev/null .. meetings/2010-06-17.md
@@ 0,0 1,10 @@
+ # Bugs
+
+ * Update on [TCP and UDP connections aren't possible in client mode](http://sourceforge.net/tracker/?func=detail&aid=2947626&group_id=48978&atid=454719)
+
+ # Other
+
+ * Community services status update
+ * Links from openvpn.net to community.openvpn.net coming up...
+ * Forums
+ * Continuous integration / packaging / publishing server ("Buildbot")
\ No newline at end of file
/dev/null .. meetings/2010-07-01.md
@@ 0,0 1,28 @@
+ # Development Discussion
+
+ - [Issues with SVN in the Beta 2.2 branch](http://thread.gmane.org/gmane.network.openvpn.devel/3806)
+
+ - [Buildbot](http://buildbot.net/trac) ([manual](http://djmitche.github.com/buildbot/docs/0.7.12/))
+ - How to inform developers of build successes/warnings/failures?
+ - Using `openvpn-devel`: ~500 subscribers, most don't care about these
+ - Using a separate mailing list (openvpn-commits/builds): requires yet another subscription
+ - Use an IRC notifier (#openvpn-devel)
+ - Should we limit access to the buildbot web interface?
+ - Most people have no use for it
+ - Public access increases risk of getting BuildBot hacked
+ - Ways to limit access: basic AUTH / SSH access + port forwarding / OpenVPN tunnel
+ - Where do we get the BuildSlaves?
+ - Background information: BuildSlaves are responsible for testing the builds. The idea is to have buildslaves running a variety of OSes (e.g. FreeBSD, Debian, Fedora). Each can then build and package OpenVPN for their respective platform. BuildSlaves run buildbot and connect to the BuildMaster server and accept BuildRequests (commands) from it. They do not need to be online all the time, but that's beneficial. They can work from behind a firewall, as they initiate the TCP connection to the BuildMaster.
+ - Should we ask our community members to provide BuildSlaves?
+ - Should we create "always online" virtual machines to provide BuildSlaves?
+ - Should we combine both approaches?
+ - What setup do we want to use to trigger builds?
+ - Option 1: use a commit mailing list and configure BuildBot to detect commits from the mails - should be relatively clean and well-supported option
+ - Option 2: developer sends a git push -> sf.net server accepts the push and updates the remote git tree -> server side calls `.git/hooks/post-update` which does a `curl https://community.openvpn.net/buildbot/git-updated` -> community.openvpn.net executes a script by the webserver which executes the git_buildbot.py script in the background and responds OK -> git_buildbot.py will then trigger a fetch and do a build
+
+ # Misc
+
+ - Launch date for forums.openvpn.net
+ - [OpenWRT wiki article](http://www.secure-computing.net/wiki/index.php/OpenVPN/OpenWRT) by cron2
+ - Feedback?
+ - Which wiki to use: [Secure Computing MediaWiki](http://www.secure-computing.net/wiki/index.php/Main_Page) or [OpenVPN Trac wiki](https://community.openvpn.net/openvpn/wiki)
\ No newline at end of file
/dev/null .. meetings/2010-07-08.md
@@ 0,0 1,16 @@
+ # Development issues
+
+ - [Issues with the beta 2.2 branch in SVN](http://thread.gmane.org/gmane.network.openvpn.devel/3806)
+
+ # New features
+
+ - Suggestion from Jason Haar: under Unix, the "http_proxy" environment variable is typically used to refer to the URL (e.g., http://proxy.server:portnum/) of the appropriate proxy server. Currently, OpenVPN's "auto-proxy" only supports Windows - surely it wouldn't take more than 20 lines of code to check that env var for Unix systems? I know it's not a thorough solution - but there isn't one for Unix systems - that's as good as it gets...
+ - [OpenVPN ticket #17](https://community.openvpn.net/openvpn/ticket/17) ... needs testing on OpenBSD - just to raise the attention to James on this one as well
+
+ # Bugs
+
+ - Another bug being debugged with OpenBSD as well, which krzee discovered lately - broken topology subnet
+
+ # Misc
+
+ - Buildbot update - how to get -testing packages ready for more distros
\ No newline at end of file
/dev/null .. meetings/2010-07-15.md
@@ 0,0 1,13 @@
+ # Bugs
+
+ * [Build failure on OpenBSD 4.7 IFF_MULTICAST](https://community.openvpn.net/openvpn/ticket/17)
+ * Fixed, needs testing and an ACK
+
+ # Development issues
+
+ * What release cycle length to aim for?
+ * How do we tackle security issues? (e.g., CVEs) How are they announced?
+
+ # Community services
+
+ * Status update on forums.openvpn.net
\ No newline at end of file
/dev/null .. meetings/2010-07-22.md
@@ 0,0 1,12 @@
+ # Development issues
+
+ - What release cycle length to aim for?
+ - [Merge conflict merging in last changes from SVN r6291](http://thread.gmane.org/gmane.network.openvpn.devel/3845)
+
+ # Bugs
+
+ - [push-reset should not reset topology and route-gateway from global config](https://community.openvpn.net/openvpn/ticket/29)
+
+ # Other
+
+ - Status update on forums and buildbot
\ No newline at end of file
/dev/null .. meetings/2010-07-29.md
@@ 0,0 1,17 @@
+ # Development
+
+ - Patches
+ - [Ticket #20](https://community.openvpn.net/openvpn/ticket/20) [Fix multiple configured scripts conflicts issue](http://thread.gmane.org/gmane.network.openvpn.devel/3839)
+
+ - Beta 2.2
+ - When will we officially release the 2.2 beta?
+ - Set a date for when the RC candidate should be released
+
+ - Automated testing
+ - Unit testing
+ - Which parts of code to write tests for?
+ - Testing that OpenVPN behavior
+ - Role of Beaker framework?
+ - Role of "make test" -type testing
+ - Code security testing
+ - Integrating [Valgrind](http://valgrind.org/) and [Coverity](http://www.coverity.com/) into Buildbot
\ No newline at end of file
/dev/null .. meetings/2010-08-05.md
@@ 0,0 1,27 @@
+ # OpenVPN Beta 2.2 Release Blockers
+
+ ## Remaining Trac Tickets
+
+ OpenVPN 2.2 beta is technically ready for release except for a few trivial work in progress issues:
+
+ - [Ticket 18](https://community.openvpn.net/openvpn/ticket/18)
+ - [Ticket 20](https://community.openvpn.net/openvpn/ticket/20)
+
+ ## Lack of Windows Client Binaries and Signed TUN/TAP Drivers
+
+ All beta 2.2 packages except *Windows binaries* can be built automatically by Buildbot. Cross-compiling Windows binaries on *NIX* **with** the TUN/TAP drivers is not possible. Therefore, a Windows computer has to be used. Unfortunately, nobody (we know of) in the community has a Windows setup that could be used to build Windows client binaries and/or signed TUN/TAP drivers for 2.2 beta.
+
+ **Question:** Who will take care of creating the Windows beta 2.2 packages/installers?
+
+ ## Hosting of OpenVPN 2.2 Beta Releases
+
+ Where shall we host the OpenVPN 2.2 beta releases? The easiest and least error-prone setup would be the following:
+
+ - Host beta releases on **build.openvpn.net**: allows buildslaves to push new builds to the public without manual intervention.
+ - Provide a direct link to the latest release from **openvpn.net**.
+
+ ## Announcing the 2.2 Beta Release
+
+ We also need to officially announce the beta 2.2 release. Any community/company member can send an email to openvpn-devel, openvpn-user, and post to ovpnforum.com (soon forums.openvpn.net). Someone from the company would need to announce the release on Twitter and our web pages.
+
+ **Question:** Who will take care of these announcements?
\ No newline at end of file
/dev/null .. meetings/2010-08-12.md
@@ 0,0 1,9 @@
+ # Development issues
+
+ - Beta 2.2 will be released tomorrow: what is still missing (if anything)?
+ - Set the deadline for next beta release
+
+ # Bugs
+
+ - [BSOD hangs when is TAP- enabled. Hyperthreaded or dual core.](http://sourceforge.net/tracker/?func=detail&atid=454719&aid=3043623&group_id=48978)
+ - [push-reset should not reset topology and route-gateway from global config](https://community.openvpn.net/openvpn/ticket/29)
\ No newline at end of file
/dev/null .. meetings/2010-08-19.md
@@ 0,0 1,14 @@
+ # Development Issues
+
+ ## Issues with Release of OpenVPN 2.2-beta2
+ - James uses a script to generate the "Downloads" page on openvpn.net, which can't be edited directly by Samuli. Can James make the 2.2-beta2 release?
+ - Windows client binary for beta2 is still missing: James is working on this. When will this be ready?
+ - "Windows TAP driver not signed" issue with 2.1.2: does this affect 2.2-beta2?
+
+ ## Relationship and Purpose of 2.1.x and 2.2 Series
+ - Is 2.1.x a pure bugfix/maintenance release? If not, should it be?
+ - Should the 2.1.x series be discontinued once 2.2 is stable?
+ - In general, we should probably try to avoid adding new features to proven, stable releases (e.g., 2.1.x). The "testing" tree and betas are safer places for those.
+
+ ## Communication Improvements Needed
+ - Communication between community and company developers definitely needs improvement: the 2.2-beta release has been postponed almost 3 weeks now, mostly due to communication issues. How do we fix this?
\ No newline at end of file
/dev/null .. meetings/2010-08-26.md
@@ 0,0 1,12 @@
+ # Development
+
+ - **Status of OpenVPN 2.1.3**
+ - James' RC works for all those who previously had problems with drivers signing on Vista/7
+ - When will it be released? 2.2-beta3 depends on this release.
+ - [Compiling OpenVPN v2.1.2 with enable-password-save option](https://forums.openvpn.net/viewtopic.php?f=10&t=7023)
+ - [Some way of supporting static compilation](https://community.openvpn.net/openvpn/ticket/46)
+ - [More Flexible TLS Verification for plugins](https://community.openvpn.net/openvpn/ticket/44)
+
+ # Packaging
+
+ - New Gentoo 2.2 beta packages: what's their status?
\ No newline at end of file
/dev/null .. meetings/2010-09-02.md
@@ 0,0 1,13 @@
+ # Development issues
+
+ - 2.2-beta3 status update
+ - [Code clean-up: pthread and mutex locking code++](http://thread.gmane.org/gmane.network.openvpn.devel/3941)
+ - OpenVPN test server (for use with "make test")
+
+ # Misc
+
+ ## Translations
+ - Lack of translator documentation
+ - What is worth translating and what is not
+
+ ## Openvpn.net "Client software -> Downloads" page confusion
\ No newline at end of file
/dev/null .. meetings/2010-09-16.md
@@ 0,0 1,13 @@
+ # Development issues
+
+ - [Windows route setup broken after standby](https://community.openvpn.net/openvpn/ticket/56)
+ - This is a nasty, old bug that has been around since 2004. What can be done to fix this?
+ - Are we talking about one bug, or several that have the same symptoms? Some can't reproduce this on WinXP anymore, only on Windows 7 (or Vista?)
+
+ # Other
+
+ - Wayne's VPS server offer (Wayne will be present)
+ - What to use the server for?
+ - Buildslave?
+ - Public OpenVPN test server?
+ - What OS to select?
\ No newline at end of file
/dev/null .. meetings/2010-09-23.md
@@ 0,0 1,20 @@
+ # Development Issues
+
+ - **Alon's build system patch + splitting Windows TAP driver, Windows installer, and easy-rsa into separate git trees.**
+ - Both issues discussed in detail in [this email thread](http://thread.gmane.org/gmane.network.openvpn.devel/3991).
+
+ - **Buildbot**
+ - Setting up a dedicated `openvpn-builds` mailing list.
+ - Buildbot can generate a lot of traffic if several builds fail at once. We definitely don't want `openvpn-devel` to get flooded with these.
+ - Some of the less important messages can be deactivated as necessary to reduce spam.
+ - Setting up a dedicated `openvpn-commits` list.
+ - Buildbot needs to know when a commit has been made so that it can trigger a build. There is a buildbot git hook available, but it can't be easily used with SF.net Git server. Also, there's no built-in RSS support which could be used to read SF.net Git commit RSS feed.
+ - Probably the easiest solution to triggering builds is to set up a dedicated `openvpn-commits` mailing list which buildbot can monitor and use to trigger builds. In case something goes wrong with the build, Buildbot can use the email to figure out the developer responsible for the broken patch and mail him privately ("blame" him in buildbot parlance).
+ - Parsing `openvpn-devel` can be risky, as it's an open list. Somebody might misuse buildbot by simply sending mails which look like git commit mails.
+ - SF.net mailing lists can be configured to be read-only and to accept mails from specific addresses (e.g. `buildmaster@buildbot-server-address`). This means they're safe to use in this kind of configurations.
+ - Could these two lists (`-builds` and `-commits`) be combined into one, e.g., `openvpn-buildbot`?
+ - Do we also want [IRC notifications](http://buildbot.net/buildbot/docs/0.7.12/#IRC-Bot) to `#openvpn-devel`?
+
+ - **Windows Builds**
+ - When will the next beta release be made?
+ - Should `mattock` focus on Windows builds right after the above buildbot stuff?
\ No newline at end of file
/dev/null .. meetings/2010-10-14.md
@@ 0,0 1,10 @@
+ # Patches
+
+ - [Support SOCKS plain text authentication](https://community.openvpn.net/openvpn/ticket/62). Patch also sent to the openvpn-devel mailing list. No ACK/NACK yet.
+ - [HTTP/1.1 Host header](http://thread.gmane.org/gmane.network.openvpn.devel/4039): Has received ACKs, but is not yet committed to the git repo.
+ - [Dynamic-Iroute config option for automatic iroutes](http://thread.gmane.org/gmane.network.openvpn.devel/4059). No ACK/NACK yet.
+
+ # Other
+
+ - Buildbot status update
+ - Public test server status update
\ No newline at end of file
/dev/null .. meetings/2010-10-21.md
@@ 0,0 1,4 @@
+ # Bugs
+
+ * agi found a potential issue with daemon() being called in plug-ins - this needs James' review
+ * [LOTS of bogus routes added on client connect](https://community.openvpn.net/openvpn/ticket/64) - hopefully fixed for good
\ No newline at end of file
/dev/null .. meetings/2010-11-18.md
@@ 0,0 1,18 @@
+ ## Generic
+ - [Handling security vulnerabilities](http://thread.gmane.org/gmane.network.openvpn.devel/3841)
+
+ ## OpenVPN 2.2-beta4
+ - When to release beta4? Which pieces are missing?
+ - Updated timeline for the full release of OpenVPN 2.2
+ - Are there any issues which need to be solved?
+ - Do we need a full-blown RC release round as well?
+
+ ## Patch queue:
+ - [Trac #35: No magic limitation on socket size](https://community.openvpn.net/openvpn/ticket/35)
+ - [Trac #8: MacOSX Keychain Certificate support](https://community.openvpn.net/openvpn/ticket/8)
+ - [New feature: floating-tls](http://thread.gmane.org/gmane.network.openvpn.devel/4106)
+ - [Dynamic iroute - what has happened?](http://thread.gmane.org/gmane.network.openvpn.devel/4059) ([Last discussion](http://thread.gmane.org/gmane.network.openvpn.devel/4080))
+
+ ## Possible bugs?
+ - [Trac #68: Windows route add command failed - should OpenVPN exit?](https://community.openvpn.net/openvpn/ticket/68)
+ - [Security vulnerability (CVE-2010-3864) in OpenSSL](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3864). Does it affect OpenVPN?
\ No newline at end of file
/dev/null .. meetings/2010-11-25.md
@@ 0,0 1,11 @@
+ - Patch queue:
+ - [Trac #35: No magic limitation on socket size](https://community.openvpn.net/openvpn/ticket/35)
+ - Update on [Trac #8: MacOSX Keychain Certificate support](https://community.openvpn.net/openvpn/ticket/8)
+ - [New feature: floating-tls](http://thread.gmane.org/gmane.network.openvpn.devel/4106)
+
+ - Bugs
+ - [WinXP: route setup broken after standby](ticket:56)
+ - Still no resolution. Heiko (d457k on IRC) probably knows this issue best.
+
+ - Possible bugs?
+ - [Trac #68: Windows route add command failed - should OpenVPN exit?](https://community.openvpn.net/openvpn/ticket/68)
\ No newline at end of file
/dev/null .. meetings/2010-12-02.md
@@ 0,0 1,13 @@
+ # 2.2 release
+
+ - 2.2-beta5 release
+ - Release plan for 2.2 (final)
+
+ # 2.3 release
+
+ - Milestone dates for 2.3-beta
+ - SSL modularity patches - going to 2.3 or a 2.4 release?
+
+ # Other
+
+ - Enabling --enable-password-save for Windows builds
\ No newline at end of file
/dev/null .. meetings/2010-12-09.md
@@ 0,0 1,3 @@
+ # Patches
+
+ - [use extv3 extensions such as subjectAltName as common_name](http://thread.gmane.org/gmane.network.openvpn.devel/4185/) needs an ACK
\ No newline at end of file
/dev/null .. meetings/2010-12-16.md
@@ 0,0 1,13 @@
+ ## Patch Queue
+
+ - [Add 'dev_type' environment variable](http://thread.gmane.org/gmane.network.openvpn.devel/4194)
+
+ - [New v3 plug-in API](http://thread.gmane.org/gmane.network.openvpn.devel/4255)
+ - Second round of this patch set
+ - Improved the general plug-in a little bit, using structs for both input and output variables to/from the plug-ins
+ - Added support for sending X509 certificates during the TLS_VERIFY phase
+
+ - [Make --x509-username-field a opt-in feature](http://thread.gmane.org/gmane.network.openvpn.devel/4266/focus=4298)
+ - Disabled by default
+ - Can open up for inclusion of the [extv3 patch](http://thread.gmane.org/gmane.network.openvpn.devel/4266/focus=4269) extending --x509-username-field feature
+ - Inclusion into beta2.2? Will that result in another beta round, or are we still aiming for RC?
\ No newline at end of file
/dev/null .. meetings/2011-01-06.md
@@ 0,0 1,57 @@
+ # Patches
+
+ - [Add 'dev_type' environment variable](http://thread.gmane.org/gmane.network.openvpn.devel/4194)
+ - [New v3 plug-in API](http://thread.gmane.org/gmane.network.openvpn.devel/4255)
+ - Second round of this patch set
+ - Improved the general plug-in a little bit, using structs for both input and output variables to/from the plug-ins
+ - Added support for sending X509 certificates during the TLS_VERIFY phase
+ - Essobi's *FIPS 140-2* patches
+
+ # Buildsystem-related
+
+ ## Build warnings
+ - `openvpnserv.c(278) : warning C4101: 'error_string' : unreferences local variable`
+ - *`ssl.c (1918): warning C4019: '=' : different 'const' qualifiers`*
+ - Should we be worried about PREfast error messages WinDDK gives? (see below)
+
+ ## Patches
+ - Handle all of mattock's latest buildsystem patches which have not been ACK'd before the meeting
+ - ACKed (with or without modifications)
+ - [Added build flag printing to win/show.py](http://thread.gmane.org/gmane.network.openvpn.devel/4318)
+ - [Added openvpnserv-specific files to clean target in win/msvc.mak.in](http://thread.gmane.org/gmane.network.openvpn.devel/4319) (ACKed)
+ - [Added automated configure.h creation to Python-based build system.](http://thread.gmane.org/gmane.network.openvpn.devel/4315) (ACKed with modifications)
+ - [Added PKCS11_HELPER_DIR directive to win/settings.in](http://thread.gmane.org/gmane.network.openvpn.devel/4317)
+ - NACKed / uncommented
+ - [Changed snprintf to _snprintf in service-win32/openvpnserv.c](http://thread.gmane.org/gmane.network.openvpn.devel/4325)
+ - How to handle *mysnprintf* in *service-win32/openvpnserv.c*? Should we use *openvpn_snprintf* from *buffer.c*?
+ - [Made Python-based build system copy openvpnserv.exe* to dist/bin directory](http://thread.gmane.org/gmane.network.openvpn.devel/4326) (trivial)
+ - [Added copying of files from service-win32 directory to build root directory.](http://article.gmane.org/gmane.network.openvpn.devel/4320)
+
+ ## Other
+ - Does Python-based build system already support prebuilt TAP drivers?
+ - Availability of SignTool python code?
+ - Could files in *service-win32* directory be moved to *$BUILDROOT*?
+
+ # Releases
+
+ - 2.2-rc release status
+
+ # PREfast error messages
+
+ ```
+ 457 typedef unsigned __int64 size_t;
+
+ crtdefs.h(457) : warning 20051: PREfast - Error processing 'cmds.cpp' : error C2371: 'size_t' :
+ redefinition; different basic types (try ' oacr log root:amd64fre ' for details)
+
+ crtdefs.h(457) : warning 20051: PREfast - Error processing 'devcon.cpp' : error C2371: 'size_t' :
+ redefinition; different basic types (try ' oacr log root:amd64fre ' for details)
+
+ crtdefs.h(457) : warning 20051: PREfast - Error processing 'dump.cpp' : error C2371: 'size_t' :
+ redefinition; different basic types (try ' oacr log root:amd64fre ' for details)
+
+ 9560 C_ASSERT(sizeof(ERESOURCE) == 0x68);
+
+ ntifs.h(9560) : warning 20051: PREfast - Error processing 'tapdrvr.c' : error C2118: negative subscript
+ (try ' oacr log root:amd64fre ' for details)
+ ```
/dev/null .. meetings/2011-01-13.md
@@ 0,0 1,12 @@
+ # Development issues
+
+ - Integrating [Coverity](http://www.coverity.com/) into Buildbot
+ - [Newline issues in log files on Windows](http://thread.gmane.org/gmane.network.openvpn.devel/4274/focus=4276)
+ - Plug-in V3 patches. [Additional patch](http://thread.gmane.org/gmane.network.openvpn.devel/4255/focus=4343) as discussed on the last meeting
+
+ # Other
+
+ - [UPnP over openVPN, is it possible](https://forums.openvpn.net/post9180.html#p9180)
+ - From krzee: "In this post i linked to [this archive](http://openvpn.net/archive/openvpn-devel/2004-04/msg00032.html). Are the details of James' post still true?"
+
+ - [OpenVPN Forum Topic 7479](https://forums.openvpn.net/topic7479.html)
\ No newline at end of file
/dev/null .. meetings/2011-02-10.md
@@ 0,0 1,32 @@
+ # Patches
+
+ - [PPP Gateway Fix](http://readlist.com/lists/lists.sourceforge.net/openvpn-users/2/10993.html): OpenVPN has issues finding out the default route when a PPP connection is used. The thread includes a few patches to address this issue, some of which are no longer available.
+ - Related tickets?
+ - [Linux gateway detection does not respect flags](https://community.openvpn.net/openvpn/ticket/39)
+ - [Default gateway not detected (linux)](https://community.openvpn.net/openvpn/ticket/41)
+ - [Default gateway not found on darwin 10.6 x86_64](https://community.openvpn.net/openvpn/ticket/42)
+
+ # 2.2-rc release
+
+ - For James: Signing the installer
+ - For James: GnuPG signatures for all release files: `exe`, `tar.gz`, `zip` and `tar.xz`
+ - Further on-the-fly Windows installer smoke-tests (if possible)
+ - Windows Vista 32/64-bit
+ - Windows 7 32-bit
+ - Windows Server versions (2003+)
+
+ # Documentation
+
+ - Trac Wiki
+ - We can now move documentation from openvpn.net to the Wiki
+ - What should be migrated? Suggestion: primarily quickly changing content, e.g., FAQ
+ - How to handle links to existing documentation such as search engine results?
+ - man page(s)
+ - Putting "Hosted service" and "Access Server" in the main Trac button row
+ - Rationale: documentation migration might eventually start diverting traffic from openvpn.net to Trac, thus reducing visibility of OpenVPN Tech's commercial products
+ - Alternative: some other way to handle this issue
+
+ # Other
+
+ - [Windows auto-connect when starting gui](https://forums.openvpn.net/topic7623.html)
+ - [sctp implementation in openvpn](https://forums.openvpn.net/topic7615.html)
\ No newline at end of file
/dev/null .. meetings/2011-02-17.md
@@ 0,0 1,25 @@
+ # Patches
+
+ - Review of Samuli's [buildsystem patches](http://thread.gmane.org/gmane.network.openvpn.devel/4406)
+ - 01/13: no ACK/NACK yet
+ - 02/13: no ACK/NACK yet
+ - 03/13: no ACK/NACK yet
+ - 04/13: no ACK/NACK yet
+ - 05/13: no ACK/NACK yet
+ - 06/13: no ACK/NACK yet
+ - 07/13: no ACK/NACK yet
+ - 08/13: no ACK/NACK yet
+ - 09/13: no ACK/NACK yet
+ - 10/13: no ACK/NACK yet
+ - 11/13: no ACK/NACK yet
+ - 12/13: no ACK/NACK yet
+ - 13/13: no ACK/NACK yet
+
+ # Automated tests
+
+ - The t_client.sh now integrated into buildbot
+ - Problem
+ - On IPv4-only hosts, IPv6 tests fail and all current buildslaves are IPv4-only.
+ - All builds on all buildslaves "fail" at the "testing" phase due to this.
+ - Temporary fix until all buildslaves are IPv6-enabled:
+ - Enable skipping IPv6-only tests.
\ No newline at end of file
/dev/null .. meetings/2011-03-24.md
@@ 0,0 1,27 @@
+ # Development
+
+ ## Bugs
+
+ - [Bugs with openvpnserv.exe](http://thread.gmane.org/gmane.network.openvpn.user/31994)
+
+ ## Patch queue for 2.2-RC2
+
+ - [Alon's cross-compilation patch](http://article.gmane.org/gmane.network.openvpn.devel/4451), More information [here](http://thread.gmane.org/gmane.network.openvpn.devel/4450) and [here](http://permalink.gmane.org/gmane.network.openvpn.devel/3991). Lacks an ACK.
+
+ ## OpenVPN 2.2-RC2 release
+
+ Everything is set, except these:
+
+ 1. TAP-driver signing *(jamesyonan)*
+ 2. Generating and testing Windows installer with signed TAP drivers *(mattock)*
+ 3. Signing the installer *(jamesyonan)*
+ 4. Tagging the Git tree *(dazo)*
+ 5. Generating source packages *(dazo/mattock)*
+ 6. Generating .deb packages *(mattock)*
+ 7. GPG Signing all release files *(jamesyonan)*
+ 8. Publishing the release *(mattock)*
+
+ ## Other
+
+ - Kaspersky (antivirus?) thinks OpenVPN 2.1.4 (and later?) is a rootkit
+ - Mattock tried installing Kaspersky, but trial download links they give are broken (404)
\ No newline at end of file
/dev/null .. meetings/2011-04-07.md
@@ 0,0 1,12 @@
+ # Development
+
+ - ## 2.2 release
+ - Any feedback on 2.2-RC2?
+ - Patches to include
+ - [Change the default --tmp-dir path to a more suitable path](http://thread.gmane.org/gmane.network.openvpn.devel/4561)
+ - Fix Windows README UNIX linefeed issue with release tarballs/zips
+ - Fix TAP_RELDATE in win/settings.in
+ - Make sure make_dist.py copies $TAP_PREBUILT/<arch>/tapinstall.exe to dist/<arch> automatically
+ - Remove mention of Win2k from Windows installer
+ - [man page needs update](wiki:ManPageUpdatesFor2.2) - what do we do?
+ - Release date?
\ No newline at end of file
/dev/null .. meetings/2011-04-14.md
@@ 0,0 1,23 @@
+ # Development
+
+ ## Bugs
+
+ - **TAP-driver release date in `win/settings.in` is incorrect**
+ - What is the correct release date?
+ - Apparently the wrong release date only shows up in `Driver properties` screen on Windows and has no negative side-effects
+ - Changing it would require resigning the TAP-drivers
+ - Shall we postpone fixing this until after 2.2 release?
+
+ ## Patch queue
+
+ - **Awaiting an ACK**
+ - [Fixed copying of tapinstall.exe to dist/bin when using prebuilt TAP-drivers](http://thread.gmane.org/gmane.network.openvpn.devel/4597)
+ - [Removed Win2k from supported platforms list in INSTALL and win/openvpn.nsi](http://thread.gmane.org/gmane.network.openvpn.devel/4596)
+ - [Fix a bug in devcon source code handling](http://thread.gmane.org/gmane.network.openvpn.devel/4595)
+ - [Change the default --tmp-dir path to a more suitable path](http://thread.gmane.org/gmane.network.openvpn.devel/4593)
+
+ ## New build computer
+
+ - **New build computer is now available**
+ - Running Windows 2008 r2
+ - First OpenVPN build done successfully
\ No newline at end of file
/dev/null .. meetings/2011-04-28.md
@@ 0,0 1,21 @@
+ # Development
+
+ ## OpenVPN 2.2.0
+ - Bug found and fixed within 6 hours of release (compile time issue only, commit b70d99fb617350b252c)
+ - Outstanding issue from James (commit 4d453a1792b04f01a8c31 / r7125)
+ - Requires backporting with more infrastructure changes. How critical is this critical bug?
+ - How long to wait until releasing 2.2.1?
+
+ ## Code repositories
+ - What to do with "openvpn-testing.git" repo
+ - What to do with "allmerged" branch
+ - Minimizing merge conflicts between SVN and Git
+ - `openvpn.8` is the biggest sore point
+
+ ## Improving automated testing (buildbot)
+ - Buildbot configuration is pretty static, needs to be generated more programmatically to allow a wider scope of testing
+ - Which build configurations to test?
+ - Automated connection tests (`t_client.sh/rc`) fail too often. For example, compare [this successful build](http://10.7.36.101:8010/builders/builder-ubuntu-1004-i386-allmerged/builds/29) and [this failed build](http://10.7.36.101:8010/builders/builder-ubuntu-1004-i386-allmerged/builds/30).
+ - Test 2 fails consistently on current buildslaves, disabled for now
+ - Which parameters to tune to prevent most failures?
+ - Prevents/discourages configuring buildbot to send mails to the public `openvpn-builds` mailing list.
\ No newline at end of file
/dev/null .. meetings/2011-05-19.md
@@ 0,0 1,9 @@
+ - **Patches**
+ - [Fix const declarations in plug-in v3 structs](http://thread.gmane.org/gmane.network.openvpn.devel/4629)
+ - [Make '--comp-lzo no' the default behaviour if LZO is enabled](http://thread.gmane.org/gmane.network.openvpn.devel/4650)
+ - **Bugs**
+ - [Visual Studio 2008 build errors in "master" branch](ticket:137)
+ - **Other**
+ - Merge --enable-small and --disable-management? [Mail discussion](http://thread.gmane.org/gmane.network.openvpn.devel/4639/focus=4647) -> Purpose: Reduce #ifdef statements which may complicate builds.
+ - Should PKCS#11 depend on management? (Currently --disable-management will fail to build if PKCS#11 is enabled)
+ - Any news on [OpenVPN MI GUI](http://openvpn-mi-gui.inside-security.de/) and [OpenVPN-GUI](http://sourceforge.net/projects/openvpn-gui/) merge?
\ No newline at end of file
/dev/null .. meetings/2011-06-09.md
@@ 0,0 1,36 @@
+ # OpenVPN 2.2.1 Release
+
+ - Queued patches
+ - Release date
+
+ # OpenVPN 2.3 Snapshot Builds for Windows
+
+ - Status of "master" branch: is it possible to build it with VS2008 already?
+
+ # Placing Small Ads into the OpenVPN Windows Installer?
+
+ The primary motivation is to raise awareness of OpenVPN Tech's commercial products. These ads would not be invasive, and will not be force-fed to the community. Here are a couple of ideas:
+
+ 1. Add small mentions of our products in the Windows installer's README file (reading it can be skipped)
+ 2. Add link icons to Windows menus (e.g., "Test Access Server", "Test hosted service") pointing to the product pages. Would allow measuring the effects if special URL or options were used. Would not be invasive, unlike, say, desktop icons.
+ 3. Add a new "commercial offerings" installation screen to the Windows installer (opt-in).
+
+ An example text for options 1 and 3 might be something like this:
+
+ ```
+ COMMERCIAL OFFERINGS
+
+ There are a number of commercial products based on OpenVPN:
+
+ - **Access Server** integrates OpenVPN with enterprise management capabilities, a simplified client GUI, and an easy to use administration GUI. It is packaged for various Linux distributions, available as virtual appliances and as an Amazon Machine Image (AMI) in the Amazon Cloud.
+ - **Shield Exchange** is an anonymizing service that also protects against various network threats by securing the traffic from user's computer to the Shield Exchange server and back.
+ - **OpenVPN Hosted Service** is a hosted version of Access Server
+
+ For further details on any of these, go to [http://openvpn.net](http://openvpn.net).
+ ```
+
+ # Misc
+
+ - [Russell's questions](http://thread.gmane.org/gmane.network.openvpn.devel/4715):
+ - "Why is the management interface not available until a connection to a remote server is initiated (and first contact proceeding)? Why not bring this interface up immediately, and perhaps limit commands that are available (until a 'full' connection is made)?"
+ - "Why does OpenVPN not support / provide exit codes (e.g., a particular exit code to indicate that no available TAP adapters are available)?"
\ No newline at end of file
/dev/null .. meetings/2011-06-16.md
@@ 0,0 1,21 @@
+ # Development
+
+ - James more active participation in the project
+ - What role to take?
+ - Management of release/stable branches?
+ - OpenVPN 2.2.1 release
+ - Is setting release date to 24th July realistic?
+ - tmp/winbuildfix branch - how to move forward, what's blocking?
+
+ # Testing
+
+ - t_client.sh changes to help with Buildbot integration
+
+ # Misc
+
+ - OpenVPN website
+ - Currently seen by the community as too commercially oriented
+ - How should we address the above concern?
+ - Increasing visibility of the OpenVPN project?
+ - How to make sure the website pleases both the company and the community?
+ - Transparency: discuss any major changes to the website beforehand in these IRC meetings
\ No newline at end of file
/dev/null .. meetings/2011-06-30.md
@@ 0,0 1,20 @@
+ # Patches awaiting an ACK
+
+ - Patches that fix [ticket #125](https://community.openvpn.net/openvpn/ticket/125) (holding back 2.2.1 release)
+ - [Introduction to the patchset](http://thread.gmane.org/gmane.network.openvpn.devel/4729)
+ - [Updated "easy-rsa" for OpenSSL 1.0.0](http://article.gmane.org/gmane.network.openvpn.devel/4781)
+ - [Made domake-win builds to use easy-rsa/2.0/openssl-1.0.0.cnf](http://article.gmane.org/gmane.network.openvpn.devel/4780)
+ - [Fixes to easy-rsa/2.0](http://thread.gmane.org/gmane.network.openvpn.devel/4729)
+ - [OpenVPN Doxygen patchset](http://thread.gmane.org/gmane.network.openvpn.devel/4740)
+ - [OpenSSL crypto function refactoring patchset](http://thread.gmane.org/gmane.network.openvpn.devel/4764)
+ - [IPV6_RECVPKTINFO vs. IPV6_PKTINFO](http://sourceforge.net/mailarchive/message.php?msg_id=27714628)
+
+ # MinGW buildsystem
+
+ The "domake-win" / MinGW buildsystem is somewhat outdated. For example, build scripts need to be modified to work with latest software dependencies, such as OpenSSL 1.0.0 and lzo 2.05. There are also some inconsistencies in how it behaves, such as looking for OpenSSL DLL's sometimes from $OPENSSL_DIR, sometimes for $PREBUILT/openssl. We also have another fully functional [Windows buildsystem](BuildingOnWindows) used to make official OpenVPN releases. A few questions:
+
+ First, should we try to actively maintain the MinGW buildsystem, provided nobody is filing bug reports or making complaints? Or should we let users who need it provide patches as necessary?
+
+ # OpenSSL 0.9.6 support
+
+ OpenVPN still supports OpenSSL 0.9.6. The last 0.9.6 release [was made in 2004](http://www.openssl.org/source/). Is there any reason **not** to remove the unused 0.9.6 codepaths a.s.a.p.?
\ No newline at end of file
/dev/null .. meetings/2011-07-07.md
@@ 0,0 1,15 @@
+ # Visual Studio 2008 Building in "Master" Branch
+
+ **Summary from Mattock:**
+
+ I finally had time to try the tmp/winbuildfix branch in openvpn-testing.git. I noticed that one patch that I had in my private Git tree was not there: it's now attached to the [ticket #137](https://community.openvpn.net/openvpn/attachment/ticket/137). However, it did not fix all issues. Build log is [available here](https://community.openvpn.net/openvpn/attachment/ticket/137/winbuildfix-log-2.txt).
+
+ I compared my tree to openvpn-testing.git's tmp/winbuildfix branch and found no differences - all patches should be included. I was wondering if you remember what's missing? The error message seems very familiar.
+
+ ## Patches
+
+ - [IPV6_RECVPKTINFO vs. IPV6_PKTINFO](http://article.gmane.org/gmane.network.openvpn.devel/4775)
+ - [Bug: Extended x509-username-field broken in git](http://thread.gmane.org/gmane.network.openvpn.devel/4801)
+ - **Status of andj's patches:** which have been reviewed/ACKed/NACKed, what have not
+ - [OpenVPN Doxygen patchset](http://thread.gmane.org/gmane.network.openvpn.devel/4740)
+ - [OpenSSL crypto function refactoring patchset](http://thread.gmane.org/gmane.network.openvpn.devel/4764)
\ No newline at end of file
/dev/null .. meetings/2011-07-14.md
@@ 0,0 1,5 @@
+ # Meeting topics
+
+ # Sprint topics
+
+ The plan was to ACK/NACK/fix as many of andj's PolarSSL patches as possible. The full source of patches can be viewed on GitHub: [https://github.com/andj/openvpn-ssl-refactoring]. The merge/ACK/NACK status of the patches is viewable from [PolarSSL integration](wiki:PolarSSLintegration). This meeting focused on [OpenSSL crypto separation](wiki:PolarSSLintegration#OpenSSLcryptoseparation) and [misc cleanup patches](wiki:PolarSSLintegration#Misccleanup).
\ No newline at end of file
/dev/null .. meetings/2011-07-21.md
@@ 0,0 1,7 @@
+ # Meeting topics
+
+ - None at the moment
+
+ # Sprint topics
+
+ This meeting will focus on [verification function patches](PolarSSLintegration.md#Verificationfunctions). Full status of PolarSSL patches is available [here](PolarSSLintegration.md).
\ No newline at end of file
/dev/null .. meetings/2011-07-26.md
@@ 0,0 1,3 @@
+ In this meeting, we select methods/tools for taking "behavioral diffs", which help ensure the PolarSSL refactoring patches don't change any functionality.
+
+ Adriaan devised a low-tech approach to this problem during the last meeting. Jamesyonan promised to research some fancier alternatives and present them here.
\ No newline at end of file
/dev/null .. meetings/2011-07-28.md
@@ 0,0 1,7 @@
+ # Meeting topics
+
+ - None at the moment
+
+ # Sprint topics
+
+ This meeting will focus on remaining [verification function patches](PolarSSLintegration#Verificationfunctions). Full status of PolarSSL patches is available [here](PolarSSLintegration).
\ No newline at end of file
/dev/null .. meetings/2011-08-03.md
@@ 0,0 1,8 @@
+ # Meeting topics
+
+ ## Web Forum
+ The forum is nearing ready to roll to vBulletin, but there are issues importing existing topics. I'm suggesting we lock current topics and make the old forum available for a limited time, and install a fresh copy of vBulletin. I'm looking for opinions and suggestions from other community members. --ecrist
+
+ # Sprint topics
+
+ This meeting will focus on remaining [verification function patches](wiki:PolarSSLintegration#Verificationfunctions). Full status of PolarSSL patches is available [here](wiki:PolarSSLintegration).
\ No newline at end of file
/dev/null .. meetings/2011-08-11.md
@@ 0,0 1,22 @@
+ # Patch queue
+
+ - **Which patches have been ACKed but are not in Git yet?**
+ - Final Visual Studio buildsystem patches from mattock
+ - **Which patches lack an ACK?**
+
+ # OpenVPN 2.2.2
+
+ - **Release date?**
+
+ # OpenVPN 2.3
+
+ - **Release date?**
+
+ # Bugs
+
+ - [Cannot access Syspro 6.0 Server with 2.2RC or 2.2.0](https://community.openvpn.net/openvpn/ticket/126): "It is no OpenVPN configuration problem, the SQL client software generates UDP packets with a frame length of 51 bits and these packets do not get forwarded through the tunnel (tcpdump on the other end didn't receive anything), but when I take the same packet, only modifying the frame length to 64 and injecting it, then the packet gets forwarded through the tunnel."
+ - Can **jamesyonan** help with this?
+
+ # Sprint topics
+
+ This meeting will focus on remaining [verification function patches](wiki:PolarSSLintegration#Verificationfunctions). Full status of PolarSSL patches is available [here](wiki:PolarSSLintegration).
\ No newline at end of file
/dev/null .. meetings/2011-08-18.md
@@ 0,0 1,117 @@
+ # Community Get-Together
+
+ A few community get-together options were discussed on the IRC earlier (17th Aug 2011):
+
+ - Long weekend in a major European city (e.g. Vienna) during October-November
+ - Next FOSDEM (spring 2012)
+
+ # Development
+
+ ## Next Releases
+
+ - OpenVPN 2.2.1
+ - OpenVPN 2.3
+
+ ## SVN Merger
+
+ Dazo made a [heroic merge](http://openvpn.git.sourceforge.net/git/gitweb.cgi?p=openvpn/openvpn-testing.git;a=commitdiff;h=e47fb603ed721bb718495e6f8ed42ec134da2f98) of James' SVN branch to "master". We need to discuss this in more detail. Here are comments from cron2:
+
+ ```plaintext
+ Random ramblings in the order I go through things...
+
+ - I git-clone'd openvpn-testing.git, went to the svn-merger branch, and
+ ran "make check" (on Gentoo Linux), with my full-featured t_client.rc
+ setup.
+
+ Test ran:
+ - p2mp tun udp (ipv4 + ipv6 ok)
+ - p2mp tun tcp (ipv4 + ipv6 ok)
+ - p2mp tun udp, "topology subnet" (ipv4 + ipv6 ok)
+ - p2mp tap udp (ipv4 ok, ipv6 fails, known issue with IPv6 auto-conf
+ on TAP, not related to the svn-merger)
+
+ so the client code (at least) is still working as well as my tests
+ cover the code.
+
+ - code alignment needed: for IPv4, the "did_redirect_default_gateway"
+ and "spec.remote_endpoint_defined" have been converted to flag bits in
+ route_list-iflags, but for IPv6, the old structure elements
+ remain - so to make the code more "in-line" for IPv4 and IPv6, this
+ needs code adjustments in the IPv6 code.
+
+ - I'm not overly happy about the "default-gateway block-local" changes -
+ this is less a code issue (the code might be fine) but a procedural
+ issue, with a huge change to route.c coming in without any sort of
+ review or discussion. Gah. (No response needed).
+
+ - I'm somewhat more annoyed by this one (route.c, line 1280):
+
+ #if defined(TARGET_LINUX)
+ #ifdef CONFIG_FEATURE_IPROUTE
+ /* FIXME -- add LR_MATCH support for CONFIG_FEATURE_IPROUTE */
+
+ this is implemented only for the "non-iproute2" case, so we have
+ differing behaviour for iproute2/non-iproute2 compiles now.
+ This MUST be fixed for 2.3
+
+ - implementations of LR_MATCH for most other platforms are missing,
+ but this is something that can be documented in the release notes,
+ and if someone thinks they need this, they can add it - but having
+ support-or-not for Linux, depending on --enable-iproute2, is a no-go
+
+ - the merger has PF_INET6 blocks, and I currently don't run tests over
+ IPv6 transport. So maybe jjo could also take a look at this branch
+ and see whether his stuff is still working.
+
+ - the web view of route.c, "-887,13 - +894,10" looks a bit weird,
+ with "++add_routes (...", but the code in the branch is fine.
+
+ - there's a functional and potentially-fatal change here:
+
+ void
+ -delete_routes (struct route_list *rl, const struct tuntap *tt, unsigned int flags, the struct env_set *es)
+ +delete_routes (struct route_list *rl, struct route_ipv6_list *rl6,
+ + const struct tuntap *tt, unsigned int flags, the struct env_set *es)
+ {
+ - if (rl && rl-routes_added)
+ + if (rl-iflags & RL_ROUTES_ADDED)
+
+ this new code does not check whether "rl" is non-NULL, but in theory
+ it could very well be NULL if we only have IPv6 routes.
+
+ So route.c line 1034 should really be:
+
+ if ( rl && rl-iflags & RL_ROUTES_ADDED)
+
+ and the corresponding code in add_routes (route.c, line 990) should
+ read:
+
+ if ( rl && !(rl-iflags & RL_ROUTES_ADDED))
+
+ ... enhancing my tests to add a "--route-nopull --route-ipv6 test"...
+ and indeed:
+
+ ./t_client.sh: Zeile 200: 8787 Speicherzugriffsfehler ./openvpn $openvpn_conf $LOGDIR/$SUF:openvpn.log
+
+ *bang*
+
+ redirect_default_route_to_vpn (rl=0x0, rl6=0x80f801c, tt=0x8101f90, flags=0,
+ es=0x80dc860) at route.c:811
+ 811 if (rl-flags & RG_ENABLE)
+
+ a proper patch is attached...
+
+ - ssl.c: it would be useful if andj or d12fk could review that - I'm not
+ actually sure I understand what changed, but it seems to be some
+ shuffling around of code and #ifdef ENABLE_CLIENT_CR, without actually
+ changing much.
+
+ the rest looks ok-ish to me... (but yes, I can understand that it took
+ you a heroic effort to merge that).
+ ```
+
+ Andj was ok with the merge after cron2's changes on #openvpn-devel:
+
+ ```plaintext
+ Ok, I can't find anything horrifying in those patches. By just looking at them (that's only ssl.c and ssl.h).
+ ```
\ No newline at end of file
/dev/null .. meetings/2011-08-25.md
@@ 0,0 1,13 @@
+ # Patch queue
+
+ * Check which ACKed patches have not yet been merged to "master" and merge them
+ * Patches without an ACK:
+ * [Make easy-rsa/2.0/vars handle paths with whitespaces](http://thread.gmane.org/gmane.network.openvpn.devel/4921/focus=4943)
+ * [Fix warnings in event.c when building for win32-64](http://thread.gmane.org/gmane.network.openvpn.devel/4941)
+ * [Remove wrapper code for Windows CryptoAPI function](http://thread.gmane.org/gmane.network.openvpn.devel/4937)
+ * [Better --auto-proxy support for Windows](http://thread.gmane.org/gmane.network.openvpn.devel/4927) (3 patches)
+ * [Allow to fill Details tab for exe files](http://thread.gmane.org/gmane.network.openvpn.devel/4883) (4 patches)
+
+ # PolarSSL patches
+
+ * Review PolarSSL [SSL library separation patches](wiki:PolarSSLintegration#SSLlibraryseparation)
\ No newline at end of file
/dev/null .. meetings/2011-09-01.md
@@ 0,0 1,12 @@
+ # Patch queue
+
+ - **Patches without an ACK:**
+ - [Fix warnings in event.c when building for win32-64](http://thread.gmane.org/gmane.network.openvpn.devel/4941)
+ - [Remove wrapper code for Windows CryptoAPI function](http://thread.gmane.org/gmane.network.openvpn.devel/4937)
+ - [Better --auto-proxy support for Windows](http://thread.gmane.org/gmane.network.openvpn.devel/4927) (3 patches)
+ - [Allow to fill Details tab for exe files](http://thread.gmane.org/gmane.network.openvpn.devel/4883) (4 patches)
+ - d12fk is on this and has promised to review these by next week
+
+ # PolarSSL patches
+
+ - Review PolarSSL [SSL library separation patches](wiki:PolarSSLintegration#SSLlibraryseparation)
\ No newline at end of file
/dev/null .. meetings/2011-09-08.md
@@ 0,0 1,17 @@
+ # Patch queue
+
+ ## Patches without an ACK:
+
+ | Patch | ACK | Notes |
+ |-------|-----|-------|
+ | [Fix warnings in event.c when building for win32-64](http://thread.gmane.org/gmane.network.openvpn.devel/4941) | jamesyonan, andj | |
+ | [Remove wrapper code for Windows CryptoAPI function](http://thread.gmane.org/gmane.network.openvpn.devel/4937) | jamesyonan | |
+ | [Better --auto-proxy support for Windows](http://thread.gmane.org/gmane.network.openvpn.devel/4927) | | introductory patch |
+ | - [Add MinGW WinHTTP compatibility layer](http://thread.gmane.org/gmane.network.openvpn.devel/4927/focus=4928) | | |
+ | - [Do automatic proxy detection on Windows right...](http://thread.gmane.org/gmane.network.openvpn.devel/4927/focus=4929) | | |
+ | - [Query auto-proxy information when connecting...](http://thread.gmane.org/gmane.network.openvpn.devel/4927/focus=4926) | | |
+ | [Add IPv6 gateway support for Linux, FreeBSD, and Darwin](http://article.gmane.org/gmane.network.openvpn.devel/4957) | | |
+
+ ## PolarSSL patches
+
+ - Review PolarSSL [SSL library separation patches](wiki:PolarSSLintegration#SSLlibraryseparation)
\ No newline at end of file
/dev/null .. meetings/2011-09-14.md
@@ 0,0 1,8 @@
+ # Patches
+
+ * [Add MinGW WinHTTP compatibility import library](https://sourceforge.net/mailarchive/forum.php?thread_name=1315932286-6992-1-git-send-email-heiko.hund%40sophos.com&forum_name=openvpn-devel)
+
+ # Bugs
+
+ * [Snapshot openvpn-2.x-20110909-master-install.exe fails](http://thread.gmane.org/gmane.network.openvpn.devel/4983)
+ * [tun.c patch breaks compile on FreeBSD](http://thread.gmane.org/gmane.network.openvpn.devel/4993)
\ No newline at end of file
/dev/null .. meetings/2011-09-15.md
@@ 0,0 1,8 @@
+ # Patches
+
+ * [Add MinGW WinHTTP compatibility import library](https://sourceforge.net/mailarchive/forum.php?thread_name=1315932286-6992-1-git-send-email-heiko.hund%40sophos.com&forum_name=openvpn-devel)
+
+ # Bugs
+
+ * [Snapshot openvpn-2.x-20110909-master-install.exe fails](http://thread.gmane.org/gmane.network.openvpn.devel/4983)
+ * [tun.c patch breaks compile on FreeBSD](http://thread.gmane.org/gmane.network.openvpn.devel/4993)
\ No newline at end of file
/dev/null .. meetings/2011-09-29.md
@@ 0,0 1,24 @@
+ # Buildslaves
+
+ - Current buildslave status is available [here](https://community.openvpn.net/openvpn/wiki/SettingUpBuildslave?version=16#Listofexistingbuildslaves)
+ - Currently there's no public connectivity test server *configured*, but one is *available* (thanks ecrist!)
+ - Cron2 *may* be able to get sponsored FreeBSD, OpenBSD, and OpenSolaris buildslaves for the project, but some acknowledgement may be necessary.
+
+ # Bugs
+
+ - [Segfault in PF](ticket:163). The configuration is described in more detail [here](http://backreference.org/2010/06/18/openvpns-built-in-packet-filter).
+
+ # Patches
+
+ - [Client's routes ageing timer](http://article.gmane.org/gmane.network.openvpn.devel/4994) from *dguerri*
+ - [PolarSSL addition patchset](https://community.openvpn.net/openvpn/wiki/PolarSSLintegration#PolarSSLaddition) from *andj*
+
+ # Other
+
+ - [Eike's question regarding *openvpn-status.log*](http://thread.gmane.org/gmane.network.openvpn.user/32525)
+ - Custom T-shirt order from [ooshirts.com](http://www.ooshirts.com/)
+ - OpenVPN Tech. will pay the bills (up to a certain point, naturally)
+
+ # Patch queue
+
+ - What is the status of the patches (for 2.3)?
\ No newline at end of file
/dev/null .. meetings/2011-10-06.md
@@ 0,0 1,3 @@
+ # Patches
+
+ * Review remaining [PolarSSL patches](PolarSSLintegration)
\ No newline at end of file
/dev/null .. meetings/2011-10-20.md
@@ 0,0 1,11 @@
+ # Bugs
+
+ * [Management interface doesn't handle PKCS11 tokens with umlaut characters in the label](http://thread.gmane.org/gmane.network.openvpn.devel/5036)
+
+ # Other
+
+ * T-shirts
+ * Select design
+ * [Black v2](http://www.ooshirts.com/d/84602203)
+ * [Navy v1](http://www.ooshirts.com/d/69042852)
+ * Select sizes and amounts
\ No newline at end of file
/dev/null .. meetings/2011-11-24.md
@@ 0,0 1,36 @@
+ # OpenVPN 2.2.2 Release
+
+ - **List of Missing Things / Blockers**
+ - Signed driver
+ - **Release Date**
+
+ # OpenVPN 2.3 Alpha Release
+
+ - **List of Missing Things / Blockers**
+
+ # Buildbot Status
+
+ - What is missing?
+ - Additional platforms, like MacOS X?
+ - t_client.rc test status
+
+ # Windows Building
+
+ - **How to Clean Up the Windows Build Mess We Got Now?**
+ - **Requirements**
+ - Cross-building OpenVPN for Windows on *NIX
+ - Building on Windows
+ - Building on *NIX
+ - Building and Signing the TAP-Driver for Windows
+ - Requires Windows + ~~Visual Studio toolchain~~ + WinDDK
+ - Can be done with mingw+msys + winddk (domake-win)
+ - **Build Options**
+ - Cygwin
+ - MinGW
+ - MinGW-w64
+ - Python buildsystem
+ - All build options probably can't be supported, especially when some toolchains (=Visual Studio) behave so differently from others
+
+ # FOSDEM 2012
+
+ - Should we arrange a community meeting at [FOSDEM](http://www.fosdem.org) on February 2012?
\ No newline at end of file
/dev/null .. meetings/2011-12-08.md
@@ 0,0 1,19 @@
+ # OpenVPN 2.2.2 Release Status
+
+ ## What's missing?
+
+ ## Who will take care of each missing part?
+
+ ## When will each missing part be ready?
+
+ ## Release date?
+
+ # OpenVPN 2.3 Alpha Release Status
+
+ ## What's missing?
+
+ ## Who will take care of each missing part?
+
+ ## When will each missing part be ready?
+
+ ## Release date?
\ No newline at end of file
/dev/null .. meetings/2012-01-19.md
@@ 0,0 1,6 @@
+ # FOSDEM
+
+ - FOSDEM hackfest ideas
+ - Squash/close as many bugs as possible
+ - 2.3 alpha release hackfest
+ - d12fk's Windows patch merge
\ No newline at end of file
/dev/null .. meetings/2012-03-15.md
@@ 0,0 1,136 @@
+ **NOTE:** The ACK status of these patches is now tracked on [this wiki page](wiki:GenericBuildsystemIntegration). Please do not update this page anymore.
+
+ # Generic development topics
+
+ - Which Microsoft Visual Studio versions do we want to support in the new "msvc" buildsystem written by Alon Bar-Lev?
+ - Move official openvpn project repositories into GitHub (creating organization etc...) Much easier to cooperate at GitHub than at SourceForge!
+
+ # Documentation
+
+ Look [here](wiki:BuildingUsingGenericBuildsystem).
+
+ # Patches
+
+ The following patchsets have been ACKed only partially, and there's a feature freeze until they have been merged. The goal of this meeting is to review the un-ACKed patches.
+
+ All available at [github](https://github.com/alonbl).
+
+ # Tap-windows patchset
+
+ These messages are viewable from [here](http://thread.gmane.org/gmane.network.openvpn.devel/5817).
+
+ A total new repository was created, preserving history. The patches are available [here](https://github.com/alonbl/tap-windows).
+
+ **PLEASE** clone this as-is when approved.
+
+ | **Patch name** | **ACKed by** | **Notes** |
+ |----------------|--------------|-----------|
+ | [tap-windows 03/11] cleanup: remove warnings of redefinition of macros | | |
+ | [tap-windows 04/11] debug: add !DbgPrint support | | |
+ | [tap-windows 05/11] build: set default to newer ddk | | |
+ | [tap-windows 06/11] cleanup: replace TAP-Win32->TAP-Windows | | |
+ | [tap-windows 08/11] cleanup: add TAP_WIN prefix to exports | | |
+ | [tap-windows 09/11] cleanup: create .gitignore | | |
+ | [tap-windows 10/11] docs: add COPYING COPYRIGHT.GPL | | |
+ | [tap-windows 11/11] build: initial build | | |
+
+ # Easy-rsa patchset
+
+ These messages are viewable from [here](http://thread.gmane.org/gmane.network.openvpn.devel/5799).
+
+ A total new repository was created, preserving history. The patches are available [here](https://github.com/alonbl/easy-rsa).
+
+ **PLEASE** clone this as-is when approved.
+
+ | **Patch name** | **ACKed by** | **Notes** |
+ |----------------|--------------|-----------|
+ | [easy-rsa 1/4] cleanup: fix execute permission | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5799/focus=5937) | |
+ | [easy-rsa 2/4] build: simple autotools build | [samuli (feature-ACK only)](http://thread.gmane.org/gmane.network.openvpn.devel/5799/focus=5938) | |
+ | [easy-rsa 3/4] build: doc | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5799/focus=5939) | ACK only if easy-rsa 2/4 was sane autotools-vise |
+ | [easy-rsa 4/4] packaging: rpm: initial add | [samuli (feature-ACK only)](http://thread.gmane.org/gmane.network.openvpn.devel/5799/focus=5940) | |
+
+ # OpenVPN-GUI build rewrite patchset
+
+ These messages are viewable from [here](http://thread.gmane.org/gmane.network.openvpn.devel/5795).
+
+ The patches are available [here](https://github.com/alonbl/openvpn-gui/tree/build).
+
+ **PLEASE** pull when approved.
+
+ | **Patch name** | **ACKed by** | **Notes** |
+ |----------------|--------------|-----------|
+ | [openvpn-gui 1/8] cleanup: resolve unused parameter warnings | | |
+ | [openvpn-gui 2/8] cleanup: resolve warnings missing malloc include | | |
+ | [openvpn-gui 3/8] debug: fix debug under unicode | | |
+ | [openvpn-gui 4/8] cleanup: add missing stdlib.h | | |
+ | [openvpn-gui 5/8] cleanup: dos2unix res/openvpn-gui-res-fi.rc | | |
+ | [openvpn-gui 6/8] cleanup: dos2unix res/openvpn-gui-res-jp.rc | | |
+ | [openvpn-gui 7/8] cleanup: dos2unix OpenVPN GUI ReadMe.txt | | |
+ | [openvpn-gui 8/8] build: rework build | | |
+
+ # Build revolution patchset
+
+ These messages are viewable from [here](http://thread.gmane.org/gmane.network.openvpn.devel/5772).
+
+ The patches are available [here](https://github.com/alonbl/openvpn/tree/build).
+
+ **PLEASE** pull when approved. There were some changes regarding the msvc build.
+
+ | **Patch name** | **ACKed by** | **Notes** |
+ |----------------|--------------|-----------|
+ | [PATCH 01/52] build: version should not contain '-' | dazo | Helps with RPMs and debs don't care. |
+ | [PATCH 02/52] package: rpm: strip should be handled by package managem | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5884) | |
+ | [PATCH 03/52] cleanup: options.c: remove redundant include | andj, samuli | |
+ | [PATCH 04/52] cleanup: remove C++ warnings | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5886) | |
+ | [PATCH 05/52] cleanup: win32.c: wrong printf format | andj, dazo | this is correct: WCHAR *cmd = wide_string (a->argv[0], &gc); |
+ | [PATCH 06/52] cleanup: remove redundant ';' | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5887) | |
+ | [PATCH 07/52] cleanup: crypto_openssl.c: remove support for pre-openss | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5888) | |
+ | [PATCH 08/52] cleanup: tun.c: fix incorrect option in message (ip-win3 | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5889) | |
+ | [PATCH 09/52] cleanup: memcmp.c: remove unused source | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5891) | |
+ | [PATCH 10/52] fixup: init.c: add missing conditional for ENABLE_CLIENT | andj, dazo | forward.h was included twice, good fix |
+ | [PATCH 11/52] build: correct place to alter WINVER is at build system | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5892) | |
+ | [PATCH 12/52] Update .gitignore | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5893) | |
+ | [PATCH 13/52] build: handle printf style format in mingw | dazo | |
+ | [PATCH 14/52] build: rename plugin directory to plugins | dazo | |
+ | [PATCH 15/52] build: plugins: properly use CC, CFLAGS and LDFLAGS | andj, dazo | |
+ | [PATCH 16/52] build: we need the sample.ovpn in future | dazo | [Samuli's comments](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5894). Dazo: "I'd say ACK, and we'll improve this later on" |
+ | [PATCH 17/52] Remove install-win32 | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5896) | |
+ | [PATCH 18/52] Remove easy-rsa | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5895) | |
+ | [PATCH 19/52] Remove tap-win32 | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5898) | |
+ | [PATCH 20/52] cleanup: rename tap-windows function from win32 to win | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5895) | |
+ | [PATCH 21/52] build: remove windows specific build system | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5903) | |
+ | [PATCH 22/52] build: split acinclude.m4 into m4/* | andj | |
+ | [PATCH 23/52] build: m4/ax_varargs.m4: cleanup | dazo | |
+ | [PATCH 24/52] build: m4/ax_emptyarray.m4: cleanup | dazo | |
+ | [PATCH 25/52] build: m4/ax_socklen_t.m4: cleanup | dazo | |
+ | [PATCH 26/52] build: autotools: first pass of trivial autotools change | andj, dazo | Simple cleanups |
+ | [PATCH 27/52] build: autoconf: remove OPENVPN_ADD_LIBS useless macro | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5919) | |
+ | [PATCH 28/52] build: remove awk and non-standard autoconf output proce | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5920) | |
+ | [PATCH 29/52] build: standard directory layout | andj | Available [here](https://github.com/alonbl/openvpn/commit/f26b8c6e498184eb53dd74eff40f205358e72404). andj: "compliments for cleaning that up" |
+ | [PATCH 30/52] build: add libtool + windows resources for executables | dazo, mattock | Fix the COMPANY_NAME and LEGAL_COPYRIGHT later |
+ | [PATCH 31/52] build: autoconf: commands as environment | andj | comments from [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5921) and [alon](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5948) |
+ | [PATCH 32/52] build: libdl usage | andj, dazo | |
+ | [PATCH 33/52] build: properly detect and use socket libs | dazo | [samuli's comments](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5922) |
+ | [PATCH 34/52] build: autoconf: minor cleanups | andj, dazo | |
+ | [PATCH 35/52] build: proper selinux detection and usage | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5954) | |
+ | [PATCH 36/52] build: distribute pkg.m4 | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5924) | |
+ | [PATCH 37/52] build: proper pkcs11-helper detection and usage | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5925) | |
+ | [PATCH 38/52] build: properly process lzo-stub | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5926) | |
+ | [PATCH 39/52] build: proper lzo detection and usage | andj, dazo | Discuss on the ml whether lzo should be enabled by default |
+ | [PATCH 40/52] build: proper crypto detection and usage | andj | andj: OpenSSL 0.9.6 needs to go |
+ | [PATCH 41/52] build: autoconf: update defaults for options | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5927) | |
+ | [PATCH 42/52] build: win-msvc: msbuild format | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5928) | |
+ | [PATCH 43/52] build: move out config.h include from syshead | dazo | |
+ | [PATCH 44/52] build: split out compat | dazo, [samuli (feature-ACK only)](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5929) | |
+ | [PATCH 45/52] build: move gettimeofday() emulation to compat | dazo | Removes #ifdefs, cleans up the code |
+ | [PATCH 46/52] build: move daemon() emulation into compat | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5930) | |
+ | [PATCH 47/52] build: move inet_ntop(), inet_pton() emulation into comp | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5952) | |
+ | [PATCH 48/52] cleanup: move console related function into its own modu | [samuli (feature-ACK only)](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5932) | |
+ | [PATCH 49/52] build: move wrappers into platform module | [samuli (feature-ACK only)](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5953) | |
+ | [PATCH 50/52] build: windows: install version.sh to allow installer re | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5951) | |
+ | [PATCH 51/52] build: distribute samples in windows | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5935) | Provided [this analysis](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5935) is correct |
+ | [PATCH 52/52] build: use tap-windows.h as external dependency | [samuli](http://thread.gmane.org/gmane.network.openvpn.devel/5772/focus=5936) | |
+
+ # Build system
+
+ Available [here](https://github.com/alonbl/openvpn-build).
\ No newline at end of file
/dev/null .. meetings/2012-04-26.md
@@ 0,0 1,77 @@
+ # OpenVPN 2.3-alpha2 Release
+
+ ## Patches
+
+ Alon hopes to get the following patches included in 2.3-alpha2:
+
+ - [cxx patch](https://github.com/alonbl/openvpn/compare/master...cxx)
+ - [warnings patch](https://github.com/alonbl/openvpn/compare/master...warnings)
+ - [unicode patch](https://github.com/alonbl/openvpn/compare/master...unicode)
+ - [git-attributes patch](https://github.com/alonbl/openvpn/compare/master...git-attributes)
+ - [bool patch](https://github.com/alonbl/openvpn/compare/master...bool)
+
+ ACK and merge, or NACK.
+
+ **@ALON**: The bool branch is the one for discussion, it is the last issue we have in building openvpn in various of configurations without warnings/errors. The question is what course should we take? stdbool (unlike its name, is far from being standard) or just rename the bool to obool to reduce risk (we actually do not change anything), achieve compiler portability and achieve C++ compatibility. I recommend taking the rename approach.
+
+ ## Git Repo Layout
+
+ Alon's refactoring/buildsystem patches split the project into two separate projects (taken from [here](http://thread.gmane.org/gmane.network.openvpn.devel/6280/focus=6297)):
+
+ - **openvpn** - standard open source project, autotool based build system, like any other project its build system only builds it-self.
+ - **openvpn-build** - a separate project to build openvpn in various of configurations. This project is divided into the following components:
+ - **generic** - a generic build using cross compiler, included the complete dependencies.
+ - **msvc** - a MSVC build using Microsoft specific msbuild system, I hope this will die eventually.
+ - **windows-nsis** - the windows installer generator, it uses the generic component to build using mingw cross compiler, then package the output using nsis.
+
+ The **openvpn** and **openvpn-build** subprojects can be developed fairly independently. Do we need/want to host both subprojects in the same place?
+
+ **@ALON**: We have few more new repositories: tap-windows, easy-rsa. Is there any reason **NOT** to host them at the same place? I just cannot think of any...
+
+ # Suggested Changes to Development Processes
+
+ ## Subsystems vs. Features
+
+ There has been [critique](http://article.gmane.org/gmane.network.openvpn.devel/6288) on our current focus on features (e.g. PolarSSL, IPv6) instead of subsystems (e.g. crypto, routing, buildsystem). This raises a few questions:
+
+ - Does the subsystem approach make sense to everyone on a theoretical level?
+ - Is the subsystem approach doable in practice, given our current developer base?
+ - Would current, active developers be interested in taking responsibility over a subsystem?
+ - If so, how do we handle practical issues such as:
+ - Do we want to allow direct commit access to official repositories for the subsystem maintainers?
+ - Do we want to use subsystem-specific trees (e.g. at GitHub) from which code is pulled into the official OpenVPN Git repository?
+ - Do we want to change the mandatory ACK/NACK process for the less-critical subsystems? For example, **openvpn-build** subsystem is not critical from a security perspective.
+
+ ## Git Repos: GitHub <-> SF.net
+
+ There have also been suggestions to move the Git repos to GitHub:
+
+ - There is anecdotal evidence that GitHub promotes collaboration greatly compared to the traditional mailing list approach.
+ - What benefits does SF.net provide?
+ - What benefits does GitHub provide?
+
+ Some discussion was [here](http://comments.gmane.org/gmane.network.openvpn.devel/6095). GitHub supports many features that SF.net lacks, RSS of changesets, review and comment, the entire merge process and more. Mainly it supports finer grain privileges for multiple repositories. I don't think there is one single advantage in keeping using the SF.net, especially if the OpenVPN project is only using git feature of SF.net.
+
+ ## ACK -> Maintenance Responsibility?
+
+ Another suggestion made by Alon is that giving an ACK would mean taking responsibility of the ACKed code, should the original developer disappear somewhere. This would have some benefits:
+
+ - Only code that was really important would get in
+ - The code that got included be the responsibility of at least two people, the author and the ACKer; this should (at least in theory) result in fairly well-maintained code with fewer "orphaned" parts
+
+ This approach has a few potential drawbacks:
+
+ - Less potentially useful code gets in
+ - Moves away responsibility from the original developer
+
+ **@ALON**: If useful code gets in and there is no active long term maintainer for this "useful" feature, what can we say about the quality of the implementation or user support?
+
+ **@ALON**: Original developer should be defined properly, by my definition James is an original developer of OpenVPN, while he did not write 100% of the code... A patch contributor is far from being "original developer", as there is no real relationship between the contributor and the project, how did the current process defined "responsibility" of this contributor? Let's say contributor succeeded in getting his code into the tree by someone ACK, then after a release, there were issues with his changeset. Is he obligated to fix his code? How can you enforce this? In my view whoever ACKed is accountable for this code for long term, this does not reduce the cooperation with contributor, just define clearly who is accountable for changes accepted to the code base.
+
+ ## OpenVPN 2.4
+
+ Should OpenVPN 2.4 release cycle focus on cleaning up the codebase, for example integrate new features (e.g. IPv6) better into the old codebase?
+
+ ## Buildbot Testing
+
+ Get automated connectivity tests with IPv4 and IPv6 going - this would have caught the Linux IPv6 regression right away, not later when it bit dazo.
\ No newline at end of file
/dev/null .. meetings/2012-05-31.md
@@ 0,0 1,1 @@
+ In this meeting we review some of the [final patches](wiki/OpenVPN2.3@3) going into 2.3-alpha2.
\ No newline at end of file
/dev/null .. meetings/2012-06-21.md
@@ 0,0 1,17 @@
+ # Unreviewed patches
+
+ - [PATCH 3/6: Remove ENABLE_INLINE_FILES conditionals](http://thread.gmane.org/gmane.network.openvpn.devel/6740/focus=6746)
+ - [PATCH 4/6: Remove ENABLE_CONNECTIONS ifdefs](http://thread.gmane.org/gmane.network.openvpn.devel/6740/focus=6744)
+ - [PATCH 6/6 Fix clang warnings for conversion from unsigned<->signed](http://thread.gmane.org/gmane.network.openvpn.devel/6740/focus=6745)
+ - [PATCH: SSL Engine support (part 1)](http://thread.gmane.org/gmane.network.openvpn.devel/6730) [(part 2)](http://thread.gmane.org/gmane.network.openvpn.devel/6734)
+
+ # 2.3-alpha2 release
+
+ We now have code-signing certificates for OpenVPN (OSS), so there are no technical obstacles holding the release back. What, if any, is still missing?
+
+ ## Missing patches
+
+ - [management: Don't require DAF_INITIAL_AUTH to send ADDRESS/DISCONNECT messages](http://thread.gmane.org/gmane.network.openvpn.devel/6456/focus=6457)
+ - [OCC ping](http://thread.gmane.org/gmane.network.openvpn.devel/6619)
+
+ # 2.3-beta1 release
\ No newline at end of file
/dev/null .. meetings/2012-11-29.md
@@ 0,0 1,27 @@
+ # Introduction
+
+ This is a special company/community meeting.
+
+ # Agenda
+
+ The agenda is still preliminary, but topics should include:
+
+ - **OpenVPN C++ implementation (currently in OpenVPN Technologies Android client)**
+ - Background/rationale
+ - Releasing it under an open source license
+ - When?
+ - Where?
+ - Which license?
+ - Requirements
+ - Challenges
+ - Will it become OpenVPN 3.0?
+ - Will it make more sense to clean up current OpenVPN during 2.4 release cycle?
+
+ - **OpenVPN 2.3**
+ - Role in the company
+ - Getting others (especially James) from the company more involved in community development
+
+ - **Joint company/community meeting in FOSDEM in Brussels**
+ - The agenda?
+ - OpenVPN 3.x (see above)?
+ - OpenVPN 2.4 planning?
\ No newline at end of file
/dev/null .. meetings/2013-04-18.md
@@ 0,0 1,32 @@
+ # Agenda
+
+ ## Handling Security Vulnerabilities in the Future
+ - Always get a CVE entry?
+ - Always make a security announcement (threat, impact, etc.)
+ - Makes handling the issue much easier for downstream
+ - Compile a list of OpenVPN package maintainer (e.g. *BSD, Linux) email addresses, so that they can be notified in advance of security updates.
+
+ ## OpenVPN 3.0
+ - Was released along with API documentation under AGPL v3 at FOSDEM 2013
+ - Currently used primarily/only in OpenVPN Connect clients for Android/iOS from OpenVPN Technologies, Inc.
+ - Getting the code to Git: currently only an outdated tarball is available
+ - [OpenVPN 3.0 staging site](http://staging.openvpn.net/openvpn3/)
+
+ ## OpenVPN 2.4
+ - What is the goal of the 2.4 release?
+ - What patches in "master" are 2.4-only material?
+
+ ### Patches
+ - Android patchsets
+ - Dual stack client patches
+ - utun on macOS
+ - Native tun, no need for extra tun.kext
+ - Supported for all OS X >= 10.6.8 (latest PPC version)
+ - Unfortunately requires root
+ - Real question: Drop tun.kext support and support only utun or "try utun first, fall back to tun.kext if it fails"
+ - svn 2.1 patchset (snappy support, push-peer-info changes, see trac#268-273)
+ - Management interface changes (status 2/3)
+ - Formatting and whitespace fixes (just before 2.4 release)
+
+ ### Additional Considerations
+ - `--version` to include git commit id and branch?
\ No newline at end of file
/dev/null .. meetings/2013-04-25.md
@@ 0,0 1,20 @@
+ # Patches
+
+ ## Gert Döring
+ - [Forward-port of all outstanding 2.1 SVN patches](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d1%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 1/5: Added remote-override option.](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d2%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 2/5: Added support for the Snappy compression algorithm](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d3%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 3/5: Minor fix to process_ipv4_header so that any combination of options can be defined.](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d4%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 4/5: Always push basic set of peer info values to server.](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d5%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 5/5: Fix usage of "compression ..." from global config.](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d6%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [Make push-peer-info visible in "normal" per-instance environment.](http://news.gmane.org/find-root.php?message_id=%3c1366483371%2d5202%2d1%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+
+ ## Arne Schwabe
+ - The Android patchset
+ - [PATCH 1/5: Remove script-security warning](http://news.gmane.org/find-root.php?message_id=%3c1366467768%2d16260%2d1%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - [PATCH 2/5: Allow routes to be set before opening tun, similar to ifconfig before opening tun](http://news.gmane.org/find-root.php?message_id=%3c1366467768%2d16260%2d2%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - [PATCH 3/5: add ability to send/receive file descriptors via management interface, only used in android so. For now under #ifdef ANDROID](http://news.gmane.org/find-root.php?message_id=%3c1366467768%2d16260%2d3%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - [PATCH 4/5: Android platform specific changes.](http://news.gmane.org/find-root.php?message_id=%3c1366467768%2d16260%2d4%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - [PATCH 5/5: Emulate persist-tun on Android](http://news.gmane.org/find-root.php?message_id=%3c1366467768%2d16260%2d5%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - [Fix client-nat only working is also mss-fix is specified.](http://news.gmane.org/find-root.php?message_id=%3c1366452267%2d15838%2d1%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - [PATCHv3 Remove unused variables or put them to the defines they are being used in](http://news.gmane.org/find-root.php?message_id=%3c1366059999%2d31731%2d1%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
\ No newline at end of file
/dev/null .. meetings/2013-05-09.md
@@ 0,0 1,23 @@
+ # Patches
+
+ Current list of unreviewed patches as of 2nd May 2013:
+
+ ## Gert Döring
+ - [Forward-port of all outstanding 2.1 SVN patches](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d1%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 1/5: Added remote-override option.](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d2%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 2/5: Added support for the Snappy compression algorithm](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d3%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 3/5: Minor fix to process_ipv4_header so that any combination of options can be defined.](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d4%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 4/5: Always push basic set of peer info values to server.](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d5%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 5/5: Fix usage of "compression ..." from global config.](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d6%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH: Make push-peer-info visible in "normal" per-instance environment.](http://news.gmane.org/find-root.php?message_id=%3c1366483371%2d5202%2d1%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e) (the [amended version from cron2](http://thread.gmane.org/gmane.network.openvpn.devel/7559), if available)
+
+ ## Arne Schwabe
+ - [PATCH: Add support of utun devices under Mac OS X](http://news.gmane.org/find-root.php?message_id=%3C1364762609-30320-1-git-send-email-arne@rfc2549.org%3E)
+ - Native tun, no need for extra tun.kext
+ - Supported for all OS X >= 10.6.8 (latest PPC version)
+ - Unfortunately requires root
+ - Real question: Drop tun.kext support and support only utun or "try utun first, fall back to tun.kext if it fails"
+ - The Android patchset
+ - [PATCH 1/5: Remove script-security warning](http://news.gmane.org/find-root.php?message_id=%3c1366467768%2d16260%2d1%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - [PATCH: Fix client-nat only working is also mss-fix is specified.](http://news.gmane.org/find-root.php?message_id=%3c1366452267%2d15838%2d1%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - [PATCHv3: Remove unused variables or put them to the defines they are being used in](http://news.gmane.org/find-root.php?message_id=%3c1366059999%2d31731%2d1%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
\ No newline at end of file
/dev/null .. meetings/2013-05-23.md
@@ 0,0 1,26 @@
+ # Patches
+
+ Current (22nd May 2013) list of unreviewed patches is this:
+
+ ## Gert Döring
+ - [Forward-port of all outstanding 2.1 SVN patches](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d1%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 1/5: Added remote-override option.](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d2%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 3/5: Minor fix to process_ipv4_header so that any combination of options can be defined.](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d4%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH 4/5: Always push basic set of peer info values to server.](http://news.gmane.org/find-root.php?message_id=%3c1366393268%2d27392%2d5%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e)
+ - [PATCH: Make push-peer-info visible in "normal" per-instance environment.](http://news.gmane.org/find-root.php?message_id=%3c1366483371%2d5202%2d1%2dgit%2dsend%2demail%2dgert%40greenie.muc.de%3e) (the [amended version from cron2, if available](http://thread.gmane.org/gmane.network.openvpn.devel/7559))
+
+ ## Arne Schwabe
+ - [PATCH: Add support of utun devices under Mac OS X](http://news.gmane.org/find-root.php?message_id=%3C1364762609-30320-1-git-send-email-arne@rfc2549.org%3E)
+ - native tun, no need for extra tun.kext
+ - Supported for all OS X >= 10.6.8 (latest PPC version)
+ - Unfortunately requires root
+ - Real question: Drop tun.kext support and support only utun or "try utun first, fall back to tun.kext if it fails"
+ - The Android patchset
+ - [PATCH 1/5: Remove script-security warning](http://news.gmane.org/find-root.php?message_id=%3c1366467768%2d16260%2d1%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - [PATCH: Fix client-nat only working if also mss-fix is specified.](http://news.gmane.org/find-root.php?message_id=%3c1366452267%2d15838%2d1%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - [PATCH: PATCHv3 Remove unused variables or put them to the defines they are being used in](http://news.gmane.org/find-root.php?message_id=%3c1366059999%2d31731%2d1%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+
+ ## Heikki Hannikainen
+ - [PATCH: pkcs12-additional-cas option to load CA+intermediate certs from both PKCS#12 and a --ca PEM file](http://news.gmane.org/find-root.php?message_id=%3cCAHqXQkNN%5fbf9G%5fSRefYTCu8EiVQCAaCZ3G%2bK4ppoXGTcN%2b1g4Q%40mail.gmail.com%3e)
+ - Current code does not load trusted CAs or intermediate certs from PKCS12 if --ca is given
+ - Alternative to this patch: Make the code simply load CAs from both PKCS12 and --ca by default, but current default behavior seems to be very intentional, might have a use case of someone needing to override PKSC12 CAs
\ No newline at end of file
/dev/null .. meetings/2013-06-20.md
@@ 0,0 1,41 @@
+ # Patches to Review
+
+ ## James' Set of Patches (Based on 2.3)
+ - [View all patches](https://github.com/jamesyonan/openvpn/commits/2.3.2-mods)
+ - [Added "setenv opt" directive prefix](https://github.com/jamesyonan/openvpn/commit/037690df22a4604a556c9b470d1f5e891991834b)
+ - [Updated the TLS negotiation logic](https://github.com/jamesyonan/openvpn/commit/6ee8faade224cc346d67a7f1716df4012782999a)
+ - [Minor fix to process_ipv4_header](https://github.com/jamesyonan/openvpn/commit/0a081bc3e0dfecde9464bddec8d775d1dbb8b9cd)
+ - Arne Schwabe objected and provided another patch for this code ([See discussion](http://thread.gmane.org/gmane.network.openvpn.devel/7527/focus=7534))
+
+ ## Arne Schwabe
+ - [PATCH: Add support of utun devices under Mac OS X](http://news.gmane.org/find-root.php?message_id=%3C1364762609-30320-1-git-send-email-arne@rfc2549.org%3E)
+ - Native tun, no need for extra tun.kext
+ - Supported for all OS X >= 10.6.8 (latest PPC version)
+ - Requires root
+ - Discussion: Drop tun.kext support and support only utun or "try utun first, fall back to tun.kext if it fails"
+ - What about Peter Sagerson's [alternative OS X/utun patch](http://thread.gmane.org/gmane.network.openvpn.devel/7689)?
+ - For version 2.3.3 or 2.4 only?
+ - [PATCH: Fix client-nat only working if mss-fix is specified](http://news.gmane.org/find-root.php?message_id=%3c1366452267%2d15838%2d1%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - [PATCHv3: Remove unused variables or put them to the defines they are being used in](http://news.gmane.org/find-root.php?message_id=%3c1366059999%2d31731%2d1%2dgit%2dsend%2demail%2darne%40rfc2549.org%3e)
+ - ACK by cron2, committed and pushed to master
+
+ ## Heikki Hannikainen
+ - [PATCH: Always load intermediate certificates from a PKCS#12 file](http://thread.gmane.org/gmane.network.openvpn.devel/7721)
+
+ ## David Sommerseth
+ - [PATCH: Extend the plugin v3 API to identify the SSL implementation used](http://article.gmane.org/gmane.network.openvpn.devel/7677)
+ - NAK by cron2 (feature-ACK, but code needs a v3)
+ - [PATCH: Update man page about the tls_digest_{n} environment variable](http://article.gmane.org/gmane.network.openvpn.devel/7659) (easy)
+ - ACK by cron2
+ - [PATCH: Fix typo in autoconf](http://article.gmane.org/gmane.network.openvpn.devel/7658) (easy)
+ - ACK by cron2
+ - [PATCH: Remove the --disable-eurephia configure option](http://article.gmane.org/gmane.network.openvpn.devel/7660)
+ - ACK by cron2
+
+ ## Kenny Root
+ - [Adding support for AEAD cipher modes (AES-GCM, et al.)](http://thread.gmane.org/gmane.network.openvpn.devel/7653)
+
+ # Development Discussion
+
+ - Proposal to have an in-person hackfest in Munich at the end of this year (November) instead of going to Brussels.
+ - Discussion and decision on [James' OpenVPN versioning proposals](http://thread.gmane.org/gmane.network.openvpn.devel/7678).
\ No newline at end of file
/dev/null .. meetings/2013-07-11.md
@@ 0,0 1,9 @@
+ # Patch review
+
+ List of unreviewed patches [here](wiki:Patches).
+
+ ACK/NACK/discuss as many as time permits.
+
+ # Ticket review
+
+ List of tickets since June 1st [here](https://community.openvpn.net/openvpn/query?status=accepted&status=assigned&status=new&status=reopened&time=06%2F01%2F13..07%2F11%2F13&col=id&col=summary&col=status&col=type&col=priority&col=milestone&col=component&order=priority). Review as many as possible.
\ No newline at end of file
/dev/null .. meetings/2013-08-08.md
@@ 0,0 1,18 @@
+ # Special topics
+
+ - [Windows 8 issue: TUN/TAP adapter does not start](http://news.gmane.org/find-root.php?message_id=%3cCAFLxGvxgzpM2n8zLhsm5Ag5BNNMp7GnFEo14d54fkgF%3dCv7PPg%40mail.gmail.com%3e)
+ - Some of [these tickets](https://community.openvpn.net/openvpn/query?status=accepted&status=assigned&status=new&status=reopened&keywords=~windows&col=id&col=summary&col=status&col=type&col=priority&col=milestone&col=component&order=priority) might be related. [This one](https://community.openvpn.net/openvpn/ticket/207) looks quite promising.
+ - Releasing new OpenVPN 2.3.2 Windows installers
+ - Mattock built upgraded installers that use openvpn-gui-5
+ - Still need testing
+ - Mattock can probably do the testing and release tomorrow
+
+ # The usual stuff
+
+ ## Patch review
+
+ If time permits, review patches from [here](/wiki/Patches). ACK/NACK/discuss.
+
+ ## Ticket review
+
+ If time permits, review some of the fairly recent tickets (June 1st -> today) listed [here](https://community.openvpn.net/openvpn/query?status=accepted&status=assigned&status=new&status=reopened&time=06%2F01%2F13..08%2F08%2F13&col=id&col=summary&col=status&col=type&col=priority&col=milestone&col=component&order=priority).
\ No newline at end of file
/dev/null .. meetings/2013-08-22.md
@@ 0,0 1,38 @@
+ # New Topics
+
+ ## 1. Issues with supplying username/password/response via file/stdin/management interface
+ - Full IRC discussion: [attachment:auth-user-pass-discussion.txt here](attachment:auth-user-pass-discussion.txt)
+ - Waldner has been adding support for supplying username only to `--auth-user-pass`
+ - It was agreed on #openvpn-devel IRC that this makes sense, as usernames rarely change
+ - Waldner's proposed changes opened a can of worms. There are at least three issues:
+ 1. Supporting inline files
+ 2. Including support for user-name only via file (inline or not)
+ - This may require significant refactoring
+ 3. Using a user-file (inline or not) with challenge-response
+ - This does not work currently: is this a bug or a design decision/feature?
+
+ ## 2. openvpn-build issues
+ - How to track build changes (from pekster)
+ - Ideas on how to make the nsis stuff easier (from pekster)
+ - Adding snappy support (from mattock)
+ - Mattock has snappy support in his local openvpn-build Git repo
+ - The problem is that snappy pulls in an 8MB library as a dependency, increasing installer size considerably
+ - Suggestions for fixing this?
+ - Static linking?
+ - Creating a slimmed down shared library?
+ - Something else?
+
+ # Review of Old Topics
+
+ - [Windows 8 issue: TUN/TAP adapter does not start](https://community.openvpn.net/openvpn/ticket/316)
+ - Any progress in solving this?
+
+ # The Usual Stuff
+
+ ## Patch Review
+
+ If time permits, review patches from [here](wiki:Patches). ACK/NACK/discuss.
+
+ ## Ticket Review
+
+ If time permits, review some of the fairly recent tickets (June 1st -> today) listed [here](https://community.openvpn.net/openvpn/query?status=accepted&status=assigned&status=new&status=reopened&time=06%2F01%2F13..08%2F22%2F13&col=id&col=summary&col=status&col=type&col=priority&col=milestone&col=component&order=priority).
\ No newline at end of file
/dev/null .. meetings/2013-11-16.md
@@ 0,0 1,36 @@
+ # OpenVPN 2.4/3.x
+
+ ## Contributor License Agreement (CLA)
+ - This is required to distribute OpenVPN on Apple's AppStore and possibly other stores (e.g., Windows Marketplace) due to their incompatibility with the AGPLv3 license.
+ - It's important to minimize the scope of the agreement:
+ - Android contributor license agreements appear well-crafted and we can assume they are backed by substantial legal expertise and resources.
+
+ ## Permissive Licensing
+ - It’s currently unclear if adopting a permissive license would completely eliminate the need for a CLA.
+ - Potential licenses include BSD, MIT, Apache.
+ - Releasing OpenVPN 3.0 under a permissive license may lead to (big) companies forking it, potentially resulting in numerous incompatible forks.
+ - To combat potential fragmentation, standardizing the OpenVPN protocol might be necessary, though this comes with substantial overhead.
+
+ ## Minimizing the Scope of the CLA
+ - This approach reduces risks related to fragmentation, forks, and loss of contributions.
+ - Aim to maximize the potential to extend OpenVPN through isolated APIs:
+ - Plugins and similar extensions would not require a CLA.
+ - Extension mechanisms in OpenVPN:
+ - **2.x:**
+ - Plugin API
+ - Management interface
+ - SSL library abstraction
+ - Platform support (isolated by `#ifdefs`)
+ - **3.x:**
+ - SSL library abstraction
+ - Other mechanisms
+ - Potential separation of server-side and client-side code, where only the client-side would need a CLA.
+
+ ## Public Release Date for OpenVPN 3.x Codebase
+ - Source packages are currently available in old tar.gz formats.
+ - James aims to release this in the coming weeks.
+
+ ## Future of OpenVPN 2.x and 3.x
+ - Transitioning to the AGPLv3-licensed OpenVPN 3.x codebase is favorable, provided that the negative impact of the CLA is minimized.
+ - OpenVPN 2.x will remain maintained until 3.x can effectively replace it:
+ - This may include releasing versions up to 2.5.
\ No newline at end of file
/dev/null .. meetings/2013-ProductNamespaces.md
@@ 0,0 1,44 @@
+ ##### Discussion on Product Namespaces
+
+ To address the confusion among users regarding GPL code and the copyrighted/EULA governed code by OpenVPN Technologies Inc, we must tackle several issues related to namespace, identity, and copyright.
+
+ This list is designed to pinpoint potential issues for further discussion to determine the best resolutions. Feel free to contribute additional ideas or concerns that are not mentioned here.
+
+ - **Webpage Cross-Linking**
+ - The community landing page features multiple 'Download' links that lead to different actions:
+ - The download link from the left index directs to GPL software.
+ - The first download link under the "Download" hover-menu leads to "Access Server Downloads" without additional clarification (Note: this comes from Joomla).
+ - The second download link in the "Download" hover-menu is "Community Downloads" -- the difference is unclear and unexplained to users.
+ - Under the "Community" hover-menu, "downloads" link to GPL downloads.
+ - The community landing page includes "VPN Service" and "VPN Solution" hover-menus (also from Joomla):
+ - Several links to Licensing/Pricing appear here, which may confuse users into thinking this Service/Solution is part of the community offering.
+ - Shifting from the prominent "Community" hover-menu-tab to one of these tabs does not strongly signal that the user is leaving the Community page, especially considering the transition from the main openvpn.net page buttons.
+
+ - **Fixing the Website (Ideas/Solutions)**
+ - An initial discussion proposed creating a well-designed landing page as part of Trac's wiki:
+ - This would circumvent Joomla's content layout limitations.
+ - Cross-linking to AS/Connect URLs could be clearly explained where necessary.
+ - The wiki could be community-editable, with possible restrictions to wiki admins if needed.
+
+ - **Product Confusion**
+ - Several users struggle to differentiate between GPL OpenVPN, OpenVPN Connect, and OpenVPN Access Server:
+ - The current layout of the community landing page does not alleviate this confusion.
+ - New users face difficulties understanding the differences between:
+ - (GPL) OpenVPN
+ - OpenVPN Access Server
+ - OpenVPN Connect
+ - OpenVPN Client (an old/deprecated name for a former Connect product, less relevant once removed from downloads).
+ - It should be made clearer that GPL OpenVPN can function both as a server and a client.
+
+ - **Fixing the Product Confusion (Ideas/Solutions)**
+ - Ideas?
+
+ - **Forum Confusion**
+ - The banner image on the forums displays "OpenVPN" "Community Support Forum."
+ - However, this forum also presents non-free forums and their sub-forums under the same banner, causing confusion:
+ - It portrays closed and EULA-bound software as community-supported products.
+ - Users seeking commercial products/support find that the "OpenVPN.net" link (correctly) redirects them to the "Community" index page.
+ - The transition between FOSS and commercial support forums is almost imperceptible unless a user is already familiar with the product names.
+
+ - **Fixing the Forum Confusion (Ideas/Solutions)**
+ - Consider separating the corporate (AS/Connect/PrivateTunnel, etc.) forums from the FOSS forums.
\ No newline at end of file
/dev/null .. meetings/2014-01-09.md
@@ 0,0 1,28 @@
+ # New topics
+
+ - Figure out definition of the new data frame format with and without session ID
+ - Recent, related mailing list conversation [here](http://thread.gmane.org/gmane.network.openvpn.devel/8128/focus=8142)
+ - Notes from the Munich Hackathon [here](wiki:MunichHackathon2013#results)
+ - Missing "IV_OPENVPN_GUI_VERSION" in OpenVPN Connect
+ - It was [agreed in Munich](wiki:MunichHackathon2013#results) that sending this information makes sense
+ - OpenVPN for Android (from plaisthos) already makes use of this feature
+ - OpenVPN Connect client (from jamesyonan) seems not to be implementing this yet
+ - Is a fix in the queue?
+ - Signal handling is a bit funny in some places:
+ - ignoring certains signal while dns resolving
+ - USR1 is promoted to a HUP if it arrives in the initialisation phase
+ - link_socket_init_phase2 ignores all signal if called with a pending signal
+ - Are these behaviours required or can we clean this up?
+ - Tap-windows NDIS 6 port
+ - Latest news from jamesyonan
+ - [PATCH]: [ssl: enable basic ecdsa](http://thread.gmane.org/gmane.network.openvpn.devel/7958/focus=7961)
+
+ # The usual stuff
+
+ ## Patch review
+
+ If time permits, review patches from [here](wiki:Patches). ACK/NACK/discuss.
+
+ ## Ticket review
+
+ If time permits, review some of the fairly recent tickets (22nd Nov 2013 -> today) listed [here](https://community.openvpn.net/openvpn/query?status=accepted&status=assigned&status=new&status=reopened&time=11%2F22%2F13..01%2F09%2F14&col=id&col=summary&col=status&col=type&col=priority&col=milestone&col=component&order=priority).
\ No newline at end of file
/dev/null .. meetings/2014-04-24.md
@@ 0,0 1,22 @@
+ # New topics
+
+ ## TLS versioning
+ - The earlier TLS versioning patches in 2.3.3 may have broken things
+ - [TLS_ERROR: BIO read tls_read_plaintext error ...](http://thread.gmane.org/gmane.network.openvpn.user/34793)
+ - [Re: TLS_ERROR: BIO read tls_read_plaintext error ...](http://thread.gmane.org/gmane.network.openvpn.user/34794)
+ - [PATCH 4/4 When tls-version-min is unspecified, revert to original versioning approach](http://thread.gmane.org/gmane.network.openvpn.devel/8558/focus=8560)
+ - Do we revert back to TLS 1.0 -only in OpenVPN 2.3.4?
+ - I posted my comments here [here](http://article.gmane.org/gmane.network.openvpn.devel/8613); I also provided a patch for Trac #188 that's not in the patch list - Timothe Litt
+
+ ## 2.3.4
+ - Anything missing for a release "as soon as possible", like "on Friday"?
+
+ # The usual stuff
+
+ ## Patch review
+
+ If time permits, review patches from [here](wiki:Patches). ACK/NACK/discuss.
+
+ ## Ticket review
+
+ If time permits, review some of the fairly recent tickets.
\ No newline at end of file
/dev/null .. meetings/2014-10-23.md
@@ 0,0 1,77 @@
+ # Topics
+
+ - OpenVPN 2.3.5 release
+ - Recent [tap-windows6 -related fixes](http://thread.gmane.org/gmane.network.openvpn.devel/9143) in OpenVPN require a new release
+ - There are other queued changes in the 2.3 branch (see below)
+ - Anything missing?
+ - Release date?
+ - [Session-ID patch](http://thread.gmane.org/gmane.network.openvpn.devel/8403)
+ - [Munich Hackathon](wiki:MunichHackathon2014)
+ - Goals, plans, etc.
+ - Suggested new option for TLSv1.2 adoption: `--tls-version-max` (similar to `--tls-version-min`)
+ - As suggested by syzzer on #openvpn-devel
+
+ # Changes in the 2.3 branch
+
+ ```plaintext
+ Andris Kalnozols (2):
+ Fix some typos in the man page.
+ Do not upcase x509-username-field for mixed-case arguments.
+
+ Arne Schwabe (1):
+ Fix server routes not working in topology subnet with --server [v3]
+
+ David Sommerseth (4):
+ Improve error reporting on file access to --client-config-dir and --ccd-exclusive
+ Don't let openvpn_popen() keep zombies around
+ Add systemd unit file for OpenVPN
+ systemd: Use systemd functions to consider systemd availability
+
+ Gert Doering (3):
+ Drop incoming fe80:: packets silently now.
+ Fix t_lpback.sh platform-dependent failures
+ Call init script helpers with explicit path (./)
+
+ Heiko Hund (1):
+ refine assertion to allow other modes than CBC
+
+ Hubert Kario (2):
+ ocsp_check - signature verification and cert staus results are separate
+ ocsp_check - double check if ocsp didn't report any errors in execution
+
+ James Bekkema (1):
+ Fix socket-flag/TCP_NODELAY on Mac OS X
+
+ James Yonan (6):
+ Fixed several instances of declarations after statements.
+ In socket.c, fixed issue where uninitialized value (err) is being passed to to gai_strerror.
+ Explicitly cast the third parameter of setsockopt to const void * to avoid warning.
+ MSVC 2008 doesn't support dimensioning an array with a const var nor using %z as a printf format specifier.
+ Define PATH_SEPARATOR for MSVC builds.
+ Fixed some compile issues with show_library_versions()
+
+ Jann Horn (1):
+ Remove quadratic complexity from openvpn_base64_decode()
+
+ Mike Gilbert (1):
+ Add configure check for the path to systemd-ask-password
+
+ Philipp Hagemeister (2):
+ Add topology in sample server configuration file
+ Implement on-link route adding for iproute2
+
+ Samuel Thibault (1):
+ Ensure that client-connect files are always deleted
+
+ Steffan Karger (10):
+ Remove function without effect (cipher_ok() always returned true).
+ Remove unneeded wrapper functions in crypto_openssl.c
+ Fix bug that incorrectly refuses oid representation eku's in polar builds
+ Update README.polarssl
+ Rename ALLOW_NON_CBC_CIPHERS to ENABLE_OFB_CFB_MODE, and add to configure.
+ Add proper check for crypto modes (CBC or OFB/CFB)
+ Improve --show-ciphers to show if a cipher can be used in static key mode
+ Extend t_lpback tests to test all ciphers reported by --show-ciphers
+ Don't exit daemon if opening or parsing the CRL fails.
+ Fix typo in cipher_kt_mode_{cbc, ofb_cfb}() doxygen.
+ ```
\ No newline at end of file
/dev/null .. meetings/2014-11-24.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - **Time:** Monday 24th Nov 2014, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ 1. `--enable-password-save` - drop `#ifdef`, make always on? Change default? Patch from Yegor Yefremov.
+ 2. Peer-id v7 / peer-id client-only v2
+ - ACK from Syzzer is on the list.
+ - Anyone else wants to review before committing?
+ - ACK on "include client-only patch in 2.3"?
+ 3. OpenVPN 2.4 release
+ - Review patches (if any).
+ - Blockers and general status.
\ No newline at end of file
/dev/null .. meetings/2014-12-22.md
@@ 0,0 1,13 @@
+ **NOTE:** This meeting was cancelled due to lack of attendees. The topics were moved to the [next meeting](wiki:Topics-2014-12-29).
+
+ ## Basic info
+
+ - **Time:** Monday 22nd Dec 2014, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ ## Patch review
+
+ 1. [Add Mac OS X keychain support](http://thread.gmane.org/gmane.network.openvpn.devel/9320/focus=9346) (Vasily Kulikov)
+ 2. [Make OpenVPN set routes on Windows Vista and later](http://thread.gmane.org/gmane.network.openvpn.devel/9237) (Heiko Hund)
+ - [Git repository](https://sourceforge.net/p/openvpn-gui/openvpn/ci/interactive_service/tree/) with the code
\ No newline at end of file
/dev/null .. meetings/2014-12-29.md
@@ 0,0 1,13 @@
+ # Basic info
+
+ - **Time:** Monday 29th Dec 2014, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details on getting help](wiki:GettingHelp))
+
+ # Patch review
+
+ 1. [Add Mac OS X keychain support](http://thread.gmane.org/gmane.network.openvpn.devel/9320/focus=9346) (Vasily Kulikov)
+ 2. [Make OpenVPN set routes on Windows Vista and later](http://thread.gmane.org/gmane.network.openvpn.devel/9237) (Heiko Hund)
+ - [Git repository](https://sourceforge.net/p/openvpn-gui/openvpn/ci/interactive_service/tree/) with the code
+ 3. [Openvpn with cryptodev on FreeBSD does not work](https://community.openvpn.net/openvpn/ticket/480) (Ermal Luçi)
+ - Proposes to change init order, need to discuss consequences
\ No newline at end of file
/dev/null .. meetings/2015-01-12.md
@@ 0,0 1,11 @@
+ # Basic info
+
+ - **Time:** Monday 12th Jan 2015, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Patch review
+
+ 1. [Make OpenVPN set routes on Windows Vista and later](http://thread.gmane.org/gmane.network.openvpn.devel/9237) (Heiko Hund)
+ - [Git repository](https://sourceforge.net/p/openvpn-gui/openvpn/ci/interactive_service/tree/) with the code
+ 2. [Mac OS X Keychain management client](http://thread.gmane.org/gmane.network.openvpn.devel/9392) (Vasily Kulikov)
\ No newline at end of file
/dev/null .. meetings/2015-01-19.md
@@ 0,0 1,13 @@
+ # Basic info
+
+ - **Time:** Monday 19th Jan 2015, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Patch review
+
+ 1. [Mac OS X Keychain management client](http://thread.gmane.org/gmane.network.openvpn.devel/9392) (Vasily Kulikov)
+ - In the previous meeting, it was agreed to cover this topic first, because it's way less massive than the second one.
+ 2. [Make OpenVPN set routes on Windows Vista and later](http://thread.gmane.org/gmane.network.openvpn.devel/9237) (Heiko Hund)
+ - [Git repository](https://sourceforge.net/p/openvpn-gui/openvpn/ci/interactive_service/tree/) with the code
+ - Windows-specific bits still need reviewing, common bits look okay (with minor modifications).
\ No newline at end of file
/dev/null .. meetings/2015-02-02.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - **Time:** Monday 2nd Feb 2015, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Patch review
+
+ 1. [Mac OS X Keychain management client (v3)](http://thread.gmane.org/gmane.network.openvpn.devel/9421) (Vasily Kulikov)
+ - ACK?
+ 2. [Make OpenVPN set routes on Windows Vista and later](http://thread.gmane.org/gmane.network.openvpn.devel/9237) (Heiko Hund)
+ - [Git repository](https://sourceforge.net/p/openvpn-gui/openvpn/ci/interactive_service/tree/) with the code
+ - Windows-specific bits have not been fully reviewed yet
+ 3. [Account for peer-id in frame size calculation](http://thread.gmane.org/gmane.network.openvpn.devel/9418)
+ 4. [Add more dash escaping to the man page](http://thread.gmane.org/gmane.network.openvpn.devel/9422)
+ - Write a new patch to remove unneeded dashes from the man-page entirely?
\ No newline at end of file
/dev/null .. meetings/2015-03-30.md
@@ 0,0 1,43 @@
+ # Basic info
+
+ - **Time:** Monday 30th Mar 2015, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ ## OpenVPN 2.4
+ - **What is missing?**
+ - Interactive service
+ - AEAD
+ - The MacOS X keychain patch
+ - The patch is ready, but there are Makefile changes which need work
+ - Minor tunings to openvpn-gui.nsi / openvpn-build integration
+ - The actual openvpn-gui.exe is not signed, can be fixed with some refactoring of openvpn-build
+ - **Candidates for inclusion**
+ - Replacement for Windows service wrapper (openvpnserv.exe)
+ - **Facts**
+ - It sucks badly
+ - People complain and have complained about it more or less constantly for years
+ - It is getting more broken with new Windows releases
+ - Apparently it works really poorly on Windows 8 and later
+ - Current developers do not know how to fix it
+ - A better alternative might be [nssm.exe](http://www.nssm.cc/)
+ - Generic service manager
+ - Code under public domain
+ - Actively maintained
+ - [openvpn-user discussion](http://thread.gmane.org/gmane.network.openvpn.user/35533)
+ - [openvpn-devel discussion](http://thread.gmane.org/gmane.network.openvpn.devel/9548)
+ - Do we move forward with nssm.exe?
+ - **Release date?**
+
+ ## OpenVPN 2.3.7 release
+ - **What is missing?**
+ - **Candidates for inclusion**
+ - [Openvpn with crytpodev on FreeBSD does not work](ticket:480)
+ - There is a workaround patch from syzzer, but it has not yet been tested sufficiently
+ - [FreeBSD topo subnet self-route not via loopback interface](ticket:481)
+ - Discuss TLS version negotiation if it is not ACKed before the meeting
+ - **Release date?**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-04-13.md
@@ 0,0 1,13 @@
+ # Basic info
+
+ - Time: Monday 13th Apr 2015, 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ - OpenVPN 2.4
+ - Interactive service
+ - Review the [AEAD patchset](https://github.com/syzzer/openvpn/tree/aead-cipher-modes8)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-04-27.md
@@ 0,0 1,11 @@
+ # Basic info
+
+ - **Time:** Monday 27th Apr 2015, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ - No verified topics yet. The AEAD and Interactive service patchsets are likely candidates.
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-05-04.md
@@ 0,0 1,36 @@
+ # Basic Info
+
+ - **Time**: Monday 4th May 2015, 20:00 CEST (18:00 UTC)
+ - **Place**: #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ ## Documentation
+ - openvpn.8 could use improvement - it's extensive and combines various aspects like a reference manual and introduction. Some sections may only be of historical interest (e.g., "this command appeared in OpenVPN 2.1"). What steps should we take to enhance it?
+
+ ## Ticket Handling in Trac
+ - What should be done about all the [OpenVPN Connect tickets](report:18)? Can someone from OpenVPN tech address these by providing feedback or, ideally, a resolution and close them?
+ - A significant number of tickets are without a milestone. Is anyone willing to help classify them for relevance (2.3.7/2.3.8 or 2.4, or simply as a feature request)?
+ - Review open tickets with milestone 2.3.7 to clarify their status and decide on the next steps:
+ - #480
+ - #93
+ - #141
+ - #233
+ - #384
+ - #461
+ - #481
+ - #128
+ - #225
+ - #373
+ - #411
+ - #512
+ - #523
+ - #522
+ - #521
+
+ ## OpenVPN 2.4
+ - RFC: [Reworking the interface for querying users](http://thread.gmane.org/gmane.network.openvpn.devel/9232)
+ - This is an initial version, with expectations for a new revision post-review.
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-05-18.md
@@ 0,0 1,20 @@
+ # Basic info
+
+ - **Time:** Monday 18th May 2015, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ 1. **OpenVPN argument parsing**
+ - Most options ignore "extra" parameters
+ - Mailing list discussion [here](http://thread.gmane.org/gmane.network.openvpn.devel/9599)
+ 2. **Support requests sent to the security list**
+ - There are plenty of these requests, despite clear explanation what the security list is for
+ - Most requests are clearly from clueless people, as they contain nowhere near enough information to figure out the exact problem, let alone resolve the problem
+ - Should we add a "honeypot" email (e.g. 'support') for these people?
+ - Emails would go to /dev/null, but a reply would get sent with instructions on how to get help
+ 3. **Status of OpenVPN 2.3.7**
+ 4. **Status of OpenVPN 2.4**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-06-01.md
@@ 0,0 1,25 @@
+ # Basic info
+
+ - **Time**: Monday 1st Jun 2015, 20:00 CEST (18:00 UTC)
+ - **Place**: #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](https://community.openvpn.net/openvpn/wiki/GettingHelp))
+
+ # Topics
+
+ 1. **Use of Trac ticket fields**
+ - Currently the fields in Trac tickets are used somewhat incoherently
+ - Create a common understanding of how the fields should be used
+ - [Wiki page](https://community.openvpn.net/openvpn/wiki/DeveloperDocumentation#ManagingTractickets)
+ 2. [Trac #427: make check doesn't play nicely with automake 1.12 and up](https://trac.openvpn.net/openvpn/ticket/427)
+ - serial-tests / automake: shall we do the [libguestfs approach](https://www.redhat.com/archives/libguestfs/2013-February/msg00102.html)?
+ 3. **Status of OpenVPN 2.3.7**
+ - Assign tickets to 2.3.7 and 2.3.8
+ - release date for 2.3.7? like, June 3?
+ 4. **Status of OpenVPN 2.4**
+ - Assign tickets to "alpha 2.4", "beta 2.4", "RC 2.4" and 2.4.0
+ 5. **Windows 8.1 DNS registration issues**
+ - [Issue with register-dns in Windows 8.1](https://trac.openvpn.net/openvpn/ticket/399)
+ - [ipconfig failing to execute during VPN connection](https://trac.openvpn.net/openvpn/ticket/516)
+ - Who will fix and how?
+
+ [Back to meeting list](https://community.openvpn.net/openvpn/wiki/IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-06-15.md
@@ 0,0 1,21 @@
+ **NOTE:** This meeting was cancelled.
+
+ # Basic info
+
+ - **Time:** Monday 15th Jun 2015, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ 1. **Updating Windows installers**
+ - OpenSSL 1.0.1o was released with [security fixes](http://openssl.org/news/secadv_20150611.txt)
+ - Do any of the vulnerabilities affect OpenVPN enough to warrant a new release Windows installer release?
+ 2. **Status of OpenVPN 2.4**
+ - Assign tickets to "alpha 2.4", "beta 2.4", "RC 2.4" and 2.4.0
+ 3. **Windows 8.1 DNS registration issues**
+ - [Issue with register-dns in Windows 8.1](ticket:399)
+ - [ipconfig failing to execute during VPN connection](ticket:516)
+ - Who will fix and how?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-06-29.md
@@ 0,0 1,34 @@
+ # Basic info
+
+ - **Time:** Monday 29th Jun 2015, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ 1. **Status of OpenVPN 2.4**
+ - Assign tickets to "alpha 2.4", "beta 2.4", "RC 2.4" and 2.4.0
+ 2. **Replacing openvpnserv.exe with [NSSM](http://nssm.cc)**
+ - Proof of concept is ready and works
+ - If OpenVPN dies, NSSM restarts it immediately
+ - NSSM installs itself as a Windows system service, meaning that the setup survives a reboot
+ - Just bundling nssm.exe is adequate as-is for the corporate use-case
+ - NSSM configuration GUI / command-line is too difficult for generic end users
+ - All nitty gritty details have to be configured manually for every connection after install
+ - NSSM configuration has to be made more automatic
+ - Writing a full-fledged application (e.g. C# + Winforms) would be an overkill
+ - A [HTML application](https://technet.microsoft.com/en-us/library/ee692768.aspx) (.hta) running in a browser is probably the least bad solution
+ - Due to the need for privileged operations the browser needs to be Internet Explorer
+ - The code itself will be Javascript that runs privileged operation in Windows Scripting Host (WSH) and parses the results
+ - More discussion in Samuli's [mailing list monologue](http://sourceforge.net/p/openvpn/mailman/message/34237056/)
+ 3. **SourceForge's modifications of project files**
+ - Sourceforge has been silently adding adware to project installers, thus betraying the trust of the project's using their service
+ - Many projects have already left SourceForge
+ - Statements from [Notepad++](https://notepad-plus-plus.org/news/notepad-plus-plus-leaves-sf.html) and [Gimp](https://mail.gnome.org/archives/gimp-developer-list/2015-May/msg00144.html)
+ - Should we follow suit?
+ 4. **Windows 8.1 DNS registration issues**
+ - [Issue with register-dns in Windows 8.1](ticket:399)
+ - [ipconfig failing to execute during VPN connection](ticket:516)
+ - Who will fix and how?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-07-13.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - **Time:** Monday 13th July 2015, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ 1. **Patch review**
+ - **Tim Small**
+ - [RFC changes to the auth-pam plugin](http://thread.gmane.org/gmane.network.openvpn.devel/9892)
+ - **Steffan Karger**
+ - [fix regression: query password before becoming daemon](http://thread.gmane.org/gmane.network.openvpn.devel/9901)
+ - [Fix overflow check in openvpn_decrypt()](http://article.gmane.org/gmane.network.openvpn.devel/9842)
+ - **David Sommerseth**
+ - [Provide OpenVPN version information to plug-ins](http://thread.gmane.org/gmane.network.openvpn.devel/9906)
+ - [Reworking the interface for querying users](http://thread.gmane.org/gmane.network.openvpn.devel/9657)
+ - **Jan Just Keijser**
+ - [verify-client-cert patch](http://thread.gmane.org/gmane.network.openvpn.devel/9826)
+ - [Add TFTP and WPAD DHCP options](http://thread.gmane.org/gmane.network.openvpn.devel/9864/focus=9908)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-07-27.md
@@ 0,0 1,25 @@
+ # Basic info
+
+ - **Time:** Monday 27th July 2015, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ 1. Should we integrate [cppcheck](http://cppcheck.sourceforge.net/) into Buildbot?
+ - Code checks would be needed only on one (dedicated) builder, not all of them
+ 2. [Minor man page issue](http://sourceforge.net/p/openvpn/mailman/message/34249691/)? (reported by Jan Just Keijser)
+ 3. 2.3.8 release (when, what else to include)?
+ 4. Patch review
+ - **Tim Small**
+ - [RFC changes to the auth-pam plugin](http://thread.gmane.org/gmane.network.openvpn.devel/9892)
+ - **Steffan Karger**
+ - [Fix overflow check in openvpn_decrypt()](http://article.gmane.org/gmane.network.openvpn.devel/9842)
+ - **David Sommerseth**
+ - [Provide OpenVPN version information to plug-ins](http://thread.gmane.org/gmane.network.openvpn.devel/9906)
+ - [Reworking the interface for querying users](http://thread.gmane.org/gmane.network.openvpn.devel/9657)
+ - **Jan Just Keijser**
+ - [verify-client-cert patch](http://thread.gmane.org/gmane.network.openvpn.devel/9826)
+ - [Add TFTP and WPAD DHCP options](http://thread.gmane.org/gmane.network.openvpn.devel/9864/focus=9908)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-08-10.md
@@ 0,0 1,23 @@
+ # Basic info
+
+ - **Time**: Monday 10th August 2015, 20:00 CEST (18:00 UTC)
+ - **Place**: #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ 1. **Patch review**
+ - **David Sommerseth**
+ - [Reworking the interface for querying users](http://thread.gmane.org/gmane.network.openvpn.devel/9657)
+ - **Jan Just Keijser**
+ - [verify-client-cert patch](http://thread.gmane.org/gmane.network.openvpn.devel/9826)
+ - [Add TFTP and WPAD DHCP options](http://thread.gmane.org/gmane.network.openvpn.devel/9864/focus=9908)
+
+ # Postponed topics
+
+ These topics can't be discussed today, because we're lacking reviewers.
+
+ - **Tim Small**
+ - [RFC changes to the auth-pam plugin](http://thread.gmane.org/gmane.network.openvpn.devel/9892)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-08-24.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - **Time:** Monday 24th August 2015, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ * No topics yet, please suggest/add
+
+ # Postponed topics
+
+ These topics can't (probably) be discussed today, because we're lacking reviewers.
+
+ - Tim Small
+ - [RFC changes to the auth-pam plugin](http://thread.gmane.org/gmane.network.openvpn.devel/9892)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-09-07.md
@@ 0,0 1,1 @@
+ See [Topics-2015-09-21](wiki/Topics-2015-09-21).
\ No newline at end of file
/dev/null .. meetings/2015-09-21.md
@@ 0,0 1,29 @@
+ # Basic info
+
+ - **Time:** Monday 21st September 2015, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ ## Windows building
+ - seems to be doing `--disable-debug` right now - please change
+
+ ## T-Shirts!
+
+ ## Patch review
+ - **Rafael Gava**
+ - [Added two features to Network Address Translator](http://thread.gmane.org/gmane.network.openvpn.devel/10047)
+ - **Tim Small**
+ - [RFC changes to the auth-pam plugin](http://thread.gmane.org/gmane.network.openvpn.devel/9892)
+ - **Gert Döring**
+ - [Fix unaligned access to TCP MSS](http://thread.gmane.org/gmane.network.openvpn.devel/10056) (trac #497)
+ - [get_default_gateway_ipv6() for Windows (10/10)](http://thread.gmane.org/gmane.network.openvpn.devel/10085)
+ - [Redirect-gateway ipv6 -- apply to 2.3.x as well?](http://thread.gmane.org/gmane.network.openvpn.devel/10086)
+ - **Lukas Kutyla**
+ - [Fix privilege dropping if first connection attempt unsuccessful](http://thread.gmane.org/gmane.network.openvpn.devel/10061)
+ - **Steffan Karger**
+ - [strdup() return checks](http://thread.gmane.org/gmane.network.openvpn.devel/10046) (trac #600)
+ - Merge [control packet MTU increase](http://thread.gmane.org/gmane.network.openvpn.devel/9841) (trac #545) into 2.3?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-10-05.md
@@ 0,0 1,40 @@
+ # Basic info
+
+ - **Time:** Monday 5th October 2015, 19:30 CEST (17:30 UTC)
+ - **Place:** #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ 1. Plan the [Delft hackthon](wiki:DelftHackathon2015)
+ 2. T-Shirts!
+ - Volunteers wanted for handling this task, mattock was traumatized beyond repair the last time
+ 3. Patch review
+ - Rafael Gava
+ - [Added two feature to Network Address Translator](http://thread.gmane.org/gmane.network.openvpn.devel/10047) (discussed Sep 21, waiting for v2 patch, split into "easy" and "FTP translator" part)
+ - Tim Small
+ - [RFC changes to the auth-pam plugin](http://thread.gmane.org/gmane.network.openvpn.devel/9892) (waiting for Dazo)
+ - Gert Döring
+ - [get_default_gateway_ipv6() for Windows (10/10)](http://thread.gmane.org/gmane.network.openvpn.devel/10085) - shall we just merge it? It's been tested quite a bit now...
+ - [inet_ntop()/inet_pton() check for windows](http://thread.gmane.org/gmane.network.openvn.devel/10165) - tested OK on mingw/ubuntu12, mingw/ubuntu14, cygwin
+ - [redirect-gateway ipv6 -- apply to 2.3.x as well?](http://thread.gmane.org/gmane.network.openvpn.devel/10086)
+ - Lukas Kutyla
+ - [fix privilege dropping if first connection attempt unsuccessful](http://thread.gmane.org/gmane.network.openvpn.devel/10061)
+ - Steffan Karger
+ - AEAD?
+ 4. Windows environment
+ - ValdikSS
+ - trac#605 Win10 DNS issues, userspace firewall plugin, way forward?
+ - GUI to bundle for Windows?
+ - iservice?
+ - Lev's MSVC building patch
+ - OpenVPN-GUI in OpenVPN 2.3.8 Windows builds not popping up the UAC prompt like 2.3.6 did?
+ - [Forum discussion](http://forums.anandtech.com/showthread.php?t=2449976)
+ - Confirmed by mator in #openvpn-devel
+ - Asked the original reporter to run a few tests
+ 5. CloudFlare on community.openvpn.net
+ - There was a DoS attack against community.openvpn.net a few days ago, due to which it was put behind CloudFlare. CloudFlare does not currently seem to intercept IPv6 connections, only IPv4.
+ - We had originally decided not to use CloudFlare on community.openvpn.net, the rationale being "no TLS man-in-the-middles".
+ - Do we wish to disable CloudFlare on community.openvpn.net or keep it enabled?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-10-26.md
@@ 0,0 1,36 @@
+ # Basic info
+
+ - **Time**: Monday 26th October 2015, 20:00 CEST (18:00 UTC)
+ - **Place**: #openvpn-devel channel on Freenode IRC network
+ - You need a registered Freenode IRC nickname to join #openvpn-devel ([details](wiki:GettingHelp))
+
+ # Topics
+
+ 1. **Windows team ideas**
+ - An [exhaustive mail](http://thread.gmane.org/gmane.network.openvpn.devel/10292/focus=10319) on the topic from Samuli
+ 2. **T-Shirts**
+ - What to print on them exactly?
+ - Print the back using a band T-shirt style, a.k.a. "OpenVPN World Tour"?
+ - Delft 2015
+ - Munich 2014
+ - Munich 2013
+ - Brussels 2012
+ - Brussels 2011
+ 3. **Changes.rst**
+ - The exact format
+ - Entries for 2.3
+ 4. **Patch review**
+ - ValdikSS
+ - [Add Windows DNS Leak fix using WFP ('block-outside-dns')](https://github.com/ValdikSS/openvpn-with-patches/commit/3bd4d503d21aa34636e4f97b3e32ae0acca407f0)
+ - Lev
+ - [Use adapter index instead of name](http://article.gmane.org/gmane.network.openvpn.devel/10361)
+ - [Support for disabled peer-id](http://article.gmane.org/gmane.network.openvpn.devel/10216)
+ - [Notify clients about server's exit/restart](http://thread.gmane.org/gmane.network.openvpn.devel/9496/focus=10278)
+ 5. **Trac tickets**
+ - [OpenVPN won't send AUTH_FAILED if client-connect plugin exited successfully but script not](https://community.openvpn.net/openvpn/ticket/180)
+ - [Shaper does not work in linux clients](https://community.openvpn.net/openvpn/ticket/91)
+ - [http://openvpn.net/faq.html#dhcpclientserv not working anymore](https://community.openvpn.net/openvpn/ticket/323)
+ - [Mssfix code is slow (see latest comment)](https://community.openvpn.net/openvpn/ticket/593)
+ - Please add links to Trac tickets that need love
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-11-09.md
@@ 0,0 1,38 @@
+ # Basic info
+
+ - **Time:** Monday 9th November 2015, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **Moneyz**
+ - set up flattr page?
+ - if money comes in, what to do with it?
+ 2. **PolarSSL 1.2 end-of-life on 31-12-2015 (syzzer)**
+ - Upgrade release/2.3 to support PolarSSL/mbedTLS 1.3
+ - Keep or remove PolarSSL 1.2 support?
+ 3. **Setting up Travis-CI and coverity for OpenVPN (syzzer)**
+ - Automatic builds and static analysis
+ 4. **2.3.9 release**
+ - what is missing?
+ - timeline?
+ 5. **Patch review**
+ - **Lev**
+ - [Use adapter index instead of name](http://article.gmane.org/gmane.network.openvpn.devel/10361)
+ - [Support for disabled peer-id](http://article.gmane.org/gmane.network.openvpn.devel/10216)
+ - [Notify clients about server's exit/restart](http://thread.gmane.org/gmane.network.openvpn.devel/9496/focus=10278)
+ - **Dazo**
+ - Query username/password patches
+ - These are lacking a final review before applying them
+ - Dazo has been running them on his laptop for quite a while without any issues.
+ - They are needed for me to further improve the username/password issues we especially see on systemd based systems.
+ - All comments have been considered and merged into these patches.
+ 6. **Trac tickets**
+ - [OpenVPN won't send AUTH_FAILED if client-connect plugin exited successfully but script not](ticket:180)
+ - [shaper does not work in linux clients](ticket:91)
+ - [http://openvpn.net/faq.html#dhcpclientserv not working anymore](ticket:323)
+ - [mssfix code is slow (see latest comment)](ticket:593)
+ - [When --disable is set for a client, the server never replies to the client](ticket:521) (from dazo)
+ - Please add links to Trac tickets that need love
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-11-23.md
@@ 0,0 1,37 @@
+ # Basic info
+
+ - **Time:** Monday 23rd November 2015, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **Moneyz**
+ - Status?
+ 2. **Setting up Travis-CI and Coverity for OpenVPN (syzzer)**
+ - Automatic builds and static analysis - status?
+ 3. **2.3.9 Release**
+ - Inclusion of commit 6e9373c84639382c in 2.3?
+ - What is missing?
+ - Timeline?
+ 4. **mbed TLS 2.x (syzzer)**
+ - Proposal: upgrade master to mbedtls 2.x
+ - What about release/2.3? (1.3.x supported until 31-12-2016)
+ 5. **Patch Review**
+ - **Dazo**
+ - Query username/password patches
+ - These are lacking a final review before applying them.
+ - Dazo has been running them on his laptop for quite a while without any issues.
+ - They are needed for further improvements on the username/password issues seen on systemd-based systems.
+ - All comments have been considered and merged into these patches.
+ - Patch to fix "[ticket:521 When --disable is set for a client, the server never replies to the client]"
+ - **Arne**
+ - Timeout Patch
+ - Compression v2 framing
+ 6. **Trac Tickets**
+ - [ticket:180 OpenVPN won't send AUTH_FAILED if client-connect plugin exited successfully but script not]
+ - [ticket:91 Shaper does not work in Linux clients]
+ - [ticket:323 http://openvpn.net/faq.html#dhcpclientserv not working anymore]
+ - [ticket:593 mssfix code is slow (see latest comment)]
+ - Please add links to Trac tickets that need love
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-12-14.md
@@ 0,0 1,34 @@
+ # Basic info
+
+ - **Time:** Monday 14th December 2015, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **Moneyz**
+ - status?
+ - OSTIF.org [kickstarter project](https://www.kickstarter.com/projects/1746978355/open-source-technology-improvement-fund-ostif)
+ 2. **OpenVPN 2.3.9 release**
+ - Include the [Make ValdikSS's DNS leak fix platform agnostic](http://article.gmane.org/gmane.network.openvpn.devel/10789) patch from Fish Wang? It allows the same openvpn.exe to be used on both Windows XP and Vista+
+ - [Distribute the GUI to run with highest privilege available](http://thread.gmane.org/gmane.network.openvpn.devel/10761)?
+ 3. **Patch review**
+ - Rafael Gava
+ - [Added two feature to Network Address Translator](http://thread.gmane.org/gmane.network.openvpn.devel/10047)
+ - Dazo
+ - Query username/password patches
+ - These are lacking a final review before applying them
+ - Dazo has been running them on his laptop for quite a while without any issues.
+ - They are needed for me to further improve the username/password issues we especially see on systemd based systems.
+ - All comments have been considered and merged into these patches.
+ - Arne
+ - Timeout Patch
+ - Compression v2 framing
+ 4. **Trac tickets**
+ - [OpenVPN won't send AUTH_FAILED if client-connect plugin exited successfully but script not](ticket:180)
+ - [shaper does not work in linux clients](ticket:91)
+ - [http://openvpn.net/faq.html#dhcpclientserv not working anymore](ticket:323)
+ - [mssfix code is slow (see latest comment)](ticket:593)
+ - [Windows ipv6 routing netsh.exe fails](ticket:637)
+ - Please add links to Trac tickets that need love
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2015-12-28.md
@@ 0,0 1,35 @@
+ # Basic info
+
+ - **Time:** Monday 28th December 2015, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **Windows-GUI - open pull request**
+ 2. **OpenVPN 2.3.10 release**
+ - PolarSSL 1.2 is EOL at Dec 31, 2015, patch for PolarSSL 1.3 has been merged
+ - Windows XP currently broken with respect to IPv6 and netsh.exe calls
+ 3. **Windows Installer - open Trac tickets**
+ 4. **AEAD (GCM) mode - the way forward**
+ 5. **Patch review**
+ - **cron2**
+ - [push-remove patch v2](http://article.gmane.org/gmane.network.openvpn.devel/10890)
+ - **Dazo**
+ - Query username/password patches
+ - These are lacking a final review before applying them
+ - Dazo has been running them on his laptop for quite a while without any issues.
+ - They are needed for me to further improve the username/password issues we especially see on systemd-based systems.
+ - All comments have been considered and merged into these patches.
+ - **Arne**
+ - Timeout Patch
+ - Compression v2 framing (reviewed by syzzer, waiting for v2)
+ - **Rafael Gava**
+ - [Added client-ip option to NAT](http://news.gmane.org/find-root.php?message_id=CAAWBBYMWbgCy74zU6OWT%2bT9eopRNbBF%2dK7HeD27KRGwGXOkAeg%40mail.gmail.com)
+ - Part of [Added two feature to Network Address Translator](http://thread.gmane.org/gmane.network.openvpn.devel/10047) patchset, which probably won't be merged as a whole.
+ 6. **Trac tickets**
+ - [OpenVPN won't send AUTH_FAILED if client-connect plugin exited successfully but script not](ticket:180)
+ - [Shaper does not work in Linux clients](ticket:91)
+ - [http://openvpn.net/faq.html#dhcpclientserv not working anymore](ticket:323)
+ - Please add links to Trac tickets that need love
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-01-11.md
@@ 0,0 1,10 @@
+ # Basic info
+
+ - Time: Monday 11th January 2016, 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ - Review as many unreviewed patches as possible. No other topics for today.
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-02-01.md
@@ 0,0 1,25 @@
+ # Basic info
+
+ - **Time:** Monday 1st February 2016, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ ## Interactive Service
+ - Review the service component
+
+ ## The Windows service
+ - `openvpnserv.exe` is crude, has many issues (e.g. [ticket #595](https://trac.openvpn.net/ticket/595) and [Selva's email](http://thread.gmane.org/gmane.network.openvpn.devel/9237/focus=11040)) and nobody has stepped in to fix the code
+ - There is now a drop-in replacement, [openvpnserv2](https://github.com/xkjyeah/openvpnserv2), written in C#
+ - [mattock's ovpnsvcsetup](https://github.com/mattock/ovpnsvcsetup) (a simple configuration frontend for [NSSM](http://nssm.cc/)) has not progressed much due to lack of time
+ - Questions:
+ - What do we do about `openvpnserv.exe`?
+ - How do we handle reviews if we decide to make the service component a separate subproject?
+ - Do we bundle `openvpnserv.exe` (replacement) in the standard installers or make it a separate download?
+ - Implementation details for `openvpnserv.exe`
+ - Handling of sleep+resume: should the service forcibly kill `openvpn.exe` on sleep, or restart it only if/when it dies after resume? Usability issues (e.g. broken connections)?
+
+ ## Update --block-outside-dns to work on Windows Vista
+ - [Discussion link](http://article.gmane.org/gmane.network.openvpn.devel/10998)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-05-09.md
@@ 0,0 1,13 @@
+ # Basic info
+
+ - Time: Monday 9th May 2016, 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ - OpenVPN 2.3.11 release
+ - Next hackathon
+ - Patches
+ - VLAN patchset
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-05-30.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - **Time:** Monday 30th May 2016, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ - Next hackathon [Helsinki Hackathon 2016](HelsinkiHackathon2016)
+ - OpenVPN 2.4 (see [Status of Openvpn 2.4](StatusOfOpenvpn24))
+ - Tickets
+ - [Protect the client from accepting arbitrary options pushed by the server #682](https://github.com/OpenVPN/openvpn/pull/50)
+ - Github PRs for OpenVPN - look at a few, decide what to do about
+ - Patches
+ - The VLAN patchset
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-06-13.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - Time: Monday 13th June 2016, 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ ## OpenVPN 2.4 patches (these are the priority)
+ - For overview, see [StatusOfOpenvpn24](wiki:StatusOfOpenvpn24)
+ - [PATCHv2 3/5: Add client-side support for cipher negotiation](http://article.gmane.org/gmane.network.openvpn.devel/11869)
+ - [PATCHv2 4/5: Add options to restrict cipher negotiation](http://article.gmane.org/gmane.network.openvpn.devel/11872)
+ - [PATCHv2 5/5: Add server-side support for cipher negotiation](http://article.gmane.org/gmane.network.openvpn.devel/11873)
+ - [Branch: dev/query-user-v4](https://gitlab.com/dazo/openvpn/commits/dev/query-user-v4)
+
+ ## Other patches ("_if time permits_")
+ - The VLAN patchset
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-08-15.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Monday 15th Aug 2016, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Re-Sync what everyone has been doing
+ 2. BF warning patch (Steffan/Arne, but not public yet)
+ 3. 2.3.12 release?
+ 4. OpenVPN 2.4 patches (these are the priority)
+ 5. tap-windows6 patches from thermi
+ 6. windows testing
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-08-22.md
@@ 0,0 1,21 @@
+ # Basic info
+
+ - **Time:** Monday 22nd Aug 2016, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Discussion with [OSTIF](https://ostif.org/) about their plans regarding OpenVPN
+ 2. OpenVPN 2.3.12 release
+ 3. Patches
+ - Do not pass env for system commands (ValdikSS)
+ - [PATCH 1/3: Do not pass env for system commands on Linux](https://sourceforge.net/p/openvpn/mailman/message/35265481)
+ - [PATCH 2/3: Do not pass env for system commands on Windows](https://sourceforge.net/p/openvpn/mailman/message/35265483)
+ - [PATCH 3/3: Do not pass env for system commands on OS X](https://sourceforge.net/p/openvpn/mailman/message/35265480)
+ - [PATCH v2: Drop recursively routed packets](https://sourceforge.net/p/openvpn/mailman/message/34737757/) (Lev)
+ - This one has had some review already, but no ACK/NACK
+ 4. Bugs
+ - [block-outside-dns and multiple tunnels](https://sourceforge.net/p/openvpn/mailman/message/35263770/) (Trac [#718](https://sourceforge.net/p/openvpn/ticket/718))
+ 5. Windows testing
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-10-10.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Monday 10th Oct 2016, 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Windows testing
+ - can we have an installer with master + d12fk_v2 please?
+ - [http://build.openvpn.net/downloads/temp/openvpn-install-2.3_git-do-ifconfig-after-tun-v2-I601-i686.exe](http://build.openvpn.net/downloads/temp/openvpn-install-2.3_git-do-ifconfig-after-tun-v2-I601-i686.exe)
+ - [http://build.openvpn.net/downloads/temp/openvpn-install-2.3_git-do-ifconfig-after-tun-v2-I601-x86_64.exe](http://build.openvpn.net/downloads/temp/openvpn-install-2.3_git-do-ifconfig-after-tun-v2-I601-x86_64.exe)
+ 2. OpenVPN 2.4-alpha1 release
+ - [Release status page](wiki:StatusOfOpenvpn24)
+ 3. OpenVPN 2.3.13 release
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-11-07.md
@@ 0,0 1,63 @@
+ # Basic info
+
+ - Time: Monday 7th Nov 2016, 20:00 CET (19:00 UTC)
+ - Place: `#openvpn-meeting` channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN QA**
+ - Quick summary of what we have now below
+ - Patchwork for openvpn-devel?
+ - [Patchwork](http://jk.ozlabs.org/projects/patchwork/)
+ - Fetch patches from list, store them in easily browsed repository
+ - CI systems can poll patchwork and auto-test apply + compile incoming patches (using throwaway VMs that get reset after each test run)
+ - Quagga is doing this [Quagga Patchwork](https://patchwork.quagga.net/project/quagga/list/)
+ 2. **OpenVPN 2.4 - next steps?**
+ - [Release status page](wiki:StatusOfOpenvpn24)
+ - RFC: deprecate or remove `--key-method 1`?
+ - Getting 2.4 into Debian 9
+ - Mail from the Debian package maintainer: "I'll consider uploading 2.4_something in early December, so we have a month to fix possible issues. After December 29 it won't be doable."
+ 3. **OpenVPN 2.3.14 release**
+ - What is missing?
+
+ # QA overview
+
+ **NOTE:** The table below is now maintained on [OpenVPN QA page](wiki:OpenVPN_QA).
+
+ Here's an overview of our current, work in progress and proposed QA tools/processes:
+
+ | Tool/process | Automated | In use | Scope | Extra requirements | B.patch | B.merge | A.merge | B.release | B.distro merge |
+ |----------------------|-----------|------------|--------------------|--------------------|---------|---------|---------|-----------|----------------|
+ | "make check" | No | Yes | Build | None | X | | | | |
+ | vagrant | No | Needs work | Build,integration | Vagrant installed | X | | | | |
+ | unit tests | Yes | Needs work | Regression | Cmocka installed | X | | | | |
+ | code review | No | Yes | Everything | None | | X | | | |
+ | travis | Yes | Yes | Build | Use a GitHub PR | | X | | | |
+ | patchwork | Yes | Proposed | Build,integration | Has to be setup | | X | | | |
+ | push scripts | No | Yes | ? | Scripts installed | | X | | | |
+ | buildbot | Yes | Yes | Build,integration | None | | (X)![3] | X | | |
+ | win builds![1] | Yes | Yes | Build | None | | (X)![3] | X | | |
+ | win snapshots![1] | Yes | Yes | Everything | Windows | | | | X | |
+ | win testsuite![2] | No![4] | Yes | Integration | Windows | | (X)![3] | (X)![3] | X | |
+ | linux packages | No![4] | Yes | Everything | Debian OS | | (X)![3] | (X)![3] | (X)![3] | X |
+
+ Notes:
+ 1. [OpenVPN Windows Build Test](https://github.com/mattock/openvpn-windows-buildtest)
+ 2. [OpenVPN Windows Test](https://github.com/mattock/openvpn-windows-test)
+ 3. This tool/process could be adapted to catch errors earlier, at this phase
+ 4. Could be automated, but requires a fair amount of work; integration with Windows snapshots could be accomplished with [Chocolatey](https://chocolatey.org/).
+
+ Key:
+ - B.patch = (Typically catches errors) before a patch is published
+ - B.merge = before merging the patch (to Git "master")
+ - A.merge = after merging the patch (to Git "master")
+ - B.release = before making a release
+ - B.distro merge = before distributions merge the release to their repositories/ports
+
+ ''Scope'' is very high-level here by design. We can improve our QA in two main ways:
+ 1. Catch the problems earlier
+ 2. Make each tool/process catch more problems
+
+ More complete description of our QA on the [OpenVPN QA page](wiki:OpenVPN_QA).
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-11-14.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Monday 14th Nov 2016, 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.4 - next steps?
+ - [Release status page](wiki:StatusOfOpenvpn24)
+ - RFC: deprecate or remove `--key-method 1`?
+ 2. OpenVPN 2.3.14 release
+ - what is missing?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-11-23.md
@@ 0,0 1,13 @@
+ # Basic info
+
+ - **Time:** Wed 23rd Nov 2016, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.4 - next steps?
+ - [Release status page](wiki:StatusOfOpenvpn24)
+ 2. OpenVPN 2.3.14 release
+ - what is missing?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-11-30.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed 30th Nov 2016, 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.4 - next steps?
+ - [Release status page](wiki:StatusOfOpenvpn24)
+ - trac#775 - decide what to do (just remove the "net stop dnscache" calls?)
+ 2. OpenVPN 2.3.14 release
+ - Release date?
+ 3. PGP key signing party
+ - cron2: 3072R/CA562812 2016-11-10 Key fingerprint = B62E 6A2B 4E56 570B 7BDC 6BE0 1D82 9EFE CA56 2812
+ - syzzer: 2048R/007ED288 2013-03-19 Key fingerprint = 0FD1 29CC 65BD 59E1 3C21 F77C 9802 CA3D 007E D288
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-12-07.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - **Time**: Wed 7th Dec 2016, 20:00 CET (19:00 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.4 - next steps?**
+ - [Release status page](wiki:StatusOfOpenvpn24)
+ - mechanics of the code reformatting - who, where, how to review, ...?
+ 2. **patchwork status**
+ 3. **Stripping out user choices from the Windows installer**
+ - The dependencies between components make it hard to cover all the corner-cases
+ - Earlier discussion on [GitHub](https://github.com/OpenVPN/openvpn-build/issues/59) and on the [mailing list](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg13390.html)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-12-14.md
@@ 0,0 1,11 @@
+ # Basic info
+
+ - Time: Wed 14th Dec 2016, 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.4 - next steps?
+ - [Release status page](wiki:StatusOfOpenvpn24)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2016-12-21.md
@@ 0,0 1,25 @@
+ # Basic info
+
+ - **Time:** Wed 21st Dec 2016, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ ## 1. OpenVPN 2.4 - next steps?
+ - [Release status page](wiki:StatusOfOpenvpn24)
+
+ ## 2. Decommissioning openvpn-testing.git (proposal from dazo)
+ - The testing git repo has not served the purpose it was designed for in a long time, due to the development model having changed dramatically.
+ - The official openvpn.git repositories users can fetch our git trees from are on GitLab, GitHub, and SourceForge.net, and they should always be in sync.
+ - openvpn-testing.git is currently only hosted on SourceForge.net and should be removed.
+ - Those branches which are only to be found in this repository carry no value anymore - most branches have been long gone merged into master and release/2.x branches.
+ - Exceptions of not merged branches:
+ - `feat_passtos` (based on v2.2_beta) and needs to be reworked to be relevant again. Considering the interest for this feature has been mostly lacking, dazo does not consider this important enough to keep around.
+ - `feat_vlan_tagging` (builds on feat_passtos) which also needs massive rework. This feature has received a few more requests over the years on the ML, but no-one has taken responsibility to care or push for this feature. This patch-set consists of 16 patches, which in addition needs thorough review. Considering the lack of ownership to these patches and someone really pushing for this to become a reality, plus that it needs a considerable rebase work, dazo is of the opinion to also drop this one. **If** someone is willing to take ownership of this patch-set and we have people willing to review it - it can be prepared in an external git repository before being sent for final review on the mailing list.
+ - Decommissioning openvpn-testing.git will happen in early January, where the last push to this git tree will be the final OpenVPN v2.4.0 release.
+
+ ## 3. Copyright updates
+ - dazo proposes to run the update-copyright.sh script on master, release/2.3, and release/2.4 branches, updating the copyright year to 2017.
+ - This should be run before the v2.4.0 release goes out.
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-01-04.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - Time: Wed 4th Jan 2017, 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Quick look at open Trac tickets
+ 2. OpenVPN 2.4.1 release
+ 3. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 4. Moving a few subprojects under the OpenVPN organization in GitHub
+ - [openvpn-windows-buildtest](https://github.com/mattock/openvpn-windows-buildtest)
+ - Builds and publishes Windows installers on every commit
+ - [sbuild_wrapper](https://github.com/mattock/sbuild_wrapper)
+ - Produces Debian and Ubuntu packages in sbuild chroots
+ - Some integration with [freight-based apt repositories](https://github.com/freight-team/freight)
+ 5. Future meeting schedule
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-02-22.md
@@ 0,0 1,13 @@
+ # Basic info
+
+ - **Time:** Wed 22nd Feb 2017, 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.4.1 release
+ 2. [OpenSSL 1.1 support patches](https://github.com/emmanuel-deloget/openvpn/commits/openvpn-1.1)
+ 3. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 4. How to deal with (good) patches without proper attribution? E.g. #825.
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-03-15.md
@@ 0,0 1,13 @@
+ # Basic info
+
+ - Time: Wed 15th March 2017, 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.4.1 release
+ 2. [OpenSSL 1.1 support patches](https://github.com/emmanuel-deloget/openvpn/commits/openvpn-1.1)
+ - What to do with "--ns-cert-type"? ([mail thread](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg14223.html))
+ 3. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-09-12.md
@@ 0,0 1,23 @@
+ # Basic info
+
+ - **Time:** Tue 12th September 2017, 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Restore a somewhat reliable meeting schedule
+ 2. Next 2.4.x release
+ 3. Buildmaster not working right
+ 4. More fine-grained signalling from OpenVPN to OpenVPN GUI
+ - OpenVPN GUI sometimes thinks connection works when, for example, route addition has actually failed
+ - This causes confusing/bad user experience
+ - [Issue #168 Comment](https://github.com/OpenVPN/openvpn-gui/issues/168#issuecomment-305243166)
+ - [Issue #9](https://github.com/OpenVPN/openvpn-gui/issues/9)
+ - [Issue #183](https://github.com/OpenVPN/openvpn-gui/issues/183)
+ 5. tls-crypt-v2 status update
+
+ # Still waiting for review
+
+ 1. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-09-20.md
@@ 0,0 1,16 @@
+ # Basic Info
+
+ - **Time:** Wed 20th September 2017, 19:00 CEST (17:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Next 2.4.x release (~25th September)
+ 2. ~~tls-crypt-v2~~: (postponed because syzzer won't be able to join)
+ - ~~avoid user fingerprinting: can we ensure the current spec will allow the introduction of a backward compatible fix?~~
+
+ # Still Waiting for Review
+
+ 1. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-09-27.md
@@ 0,0 1,21 @@
+ # Basic info
+
+ - Time: Wed 27th September 2017, 19:00 CEST (17:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.4.4 release aftermath (if any)
+ 2. tls-crypt-v2:
+ - avoid user fingerprinting: can we ensure the current spec will allow the introduction of a backward compatible fix?
+ 3. patchwork pending (help needed?)
+ 4. our release cycle (maybe something that we should deepen during the hackathon):
+ - smooth patch review (our ML is crying a bit)
+ - better distinction of what goes into master and what not
+ - reduce time between major releases
+ 5. Review of how to accept contrib scripts.
+ - Do they become audited / approved code?
+ - Are they user beware?
+ - How do we accept new contrib items?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-10-04.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 4th October 2017, 19:00 CEST (17:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tls-crypt-v2:
+ - avoid user fingerprinting: can we ensure the current spec will allow the introduction of a backward compatible fix?
+ 2. patchwork status
+ 3. Review of how to accept contrib scripts.
+ - Do they become audited / approved code?
+ - Are they user beware?
+ - How do we accept new contrib items?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-10-11.md
@@ 0,0 1,11 @@
+ # Basic info
+
+ - Time: Wed 11th October 2017, 19:00 CEST (17:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tls-crypt-v2:
+ - avoid user fingerprinting: can we ensure the current spec will allow the introduction of a backward compatible fix?
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-10-18.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - **Time**: Wed 18th October 2017, 19:00 CEST (17:00 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **tls-crypt-v2**:
+ - Avoid user fingerprinting: discuss Antonio's alternative proposal using asymmetric keys.
+ 2. **openvpn-build PR**: [Add "PKCS#11 URIs compliant with RFC7512" patch](https://github.com/OpenVPN/openvpn-build/pull/110)
+ - [Upstream patch](https://github.com/OpenSC/pkcs11-helper/pull/4)
+ - [Earlier discussion](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg00156.html) on openvpn-devel
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-10-25.md
@@ 0,0 1,11 @@
+ # Basic info
+
+ - Time: Wed 25th October 2017, 19:00 CEST (17:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tls-crypt-v2:
+ - avoid user fingerprinting: discuss Antonio's alternative proposal using asymmetric keys.
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-11-01.md
@@ 0,0 1,23 @@
+ # Basic info
+
+ - **Time:** Wed 1st November 2017, 11:30 CEST (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ ## 1. Test branches on github, targeting buildslaves
+ - if one of us wants to try out "does this patch break NetBSD? Or OpenSolaris?" it is quite cumbersome today
+ - shall we have special branches that are writeable for all "regular and trusted" developers which can be used to run a buildbot test? (Maybe not automatic, but via community VPN request on buildmaster)
+ - other ideas welcome
+ - (note: vagrant would work, if we had templates for all the OSes we support, including MacOS and OpenSolaris - but I feel it's more heavy than just using the existing slaves)
+
+ ## 2. Revisit our support policy for "oldstable"
+ - Right now we support two stable releases:
+ - "stable": 2.4
+ - "oldstable": 2.3
+ - What if we stopped supporting "oldstable" after
+ - some months have passed since current "stable" release?
+ - certain number of "stable" point releases have been made?
+ - Even moving "oldstable" to "source-only" maintenance mode would lighten the release process significantly
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-12-06.md
@@ 0,0 1,10 @@
+ # Basic info
+
+ - Time: Wed 6th December 2017, 11:30 CEST (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-12-13.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 13th December 2017, 11:30 CEST (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenBSD/LibreSSL support
+ - OpenBSD uses a fork of OpenSSL called LibreSSL
+ - LibreSSL is not 100% compatible with OpenSSL
+ - We want to support OpenVPN on OpenBSD
+ - How do we resolve this conundrum?
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 3. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2017-12-20.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - Time: Wed 20th December 2017, 11:30 CEST (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. [Internet Bug Bounty](https://internetbugbounty.org/)
+ - We were approached by IBB a while ago and they were interested in putting OpenVPN on their supported project list
+ - They try to avoid overlap with other supporting organizations (in our case [OSTIF.org](https://ostif.org/))
+ - Is there something we can do to coordinate this?
+ 2. Putting CloudFlare on front of community.openvpn.net and forums.openvpn.net?
+ 3. Update on control channel optimization (gertvandijk, syzzer)
+ 4. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 5. FIPS patches
+ 6. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-01-03.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed 3rd Jan 2018 11:30 CEST (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. [Internet Bug Bounty](https://internetbugbounty.org/)
+ 2. Update on control channel optimization (gertvandijk, syzzer)
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-01-10.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Wed 10th Jan 2018 11:30 CEST (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-01-17.md
@@ 0,0 1,55 @@
+ # Basic info
+
+ - Time: Wed 17th Jan 2018 11:30 CEST (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Building release/2.4 branch in Buildbot?
+ - "release/2.4" has the --disable-crypto flag
+ - "master" does not
+ 2. 2.4.5 release status
+ 3. Selva requested feedback on 'ecdsa-sig' management interface command, see below for details
+ 4. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 5. Create new "Components" in bug tracker to improve bugs classification (i.e. OpenVPN for Android is mixed up with Connect)
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ # ecdsa-sig
+
+ Email from Selva:
+
+ ```
+ I do not think I can make any coherent case at 5:30am even if I
+ somehow manage to make it to the meeting, but would like some feedback
+ on one thing:
+
+ Topic: 'ecdsa-sig' management interface command that I proposed (the
+ patch for supporting EC certs with external key being reviewed by
+ Arne).
+ Ref: https://patchwork.openvpn.net/project/openvpn2/list/?series=126
+
+ We currently have rsa-sig for RSA signatures[*]. With hindsight we
+ could say this naming was not ideal as now we want to support
+ multiple key types. I think it may be better to name the new command
+ as type-agnostic like 'pkey-sig' so that we can deprecate rsa-sig and
+ eventualy remove it. As only management clients are affected this
+ should be easier than deprecating a config option. In the mean time
+ exclusively use
+ the new command for ECDSA signatures.
+
+ Including the key/signature type in the command name is not necessary as the
+ UI knows which key to use and that fixes the signature type.
+
+ If the meeting is already loaded with topics, I can ask this on the devel list.
+
+ Thanks,
+
+ Selva
+ [*] The daemon sends RSA-SIGN, the management client responds with rsa-sig
+ ```
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-01-24.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - Time: Wed 24th Jan 2018 11:30 CEST (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.4.5 release
+ - Release date set to 25th Jan
+ - Coordinate the release
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-01-31.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - **Time**: Wed 31st Jan 2018 11:30 CEST (10:30 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.4.5 release**
+ - Release date was postponed from the original (25th Jan)
+ - Coordinate the release
+ 2. **mgmt version 2 / pk-sign and 2.4**
+ - Is this something we want in 2.4? If not, how's the GUI going to deal with 2.4 and master being different?
+ 3. **Copyright notices in files, and in --version (2018, patch from eworm)**
+ 4. **Finalize and publish the SupportedVersions page**
+ 5. **Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)**
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-02-21.md
@@ 0,0 1,21 @@
+ # Basic info
+
+ - Time: Wed 21st Feb 2018 11:30 CEST (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.4.5 release
+ - The "release/2.4" branch is currently broken on CentOS 6, OpenSolaris, and OpenBSD
+ - Windows is also broken
+ - Goal: release Thursday 22nd Feb
+ 2. SF.net Git repository
+ - There seem to be sporadic connectivity issues: "git.code.sf.net[0: 216.105.38.16]: errno=Connection refused"
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-03-07.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - **Time:** Wed 7th Mar 2018 11:30 CEST (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **LibreSSL support**
+ - We don't officially support LibreSSL.
+ - We would like to, if somebody takes the ball (who?).
+ - How could we make maintenance less stressful?
+ 2. [PATCH: Rework OpenVPN auth-token support](https://patchwork.openvpn.net/patch/263/)
+ 3. **Multi-port/multi-ip listening support:** config format
+ 4. **Netlink support:** quick roadmap recap
+ 5. **Review patches on** [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-03-14.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - Time: Wed 14th Mar 2018 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. [PATCH: Rework OpenVPN auth-token support](https://patchwork.openvpn.net/patch/263/)
+ 2. Multi-port/multi-ip listening support: config format
+ 3. Netlink support: quick roadmap recap
+ 4. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-03-21.md
@@ 0,0 1,23 @@
+ # Basic info
+
+ - Time: Wed 21st Mar 2018 11:30 CEST (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. [PATCH: Rework OpenVPN auth-token support](https://patchwork.openvpn.net/patch/263/)
+ 2. multi-port/multi-ip listening support: config format
+ 3. netlink support: quick roadmap recap
+ 4. Tap-windows fix
+ 5. Security list GPG key expiry policies
+ 6. OpenBSD+LibreSSL buildbot
+ 7. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ These topics are a reminder of things that "should be done".
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-04-04.md
@@ 0,0 1,25 @@
+ # Basic info
+
+ - **Time:** Wed 4th Apr 2018 11:30 CEST (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.4.6 release**
+ - Tap-windows fix (does it work?)
+ 2. [PATCH: Rework OpenVPN auth-token support](https://patchwork.openvpn.net/patch/263/)
+ 3. **netlink support: quick roadmap recap**
+ - Progress with unit tests?
+ 4. Security list GPG key expiry policies
+ 5. OpenBSD+LibreSSL buildbot
+ 6. [--preresolve is undocumented](https://community.openvpn.net/openvpn/ticket/1049)
+ 7. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ These topics are a reminder of things that "should be done".
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-04-18.md
@@ 0,0 1,27 @@
+ # Basic info
+
+ - **Time:** Wed 18th Apr 2018 11:30 CEST (10:30 UTC)
+ - **Place:** `#openvpn-meeting` channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.4.6 release**
+ 2. **tap-windows6 versioning**
+ - PRODUCT_VERSION is out of sync with the rest of version parameters:
+ - Currently version is 9.21.2 but PRODUCT_VERSION is 9,0,0,21 (maj,min,rev,build)
+ - Fix this now so that for version 9.22.1 PRODUCT_VERSION is 9,22,1,601 (maj,min,rev,build)
+ 3. **netlink support: quick roadmap recap**
+ - Progress with unit tests?
+ 4. **Security list GPG key expiry policies**
+ 5. **OpenBSD+LibreSSL buildbot**
+ 6. **[ticket:1049 --preresolve is undocumented]**
+ 7. **Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)**
+
+ # Topics on hold
+
+ These topics are a reminder of things that "should be done".
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-05-02.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - Time: Wed 2nd May 2018 11:30 CEST (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Networking API: discussion and high-level review (netlink patchset)
+ 2. Get feedback for approach taken by obfuscation via plugin (Jigsaw project)
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 4. (Attempt/low priority) High-level review of multi-port patchset
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-05-23.md
@@ 0,0 1,20 @@
+ # Basic info
+
+ - Time: Wed 23rd May 2018 11:30 CEST (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Tap-windows6 patches and updates
+ 2. Obfuscation for Jigsaw project: quick status update
+ 3. Networking API patch: status update
+ 4. tls-crypt-v2
+ 5. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 6. (attempt/low prio) High-level review of multi-port patchset
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-05-30.md
@@ 0,0 1,20 @@
+ # Basic info
+
+ - Time: Wed 30th May 2018 11:30 CEST (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Tap-windows6 patches, building and testing
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 3. (attempt/low prio) high-level review of multi-port patchset
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 3. obfuscation for Jigsaw project: quick status update
+ 4. networking API patch: status update
+ 5. tls-crypt-v2 update
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-06-06.md
@@ 0,0 1,23 @@
+ # Basic info
+
+ - Time: Wed 6th June 2018 11:30 CEST (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. style: space in cast expression
+ 2. Hackathon 2018: next steps?
+ 3. potential mailing list migration
+ 4. obfuscation for Jigsaw project: quick status update
+ 5. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/). Plan multi-port patches review. Plan netlink/networking API patches review.
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 3. tls-crypt-v2 update (ordex offered to review)
+ 4. packet filter: --packet-filter-dir OR IPv6 .. first ? (opinion requested)
+ - --packet-filter-dir = no more plugin.
+ - IPv6 packet filter
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-06-13.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - **Time**: Wed 13th June 2018 11:30 CEST (09:30 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Community services outage
+ 2. Tap-windows6 patches, building and testing
+ 3. Do we still want to switch to another ML provider? Or are we happy with sf.net for the time being?
+ 4. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 5. (attempt/low prio) high-level review of multi-port patchset
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 3. obfuscation for Jigsaw project: quick status update
+ 4. networking API patch: status update
+ 5. tls-crypt-v2 update
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-07-04.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - **Time:** Wed 4th July 2018 11:30 CEST (09:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Tap-windows6 / HLK test updates
+ 2. Proposal for HackerOne demo from Reed
+ 3. Microsoft's OpenVPN fork in GitHub (pqcrypto, dialer)
+ 4. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 5. (attempt/low prio) high-level review of multi-port patchset
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 3. obfuscation for Jigsaw project: quick status update
+ 4. networking API patch: status update
+ 5. tls-crypt-v2 update
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-09-19.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - Time: Wed 4th July 2018 11:30 CEST (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Tap-windows6 / HLK test updates
+ 2. Lviv Hackathon planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 3. networking API patch: status update
+ 4. tls-crypt-v2 update
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-09-26.md
@@ 0,0 1,20 @@
+ # Basic info
+
+ - **Time:** Wed 26th Sep 2018 11:30 CEST (09:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Tap-windows6 / HLK test updates
+ 2. Lviv Hackathon planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 4. Broken reconnect on 2.4.6 [Ticket #1105](https://community.openvpn.net/openvpn/ticket/1105)
+
+ # Topics on hold
+
+ 1. FIPS patches
+ 2. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76) (help is needed to get these through)
+ 3. networking API patch: status update
+ 4. tls-crypt-v2 update
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-10-03.md
@@ 0,0 1,22 @@
+ **NOTE:** This meeting was cancelled.
+
+ # Basic info
+
+ - Time: Wed 3rd Oct 2018 11:30 CEST (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Deprecating `--opt-verify` and `--server` in 2.5?
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 3. Broken reconnect on 2.4.6 [OpenVPN Issue #1105](https://community.openvpn.net/openvpn/ticket/1105)
+
+ # Topics on hold
+
+ 1. Tap-windows6 / HLK test updates
+ 2. FIPS patches
+ 3. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76) (help is needed to get these through)
+ 4. Networking API patch: status update
+ 5. tls-crypt-v2 update
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-10-10.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - Time: Wed 10th Oct 2018 11:30 CEST (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Post-hackathon discussion (OpenVPN 2.5 etc.)
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. Tap-windows6 / HLK test updates
+ 2. FIPS patches
+ 3. [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76) (help is needed to get these through)
+ 4. networking API patch: status update
+ 5. tls-crypt-v2 update
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-10-24.md
@@ 0,0 1,30 @@
+ # Basic info
+
+ - **Time**: Wed 24th Oct 2018 11:30 CEST (09:30 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Adding Google Analytics to community.openvpn.net
+ 2. tls-crypt-v2: status update
+ 3. networking API patch: status update
+ 4. OpenVPN 2.5 status
+ 5. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. Tap-windows6 / HLK test updates
+ 2. FIPS patches
+ 3. ~~[VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)~~ discussed at the hackathon in Lviv (2018)
+
+ # Notes
+
+ Quoting Matt, the person responsible for OpenVPN websites:
+
+ "The goal of this would be to understand what information first-time users are finding the most valuable on community.openvpn.net."
+
+ "As this is a publicly accessible community without the requirement to join to read the articles, it would be advantageous for all to understand which pieces of content the public are finding the most useful, what encourages them to become a part of the community, and what potentially persuaded them to start using a commercial product."
+
+ "As openvpn.net links to community.openvpn.net and vice versa this will also help us to understand the complete journey of a user and help to improve the website experience, which can only be seen as a positive."
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-11-14.md
@@ 0,0 1,21 @@
+ # Basic info
+
+ - Time: Wed 14th Nov 2018 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tls-crypt-v2: status update
+ 2. networking API patch: status update
+ 3. tap-windows6 HLK testing: status update
+ 4. Making OpenVPN on Windows more robust against (generic) DLL hijacking vulnerabilities
+ - Prompted by a HackerOne report
+ 5. OpenVPN 2.5 status
+ - [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 6. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-11-28.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - **Time**: Wed 28th Nov 2018 11:30 CET (10:30 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Security-auditing changes between OpenVPN 2.4.0 and 2.5.0
+ - According to OSTIF this should be very doable, but is it worth it?
+ - Which places in code to focus on in particular?
+ 2. tls-crypt-v2: status update
+ 3. networking API patch: status update
+ 4. tap-windows6 HLK testing: status update
+ 5. OpenVPN 2.5 status
+ - [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 6. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-12-05.md
@@ 0,0 1,23 @@
+ # Basic info
+
+ - Time: Wed 5th Dec 2018 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. T-shirts
+ 2. Using tags to mark important events in Git?
+ - E.g. "tlscryptv2" (or just "timestamps")
+ 3. Samuli's new buidslaves: status update
+ 4. networking API patch: status update
+ 5. tap-windows6 HLK testing: status update
+ 6. rate-limiting of unauthorized incoming packets?
+ 7. OpenVPN 2.5 status
+ - [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 8. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-12-12.md
@@ 0,0 1,21 @@
+ # Basic info
+
+ - **Time:** Wed 12th Dec 2018 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. networking API patch: status update
+ 2. tap-windows6 HLK testing: status update
+ 3. MSI packaging: status update
+ 4. rate limiting patches - comments, reviews?
+ 5. uncrustify patches - comments, reviews?
+ 6. OpenVPN 2.5 status
+ - [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 7. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2018-12-19.md
@@ 0,0 1,24 @@
+ # Basic info
+
+ - Time: Wed 19th Dec 2018 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. builder VM: status update (openvpn-build and sbuild_wrapper)
+ 2. openvpn-vagrant PRs
+ - [Add openvpn-build VM for Ubuntu 18.04 (openvpn-build-bionic)](https://github.com/OpenVPN/openvpn-vagrant/pull/4)
+ - [Update apt's package cache before attempting to install any packages](https://github.com/OpenVPN/openvpn-vagrant/pull/5)
+ 3. networking API patch: status update
+ 4. tap-windows6 HLK testing: status update
+ 5. MSI packaging: status update
+ 6. rate limiting patches - comments, reviews?
+ 7. OpenVPN 2.5 status
+ - [VLAN patches v2](https://github.com/OpenVPN/openvpn/pull/76)
+ 8. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-02-13.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - **Time:** Wed 13th Feb 2019 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.4.7 release (detailed planning)**
+ - berniv6 wants to include 2.4.7 in Debian Buster, so we need to really really release Feb 19 latest
+ 2. **tap-windows6 HLK testing updates**
+ 3. **Plugin API for 2.5.0 and the potential Meek plugins that OSTIF.org would like to develop**
+ 4. **Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)**
+
+ # Topics on hold
+
+ 1. **FIPS patches**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-03-12.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed 12th Mar 2019 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ - Update [status page](wiki:StatusOfOpenvpn25) which is badly outdated
+ 2. tap-windows6 HLK testing updates
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-03-20.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - **Time:** Wed 20th Mar 2019 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.5 updates / planning**
+ - [Windows MSI packaging PR](https://github.com/OpenVPN/openvpn-build/pull/141): merge?
+ - [https://github.com/OpenVPN/openvpn-build/pull/149](https://github.com/OpenVPN/openvpn-build/pull/149)
+ - ordex: update on transport-api
+ 2. **tap-windows6 HLK testing updates**
+ 3. **Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)**
+
+ # Topics on hold
+
+ 1. **FIPS patches**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-03-27.md
@@ 0,0 1,24 @@
+ # Basic info
+
+ - Time: Wed 27th Mar 2019 11:30 CET (10:30 UTC)
+ - Place: `#openvpn-meeting` channel on Freenode IRC network
+
+ # Topics
+
+ 1. Future meeting schedule (see [Doodle](https://doodle.com/poll/qbnsw7d4mvb5iysn#table))
+ 2. OpenVPN 2.5 updates/planning
+ 3. tap-windows6 HLK testing updates
+ 4. Poor "INSTALL" doc
+ - [https://github.com/OpenVPN/openvpn/pull/110](https://github.com/OpenVPN/openvpn/pull/110) → suggest to change "make-install" with "make install", obviously "make-install" is wrong. but nobody cares, so... why to keep that guide at all?
+ 5. "enable-lzo-stub" was removed (but still present in INSTALL)
+ - [https://github.com/OpenVPN/openvpn/blob/master/INSTALL#L163](https://github.com/OpenVPN/openvpn/blob/master/INSTALL#L163)
+ 6. Outdated !ChangeLog
+ - [https://github.com/OpenVPN/openvpn/blob/master/ChangeLog](https://github.com/OpenVPN/openvpn/blob/master/ChangeLog)
+ - So, should we just remove both ChangeLog and INSTALL?
+ 7. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-04-03.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 3rd Apr 2019 11:30 CET (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 release planning
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-04-11.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - **Time:** Thu 11th Apr 2019 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-04-17.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 17th Apr 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-04-25.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Thu 25th Apr 2019 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-05-01.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 1st May 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-05-09.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - **Time**: Thu 9th May 2019 20:00 CEST (18:00 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Enabling Cirrus-CI for FreeBSD testing in GitHub
+ 2. ACKed but not merged: [https://patchwork.openvpn.net/patch/579](https://patchwork.openvpn.net/patch/579)
+ 3. Trivial to ACK? [https://patchwork.openvpn.net/patch/725/](https://patchwork.openvpn.net/patch/725/)
+ 4. tap-windows6 updates
+ 5. OpenVPN 2.5 updates / planning
+ 6. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-05-15.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 15th May 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-05-23.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - **Time:** Thu 23rd May 2019 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-05-29.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed 29th May 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 4. OpenVPN Forums to Cloudflare? (ecrist opposes any changes)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-06-06.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - **Time**: Thu 6th June 2019 20:00 CEST (18:00 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Hackathon planning
+ 2. Making forums server more robust against DoS or DoS-like things
+ - Forums was down last week due to either a misbehaving bot or due to DoS
+ - Put CloudFlare in front of it?
+ - Wait and see if similar issues arise (in the near future)?
+ - Some other technical solution we could use, if we don't want Cloudflare?
+ 3. tap-windows6 updates
+ 4. OpenVPN 2.5 updates / planning
+ 5. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-06-12.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 12th June 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-06-20.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - **Time:** Thu 20th June 2019 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. Can we drop the cmocka sub-module? It adds complications (like the networking_testdriver failing due to missing libcmocka.so.0) and distributions seem to have picked up cmocka... at least on gentoo, it gets pulled in by samba and ldb ebuilds.
+ 3. Windows buildslave gone? ("no more build breakage mails are received")
+ 4. Travis-CI - is there a way known how to receive build failures by mail? like this one [Travis CI Build Failure](https://travis-ci.org/OpenVPN/openvpn/builds/542115811?utm_medium=notification&utm_source=email)
+ 5. OpenVPN 2.5 updates / planning
+ 6. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-06-26.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - Time: Wed 26th June 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. fedora29 buildslave - or general: buildslave maintenance
+ 3. HackerOne report about sample plugin issue
+ 4. OpenVPN 2.5 updates / planning
+ 5. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-07-04.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Thu 4th July 2019 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-07-10.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 10th July 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-07-18.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Thu 18th July 2019 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-07-24.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 24th July 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-08-07.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 7th August 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-08-15.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - **Time:** Thu 15th August 2019 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-08-21.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed 21st August 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. 2.4.8 release schedule?
+ 3. OpenVPN 2.5 updates / planning
+ 4. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-08-29.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Thu 29th August 2019 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-09-04.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - **Time:** Wed 4th August 2019 11:30 CEST (9:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-09-12.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Thu 12th September 2019 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. VLAN patches layout: patches currently available at [https://gitlab.com/ordex986/openvpn/commits/vlan](https://gitlab.com/ordex986/openvpn/commits/vlan)
+ 3. OpenVPN 2.5 updates / planning
+ 4. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-09-18.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - Time: Wed 18th September 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. VLAN patchset review progress
+ 3. should we get rid of --disable-server?
+ 4. OpenVPN 2.5 updates / planning
+ 5. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-09-26.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Thu 26th September 2019 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. tap-windows6 updates
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-10-02.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - **Time**: Wed 2nd October 2019 11:30 CEST (9:30 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. vlan patches / --enable-vlan or --disable-vlan? or no #ifdef at all?
+ 2. 2.4 release: what patches are missing, and when do we want the release?
+ 3. tap6 updates: what PRs are missing, test installer, release?
+ 4. OpenVPN 2.5 updates / planning
+ 5. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-10-10.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Thu 10th October 2019 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+ 3. Update, *or something*, these repos: [Openvpn-repos](https://community.openvpn.net/openvpn/wiki/OpenvpnSoftwareRepos)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-10-16.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 16th October 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-10-24.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Thu 24th October 2019 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. OpenVPN 2.4.x release
+ 3. trac #1221 - approach OK?
+ 4. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-10-30.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed 30th October 2019 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. 2.4.8 release
+ 2. OpenVPN 2.5 updates / planning
+ 3. pull-resolv-conf/client.up adjustments needed for "resolvectl" systems (Arch, and maybe others?)
+ 4. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-11-21.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Thursday 21st November 2019 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-11-27.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 27th November 2019 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-12-05.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time**: Thursday 5th December 2019 20:00 CET (19:00 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-12-11.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 11th December 2019 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2019-12-19.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - **Time:** Thursday 19th December 2019 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Windows buildslave? Windows snapshot building? "Pretty please!"
+ 2. IPv6 connects to forums still broken (since 4+ weeks) - who is responsible for the OS maintenance and firewalls?
+ 3. OpenVPN 2.5 updates / planning
+ 4. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-01-06.md
@@ 0,0 1,3 @@
+ ```
+ Delete
+ ```
\ No newline at end of file
/dev/null .. meetings/2020-01-08.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 8th January 2020 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-01-16.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Thursday 16th January 2020 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-01-22.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 22nd January 2020 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-01-30.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Thursday 30th January 2020 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-02-05.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - Time: Wed 5th February 2020 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Signing tap-windows6 tags
+ - [https://github.com/OpenVPN/tap-windows6/issues/101](https://github.com/OpenVPN/tap-windows6/issues/101)
+ - Which key to use?
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-02-13.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Thursday 13th February 2020 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-02-19.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Wed 19th February 2020 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-02-27.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Thursday 27th February 2020 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Removal of [--disable-server](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg18829.html) compile-time option
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-03-04.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Wed 4th March 2020 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-03-12.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Thursday 12th March 2020 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-03-18.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 18th March 2020 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-03-26.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Thursday 26th March 2020 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Review [PATCHv3: travis-ci: add arm64, s390x builds](https://patchwork.openvpn.net/patch/1045/)
+ 2. OpenVPN 2.5 updates / planning
+ - Merging MSI/MSM-related changes (see [status page](wiki:StatusOfOpenvpn25))
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-04-01.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Wed 1st April 2020 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-04-09.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Thursday 9th April 2020 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-04-15.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 15th April 2020 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.4 release / peer-id float bug
+ 2. OpenVPN 2.5 updates / planning
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-04-23.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Thursday 23rd April 2020 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. pkcs11-helper patch update: [https://github.com/OpenVPN/openvpn-build/pull/172](https://github.com/OpenVPN/openvpn-build/pull/172)
+ 2. OpenVPN 2.5 updates / planning
+ 3. IPv6 to community (DNS broken)
+ 4. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-04-29.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 29th April 2020 11:30 CET (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-05-07.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - **Time:** Thursday 7th May 2020 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. IPv6 to community (!CloudFlare IPv6 not enabled)
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-05-13.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 13th May 2020 11:30 CET (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-05-21.md
@@ 0,0 1,20 @@
+ # Basic info
+
+ - **Time:** Thursday 21st May 2020 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **Server-side testing - what do we have, what can we do more**
+ 1. "static configs"
+ 1. Management-interface driven
+ 1. **OpenVPN 2.5 updates / planning**
+ 1. man-page reformatting discussions - [working draft](https://gist.github.com/dsommers/015dfbbca099efb92ebd36236b67e991), [source](https://gist.githubusercontent.com/dsommers/015dfbbca099efb92ebd36236b67e991/raw/fdf18768123d0d8bc7d91010467cb34700ace0ab/man.8.rst)
+ 1. Deprecated options for 2.5
+ 1. **Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)**
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-05-27.md
@@ 0,0 1,20 @@
+ # Basic info
+
+ - Time: Wed 27th May 2020 11:30 CET (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Server-side testing - what do we have, what can we do more
+ 1. "static configs"
+ 1. Management-interface driven
+ 1. OpenVPN 2.5 updates / planning
+ 1. man-page reformatting discussions - [working draft](https://gist.github.com/dsommers/015dfbbca099efb92ebd36236b67e991), [source](https://gist.githubusercontent.com/dsommers/015dfbbca099efb92ebd36236b67e991/raw/395fe9cef2db7f03645b60c40e26a7881de3d368/man.8.rst)
+ 1. Deprecated options for 2.5
+ 1. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-06-04.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time**: Thursday 4th June 2020 20:00 CET (19:00 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-06-10.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - **Time:** Wed 10th June 2020 11:30 CET (09:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.5 updates / planning**
+ 1. Revise(d) timeline
+ 2. Status of work items in the wiki
+ 3. Who does what? Until when?
+ 2. Deprecate "net30" for 2.5, remove for 2.6? (quite a bit of special-casing in the code...)
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-06-18.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Thursday 18th June 2020 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-06-24.md
@@ 0,0 1,23 @@
+ # Basic info
+
+ - **Time:** Wed 24th June 2020 11:30 CET (09:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+ 1. OpenVPN 2.5 updates / planning
+ 2. Moving 2.3 into "Old stable"
+ 3. Starting deprecation of `--ncp-disable`
+ 4. `--cipher` usage in OpenVPN 2.5 and possibly moving towards facilitating `--ncp-ciphers` instead
+ 5. DNS reworking proposal on the openvpn-devel list
+ - names of the options
+ - IV_PROTO use?
+ - Or keep IV_PROTO for "transport related" (packet format etc) and use something new (IV_DNS?).
+ - Folding IV_TCPNL into IV_PROTO is a good idea in any case ("transport related").
+ - 2.5 or 2.6?
+ 6. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-07-02.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 2nd July 2020 20:00 CET (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-07-08.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 8th July 2020 11:30 CET (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-07-16.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - **Time:** Wed 16th July 2020 20:00 CET (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.5 updates / planning**
+ 1. man page integration
+ 2. depreciation patches (something missing? Check list: DeprecatedOptions)
+ 3. async-cc patches
+ 4. timeline? testing MSI, testing new code in all possible variants client/server?
+ 2. **server test framework** - short bragging (cron2)
+ 3. **plugin collection** (cron2)
+ 4. **auth-token and network manager and suspend/resume** (cron2)
+ 5. **Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)**
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-07-22.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - **Time**: Wed 22nd July 2020 11:30 CET (09:30 UTC)
+ - **Place**: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.5 updates / planning**
+ - rename `--ncp-ciphers` to `--data-ciphers` [Patch 1284](https://patchwork.openvpn.net/patch/1284/)
+ - rework NCP compatibility, drop BF-CBC "as default if nothing is configured" [Patch 1291](https://patchwork.openvpn.net/patch/1291/)
+ - how to track remaining "smallish warts / bugs"? trac with milestone 2.5.0?
+ - time planning for next steps - testing, alpha, beta, ...
+ - MSI testing?
+ - "git master" client to "older servers" (2.3, 2.4, AS) testing?
+ - ...?
+ 2. **Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)**
+
+ # Topics on hold
+
+ 1. **FIPS patches**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-07-30.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 30th July 2020 20:00 CET (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-08-13.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - **Time:** Thu 13th August 2020 20:00 CET (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.5 updates / planning**
+ - timeline?
+ 2. **buildbot infrastructure**
+ - which buildbots need to retire (CentOS 6, Ubuntu 14)
+ - which buildbots need to be added (FreeBSD 12, Ubuntu 20, ...?)
+ - buildbot differentiation 2.4/2.5/master?
+ 3. **"what is our stance on null/no encryption"**
+ - consequences on code, NCP, option depreciation
+ 4. **Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)**
+
+ # Topics on hold
+
+ 1. **FIPS patches**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-08-19.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed 19th August 2020 11:30 CEST (9:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. "what is our stance on null/no encryption"
+ - consequences on code, NCP, option depreciation
+ 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-08-27.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Thu 27th August 2020 20:00 CET (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-09-02.md
@@ 0,0 1,20 @@
+ # Basic info
+
+ - **Time:** Wed 2nd September 2020 11:30 CEST (09:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.5 updates / planning**
+ - Tentative release date for 2.5.0 is "September 17". Should we postpone to have more time for Windows installer testing?
+ 2. **Trac status**
+ - Please notify "yuriy" that there is a ton of old and very old tickets related to OpenVPN Connect - either answer them, or close them, but do not just leave them dangling.
+ - Please check **your** tickets on Trac if there is something that is already done ("no need to keep around tickets forever if fixed") or if something urgently needs to be in 2.5.0 - and please set "Milestone" appropriately. Milestones for 2.4.10, 2.5, and 2.5.1 have been created.
+ 3. **IPv6 to Community... (again)**
+ 4. **Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)**
+
+ # Topics on hold
+
+ 1. **FIPS patches**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-09-10.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - Time: Thu 10th September 2020 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Buildbots
+ 3. IPv6 to Community
+ 4. Trac status
+ 5. Tunnelblick update (regarding bundled openvpn versions)
+ 6. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-09-16.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - **Time:** Wed 16th September 2020 11:30 CEST (09:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.5 updates / planning**
+ - open patches in patchwork (for 2.5 = bugfixes and documentation)
+ - trac tickets with "milestone 2.5"
+ - upgrade easy-rsa - in 2.5.0 or 2.5.1?
+ - timeline? beta5 or rc1?
+ 2. **Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)**
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-09-24.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Thu 24th September 2020 20:00 CEST (18:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-09-30.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 30th September 2020 11:30 CEST (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-10-08.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Thu 6th October 2020 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-10-14.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 14th October 2020 11:30 CEST (09:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-10-22.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - **Time:** Thu 22nd October 2020 20:00 CEST (18:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **OpenVPN 2.5 updates / planning**
+ 1. any feedback on RC3?
+ 2. 2.5.0 release date
+ 3. OpenVPN 2.5.0 release announcement: warning about 2.5 clients to 2.3 servers with BF-CBC default = broken (see discussion on #openvpn-devel)
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-10-28.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Wed 28th October 2020 11:30 CEST (09:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5 updates / planning
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-11-05.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Thu 5th November 2020 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5/2.6 updates
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-11-11.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 11th November 2020 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5/2.6 updates
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-11-19.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Thu 19th November 2020 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5/2.6 updates
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-11-25.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 25th November 2020 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5/2.6 updates
+ 2. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-12-03.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - Time: Thu 3rd December 2020 20:00 CET (19:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN updates
+ 1. 2.4 - 2.4.10 release?
+ 1. 2.5 - 2.5.1 release?
+ 1. 2.6 - anything big?
+ 2. auth-nocache
+ 3. HackerOne bounties
+ 4. IPv6 to community
+ 5. Buildbot upgrades - timeline?
+ 6. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-12-09.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - **Time:** Wed 9th December 2020 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN 2.5/2.6 updates
+ 2. OpenVPN Legacy Service - do we have a "how to get from there to openvpnsrv2" document? (trac #1344)
+ 3. Review HackerOne reports, set bounties and close all the reports down, if possible
+ 4. General trac attention keeping...
+ 5. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2020-12-17.md
@@ 0,0 1,23 @@
+ # Basic info
+
+ - **Time:** Thu 17th December 2020 20:00 CET (19:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. OpenVPN updates
+ 2. Officially deprecate OpenVPN legacy service for Windows
+ - [Ticket 1344](https://community.openvpn.net/openvpn/ticket/1344)
+ 3. Other Trac tickets of interest
+ - yuriy?
+ - [#1342](https://community.openvpn.net/openvpn/ticket/1342)
+ - [#1345](https://community.openvpn.net/openvpn/ticket/1345)
+ - [#1355](https://community.openvpn.net/openvpn/ticket/1355)
+ 4. Next meeting?
+ 5. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-01-06.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - **Time:** Wed 6th January 2021 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ - Moving away from Travis-CI due to new OSS policies at their end?
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-01-20.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed 20th January 2021 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ - To be decided
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-01-27.md
@@ 0,0 1,27 @@
+ # Basic info
+
+ - **Time:** Wed 27th January 2021 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ - Sync up on OpenVPN 2.5 and 2.6
+ - server side auth/token/rekey cleanup
+ - 2.5.1?
+ - possible DoS vector with non-successful auth for the same client cert as for an existing session?
+ - `--enable-inetd` ripout
+ - patch exists, no feedback on list whatsoever
+ - out it goes!
+ - pf packet filter ripout
+ - no patch yet. Feedback on list: one private mail that says "yeah, kill it", one public mail (in a different thread) "I am using it but won't miss it)
+ - out it goes for 2.6, and not built by default for 2.5 (starting with 2.5.1)?
+ - maintenance of Changes.rst
+ - cumbersome to deal with if changes are part of regular "mail to openvpn-devel" patch
+ - suggestion: just add change-to-changes.rst as comment in the commit message, and let cron2 deal with it at merge time
+ - delegate https://patchwork.openvpn.net/patch/1566/ to @dazo :-)
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-02-03.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 3rd Feb 2021 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ - Sync up on OpenVPN 2.5 and 2.6
+ - server side auth/token/rekey cleanup 2.5.1?
+ - possible DoS vector with non-successful auth for the same client cert as for an existing session?
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-02-10.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed 10th Feb 2021 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ - Sync up on OpenVPN 2.5 and 2.6
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-02-17.md
@@ 0,0 1,30 @@
+ # Basic info
+
+ - **Time:** Wed 17th Feb 2021 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ - Sync up on OpenVPN 2.5 and 2.6
+ - Release 2.5.1
+ - Suggestion: "as is", soonish, with client-side token/reneg fixes
+ - Server-side reneg fixes later (already in master, but slightly problematic, see discussion two weeks ago)
+ - "Denys" on Trac not working well
+ - Example: #1373 - 6 weeks, no response
+ - New forums shared account "openvpn_inc" that will take over Access Server / Connect support in forums and Trac
+ - Containerized buildmaster and mattock's buildslaves
+ - Propose new, more sensibly laid out Community forum (and archive the current one?).
+ - [Bridged Windows 10 Causes Sporadic Crashes](https://community.openvpn.net/openvpn/ticket/1385)
+ - **Suggestion**: Old Patches
+ - [Patchwork series 874](https://patchwork.openvpn.net/project/openvpn2/list/?series=874&state=%2A&archive=both)
+ - [Patch 1](https://patchwork.openvpn.net/patch/1384/) is already NAK'ed.
+ - [Patch 2](https://patchwork.openvpn.net/patch/1383/) has no discussion. Reject, to close this series out?
+ - [Patch 636](https://patchwork.openvpn.net/patch/636/)
+ - Not ACK'ed, but is a positively-received single change that would increase DoS posture.
+ - Appears simple but stalled / overlooked.
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-02-24.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed 24th Feb 2021 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ - Sync up on OpenVPN 2.5 and 2.6
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-03-03.md
@@ 0,0 1,24 @@
+ # Basic info
+
+ - **Time:** Wed 3rd March 2021 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ - Sync up on OpenVPN 2.5 and 2.6
+ - Containerized buildmaster and mattock's buildslaves
+ - Propose new, more sensible laid out Community forum (and archive the current one?).
+ - [Bridged Windows 10 Causes Sporadic Crashes](https://community.openvpn.net/openvpn/ticket/1385)
+ - **Suggestion: Old Patches**
+ - [Patchwork series 874](https://patchwork.openvpn.net/project/openvpn2/list/?series=874&state=%2A&archive=both)
+ - [patch 1](https://patchwork.openvpn.net/patch/1384/) is already NAK'ed.
+ - [patch 2](https://patchwork.openvpn.net/patch/1383/) has no discussion. Reject, to close this series out?
+ - [patch 636](https://patchwork.openvpn.net/patch/636/)
+ - not ACK'ed, but is a positively-received single change that would increase DoS posture.
+ - Appears simple but stalled / overlooked.
+
+ # Topics on hold
+
+ 1. FIPS patches
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-03-10.md
@@ 0,0 1,34 @@
+ # Basic Info
+
+ - **Time:** Wed 10th Mar 2021 11:30 CET (10:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. **Sync up on OpenVPN 2.5 and 2.6**
+ 2. **Release 2.5.2**
+ - Timeline (March 17th) still stands?
+ 3. **Security@ subkey has expired**
+ - A new key has been created and distributed. Thanks, David.
+ 4. **mbedTLS 2.25.0 crash bug/patch**
+ - How to deal with it?
+ 5. **Review culture**
+ - Nothing happens for weeks, and then a review focuses solely on "bah, your whitespace is not right."
+ - This is very frustrating for the patch author and slows down the whole process even further.
+ - Please focus on code quality and functionality **first**, and if all that is OK, point out the remaining whitespace issues (which can be fixed at commit time in most cases).
+ - Of course, submitters are encouraged to run uncrustify **before** git-send-email...
+ 6. **Containerized buildmaster and mattock's buildslaves**
+ 7. [**Bridged Windows 10 Causes Sporadic Crashes**](https://community.openvpn.net/openvpn/ticket/1385)
+ 8. **[Suggestion] Old Patches**
+ - [Patchwork series 874](https://patchwork.openvpn.net/project/openvpn2/list/?series=874&state=%2A&archive=both)
+ - [Patch 1](https://patchwork.openvpn.net/patch/1384/) is already NAK'ed.
+ - [Patch 2](https://patchwork.openvpn.net/patch/1383/) has no discussion. Reject, to close this series out?
+ - [Patch 636](https://patchwork.openvpn.net/patch/636/)
+ - Not ACK'ed, but is a positively-received single change that would increase DoS posture.
+ - Appears simple but stalled/overlooked.
+ 9. **FIPS patches**
+ - Should be "integrated" by 06f6cf3ff850 (PRF patch)
+
+ # Topics on Hold
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-03-24.md
@@ 0,0 1,29 @@
+ # Basic info
+
+ - Time: Wed 24th Mar 2021 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ 2. Release 2.5.2
+ - The timeline is slightly unclear
+ - CVE bug has morphed
+ 3. Windows building with MSVC
+ - Suggestion from Lev to move away from openvpn-build towards "something new"
+ 4. Deprecate `--secret` mode in 2.6, remove in 2.7?
+ 5. Containerized buildmaster and mattock's buildslaves
+ 6. [Bridged Windows 10 Causes Sporadic Crashes](https://community.openvpn.net/openvpn/ticket/1385)
+ 7. Suggestion: Old Patches
+ - [Patchwork series 874](https://patchwork.openvpn.net/project/openvpn2/list/?series=874&state=%2A&archive=both)
+ - [Patch 1](https://patchwork.openvpn.net/patch/1384/) is already NAK'ed.
+ - [Patch 2](https://patchwork.openvpn.net/patch/1383/) has no discussion. Reject, to close this series out?
+ - [Patch 636](https://patchwork.openvpn.net/patch/636/)
+ - Not ACK'ed, but is a positively-received single change that would increase DoS posture.
+ - Appears simple but stalled / overlooked.
+ 8. FIPS patches
+ - Should be "integrated" by 06f6cf3ff850 (PRF patch)
+
+ # Topics on hold
+
+ [Back to meeting list](https://community.openvpn.net/openvpn/wiki/IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-03-31.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - Time: Wed 31th Mar 2021 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network, and [Jitsi Meeting](https://demo.vct.spacenet.de/openvpn)
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ 2. Release 2.5.2
+ - Time line is slightly unclear
+ - Windows wants a new installer with fixed OpenSSL library - so, 2.5.1-I602, or 2.5.2?
+ - AS release time line?
+ 3. Remove OCC warnings altogether?
+ - The ugly bits of "compress migrate" patch are all "deal with OCC"...
+ 4. Containerized buildmaster and mattock's buildslaves
+ 5. [Bridged Windows 10 Causes Sporadic Crashes](https://community.openvpn.net/openvpn/ticket/1385)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-04-07.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - Time: Wed 7th Mar 2021 11:30 CET (10:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network, and [Jitsi Meeting](https://demo.vct.spacenet.de/openvpn)
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ 2. Release 2.5.2
+ - Synchronized with AS, on April 20/21th
+ - Windows wants a new installer with fixed OpenSSL library - so, 2.5.1-I602, or 2.5.2?
+ 3. Release 2.4.11
+ - With 2.5.2 release, on April 20/21th
+ 4. Remove OCC warnings altogether?
+ - The ugly bits of "compress migrate" patch are all "deal with OCC"...
+ 5. Containerized buildmaster and mattock's buildslaves
+ 6. [Bridged Windows 10 Causes Sporadic Crashes](https://community.openvpn.net/openvpn/ticket/1385)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-04-14.md
@@ 0,0 1,54 @@
+ # Basic Info
+
+ - **Time:** Wed 14th April 2021 14:00 CET (12:30 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network + [Jitsi Meet](https://demo.vct.spacenet.de/openvpn)
+
+ # Topics
+
+ ## 1. Sync up on OpenVPN 2.5 and 2.6
+ - **2.5:** next Tuesday.
+ - patches pending:
+ - route lookup
+ - compress-restore-on-SIGUSR1
+ - 1666+1667 (fix client with --bind)
+ - **2.6:**
+ - please get ACKed patches in!
+ - configure.ac coming
+ - DCOoooooh :-)
+
+ ## 2. --key and --chroot (with and without --persist-key)
+ - (Ordex, MaxF21, patches on the list)
+ - Key reloading on SIGUSR1 fails in chroot (it works with persist-key)
+ - **Consensus:** we remove the "no-persist-key" path, make the feature always-on and the option a no-op
+
+ ## 3. Option to set http-proxy on Android
+ - Suggestion: "dhcp-option HTTP-PROXY IP PORT"
+ - This is for programs using the VPN, and they should use this proxy. Configured via the VPN API. Not "for OpenVPN" but "for everyone else". Check with 3 clients on iOS what that one uses.
+
+ ## 4. Lev: dco-win Driver in Windows installer
+ - How do we want to do this?
+ - msm package inside msi? (like for tap+wintun)
+ - Wintun created msm approach but uses different approach now
+ - Connect client brings tap binary + tapinstall.exe, no msm for tap-windows6
+ - Cron2 and mattock seem to recall "msm works better for driver upgrades than the old NSIS approach" but nobody knew for sure
+ - Mattock is talking to MS about arm64 support, we can ask the experts
+ - Ask Simon :-)
+
+ ## 5. --cipher in 2.6
+ - Currently, this always adds that likely non-AEAD cipher to the data-ciphers list. This is bad for DCO.
+ - We have to pick one:
+ - Make DCO work without having user to reconfigure --cipher/--data-ciphers
+ - Requires modifying config if you still want to connect to a 2.3 server, allow 2.3 clients
+ - Keep configuration compatibility with non-NCP server/clients
+ - Requires configuration changes to allow DCO
+ - Windows OpenVPN 2.x with ovpn-dco-win will refuse to start with most configs
+ - The complex interaction between data-ciphers, cipher and data-ciphers-fallback is still there.
+ - Need to add an option like 'occ-cipher' to avoid OCC warnings with 2.4/2.5 clients/server.
+ - Make behaviour of OpenVPN dependent on selected driver
+ - Only interims solution. With 2.7 we still have to decide if we want to go one of the other options
+ - Will create a lot of confusion.
+ - Breaks opportunistic approach of allowing OpenVPN to automatically enable DCO if the config is DCO compatible
+ - Introduce "--compat-mode"
+ - OpenVPN will behave like first option without option
+ - Also increase TLS min version to 1.2 by default
+ - Default to --nobind when --pull is active
\ No newline at end of file
/dev/null .. meetings/2021-04-21.md
@@ 0,0 1,13 @@
+ # Basic info
+
+ - Time: Wed 21st April 2021 14:00 CET (12:30 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5: aftermath
+ - 2.6
+ 2. Containerized buildmaster and mattock's buildslaves
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-04-28.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - **Time:** Wed 28st April 2021 14:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. CVE aftermath: patches for 2.3?
+ 3. Containerized buildmaster and mattock's buildslaves
+ 4. IPv6 to community?
+ 5. `no-replay` patch [https://patchwork.openvpn.net/patch/1297/] - how to proceed?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-05-05.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed 5th May 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. `no-replay` patch [patch link](https://patchwork.openvpn.net/patch/1297/) - how to proceed?
+ 4. `CRL extractor` script [script link](https://patchwork.openvpn.net/patch/1502/) - opinions? Does this work?
+ 5. Support ovpn-dco out of the box vs old clients (related to compat-code from Arne?)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-05-12.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed 12th May 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. `--no-replay` patch [https://patchwork.openvpn.net/patch/1297/] - how to proceed?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-05-19.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - **Time:** Wed 19th May 2021 14:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. --no-replay ?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-05-26.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed 29th May 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on Freenode IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. What is the exit strategy for bridging Freenode to Libera?
+ - Bridge forever? Mute-and-close the channel? Simply abandon the channel? (When?)
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-06-02.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed June 2nd 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Team meetup in [https://demo.vct.spacenet.de/openvpn](https://demo.vct.spacenet.de/openvpn)
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. subdir-objects (automake, autoreconf warnings)
+ 4. IPv6 to community?
+ 5. "openvpn --version" lists "Copyright (C) 2002-2018 OpenVPN Inc" (in master) - update to 2021?
+ 6. Hackathon 2021
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-06-09.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed June 9th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. 2.5.3 release date?
+ - anything particular that should go in?
+ 3. IPv6 to community?
+ 4. "openvpn --version" lists "Copyright (C) 2002-2018 OpenVPN Inc" (in master) - update to 2021?
+ 5. CR_TEXT thread in openvpn-gui - what next?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-06-16.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed June 16th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. Deprecate --hand-window and --reneg-sec < 120?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-06-23.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed June 23rd 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. CVE-2121-3606 / 2021-3606
+ 4. Windows saved_stderr breakage
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-06-30.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed June 30th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 3. IPv6 to community?
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-07-07.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - **Time**: Wed July 7th 2021 14:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 3. IPv6 to community?
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-07-14.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed July 14th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](wiki:SupportedVersions))
+ 3. IPv6 to community?
+ 4. `resolvconf -p` patch [https://patchwork.openvpn.net/patch/1840/](https://patchwork.openvpn.net/patch/1840/)
+ 5. hackathon planning
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-07-21.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed July 21st 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 3. IPv6 to community?
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-07-28.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed July 28th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 3. IPv6 to community?
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-08-04.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed August 4th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](wiki:SupportedVersions))
+ 3. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-08-11.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed August 11th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 3. IPv6 to community?
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-08-18.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed August 18th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 3. IPv6 to community?
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-08-25.md
@@ 0,0 1,21 @@
+ # Basic info
+
+ - **Time:** Wed August 25th 2021 14:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+
+ ## 2. Adding "Client" board to forums
+ - Brought up by Selva
+ - Idea is to be able to direct people who have client usage questions to that board
+
+ ## 3. Moving OpenVPN 2.4 support from fully supported to old stable.
+ - [Supported Versions](wiki:SupportedVersions)
+
+ ## 4. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-09-01.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed September 1st 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Adding "Client" board to forums
+ - Brought up by Selva
+ - Idea is to be able to direct people who have client usage questions to that board
+ 3. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](wiki:SupportedVersions))
+ 4. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-09-08.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed September 8th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 3. IPv6 to community?
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-09-15.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed September 15th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([SupportedVersions](SupportedVersions))
+ 3. IPv6 to community?
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-09-22.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed September 22nd 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 3. IPv6 to community?
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-09-29.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed September 29th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.5.4 release?
+ - 2.6
+ 3. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 4. IPv6 to community?
+ 5. buildbot status, next steps
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-10-13.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - Time: Wed October 13th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 4. IPv6 to community?
+ 5. Add tls-cert-profile insecure option below legacy for OpenSSL
+ 6. Buildbot status, next steps
+ - Migrate buildbot code to openvpn-build repo (too big to "fit in" to openvpn-vagrant)
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-10-20.md
@@ 0,0 1,24 @@
+ # Basic info
+
+ - Time: Wed October 20th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.5.4 I604 re-release
+ - 2.5.5 release
+ - 2.6
+ 3. Moving OpenVPN 2.4 support from fully supported to old stable. ([SupportedVersions](wiki:SupportedVersions))
+ 4. Trac hygiene
+ 5. IPv6 to community?
+ 6. buildbot status, next steps
+
+ # External questions
+
+ Please note: [https://community.openvpn.net/openvpn/ticket/1170#comment:7](https://community.openvpn.net/openvpn/ticket/1170#comment:7)
+ I add this here because I presume it is Corp stuff.
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-10-27.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed October 12th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. Moving OpenVPN 2.4 support from fully supported to old stable. ([SupportedVersions](wiki:SupportedVersions))
+ 4. IPv6 to community?
+ 5. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-11-10.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - Time: Wed November 10th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ - Reduce scope to only include Linux and Windows DCO to get it out?
+ - 2.7
+ - Assuming scope for 2.6 is reduced, what would 2.7 contain?
+ 3. Moving OpenVPN 2.4 support from fully supported to old stable. ([SupportedVersions](wiki:SupportedVersions))
+ 4. IPv6 to community?
+ 5. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-11-17.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed November 17th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon / T-Shirts
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. "multiple remotes" patchset [https://patchwork.openvpn.net/project/openvpn2/list/?series=1270](https://patchwork.openvpn.net/project/openvpn2/list/?series=1270)
+ 4. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](wiki:SupportedVersions))
+ 5. IPv6 to community?
+ 6. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-11-24.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed November 24th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 4. IPv6 to community?
+ 5. buildbot status, next steps
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-12-01.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed December 1st 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Improving testing (plaisthos)
+ 3. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](wiki:SupportedVersions))
+ 4. IPv6 to community?
+ 5. Buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-12-08.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed December 8th 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](wiki:SupportedVersions))
+ 3. IPv6 to community?
+ 4. T-Shirts
+ 5. Buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-12-15.md
@@ 0,0 1,26 @@
+ # Basic info
+
+ - **Time:** Wed December 15th 2021 14:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. **Meeting time**
+ 2. **Licensing incompatibility clarification**
+ - Brought up by m-a in [mailing list](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg23389.html)
+ - Which interpretation is correct?
+ - Do we need to do anything?
+ 3. **Yubikey and Google Titankey giveaway**
+ 4. **New default for MSSFIX in patch set**
+ - Current default is 1450, which translates to 1478 packets for udp4 and 1498 for udp6
+ - Proposal to have a new default based on the outer size (mtu as new option)
+ - Idea for new default: 1472 (1500 - one extra IPv4/UDP header) or 1452 (1500 - one extra IPv6/UDP header) so we have a good chance to work if tunneled ourselves.
+ - Datapoint: Wireguard uses mtu 1420 as default, which assumes that it can use 1500 on the outer packets with IPv6 and 1480 with IPv4.
+ 5. **Sync up on OpenVPN 2.5 and 2.6**
+ - 2.5
+ - 2.6
+ 6. **Multiple async auth plugin issue - next steps?**
+ 7. **IPv6 to community?**
+ 8. **Buildbot status, next steps**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2021-12-22.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed December 22nd 2021 14:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([SupportedVersions](wiki:SupportedVersions))
+ 3. IPv6 to community?
+ 4. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-01-05.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed January 5th 2022 10:30 CET (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 3. IPv6 to community?
+ 4. buildbot status, next steps
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-01-12.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed January 12th 2022 10:30 CET (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([SupportedVersions](wiki:SupportedVersions))
+ 3. IPv6 to community?
+ 4. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-01-19.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed January 19th 2022 10:30 CET (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Moving OpenVPN 2.4 support from fully supported to old stable. ([Supported Versions](SupportedVersions))
+ 3. IPv6 to community?
+ 4. Buildbot status, next steps
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-01-26.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - **Time:** Wed January 26th 2022 10:30 CET (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. **Sync up on OpenVPN 2.5 and 2.6**
+ - 2.5
+ - 2.6
+ 2. **OpenVPN 2.6 release, Windows builds, and OpenSSL version?**
+ - use 3.0.1 -> new xkey support, long-term platform, but breaks MD5/SHA1 CAs (tls-cert-profile insecure)
+ - use 1.1.1 -> "at some point we **need** to upgrade"
+ - while at it: can we drop cryptoapi and management-external-key support for "non 3.0.1" builds?
+ 3. **IPv6 to community?**
+ 4. **buildbot status, next steps**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-02-02.md
@@ 0,0 1,20 @@
+ # Basic info
+
+ - Time: Wed February 2nd 2022 10:30 CET (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Easy-RSA3 plans **Solved**
+ 2. Handling of OpenVPN Corp tickets in trac... (hello novaflash)
+ 3. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 4. OpenVPN 2.6 release, Windows builds, and OpenSSL version?
+ - use 3.0.1 -> new xkey support, long-term platform, but breaks MD5/SHA1 CAs (tls-cert-profile insecure)
+ - use 1.1.1 -> "at some point we **need** to upgrade"
+ - while at it: can we drop cryptoapi and management-external-key support for "non 3.0.1" builds?
+ 5. IPv6 to community?
+ 6. buildbot status, next steps
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-02-09.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - **Time**: Wed February 9th 2022 10:30 CET (8:30 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. **Sync up on OpenVPN 2.5 and 2.6**
+ - 2.5
+ - 2.6
+ 2. **OpenVPN 2.6 release, Windows builds, and OpenSSL version?**
+ - use 3.0.1 -> new xkey support, long-term platform, but breaks MD5/SHA1 CAs (tls-cert-profile insecure)
+ - use 1.1.1 -> "at some point we **need** to upgrade"
+ - while at it: can we drop cryptoapi and management-external-key support for "non 3.0.1" builds?
+ 3. **IPv6 to community?**
+ 4. **Buildbot status, next steps**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-02-16.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed February 16th 2022 10:30 CET (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. license issue?
+ 3. trac message notification (SMTP AUTH fail)
+ 4. IPv6 to community?
+ 5. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-02-23.md
@@ 0,0 1,23 @@
+ # Basic info
+
+ - Time: Wed February 23rd 2022 10:30 CET (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Open follow-up questions on the frame rewrite
+ - Make `--fragment` pushable?
+ - `--mtu-disc` not working (trac #1452 and [Patchwork link](https://patchwork.openvpn.net/patch/2308/))?
+ - `--mtu-test` losing its functionality (`entry->delta`)
+ - `--mssfix` default change
+ - Changes.rst
+ - Can we do `--mssfix` on inner MTU for non-1500 `--tun-mtu`?
+ - Reintroduce explicit "incoming packet too big for frame" check?
+ - How to move forward with `--tun-mtu` (default) setting, Linux-DCO, Windows-DCO, and external fragmentation?
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. IPv6 to community?
+ 4. Buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-03-02.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Wed March 2nd 2022 10:30 CET (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. Buildbot status, next steps
+ 4. `--dns` patch ready for the mailing list?
+
+ [Back to meeting list](IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-03-09.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed March 9th 2022 10:30 CET (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. 2.4/2.5 authentication multiple auth-plugins misbehavior when deferred is used: what to do with it?
+ 3. IPv6 to community?
+ 4. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-03-16.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - **Time:** Wed March 16th 2022 10:30 CET (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. **Sync up on OpenVPN 2.4, 2.5 and 2.6**
+ - **2.4**
+ - 2.4.12 release
+ - **2.5**
+ - 2.5.6 release
+ - building, vcpkg ports, openvpn-build repo?
+ - **2.6**
+ - DCO news
+ - multi-deferred patch ([request for comments](https://patchwork.openvpn.net/patch/2327/))
+ - how to deal with "other" multi-plugin issue (sync LDAP, deferred DUO)? short-circuit auth plugin handling? all plugins ("on the first failure, do not call any further plugin in this call")?
+ - other updates
+ 2. **IPv6 to community?**
+ 3. **buildbot status, next steps**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-03-23.md
@@ 0,0 1,29 @@
+ # Basic info
+
+ - **Time:** Wed March 23rd 2022 10:30 CET (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Sync up on OpenVPN 2.5 and 2.6
+ - 2.4
+ - 2.5
+ - 2.6
+ - DCO news
+ - multi-deferred patch ([patch](https://patchwork.openvpn.net/patch/2327/)) - request for comments
+ - How to deal with "other" multi-plugin issue (sync LDAP, deferred DUO)? Short-circuit auth plugin handling? All plugins ("on the first failure, do not call any further plugin in this call")?
+ - DNS patch, and openvpn_snprintf() return
+ - Other updates
+
+ ## Open follow-up questions on the frame rewrite
+ - Make --fragment pushable?
+ - --mtu-disc for IPv6 ([patch](https://patchwork.openvpn.net/patch/2318/))?
+ - --mtu-test losing its functionality (entry->delta)
+ - Reintroduce explicit "incoming packet too big for frame" check?
+ - How to move forward with --tun-mtu (default) setting, Linux-DCO, Windows-DCO, and external fragmentation?
+
+ ## IPv6 to community?
+
+ ## Buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-03-30.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - **Time:** Wed March 30th 2022 10:30 CET (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Developer documentation review needed - [OpenVPN Developer Documentation](https://community.openvpn.net/openvpn/wiki/DeveloperDocumentation)
+ 3. IPv6 to community?
+ 4. Buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-04-06.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed April 6th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.5.6 re-release for windows due to GUI bug (escaping of ' in passwords)
+ - 2.6
+ 2. IPv6 to community?
+ 3. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-04-13.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed April 13th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-04-20.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed April 20th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-04-27.md
@@ 0,0 1,31 @@
+ # Basic info
+
+ - **Time:** Wed April 27th 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## 1. Uncrustify
+ - 0.72 does what we have in our tree now (except pkt_test.c)
+ - 0.74 introduces spurious changes that look buggy
+ - 0.72 is it.
+ - pre-commit check does not fire on "git am" or "git rebase"
+ - Can someone find a magic option to make uncrustify (0.72) indent array initializations in a nice way? like this:
+ ```
+ char foo[] =
+ { 0x01, 0x02,
+ 0x03, 0x04 };
+ ```
+
+ ## 2. Sync up on OpenVPN 2.5 and 2.6
+ - OpenVPN 2.5.6-I602 preparations
+ - openvpn-build PR: [bump pkcs11-helper to v1.29.0](https://github.com/OpenVPN/openvpn-build/pull/242)
+ - openvpn-build PR: [windows-msi: introduce a Powershell script for bumping version.m4](https://github.com/OpenVPN/openvpn-build/pull/243)
+ - 2.5
+ - 2.6
+
+ ## 3. IPv6 to community?
+
+ ## 4. Buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-05-04.md
@@ 0,0 1,29 @@
+ # Basic info
+
+ - **Time:** Wed May 4th 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## 1. Uncrustify
+ - Can someone find a magic option to make uncrustify (0.72) indent array initializations in a nice way? Like this:
+ ```
+ char foo[] =
+ { 0x01, 0x02,
+ 0x03, 0x04 };
+ ```
+
+ ## 2. Sync up on OpenVPN 2.5 and 2.6
+ - **OpenVPN 2.5.6-I602 preparations**
+ - openvpn-build PR:
+ - **2.5**
+ - Ubuntu 22.04 ships with ossl 3.0.0, should have backport of commit 23efeb7a0bd9e0a6 (tls-cert-profile insecure)
+ - Contact the Ubuntu OpenVPN maintainers? [Ubuntu OpenVPN Package](https://packages.ubuntu.com/jammy/net/openvpn)
+ - Merged! and reported to Ubuntu bug [Launchpad Bug 1968629](https://bugs.launchpad.net/ubuntu/+source/openvpn/+bug/1968629)
+ - **2.6**
+
+ ## 3. IPv6 to community?
+
+ ## 4. Buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-05-11.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed May 10th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. Buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-05-18.md
@@ 0,0 1,20 @@
+ # Basic Info
+
+ - **Time:** Wed May 18th 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## 1. Sync up on OpenVPN 2.5 and 2.6
+ - **2.5**
+ - We should do a 2.5.7 release (good-enough OpenSSL 3.0.x support)
+ - Volunteer to talk FC36 maintainer into either bumping their package, or merge the 7-set +1 OpenSSL 3.0.x support patches merged into release/2.5 after 2.5.6 release?
+ - Volunteer to talk to Ubuntu 22.04 maintainer
+ - 2.5.6 + ossl 3.0.x really does not work very well for "slightly older" setups (no sha1 or bf-cbc support)
+ - **2.6**
+
+ ## 2. IPv6 to community?
+
+ ## 3. Buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-05-25.md
@@ 0,0 1,27 @@
+ # Basic info
+
+ - **Time:** Wed May 25th 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. **Sync up on OpenVPN 2.5 and 2.6**
+ - 2.5
+ - 2.6
+ 2. **Snapshot building & publishing**
+ - Windows, Debian
+ 3. **P2P and --explicit-exit-notify**
+ - Is there a specific reason why it is the way it is (peer exits, no way to make it not-exit)
+ - Shall we change this for P2P TLS?
+ 4. **DNS bit in IV_PROTO**
+ - What do we want?
+ 5. **DCO**
+ - Status?
+ - How to move forward? Break out smaller hunks? Or merge the jumbo patch and add bugfixes later?
+ - P2P
+ - P2P with no --remote
+ - Float on Linux (P2P and P2MP)?
+ 6. **IPv6 to community?**
+ 7. **Buildbot status, next steps**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-06-01.md
@@ 0,0 1,36 @@
+ # Basic info
+
+ - **Time:** Wed June 1st 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+
+ ## 2. Snapshot Building & Publishing
+ - Consider dropping Windows buildbot worker to reduce Windows CI/CD maintenance efforts
+ - GitHub Actions already produces end-user usable MSI installers
+ - Multiple places (openvpn-vagrant, openvpn-buildbot, GHA) have similar provisioning/build processes, leading to redundant development efforts
+ - Debian
+
+ ## 3. P2P and --explicit-exit-notify
+ - Is there a specific reason for current behavior (peer exits, no option to prevent exit)
+ - Consider changes for p2p TLS?
+
+ ## 4. DNS Bit in IV_PROTO
+ - Desired modifications?
+
+ ## 5. DCO
+ - Current status?
+ - Strategy forward: Break into smaller parts or merge the large patch and address issues later?
+ - P2P specifics
+ - Handling of `--remote` in p2p
+ - `float` option on Linux (in both p2p and p2mp contexts)?
+
+ ## 6. IPv6 to Community
+
+ ## 7. Buildbot Status and Next Steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-06-08.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed June 8th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-06-15.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - **Time**: Wed June 15th 2022 10:30 CEST (8:30 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-06-22.md
@@ 0,0 1,56 @@
+ # Basic info
+
+ - **Time**: Wed June 22nd 2022 10:30 CEST (8:30 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+
+ ## 2. Migrating to the [new Patchwork instance](https://18.192.149.255/project/openvpn2/list/)
+ - New Patchwork is ready to be used; it has already collected the most recent patches.
+ - Ordex is able to resend relevant patches so the new Patchwork gets them.
+ - Our mailing list archive contains the discussion history for patches that have been merged/are not relevant anymore -> no real need to have those in new Patchwork.
+ - DNS can be switched at any time.
+ - Users need to be added for those who need Patchwork, but doing this will be easier once patches are in.
+ - In Patchwork, Git authors and users are kind of the same thing afaik, so this is mostly about permissions.
+ - When to do this?
+
+ ## 3. What to do with Trac?
+ - **Background**
+ - Trac project has struggled quite a bit to get Python 3 support in ([see Trac ticket #12130](https://trac.edgewall.org/ticket/12130)).
+ - This was somewhat expected, given that a large number of its dependencies needed to become Python 3 compatible first.
+ - There are no stable Trac releases with Python 3 support.
+ - The only Trac version that supports Python 3 is the development release (1.5).
+ - While Trac is still being developed, it is not moving forward very fast.
+ - e.g., Python 3 support was supposed to land in Trac 1.3.
+ - Our Trac setup is fairly complex (LDAP auth, lots of plugins, spam filtering, etc.).
+ - When Trac was set up originally it was deemed important by OpenVPN Inc. management to self-host everything: this may have changed since then.
+ - **Options**
+ - Update to Trac 1.5
+ - Can be done, but users may experience issues.
+ - Some of the Trac plugins may no longer work (warrants research).
+ - Migrate to Github
+ - We are using Github for most of our development already (excluding a subset of OpenVPN 2.x development).
+ - Benefit: contents of "community.openvpn.net" would be reachable via IPv6 - assuming Github supports IPv6 :)
+ - Wiki import seems possible and can even be done manually (we don't have hundreds or thousands of pages).
+ - Issue import (without comments) can apparently be done from CSV with [github-csv-tools](https://github.com/gavinr/github-csv-tools).
+ - Issue comments can be imported with a custom script that drives the [GitHub issues API](https://docs.github.com/en/rest/issues/comments).
+ - We'd want HTTP redirects for the most important pages at least.
+ - A simple nginx/apache server doing these redirects would be sufficient.
+ - Overall: it will be a hassle, but can be done.
+ - Use separate software for Wiki and Bug tracking
+ - Wikis
+ - [Self-hosted wiki software](https://geekflare.com/self-hosted-wiki-software/)
+ - [Best self-hosted wiki software](https://rooferne.mooo.com/best-self-hosted-wiki-software/)
+ - Bug tracking
+ - [OS bug and issues tracking and management solutions](https://medevel.com/19-os-bug-and-issues-tracking-and-management-solutions/)
+ - Other options?
+ - Self-hosted gitlab or gitlab.com
+ - Mattock is not very keen on doing this even though he does have a self-hosted Gitlab instance and uses gitlab.com to an extent: Gitlab has turned into a pig/beast with a gazillion of features most of which we would not even use. If we wanted to use Gitlab then we should probably go all the way in or not at all.
+
+ ## 4. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-06-29.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed June 31st 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. IPv6 to community?
+ 3. buildbot status, next steps
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-07-06.md
@@ 0,0 1,63 @@
+ # Basic info
+
+ - **Time:** Wed July 07th 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+
+ ## 2. Hackathon
+
+ ## 3. Drop `--mktun` / `--rmtun` support?
+ - This adds quite a bit of code complexity
+ - Especially with DCO vs. Tuntap and devices being always called "tunX"
+ - `ip tuntap add mode tun name tun10` seems to get the same job done as `openvpn --mktun --dev tun10`
+
+ ## 4. Migrating to the [new Patchwork instance](https://18.192.149.255/project/openvpn2/list/)
+ - New Patchwork is ready to be used, it has already collected the most recent patches
+ - Ordex is able to resend relevant patches so the new Patchwork gets them
+ - Our mailing list archive contains the discussion history for patches that have been merged/are not relevant anymore -> no real need to have those in new Patchwork
+ - DNS can be switched at any time
+ - Users need to be added for those who need Patchwork, but doing this will be easier once patches are in
+ - In Patchwork, Git authors and users are kind of the same thing afaik, so this is mostly about permissions
+ - When to do this?
+
+ ## 5. What to do with Trac?
+ - **Background**
+ - Trac project has struggled quite a bit to get Python 3 support in ([see Trac ticket #12130](https://trac.edgewall.org/ticket/12130))
+ - This was somewhat expected, given that a large number of its dependencies needed to become Python 3 compatible first
+ - There are no stable Trac releases with Python 3 support
+ - The only Trac version that supports Python 3 is development release (1.5)
+ - While Trac is still being developed, it is not moving forward very fast
+ - e.g. Python 3 support was supposed to land in Trac 1.3
+ - Our Trac setup is fairly complex (LDAP auth, lots of plugins, spam filtering, etc.)
+ - When Trac was set up originally it was deemed important by OpenVPN Inc. management to self-host everything: this *may* have changed since then
+ - **Options**
+ - Update to Trac 1.5
+ - Can be done, but users *may* experience issues
+ - Some of the Trac plugins may no longer work (warrants research)
+ - Migrate to GitHub
+ - We are using GitHub for most of our development already (excluding a subset of OpenVPN 2.x development)
+ - Benefit: contents of "community.openvpn.net" would be reachable via IPv6 - assuming GitHub supports IPv6 :)
+ - Wiki import [seems possible](https://stackoverflow.com/questions/9710129/how-do-i-export-trac-wiki-to-github-wiki) and can even be done manually (we don't have hundreds or thousands of pages)
+ - Issue import (without comments) can be done from CSV with [github-csv-tools](https://github.com/gavinr/github-csv-tools)
+ - Issue comments can be imported with a custom script that drives [the GitHub issues API](https://docs.github.com/en/rest/issues/comments)
+ - We'd want HTTP redirects for the most important pages at least
+ - Simple Nginx/Apache server doing these redirects would be sufficient
+ - Overall: it will be a hassle, but can be done
+ - Use separate software for Wiki and Bug tracking
+ - **Wikis**
+ - [Self-hosted Wiki software options](https://geekflare.com/self-hosted-wiki-software/)
+ - [Best self-hosted Wiki software](https://rooferne.mooo.com/best-self-hosted-wiki-software/)
+ - **Bug tracking**
+ - [Open Source Bug and Issues Tracking Management Solutions](https://medevel.com/19-os-bug-and-issues-tracking-and-management-solutions/)
+ - Other options?
+ - Self-hosted GitLab or GitLab.com
+ - Mattock is not very keen on doing this even though he does have a self-hosted GitLab instance and uses GitLab.com to an extent: GitLab has turned into a pig/beast with gazillion of features most of which we would not even use. If we wanted to use GitLab then we should probably go all the way in or not at all.
+
+ ## 6. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-07-13.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - **Time:** Wed July 13th 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 2. Hackathon!
+ 3. builds on demand
+ 4. buildslaves and t_client tests
+ 5. IPv6 to community?
+ 6. trac upgrade plans
+ 7. patchwork migration plans
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-07-20.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed July 20th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-07-27.md
@@ 0,0 1,15 @@
+ # Basic info
+
+ - Time: Wed July 27th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Updates on Buildbot Army (djpig)
+ 2. Hackathon
+ 3. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 4. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-08-03.md
@@ 0,0 1,42 @@
+ # Basic info
+
+ - **Time:** Wed August 3rd 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Updates on Buildbot Army (djpig)
+ 2. t_client setup for djpig's MacOS buildbot worker
+ 3. Hackathon
+ 4. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 5. remove --disable-management?
+
+ ```
+ gert@blueNUC2:/tmp/o$ size src/openvpn/openvpn
+ text data bss dec hex filename
+ 844853 7936 2104 854893 d0b6d src/openvpn/openvpn
+
+ --disable-management:
+
+ gert@blueNUC2:/tmp/o$ size src/openvpn/openvpn
+ text data bss dec hex filename
+ 771910 7504 2040 781454 bec8e src/openvpn/openvpn
+
+ --enable-small:
+
+ gert@blueNUC2:/tmp/o$ size src/openvpn/openvpn
+ text data bss dec hex filename
+ 762947 7928 2104 772979 bcb73 src/openvpn/openvpn
+
+ --enable-small --disable-management:
+
+ gert@blueNUC2:/tmp/o$ size src/openvpn/openvpn
+ text data bss dec hex filename
+ 693180 7496 2040 702716 ab8fc src/openvpn/openvpn
+ ```
+
+ 6. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-08-10.md
@@ 0,0 1,18 @@
+ # Basic info
+
+ - **Time:** Wed August 10th 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. `--enable-dco + openssl 3.0 fails to build on ubuntu20 due to pkg-config misbehaviour for libnl` (adding `-L/usr/lib/x86_64-linux-gnu`) (#1469)
+ 4. New installer + openvpnmsica patch ([link](https://community.openvpn.net/openvpn/wiki/Topics-2022-08-10)) -> for 2.5.8 as well?
+ 5. Windows buildslave with actual tests?
+ 6. IPv6 to community?
+ 7. Remove Changelog file
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-08-17.md
@@ 0,0 1,26 @@
+ # Basic info
+
+ - **Time:** Wed August 17th 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. **Hackathon**
+ 2. **Sync up on OpenVPN 2.5 and 2.6**
+ - 2.5
+ - 2.6
+ 3. **Linux-DCO vs. Network-Manager**
+ - [Mail Archive Discussion](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg24932.html)
+ - disable DCO if CAP_NET_ADMIN cannot be retained?
+ - or FATAL out?
+ - how to fix NM issue [Debian Bug Report](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1017379)
+ 4. **2.6.0 release timeline? Proposed date: November 1st**
+ - Debian "bookworm" freeze is "end of the year" (2023-01-12) - [Debian Freeze Info](https://lists.debian.org/debian-devel/2022/03/msg00251.html)
+ 5. **New 2.5.7 installers and new TAP-Driver-Bundle needed**
+ 6. **Master/dco package status across the OSes (exposure to testing)?**
+ 7. **Windows buildslave with actual tests?**
+ 8. **`--enable-dco + openssl 3.0` fails to build on ubuntu20 due to pkg-config misbehaviour for libnl (adding `-L/usr/lib/x86_64-linux-gnu`)** (#1469)
+ 9. **New installer + openvpnmsica patch** [OpenVPN Community](https://community.openvpn.net/openvpn/wiki/Topics-2022-08-10) -> for 2.5.8 as well?
+ 10. **IPv6 to community?**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-08-24.md
@@ 0,0 1,33 @@
+ # Basic info
+
+ - Time: Wed August 24th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. **Hackathon**
+ 2. **Community services migration tomorrow (Thursday) during EET working time (9-17) is ok?**
+ - Replacement VMs are ready for ldap (updated OS + app), pwm (updated OS + app), trac (copied as-is) and forums (copied as-is)
+ - Migration procedures for each service are available and have been tested
+ - Total time for migration is probably ~2 hours, downtime for users should be less
+ 3. **Sync up on OpenVPN 2.5 and 2.6**
+ - **2.5**
+ - new 2.5.7 installers and new TAP-Driver-Bundle needed (TAP driver bugfix merged)
+ - new installer + openvpnmsica patch ([OpenVPN Wiki](https://community.openvpn.net/openvpn/wiki/Topics-2022-08-10)) -> for 2.5.8 as well?
+ - **2.6**
+ - FreeBSD-DCO fully merged, some MR_WITH_NETBITS issues remain (please review patch), some route/iroute clarifications sought (mail on list), double fragmentation still broken (kp looking into it)
+ - FreeBSD "openvpn-devel" port/pkg has been updated to 734de8f9aa
+ - Linux-DCO fully merged, some P2P renegotiation / reconnection issues remain (also seem to affect FreeBSD-DCO)
+ - Linux port builders beware: if userland RPMs are upgraded, kernel RPMs need to be upgraded as well(!) - to 383a897a5cb or later - otherwise P2P will no longer work (at all) (Debian is up to date on both accords)
+ - Windows-DCO is waiting for testers, code seems ready to be merged
+ 4. **Linux-DCO vs. Network-Manager**
+ - NM issue ([Debian Bug report](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1017379)) has been worked around (disable DCO if CAP_NET_ADMIN can not be retained)
+ - dazo to establish contacts with NM maintainers for "real" solution, like "run as uid=nm-openvpn, but with CAP_NET_ADMIN, and no --user switch" - any news?
+ - Syzzer's comment: can we make this work without retaining CAP_NET_ADMIN after openvpn startup? At least for clients?
+ 5. **2.6.0 release timeline?** proposed date: November 1st
+ - Debian "bookworm" freeze is "end of the year" ([Debian-devel](https://lists.debian.org/debian-devel/2022/03/msg00251.html))
+ 6. **Windows buildslave with actual tests?**
+ 7. **--enable-dco + openssl 3.0 fails to build on ubuntu20 due to pkg-config misbehaviour for libnl (adding `-L/usr/lib/x86_64-linux-gnu`)** (#1469)
+ 8. **IPv6 to community?**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-08-31.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed August 31st 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-09-07.md
@@ 0,0 1,14 @@
+ # Basic info
+
+ - Time: Wed September 7th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-09-14.md
@@ 0,0 1,16 @@
+ # Basic info
+
+ - Time: Wed September 14th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. IPv6 to community?
+ 4. Any news on network manager integration (2.6, DCO, CAP_NET_ADMIN)?
+ 5. Automated windows testing
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-09-21.md
@@ 0,0 1,17 @@
+ # Basic info
+
+ - Time: Wed September 21st 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. automated testing (unix and windows)
+ - "spread the word" on what we have
+ - improvements?
+ 3. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 4. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-09-28.md
@@ 0,0 1,27 @@
+ # Basic info
+
+ - **Time**: Wed September 28th 2022 10:30 CEST (8:30 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. **Hackathon**
+ 2. **Automated testing (unix and windows)**
+ - "Spread the word" on what we have
+ - Improvements?
+ 3. **Sync up on OpenVPN 2.5 and 2.6**
+ - 2.5
+ - 2.6
+ 4. **2.6 release - what is missing, who is working on it**
+ - p2p DCO (ordex, plaisthos)
+ - Initial handshake rate limiting (cron2)
+ - Platform "undo_ifconfig" cleanup (cron2)
+ - FreeBSD DCO iroute / metric (cron2)
+ - NM integration / CAP_NET_ADMIN (dazo)
+ - Control channel, MTU, reliable ACK, renegotiation... (plaisthos + reviewer)
+ - Inline --auth-user-pass (ordex, needs review)
+ - "Do not push route-ipv6" (cron2 to test & merge)
+ - Build fail with private-install openssl 3 & DCO (in trac, any takers?)
+ 5. **IPv6 to community?**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-10-05.md
@@ 0,0 1,27 @@
+ # Basic info
+
+ - **Time:** Wed October 5th 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Automated testing (unix and windows)
+ - "spread the word" on what we have
+ - Improvements?
+ 3. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 4. 2.6 release - what is missing, who is working on it
+ - p2p DCO (ordex, plaisthos)
+ - initial handshake rate limiting (cron2)
+ - platform "undo_ifconfig" cleanup (cron2)
+ - FreeBSD DCO iroute / metric (cron2)
+ - NM integration / CAP_NET_ADMIN (dazo)
+ - Control channel, MTU, reliable ACK, renegotiation... (plaisthos + reviewer)
+ - Inline --auth-user-pass (ordex, needs review)
+ - "do not push route-ipv6" (cron2 to test & merge)
+ - Build fail with private-install openssl 3 & DCO (in trac, any takers?)
+ 5. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-10-12.md
@@ 0,0 1,27 @@
+ # Basic info
+
+ - **Time**: Wed October 12th 2022 10:30 CEST (8:30 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Automated testing (unix and windows)
+ - "spread the word" on what we have
+ - improvements?
+ 3. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 4. 2.6 release - what is missing, who is working on it
+ - p2p DCO (ordex, plaisthos)
+ - initial handshake rate limiting (cron2)
+ - platform "undo_ifconfig" cleanup (cron2)
+ - FreeBSD DCO iroute / metric (cron2)
+ - NM integration / CAP_NET_ADMIN (dazo)
+ - control channel, MTU, reliable ACK, renegotiation... (plaisthos + reviewer)
+ - inline --auth-user-pass (ordex, needs review)
+ - "do not push route-ipv6" (cron2 to test & merge)
+ - build fail with private-install openssl 3 & DCO (in trac, any takers?)
+ 5. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-10-19.md
@@ 0,0 1,22 @@
+ # Basic info
+
+ - Time: Wed October 19th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. 2.6 release - what is missing, who is working on it
+ - p2p DCO (ordex, plaisthos)
+ - initial handshake rate limiting (cron2)
+ - FreeBSD DCO iroute / metric (cron2)
+ - NM integration / CAP_NET_ADMIN (dazo)
+ - control channel, MTU, reliable ACK, renegotiation... (plaisthos + reviewer)
+ - build fail with private-install openssl 3 & DCO (in trac, any takers?)
+ - automated testing on windows
+ 4. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-10-26.md
@@ 0,0 1,21 @@
+ # Basic info
+
+ - Time: Wed October 26th 2022 10:30 CEST (8:30 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. Sync up on OpenVPN 2.5 and 2.6
+ - 2.5
+ - 2.6
+ 3. 2.6 release - what is missing, who is working on it
+ - automated windows testing
+ - p2p DCO (ordex, plaisthos)
+ - initial handshake rate limiting (cron2)
+ - NM integration / CAP_NET_ADMIN (dazo)
+ - control channel, MTU, reliable ACK, renegotiation... (plaisthos + reviewer)
+ - build fail with private-install openssl 3 & DCO (in trac, any takers?)
+ 4. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-11-09.md
@@ 0,0 1,24 @@
+ # Basic info
+
+ - **Time:** Wed November 09th 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. **Hackathon**
+ 2. **2.5.8 release - what went well, what went wrong?**
+ - communications, announcements, time delay between "chatter in IRC", "tag in (public) git" and "announcement mail"
+ - windows binary showing "2.5.7" version number
+ - windows-gui version number bump + tag missing
+ 3. **2.6 release**
+ - timeline!
+ 4. **2.6 release - what is missing, who is working on it**
+ - automated windows testing
+ - p2p DCO (ordex, plaisthos)
+ - initial handshake rate limiting (cron2)
+ - NM integration / CAP_NET_ADMIN (dazo)
+ - control channel, MTU, reliable ACK, renegotiation... (plaisthos + reviewer)
+ - build fail with private-install openssl 3 & DCO (in trac, any takers?)
+ 5. **IPv6 to community?**
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-11-23.md
@@ 0,0 1,19 @@
+ # Basic info
+
+ - **Time:** Wed November 23th 2022 10:30 CEST (8:30 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ 1. Hackathon
+ 2. 2.6 release - update on status and missing pieces
+ - automated windows testing (lev)
+ - p2p DCO (ordex, plaisthos)
+ - initial handshake rate limiting (cron2)
+ - NM integration / CAP_NET_ADMIN (dazo)
+ - build fail with private-install openssl 3 & DCO (in trac, any takers?)
+ - SRV support (testers + OpenBSD decision needed)
+ - management interface improvement patches from Selva (review needed)
+ 3. IPv6 to community?
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-11-30.md
@@ 0,0 1,65 @@
+ # Basic Info
+
+ - **Time**: Wed November 30th 2022 13:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ - **It has been suggested to move the meeting time slot to 1PM CET.**
+ - *This has been accepted. The new official meeting time is now 1PM CET.*
+
+ - **[OpenVPN Community Resources - Differences between TAP-Windows driver and CIPE driver](https://openvpn.net/community-resources/notes-differences-between-tap-windows-driver-and-cipe-driver/) is outdated.**
+ - *This will be deleted in this week's website update.*
+
+ - **[OpenVPN Manual](https://openvpn.net/man.html) is a wrong redirect.**
+ - *This will be updated to point to an overview of OpenVPN 2.* reference manuals in this week's website updates.*
+
+ - **The reference manual for OpenVPN 2.5 will (finally) be posted on the main website.**
+ - *This will be included in this week's website updates.*
+
+ - **Can we remove the migration notices from the forums and the wiki front page?**
+ - *Yes, already removed from community.openvpn.net, any other places it can be removed from as well.*
+
+ - **Where to find updated management interfaces notes to update it on the main website?**
+ - *doc/management-notes.txt in the OpenVPN GitHub repo has this information.*
+
+ - **Automated windows testing status. (lev)**
+ - *Have not yet had time to look further into it, but intend to increase coverage with more Windows versions. Did add openvpn-gui --connect testing.*
+
+ - **Peer-to-peer DCO handling status. (ordex, plaisthos)**
+ - *Blocker for 2.6 alpha1. Must make it before Friday 2 December, or as fallback option we document bad behavior or disable it for peer-to-peer mode.*
+
+ - **Initial handshake rate limiting status (cron2)**
+ - *Not a blocker. Nice-to-have item. May not make it into 2.6. Patches currently already in place already mitigate misbehavior significantly.*
+
+ - **NM integration / CAP_NET_ADMIN status. (dazo)**
+ - *Not a blocker. Nice-to-have item. Will likely not make it into 2.6. Dazo currently unavailable.*
+
+ - **Build failure with private-install openssl 3 & DCO ticket #1469. (cron2)**
+ - *Situation was reviewed by djpig. Looks like a bug in Ubuntu we can't solve on our end. cron2 will make an Ubuntu bug report.*
+
+ - **SRV support, testers and OpenBSD decision needed. (cron2)**
+ - *At the moment, the patch breaks OpenBSD compilation so that needs fixing. cron2 will provide an updated patch that disables the feature on OpenBSD. djpig promised to review it. If it makes it in before 2.6_beta1 we're good.*
+
+ - **Management interface improvement patches. (selva)**
+ - *2 parts are now merged, rest is in review/merge process.*
+
+ - **Release date of OpenVPN 2.6_alpha1.**
+ - *Friday 2 December.*
+
+ - **Instead of Trac we want to use GitHub issues for bug reports.**
+ - *We will immediately switch to GitHub for new bug reports. We will turn off the 'new ticket' function in Trac. Over time we will migrate or close tickets. Urgent items should be resubmitted to GitHub.*
+
+ - **As discussed in Hackathon we want to do a PoC with using Gerrit for code review.**
+ - *This requires an environment to be setup and tuned. This is postponed until after 2.6 stable release.*
+
+ - **Release build automation.**
+ - *Since we are going into a cycle of alpha and beta releases, now would be the most opportune time to work on and test release automation improvements.*
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - *mattock agreed to convert it to rocky linux 8 with ecrist's blessing.*
+
+ - **IPv6 to community.**
+ - *No new information to report.*
+
+ [Back to meeting list](wiki:IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-12-07.md
@@ 0,0 1,87 @@
+ # Basic Info
+
+ - **Time:** Wednesday 7 December 2022 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ### How do we tag issues received on Github in our commit messages?
+ - djpig indicated the GitHub parses this format: "Github: OpenVPN/openvpn#123"
+
+ ### We will no doubt get bug reports about OpenVPN Connect software on GitHub issues. They do not belong there. How to deal with them?
+ - novaflash will discuss with the team lead of OpenVPN Connect team and discuss options.
+
+ ### Collect and discuss feedback on 2.6_beta1 release.
+ - Windows I601 missing legacy.dll OpenSSL provider is fixed (lev)
+ - eduvpn node crashed machine with 2.6_beta1 ouch, berniv6 should open an issue (berniv6) (cron2)
+ - FreeBSD openvpn-devel port updated (cron2/m-a)
+ - maxf has found a junior victim to test openvpn 2.6_beta1 (maxf)
+ - Anything else?
+
+ ### Should we do a 2.6_beta1 I602 windows release?
+ - Only change is the legacy fix. Let's just do a release next week on December 15.
+
+ ### 2.6_beta2 release date
+ - We aim to do this on December 15. Website release to be planned in accordance.
+
+ ### Patchset that makes pkcs11 code even worse but will make users happy (becm)
+ - This patch makes it possible to tell pkcs11 thingee where to look for libraries and then things will just work.
+
+ ### License amendment for OpenVPN2 to accommodate mbedtls.
+ - plaisthos made a first draft. plaisthos asked to get novaflash to ask francis and james to sign off on it.
+ - In the meantime, we need to compile a list of contributors and get ready to ask them to accept the changes.
+
+ ### The reference manual for OpenVPN 2.6 will be posted on the main website this week.
+ - This will be included in this week's website updates. Note: if there are updates to the documentation in the future kindly advise novaflash so he can update it on the main website too.
+
+ ### OpenVPN2 build environment and improving it.
+ - djpig is currently working on this. The company has decided to prioritize this task.
+ - In light of the recent security incident, we also want to move the code signing key to an HSM type solution. Working on it.
+
+ ### Management interface documentation on the main website will be updated with info from doc/management-notes.txt
+
+ ### Automated windows testing status. (lev)
+
+ ### What is this page https://community.openvpn.net/openvpn/wiki/CodeRepositories, can we delete it?
+ - No, we need to keep it, just has some outdated items that we can update.
+
+ ### Peer-to-peer DCO handling status. (ordex, plaisthos)
+ - For Windows, it works if both peers have --remote, because it is client-only on Windows and therefore expected to work this way.
+ - On Linux/FreeBSD all previously found nastiness is now resolved and in beta1 already.
+
+ ### Initial handshake rate limiting status (cron2, plaisthos)
+ - plaisthos brought up the idea to do a particular filter method.
+
+ ### NM integration / CAP_NET_ADMIN status. (dazo)
+ - Dazo currently unavailable.
+
+ ### Build failure with private-install openssl 3 & DCO ticket #1469. (cron2)
+ - djpig's environment does not show the bug, but cron2's does. Not sure what's going on yet.
+ - Will need to investigate further before deciding to make a bug report or not.
+
+ ### SRV support, testers, and OpenBSD decision needed. (cron2)
+ - djpig tested and nacked it - themiron promised to test and did not deliver anything, so it missed the boat.
+ - Unless a fix comes in early next week and makes it into beta2, then it's likely going to miss the 2.6.0 boat.
+
+ ### Management interface improvement patches. (selva)
+ - 2 parts are now merged, the rest is in the review/merge process.
+
+ ### As discussed in Hackathon, we want to do a PoC with using Gerrit for code review.
+ - This requires an environment to be set up and tuned. This is postponed until after the 2.6 stable release.
+
+ ### Forums machine on community infrastructure is only non-Linux system.
+ - mattock agreed to convert it to rocky linux 8 with ecrist's blessing.
+ - Was blocked from creating a VM, am now unblocked, will work on it now.
+
+ ### Forums issues, permissions, layout.
+ - Over the weekend things were broken on the forums, they're working again now. For some reason, novaflash and openvpn_inc are being denied permissions, why?
+
+ ### novaflash needs some input on https://www-dev.openvpn.in/community-resources/openvpn-quickstart/
+ - Static-key will be deprecated, there's already a warning about that in OpenVPN if you use it.
+ - plaisthos has a tutorial for peer fingerprint that will be much easier to use. It is at https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst
+ - novaflash will update this outdated page.
+
+ ### IPv6 to community.
+ - No new information to report.
+
+ [Back to meeting list](https://community.openvpn.net/openvpn/wiki/IrcMeetings)
\ No newline at end of file
/dev/null .. meetings/2022-12-14.md
@@ 0,0 1,48 @@
+ # Basic info
+
+ - **Time:** Wednesday 14 December 2022 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## novaflash temporarily unavailable due to personal situation
+ novaflash will be back to resume meeting duties next week.
+
+ ## 2.6_beta2 release date
+ This will be released on December 15th.
+
+ ## Status of OpenVPN 2.6 beta2 plans
+ cron2 would like to include counter patches in beta2, especially lev's patches for Windows. The plan is to tag beta2 Thursday at about 15:00 CET. This should give djpig enough time to produce binaries. Beta downloads will for now be published at wiki:Downloads to avoid dependency on Corp website team. Later when 2.6 is stable, we can revert things again. There are a few issues reported at GitHub, mostly around renegotiation. Some are sadly not very usable.
+
+ ## 2.6 MSVC toolchain, update to VS 2022? Windows Server 2022?
+ Not for beta2. But might try to do before 2.6.0 stable release. lev will send patches.
+
+ ## openvpn-build/generic and openvpn-build/windows-nsis: unmaintained. Should those be removed?
+ lev says yes, they are unmaintained. djpig will include a note in the next release announcements and post notes in the related GitHub issues to raise awareness.
+
+ ## pkcs11-helper dynamic loader flags: yes/no(/cancel), add patch to openvpn/contrib to get support/exposure in 2.6(.0/beta2)?
+ becm needs someone to review the pkcs11-helper patches on the list so we can merge them before beta2. plaistos said he might be able to take a look after some work he is currently doing on his app. Patch to vcpkg-ports adds support for the feature before the next pkcs11-helper release, so that Windows installers provide more consistent behavior over 2.6.x lifetime.
+
+ ## OpenVPN2 build environment and improving it
+ djpig is currently working on this. The company has decided to prioritize this task. Code signing key was moved to an HSM system for increased security. Further improvements to the build process are underway.
+
+ ## License amendment for OpenVPN2 to accommodate mbedtls
+ plaisthos made a first draft. plaisthos asked to get novaflash to ask francis and james to sign off on it. In the meantime, we need to compile a list of contributors and get ready to ask them to accept the changes. This was delayed due to the temporary unavailability of novaflash.
+
+ ## Management interface documentation on main website will be updated with info from doc/management-notes.txt
+ This is a task on novaflash, temporarily postponed due to unavailability of novaflash.
+
+ ## https://www-dev.openvpn.in/community-resources/openvpn-quickstart/ will be updated from /doc/man-sections/example-fingerprint.rst information.
+ Static-key will be deprecated and contents updated with peer-fingerprint stuff. This is temporarily postponed due to unavailability of novaflash.
+
+ ## As discussed in Hackathon we want to do a PoC with using Gerrit for code review
+ This requires an environment to be set up and tuned. This is postponed until after 2.6 stable release.
+
+ ## Forums machine on community infrastructure is only non-Linux system
+ mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist. Currently waiting for ecrist to test if he has access and all is well before we're able to make the switch.
+
+ ## Forums issues, permissions, layout
+ Forums had issues with bread crumbs, inability to post due to malfunctioning spam plugin, and deleted posts cannot be reviewed in the usual way. novaflash complains that forums are clogged up with deleted posts that never actually get deleted. ecrist worked on these issues. Breadcrumbs are now working again. Malfunctioning spam plugin issue now seems to be resolved. Agreed to use a board only visible for moderators/administrators to move all deleted posts so that the forums can finally be cleaned up from spam.
+
+ ## IPv6 to community
+ No new information to report.
\ No newline at end of file
/dev/null .. meetings/2022-12-21.md
@@ 0,0 1,59 @@
+ # Basic Info
+
+ - **Time:** Wednesday 21 December 2022 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **novaflash is back to resume meeting duties.**
+
+ - **Do we even do a meeting on the 28th?**
+ "Yes, but we won't have full attendance. Would be good to sync up about a new 2.6 beta3/rc1 release."
+
+ - **2.6 release plans**
+ "We haven't decided if we want to do beta3 or rc1, but definitely not a stable release yet.
+ We have decided that we should do a release on the 28th of December."
+
+ - **How do we judge remaining known bugs?**
+ - **Must solve:** crashbug with TCP ([#190 on GitHub](https://github.com/OpenVPN/openvpn/issues/190)) is something plaisthos will take a look at.
+ - **Not critical:** keepalive not working in DCO p2p mode (#1476) [fixed in 7c66a6dab54d8]
+ - **Not critical as long as keep-alive is used:** p2p TLS renegotiations getting all confused if client reconnects after server failed renegotiation, but *before* server-connect-timeout expires.
+ - **Not critical:** UDP gremlin uncovers "sometimes p2mp server on linux-dco is not notified / is ignoring if client expires" (8 clients out of about 5000 connects), keeps sending TLS renegotiation packets.
+ - **Must solve:** Seems DCO is not sending a signal to user space when a tcp client disconnects or gets connection reset. Will check if ordex has availability to fix.
+
+ - **2.6 MSVC toolchain, update to VS 2022? Windows Server 2022?**
+ "Not for beta2. But might try to do before 2.6.0 stable release. lev has sent patches that need review."
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ "mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
+ Currently waiting for ecrist to test if he has access and all is well before we're able to make the switch."
+
+ - **License amendment for OpenVPN2 to accommodate mbedtls.**
+ "plaisthos made a first draft. plaisthos asked to get novaflash to ask francis and james to sign off on it.
+ In the meantime we need to compile a list of contributors and get ready to ask them to accept the changes.
+ novaflash will pick this up again now that he is back."
+
+ - **pkcs11-helper dynamic loader flags: yes/no(/cancel), add patch to openvpn/contrib to get support/exposure in 2.6(.0/beta2)?**
+ "These changes were merged."
+
+ ## Topics on Standby
+
+ - **OpenVPN2 build environment and improving it.**
+ "djpig is currently working on this. The company has decided to prioritize this task.
+ Code signing key was moved to an HSM system for increased security.
+ Further improvements to the build process are underway."
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ "novaflash will pick this up again now that he is back."
+
+ - **<https://www-dev.openvpn.in/community-resources/openvpn-quickstart/> will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ "Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ novaflash will pick this up again now that he is back."
+
+ - **As discussed in Hackathon we want to do a PoC with using Gerrit for code review.**
+ "This requires an environment to be setup and tuned. This is postponed until after 2.6 stable release."
+
+ - **IPv6 to community.**
+ "No new information to report."
\ No newline at end of file
/dev/null .. meetings/2022-12-28.md
@@ 0,0 1,53 @@
+ # Basic info
+
+ - **Time**: Wednesday 28 December 2022 at 13:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **2.6 release plans**
+ 'We will do an OpenVPN 2.6 rc1 release.
+ We have decided that we should do a release on the 28th of December.'
+
+ - **Status of current bugs?**
+ 'The crashbug with TCP seems to be solved.
+ There are notification issues regarding status of client connected or not between 2.6 and kernel module.
+ **Must solve before Jan 15th:** Seems DCO is not sending a signal to user space when a TCP client disconnects or gets connection reset. This is a task for ordex.'
+
+ - **2.6 MSVC toolchain, update to VS 2022? Windows Server 2022?**
+ 'This has been done and will be part of OpenVPN 2.6 rc1 release.'
+
+ - **OpenVPN2 build environment and improving it.**
+ 'djpig is currently working on this. The company has decided to prioritize this task.
+ Code signing key was moved to an HSM system for increased security.
+ djpig overhauled openvpn-build, it now uses submodules for openvpn and openvpn-gui, and contains debian packaging scripts.
+ Further improvements to the build process are underway.'
+
+ - **OpenVPN 2.6 performance results.**
+ 'Now that we have a beta out, and soon an rc1, we want to have an article on main site and press release about performance results.'
+
+ ## Topics on standby
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ 'mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
+ Currently waiting for ecrist to test if he has access and all is well before we're able to make the switch.'
+
+ - **License amendment for OpenVPN2 to accommodate mbedtls.**
+ 'plaisthos made a first draft. plaisthos asked to get novaflash to ask francis and james to sign off on it.
+ In the meantime, we need to compile a list of contributors and get ready to ask them to accept the changes.
+ novaflash will pick this up again now that he is back.'
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ 'novaflash will pick this up again now that he is back.'
+
+ - **[OpenVPN Quickstart Guide Update](https://www-dev.openvpn.in/community-resources/openvpn-quickstart/)**
+ 'Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ novaflash will pick this up again now that he is back.'
+
+ - **As discussed in Hackathon, we want to do a PoC with using Gerrit for code review.**
+ 'This requires an environment to be set up and tuned. This is postponed until after 2.6 stable release.'
+
+ - **IPv6 to community.**
+ 'No new information to report.'
\ No newline at end of file
/dev/null .. meetings/2023-01-11.md
@@ 0,0 1,70 @@
+ # Basic info
+
+ - **Time:** Wednesday 11 January 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Can we have someone at OpenVPN create nicer windows traybar logos?** (#1276)
+
+ - **2.6 release plans (for rc2 and 2.6.0 stable)**
+ - Plan is to do an rc2 release on 12th of January
+ - Want to get Lev's patch for config folder migration for GUI in.
+ - Want to try and get Plaisthos's patch for dynamic tls-crypt in
+ - Can we do stable release 2.6.0 in 2 weeks (Jan 26)?
+ - What to do about `SRV`? This probably won't make it in 2.6.0.
+ - What to do about `dynamic tls-crypt`? Going to try to get it into rc2.
+
+ ## OpenVPN 2.6.0 stable release open issues
+
+ - **Blockers (must be fixed before 2.6.0)**
+
+ - **Nice to have**
+ - P2P `--tls-server` still gets confused sometimes when "client just disappears" and no `--keepalive` is configured.
+ - Duplicate route addition / EEXIST with SITNL is not handled correctly (will lead to duplicate route removal).
+ - `route_add()` status code uses 0/1/2 magic numbers, should use MAGIC_CONSTANTS.
+ - `dco.dco_del_peer_reason` etc. should be initialized "upfront" not "after the fact" (see commit aaccf8843).
+ - Engine test failing with openssl 3.0.x **iff** built with engine support (non-default) (this is already merged).
+
+ - **Additional features**
+
+ - **DCO showstoppers (not holding up 2.6.0 release, but a reason to not use DCO in production)**
+ - OOM in netlink on busy servers [Issue #16](https://github.com/OpenVPN/ovpn-dco/issues/16)
+ - OpenVPN hang on "close tun, before restarting" [Issue #18](https://github.com/OpenVPN/ovpn-dco/issues/18)
+ - More issues listed [here](https://github.com/OpenVPN/ovpn-dco/issues)
+
+ - **OpenVPN2 build environment and improving it.**
+ - Djpig is currently working on this. The company has decided to prioritize this task.
+ - Code signing key was moved to an HSM system for increased security.
+ - Djpig overhauled openvpn-build, it now uses submodules for openvpn and openvpn-gui, and contains Debian packaging scripts.
+ - Further improvements to the build process are underway.
+
+ - **OpenVPN 2.6 performance results.**
+ - Now that we have a beta out, and soon an rc1, we want to have an article on the main site and press release about performance results.
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.
+ - Currently waiting for ecrist to test if he has access and all is well before we're able to make the switch.
+ - Ecrist indicated that he is missing some information, Mattock will provide.
+
+ ## Topics on standby
+
+ - **License amendment for OpenVPN2 to accommodate mbedtls.**
+ - Plaisthos made a first draft. Plaisthos asked to get novaflash to ask Francis and James to sign off on it.
+ - In the meantime, we need to compile a list of contributors and get ready to ask them to accept the changes.
+ - Novaflash will pick this up again now that he is back.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up again now that he is back.
+
+ - **[OpenVPN Quickstart](https://www-dev.openvpn.in/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again now that he is back.
+
+ - **As discussed in Hackathon, we want to do a PoC with using Gerrit for code review.**
+ - This requires an environment to be set up and tuned. This is postponed until after the 2.6 stable release.
+
+ - **IPv6 to community.**
+ - No new information to report.
\ No newline at end of file
/dev/null .. meetings/2023-01-18.md
@@ 0,0 1,77 @@
+ # Basic info
+
+ - Time: Wednesday 18 January 2023 at 13:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Can we have someone at OpenVPN create nicer windows traybar logos (#1276)?**
+ "yes, novaflash will check with a designer to see if he can be motivated to generate something."
+
+ - **Press release of 2.6 to go out with stable release**
+ "novaflash will work with openvpn inc folks to prepare something."
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ "plaisthos and novaflash brought this to francis and james. they consent.
+ plaisthos sent proposal to the developer mailing list. response was mostly not seeing the need.
+ but debian obviously does see a problem. we need a lawyer to advise us if there is a problem and if how, how to solve.
+ so it's back to plaisthos and novaflash to contact the specific lawyer and figure this out.
+ main issue is convincing the developers that there is an issue, they currently do not see/understand it."
+
+ - **As discussed in Hackathon we want to do a PoC with using Gerrit for code review.**
+ "openvpn inc is working on setting up a poc for this."
+
+ - **2.6 release plans**
+ "2.6 rc2 went out on January 12th. Intend to do another release on 25th.
+ lev_'s config folder patches made it in.
+ plaisthos' dynamic tls-crypt patches did not. pushed to 2.6.1.
+ what about `SRV`? pushed to 2.6.1
+ Looks like we're going to do a stable 2.6.0 release on January 25th.
+ lev_ wants to slip in some minor changes to driver installation on windows.
+ script-security behavior is different from 2.5 to 2.6 - permissions are less. need to decide on approach to fix. affects only linux."
+
+ ## OpenVPN 2.6.0 stable release open issues
+
+ - **blockers (must be fixed before 2.6.0)**
+
+ - **nice to have**
+ "P2P --tls-server still gets confused sometimes when 'client just disappears' and no `--keepalive` is configured
+ duplicate route addition / EEXIST with SITNL is not handled correctly (will lead to duplicate route removal)
+ route_add() status code uses 0/1/2 magic numbers, should use MAGIC_CONSTANTS
+ dco.dco_del_peer_reason etc. should be initialized 'upfront' not 'after the fact' (see commit aaccf8843)"
+
+ - **additional features**
+ "---?"
+
+ - **DCO showstoppers (not holding up 2.6.0 release, but a reason to not use DCO in production)**
+ "OOM in netlink on busy servers [Issue #16](https://github.com/OpenVPN/ovpn-dco/issues/16)
+ openvpn hang on 'close tun, before restarting' [Issue #18](https://github.com/OpenVPN/ovpn-dco/issues/18)
+ more... [See issues](https://github.com/OpenVPN/ovpn-dco/issues)"
+
+ - **OpenVPN2 build environment and improving it.**
+ "djpig is currently working on this. The company has decided to prioritize this task.
+ Code signing key was moved to an HSM system for increased security.
+ djpig overhauled openvpn-build, it now uses submodules for openvpn and openvpn-gui, and contains debian packaging scripts.
+ Further improvements to the build process are underway."
+
+ - **OpenVPN 2.6 performance results.**
+ "We should work on an article to publish some performance results when 2.6 is out as stable."
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ "mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
+ Currently waiting for ecrist to test if he has access and all is well before we're able to make the switch.
+ ecrist indicated that he is missing some information, mattock will provide."
+
+ ## Topics on standby
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ "novaflash will pick this up again now that he is back."
+
+ - **[OpenVPN Quickstart](https://www-dev.openvpn.in/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ "Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ novaflash will pick this up again now that he is back."
+
+ - **IPv6 to community.**
+ "No new information to report."
\ No newline at end of file
/dev/null .. meetings/2023-01-25.md
@@ 0,0 1,43 @@
+ # Basic info
+
+ - **Time**: Wednesday 25 January 2023 at 13:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Can we have someone at OpenVPN create nicer windows traybar logos (#1276)?**
+ "Yes, Matt is working on it. However, he got spam-blocked by Trac and can't collaborate there for some reason. It was suggested we switch to GitHub issues and continue there. Novaflash and Matt will create a new ticket and continue there."
+
+ - **Press release of 2.6 to go out with stable release**
+ "Going to do a release of 2.6.0 today. It will go up on community.openvpn.net first and then tomorrow with the website release it will be on the main website instead. Novaflash will work on pushing for a press release."
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ "Current status is that Francis and James are on-board, but developers are not understanding the need. Next step is Dazo will contact a known open source lawyer and get motivation/story straight. Currently working on clearing funds for that with OpenVPN Inc."
+
+ - **As discussed in Hackathon, we want to do a PoC with using Gerrit for code review.**
+ "OpenVPN Inc is working on setting up a POC for this."
+
+ - **2.6 release plans**
+ "Going to do a stable release on January 25th. Lev's fixes for Windows driver installation made it in. Also, permissions fix for scripting made it in. Plaisthos' dynamic tls-crypt patches did not. Pushed to 2.6.1. What about `SRV`? Pushed to 2.6.1."
+
+ - **OpenVPN2 build environment and improving it.**
+ "Djpig is currently working on this. The company has decided to prioritize this task. Code signing key was moved to an HSM system for increased security. Djpig overhauled openvpn-build, it now uses submodules for openvpn and openvpn-gui, and contains Debian packaging scripts. Further improvements to the build process are underway."
+
+ - **OpenVPN 2.6 performance results.**
+ "We should work on an article to publish some performance results when 2.6 is out as stable. But first, press release."
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ "Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist. Currently waiting for Ecrist to test if he has access and all is well before we're able to make the switch. Ecrist indicated that he is missing some information, Mattock provided this."
+
+ ## Topics on standby
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ "Novaflash will pick this up again now that he is back."
+
+ - **https://www-dev.openvpn.in/community-resources/openvpn-quickstart/ will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ "Static-key will be deprecated and contents updated with peer-fingerprint stuff. Novaflash will pick this up again now that he is back."
+
+ - **IPv6 to community.**
+ "No new information to report."
\ No newline at end of file
/dev/null .. meetings/2023-02-01.md
@@ 0,0 1,64 @@
+ # Basic info
+
+ - Time: Wednesday 01 February 2023 at 13:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Planning to have a new release of OpenVPN 2.6 around March 8th.**
+
+ - **Can we have someone at OpenVPN create nicer windows traybar logos?**
+ *Yes, Matt is currently working on it in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)*
+
+ - **Press release of 2.6**
+ *In progress*
+
+ - **Review support status for OpenVPN versions. (SupportedVersions document)**
+ *2.4 was not placed in git tree only support mode yet - will do that now. That was an oversight.
+ OpenVPN 2.6 was added and is in support now until undefined.
+ About Windows 7/8/8.1, we'll add some note that people are lucky if it still works, and we still try to keep it working, but we can't offer any real guarantees there anymore.*
+
+ - **Review DCO-for-Linux release status**
+ *Working on making control packets go through transport socket instead of netlink. Easy for UDP, not so easy for TCP.
+ Then next item is TCP notification missing under heavy load bug. Will retest after control channel moved to socket.
+ Will then work on removing the netlink code entirely since it's not in use anymore then.*
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ *Dazo is in contact with open source legal expert, explaining the issues, getting feedback.
+ Our concern about system libraries is definitely warranted - on Linux it may be considered so but not on most other platforms.
+ Main question is, do we have to limit the exception to apply only to cryptographic libraries?
+ Question really being; do we expect it to be abused if we blanket approve all apache2 libraries?*
+
+ - **As discussed in Hackathon we want to do a PoC with using Gerrit for code review.**
+ *The proof of concept is online. Yuriy will provide information on this.
+ Using credentials from community it should now be possible to access it at [Gerrit OpenVPN](https://gerrit.openvpn.net/)*
+
+ - **2.6 release - did we get some feedback, and is any of it vital to respond on?**
+ *Fedora/EPEL world has been silent (good sign). Fedora 38 will ship with 2.6 in native repo.
+ On GitHub there's a lot of windows interesting reports - half are DCO related, half because of crappy configs from VPN providers.
+ Dazo reports that a change is needed to SELinux policies to allow access to netlink, otherwise OpenVPN2 can't use DCO by default with SELinux enabled.
+ Dazo upstreamed a fix but this takes time to distribute. Will in the intermediate period prepare to bundle that particular policy, for Fedora/COPR packages.*
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ *Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
+ Currently waiting for Ecrist to test if he has access and all is well before we're able to make the switch.
+ Ecrist indicated that he is missing some information, Mattock provided this.*
+
+ ## Topics on standby
+
+ - **Have to remember to update SupportedVersions to put 2.4 out of support at around end of March**
+
+ - **OpenVPN 2.6 performance results.**
+ *We should work on an article to publish some performance results when 2.6 is out as stable. But first, press release.*
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ *Novaflash will pick this up again now that he is back.*
+
+ - **[OpenVPN Quickstart](https://www-dev.openvpn.in/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ *Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ Novaflash will pick this up again now that he is back.*
+
+ - **IPv6 to community.**
+ *No new information to report.*
\ No newline at end of file
/dev/null .. meetings/2023-02-08.md
@@ 0,0 1,61 @@
+ # Basic Info
+
+ - **Time:** Wednesday, February 8, 2023, at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ ### Planning New Release of OpenVPN 2.6
+ - Target release date around March 8th.
+
+ ### Press Release of 2.6
+ - In progress, draft made, needs review from some community members.
+ - Suggested to have the draft on cryptpad; novaflash will handle this post-meeting.
+
+ ### Build I005 of 2.6.0 Due to OpenSSL 3 Update?
+ - No urgency observed, doesn't significantly affect OpenVPN2. Reconsideration possible.
+
+ ### Website Release Process Woes
+ - Changes in company website team causing delays.
+ - Proposed solution: repo access for certain community members to push updates, with automatic system for regular publishing.
+
+ ### Review DCO-for-Linux Release Status
+ - Efforts to make control packets go through the transport socket.
+ - TCP notification issues under heavy load to be retested after control channel improvements.
+
+ ### License Amendment for OpenVPN2
+ - Necessary exception addition confirmed by legal expert.
+ - Draft refined, pending community approval.
+
+ ### Status of PoC Using Gerrit for Code Review
+ - Proof of concept online, aiming to replace patchwork and streamline reviews.
+ - D12fk and uddr collaborating on integrating email list patches into Gerrit.
+
+ ### Feedback on 2.6 Release
+ - Addressed boot failure issue on specific computer models.
+ - Intermediate solution for SELinux policy by packaging for Fedora/Copr, pending wider distribution.
+
+ ## Topics on Standby
+
+ ### Forums Machine on Community Infrastructure
+ - New forums system on Rocky Linux 8, pending approval from ecrist.
+
+ ### Windows Traybar Logos
+ - Ongoing work by Matt, tracked on [GitHub issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595).
+
+ ### Updating Supported Versions
+ - Plan to mark version 2.4 as out of support by end of March.
+
+ ### OpenVPN 2.6 Performance Results
+ - Consider publishing performance results post stable release of 2.6, after press release.
+
+ ### Management Interface Documentation Update
+ - Update planned with info from `doc/management-notes.txt`.
+
+ ### Quickstart Guide Update on Community Website
+ - Update to reflect deprecation of static-key and inclusion of peer-fingerprint info.
+
+ ### IPv6 to Community
+ - No new updates.
\ No newline at end of file
/dev/null .. meetings/2023-02-15.md
@@ 0,0 1,67 @@
+ # Basic Info
+
+ - **Time:** Wednesday 15 February 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **Planning to have a new release of OpenVPN 2.6 around March 8th.**
+
+ - **2.6 Release - Any New Feedback, Anything Vital?**
+ - A DCO with BSOD on systems with legacy standby modes, Lev reproduced and fixed it.
+ - Azure VPN gateway has their own implementation of OpenVPN that is incompatible with 2.6.
+ Lev contacted them and offered to help to find and resolve the problem.
+ - We should prepare an I005 release today and get that pushed out.
+
+ - **License Amendment for OpenVPN2 to Solve openssl/mbedtls Licensing Issues**
+ - Current status is that we know for sure from a legal expert that an exception addition is necessary.
+ - A refined and lawyer-approved proposal is ready to be sent to the mailing list.
+
+ - **Hackathon Blog Post on OpenVPN Website is Ready**
+ - This is about the hackathon in Delft in November.
+ - Community review is requested - if it's good to go it will be published.
+
+ - **Press Release of 2.6**
+ - In progress. A draft was made and edited by the community quite a bit.
+ - It will now go to the OpenVPN marketing team for polishing and publishing.
+
+ - **Review DCO-for-Linux Release Status**
+ - Working on making control packets go through transport socket instead of netlink. Easy for UDP, not so easy for TCP.
+ - Looks like Ordex will have this change ready for the upcoming 2.6.1 release. We'll rename the DCO module to ovpn-dco2 then.
+ - Next item is TCP notification missing under heavy load bug. Will retest after control channel moved to socket.
+
+ - **Status of PoC Using Gerrit for Code Review**
+ - Gerrit proof of concept is online.
+ - Goal seems to have settled on - we want to keep existing mailing list since not everyone will be using Gerrit. But Gerrit will add easier review abilities.
+ - So Gerrit has to send emails to mailing list, pick up patches from mailing list, and review responses to emails sent to mailing list should feed also into Gerrit.
+ - Uddr will set up a PoC with a dummy repo so we can start testing out some email functionality of Gerrit.
+
+ - **Website Release Process Woes**
+ - Work started on an API to allow updates at any time on the main website for the community downloads section.
+
+ ## Topics on Standby
+
+ - **Forums Machine on Community Infrastructure is Only Non-Linux System**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
+ - There was some trouble with him getting credentials but that should be resolved now.
+ - Last known status is that it is waiting for approval from Ecrist.
+
+ - **Can We Have Someone at OpenVPN Create Nicer Windows Traybar Logos (#1276)?**
+ - Yes, Matt is currently working on it in [GitHub Issue 595](https://github.com/OpenVPN/openvpn-gui/issues/595).
+
+ - **Have to Remember to Update SupportedVersions to Put 2.4 Out of Support at Around End of March**
+
+ - **OpenVPN 2.6 Performance Results**
+ - We should work on an article to publish some performance results when 2.6 is out as stable, but first press release.
+
+ - **Management Interface Documentation on Main Website Will Be Updated with Info from doc/management-notes.txt**
+ - Novaflash will pick this up again now that he is back.
+
+ - **[OpenVPN Quickstart](https://www-dev.openvpn.in/community-resources/openvpn-quickstart/) Will Be Updated from /doc/man-sections/example-fingerprint.rst Information**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again now that he is back.
+
+ - **IPv6 to Community**
+ - No new information to report.
\ No newline at end of file
/dev/null .. meetings/2023-02-22.md
@@ 0,0 1,56 @@
+ # Basic info
+
+ - **Time:** Wednesday, 22 February 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** `#openvpn-meeting` channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ ### Planning to have a new release of OpenVPN 2.6 around March 8th
+
+ ### 2.6 release - any new feedback, anything vital?
+ "Azure VPN Gateway has their own implementation of OpenVPN that is incompatible with 2.6. We contacted them and offered our help."
+
+ ### New --dns directive - when to publish that. Can it go in 2.6.1?
+ d12fk is working on the new --dns directives and has gotten pretty far. He's now in the jungle of edge cases and corner cases. The question is, can this be added to 2.6.1, or should it wait until 2.7 or such? It seems the consensus is that new features can be added to 2.6.1 and maybe even 2.6.2. Dynamic tls-crypt, for example, is also going into 2.6.1.
+
+ ### License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues
+ "A refined and approved by legal expert proposal for a license amendment was sent to the mailing list. No reactions yet. We will have to contact the contributors one by one."
+
+ ### Hackathon blog post on OpenVPN website is done
+ This is published at [OpenVPN Hackathon 2022 Blog](https://openvpn.net/blog/hackathon-2022/).
+
+ ### Press release of 2.6
+ The community rewrote the draft. This draft was further refined by the community and sent to the team for publishing. There was confusion about what actually a press release is. From the community point of view, we just want the blog post, and that draft is done and sent for publishing. We don't need a paid press release with hyperbolic language to entice other journalists to write about it.
+
+ ### Review DCO-for-Linux release status
+ Ordex submitted code for testing and review that focuses on handling the data channel in DCO and let the control channel be handled by user space. It looks like this change will be ready for the upcoming 2.6.1 release. Then, we'll rename the DCO module to ovpn-dco-v2. The next item is the TCP notification missing under heavy load bug. Will retest after this change.
+
+ ### Status of PoC using Gerrit for code review
+ The Gerrit proof of concept is online. Ordex and uddr are trying it out together, inviting others to join in testing.
+
+ ### Website release process woes
+ For the community downloads section, some method is being worked on to provide fast update capability. The website team promised 'before end of the month'.
+
+ ## Topics on standby
+
+ ### Can we have someone at OpenVPN create nicer Windows traybar logos (#1276)?
+ "Yes, Matt is currently working on it in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)."
+
+ ### Forums machine on community infrastructure is only non-Linux system.
+ Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist. Ecrist has looked at it, but the current state of the migration is unknown.
+
+ ### Have to remember to update SupportedVersions to put 2.4 out of support at around the end of March
+
+ ### OpenVPN 2.6 performance results
+ "We should work on an article to publish some performance results when 2.6 is out as stable. But first, the press release."
+
+ ### Management interface documentation on the main website will be updated with info from doc/management-notes.txt
+ Novaflash will pick this up again now that he is back.
+
+ ### [OpenVPN Quickstart](https://www-dev.openvpn.in/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.
+ Static-key will be deprecated and contents updated with peer-fingerprint stuff. Novaflash will pick this up again as time permits and other more important topics are done.
+
+ ### IPv6 to community
+ No new information to report.
\ No newline at end of file
/dev/null .. meetings/2023-03-01.md
@@ 0,0 1,73 @@
+ # Basic info
+
+ - Time: Wednesday 01 March 2023 at 13:00 CET (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Planning to have OpenVPN 2.6.1 around March 8th.**
+
+ - **2.6.1 planning**
+ - Are there any items still in progress intended for 2.6.1 release? Yes.
+ - Will the DCO control channel changes be done? Depends if it can pass tests on time.
+ - Will --dns directive be ready? Maybe, depends on how fast review/test/merge goes.
+ - Is dynamic tls-crypt ready? It's just waiting to be merged.
+ - plaisthos says compression patch dco + compression should go into 2.6.1.
+
+ - **DCO topics**
+ - In theory, DCO control changes should go out with 2.6.1.
+ - With 2.6.1 release, DCO module will be renamed to ovpn-dco-v2.
+ - TCP notification missing under heavy load bug - this is resolved now.
+ - Any other DCO topics?
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - A refined and approved by legal expert proposal for a license amendment was sent to the mailing list.
+ - No reactions yet. We will have to contact the contributors one by one.
+ - dazo is working on this. maxf reports an okay to the license amendment.
+
+ - **Press release of 2.6**
+ - Currently waiting for the release of a blog post by the community on the main website regarding the 2.6 release. Expected this week.
+ - OpenVPN Inc also wants to do their own real press release, it will probably be full of hyperbole.
+ - novaflash has been 'volunteered' for a quote. Lovely.
+
+ - **Status of PoC using Gerrit for code review.**
+ - Gerrit proof of concept is online.
+ - ordex, uddr, df12k, plaisthos, are trying it out together, inviting others to join in testing.
+ - Any blockers/issues/suggestions?
+ - Basically, so far so good.
+
+ - **Website release process woes**
+ - For the community downloads section, some method is being worked on to provide fast update capability. The website team promised 'before end of month' February.
+ - Haven't seen anything yet, novaflash will check internally for an update.
+
+ - **2.7 plans, if any?**
+ - I know, very early. Are there any features that we have in mind that will not make it into 2.6.*?
+ - Signal handling respin.
+ - Take everything apart and rebuild, 2.6 is made of duct tape.
+ - Bloom filter DDoS reflection protection.
+
+ ## Topics on standby
+
+ - **Can we have someone at OpenVPN create nicer windows traybar logos (#1276)?**
+ - Yes, matt is currently working on it in https://github.com/OpenVPN/openvpn-gui/issues/595
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
+ - ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Have to remember to update SupportedVersions to put 2.4 out of support at around end of March**
+
+ - **OpenVPN 2.6 performance results.**
+ - We should work on an article to publish some performance results when 2.6 is out as stable, but first press release.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - novaflash will pick this up again now that he is back.
+
+ - **https://www-dev.openvpn.in/community-resources/openvpn-quickstart/ will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - novaflash will pick this up again as time permits and other more important topics are done.
+
+ - **IPv6 to community.**
+ - No new information to report.
\ No newline at end of file
/dev/null .. meetings/2023-03-08.md
@@ 0,0 1,68 @@
+ # Basic Info
+
+ - **Time**: Wednesday 08 March 2023 at 13:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **Release planning for 2.6.1 (planned today)**
+ - Are we good to do a 2.6.1 release?
+ - Status on DCO? Currently has issues to resolve still.
+ - Status on `--dns` directive? Not fully ready but DNS option changes d12fk would like to have in.
+ - Status on dynamic tls-crypt? This made it in.
+ - Status on DCO + compression patch? Some discussion still ongoing here.
+ - Plan for now is to release 2.6.1 today and plan a 2.6.2 for next week or the week after with at the very least the DCO changes in there but ideally also the DNS and compression patch.
+ - We need to remember to ask Debian maintainer then to pick up 2.6.2.
+
+ - **SBOM Topic**
+ - Cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ - **License amendment for OpenVPN2 to solve OpenSSL/mbedTLS licensing issues**
+ - A refined and approved by legal expert proposal for a license amendment was sent to the mailing list.
+ - Developers will be contacted individually by plaisthos and dazo to try and get approvals.
+
+ - **Press Release of 2.6**
+ - Still waiting on blog post release - now planned for this week.
+
+ - **Status of PoC using Gerrit for code review**
+ - Gerrit proof of concept is online.
+ - Ordex, uddr, df12k, plaisthos, are trying it out together, inviting others to join in testing.
+ - Any blockers/issues/suggestions?
+ - Basically, so far so good.
+
+ - **Website release process woes**
+ - Website team did not deliver solution as promised in February. They now promise this month. We shall see.
+
+ ## Topics on Standby
+
+ - **2.7 Plans, if any?**
+ - Are there any features that we have in mind that will not make it into 2.6.*?
+ - Signal handling respin.
+ - Take everything apart and rebuild, 2.6 is made of duct tape.
+ - Bloom filter DDoS reflection protection.
+
+ - **Can we have someone at OpenVPN create nicer Windows traybar logos (#1276)?**
+ - Yes, Matt is currently working on it in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+
+ - **Forums machine on community infrastructure is only non-Linux system**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Have to remember to update SupportedVersions to put 2.4 out of support around end of March**
+
+ - **OpenVPN 2.6 performance results**
+ - We should work on an article to publish some performance results when 2.6 is out as stable. But first, press release.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up again now that he is back.
+
+ - **[OpenVPN Quickstart](https://www-dev.openvpn.in/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
+
+ - **IPv6 to community**
+ - No new information to report.
\ No newline at end of file
/dev/null .. meetings/2023-03-15.md
@@ 0,0 1,82 @@
+ # Basic info
+
+ - **Time**: Wednesday 15 March 2023 at 13:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Release of 2.6.1 was done last week**
+ - We released last week, but it seems there was no forum post. Novaflash quickly added one, but there is Copr/Fedora stuff missing.
+ - The forum post seems to also be not at the top - no permissions to change this?
+ - We also forgot to send out an email.
+
+ - **Release planning for 2.6.2 - planned for 22 March**
+ - In last week's meeting, it was suggested to do some small quick releases in the short term.
+ - How are things looking for a 2.6.2?
+ - Items that didn't make it into 2.6.1:
+ - DNS directive.
+ - DCO control channel switch (DCO 0.2xx).
+ - DCO + compression patch.
+ - We should also add in the fix for auth-pending.
+ - And add in --inactive support for DCO.
+ - And PKCS11-helper bugfix.
+ - And a memory leak fix.
+ - Have to remember to ask Debian maintainer to pick up a version of OpenVPN 2.6.x that includes the DCO control channel switch.
+
+ - **License amendment for OpenVPN2 to solve OpenSSL/mbedTLS licensing issues**
+ - In discussion with the legal expert, it was thought to be a good idea to send in the license change as a PR.
+ - This obviously won't just go in so easily until we have all the necessary approvals, but it was thought a good way to give it some attention.
+ - A next step would be to reach out to individual developers to get approvals.
+
+ - **Blog post for OpenVPN 2.6 release on main site**
+ - This is here: [OpenVPN 2.6 Blog Post](https://openvpn.net/blog/openvpn-2-6)
+ - A real press release by OpenVPN Inc. is also coming this week.
+
+ - **Status of PoC using Gerrit for code review.**
+ - For authentication, we've decided to:
+ - Not accept anonymous submissions.
+ - Do authentication via LDAP now.
+ - Add GitHub later as an extra.
+ - Uddr will write a document that describes the future workflow for company and community people.
+ - To be reviewed in 2 weeks from now.
+
+ - **Can we have someone at OpenVPN create nicer Windows traybar logos (#1276)?**
+ - Yes, Matt is currently working on it in [GitHub Issue 595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Should we perhaps accept the current icon set and set up another ticket to go through another set of improvements? This seems to be what Selva suggested.
+
+ ## Topics on standby
+
+ - **Website release process woes**
+ - Website team did not deliver solution as promised in February. They now promise this month. We shall see.
+
+ - **SBOM topic**
+ - Cron2 was asked if OpenVPN has a Software Bill of Materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task, we can coordinate on it.
+
+ - **2.7 plans, if any?**
+ - Are there any features that we have in mind that will not make it into 2.6.*?
+ - Signal handling respin.
+ - Take everything apart and rebuild, 2.6 is made of duct tape.
+ - Bloom filter DDoS reflection protection.
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Have to remember to update SupportedVersions to put 2.4 out of support at around end of March**
+
+ - **OpenVPN 2.6 performance results.**
+ - We should work on an article to publish some performance results when 2.6 is out as stable, but first press release.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up again now that he is back.
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
+
+ - **IPv6 to community.**
+ - No new information to report.
\ No newline at end of file
/dev/null .. meetings/2023-03-22.md
@@ 0,0 1,66 @@
+ # Basic Info
+
+ - **Time:** Wednesday 22 March 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **Release planning for 2.6.2 - planned for 23 March**
+ - Items that didn't make it into 2.6.1:
+ - DNS directive needs some acks.
+ - DCO control channel switch (dco 0.2xx) is done.
+ - DCO + compression patch needs acks.
+ - Auth-pending control channel issue is done.
+ - Add in -inactive support for DCO is done.
+ - Memory leak fix is done.
+ - PKCS11-helper bugfix is done.
+ - Have to remember to ask Debian maintainer to pick up a version of OpenVPN 2.6.x that includes the DCO control channel switch!
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - Current status is that individual contributors are being contacted, and approvals gathered.
+
+ - **Status of PoC using Gerrit for code review.**
+ - There's a workflow proposal [here](https://community.openvpn.net/openvpn/wiki/Proposed%20Gerrit%20Workflow).
+ - It was agreed to review this next week.
+
+ - **Can we have someone at OpenVPN create nicer windows traybar logos (#1276)?**
+ - Matt is currently working on it in [GitHub OpenVPN-GUI issues](https://github.com/OpenVPN/openvpn-gui/issues/595).
+ - Selva had some comments about the icons, Matt has been pinged to look into it.
+
+ - **IPv6 to community.**
+ - Cloudflare IPv6 compatibility is turned off on openvpn.net because the company is worried it might break something.
+ - Ultimatum from community: Give us a date when IPv6 will be turned on, or we move to another domain.
+
+ ## Topics on Standby
+
+ - **Website release process woes**
+ - The website team did not deliver solution as promised in February. They now promise this month. We shall see.
+
+ - **SBOM Topic**
+ - Cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ - **2.7 Plans, if any?**
+ - Are there any features that we have in mind that will not make it into 2.6.*?
+ - Signal handling respin.
+ - 2.6 refactor.
+ - Bloom filter DDoS reflection protection.
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Have to remember to update SupportedVersions to put 2.4 out of support at around end of March.**
+
+ - **OpenVPN 2.6 Performance Results.**
+ - We should work on an article to publish some performance results when 2.6 is out as stable, but first, a press release.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up again now that he is back.
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-03-29.md
@@ 0,0 1,71 @@
+ # Basic info
+
+ - **Time**: Wednesday 29 March 2023 at 13:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ ### Release planning for 2.6.3 - tentatively April 12
+ - We have a crash bug in 2.6.2 that affects Linux users that use DCO and NetworkManager ("sometimes").
+
+ ### When going back to normal operating mode?
+ - New features and refactors in master,
+ - Bugfixes to master + release/2.6,
+ - Serious bugfixes also ported to 2.5.
+ - This would hit the selva pkcs11 unit test series first.
+
+ ### Status of PoC using Gerrit for code review
+ - There's a workflow proposal here: [Proposed Gerrit Workflow](https://community.openvpn.net/openvpn/wiki/Proposed%20Gerrit%20Workflow)
+ - It was agreed to review workflow this week.
+ - Want to have something like this appear on the mailing list:
+ - Initial patch notification mail, daily digest mail, final patch+discussion+who acked mail.
+
+ ### Security assessment of OpenVPN2 codebase
+ - Need to review security assessment, see if we are in agreement about it.
+ - Dazo will reach out to cron2 about this to gather his feedback.
+
+ ### IPv6 to community
+ - Cloudflare IPv6 compatibility is turned off on openvpn.net because the company is worried it might break something.
+ - Community wants a date when this is resolved.
+ - Novaflash working to get a date that the company will commit to.
+ - Informally head of ops sees it as being turned on in 'about a month', but will work to get a date we can hold him to.
+
+ ## Topics on standby
+
+ ### License amendment for OpenVPN2 to solve OpenSSL/mbedTLS licensing issues
+ - Current status is that individual contributors are being contacted, and approvals gathered.
+
+ ### Can we have someone at OpenVPN create nicer Windows traybar logos (#1276)?
+ - Matt is currently working on it in [this GitHub issue](https://github.com/OpenVPN/openvpn-gui/issues/595).
+
+ ### Website release process woes
+ - Website team did not deliver solution as promised in February. They now promise this month. We shall see.
+
+ ### SBOM topic
+ - Cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ ### 2.7 plans, if any?
+ - Are there any features that we have in mind that will not make it into 2.6.*?
+ - Signal handling respin,
+ - 2.6 refactor,
+ - Bloom filter DDoS reflection protection.
+
+ ### Forums machine on community infrastructure is only non-Linux system
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ ### Have to remember to update SupportedVersions to put 2.4 out of support at around end of March
+
+ ### OpenVPN 2.6 performance results
+ - We should work on an article to publish some performance results when 2.6 is out as stable, but first press release.
+
+ ### Management interface documentation on main website will be updated with info from doc/management-notes.txt
+ - Novaflash will pick this up again now that he is back.
+
+ ### [OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-04-12.md
@@ 0,0 1,58 @@
+ # Basic Info
+
+ - **Time**: Wednesday 12 April 2023 at 13:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **Release Planning for 2.6.3 - April 13**
+ _"We have a crash bug in 2.6.2 that affects Linux users that use DCO and NetworkManager ('sometimes')."_
+
+ - **When Going Back to Normal Operating Mode?**
+ _"New features and refactors in master, bugfixes to master + release/2.6, serious bugfixes also ported to 2.5. This would hit the selva pkcs11 unit test series first."_
+
+ - **Status of PoC Using Gerrit for Code Review**
+ _"There's a workflow proposal here: [Proposed Gerrit Workflow](https://community.openvpn.net/openvpn/wiki/Proposed%20Gerrit%20Workflow). This was reviewed 2 weeks ago. Want to have something like this appear on the mailing list: initial patch notification mail, daily digest mail, final patch+discussion+who acked mail."_
+
+ - **Security Assessment of OpenVPN2 Codebase**
+ _"Need to review security assessment, see if we are in agreement about it. Dazo will reach out to cron2 about this to gather his feedback."_
+
+ - **IPv6 to Community**
+ _"Cloudflare IPv6 compatibility is turned off on openvpn.net because the company is worried it might break something. Community wants date when this is resolved. Novaflash working to get a date that the company will commit to. Informally head of ops sees it as being turned on in 'about a month'. But will work to get a date we can hold him to."_
+
+ - **security@openvpn.net Mailing List**
+ _"Company is trying to get to SOC2 compliance. Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net. This seems reasonable, company will investigate and prepare such a thing."_
+
+ - **Update SupportedVersions to Put 2.4 Out of Support at Around End of March**
+ _"Yeah, we'll update this."_
+
+ - **License Amendment for OpenVPN2 to Solve openssl/mbedtls Licensing Issues**
+ _"Current status is that individual contributors are being contacted, and approvals gathered."_
+
+ ## Topics on Standby
+
+ - **Can We Have Someone at OpenVPN Create Nicer Windows Traybar Logos (#1276)?**
+ _"Matt is currently working on it in https://github.com/OpenVPN/openvpn-gui/issues/595"_
+
+ - **Website Release Process Woes**
+ _"Website team did not deliver solution as promised in February, then March. Still not delivered. Now they promise April. We will see."_
+
+ - **SBOM Topic**
+ _"Cron2 was asked if OpenVPN has a software bill of materials. Answer was no. Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do. When we pick up this task we can coordinate on it."_
+
+ - **2.7 Plans, If Any?**
+ _"Are there any features that we have in mind that will not make it into 2.6.*? Signal handling respin, 2.6 refactor, bloom filter DDoS reflection protection."_
+
+ - **Forums Machine on Community Infrastructure is Only Non-Linux System.**
+ _"Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist. Ecrist has looked at it but the current state of the migration is unknown."_
+
+ - **OpenVPN 2.6 Performance Results.**
+ _"We should work on an article to publish some performance results when 2.6 is out as stable. But first press release."_
+
+ - **Management Interface Documentation on Main Website Will Be Updated with Info from doc/management-notes.txt**
+ _"Novaflash will pick this up again now that he is back."_
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) Will Be Updated from /doc/man-sections/example-fingerprint.rst Information.**
+ _"Static-key will be deprecated and contents updated with peer-fingerprint stuff. Novaflash will pick this up again as time permits and other more important topics are done."_
\ No newline at end of file
/dev/null .. meetings/2023-04-19.md
@@ 0,0 1,82 @@
+ # Basic Info
+
+ - **Time:** Wednesday 19 April 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ ### OpenVPN 2.6.3
+ - This was released on April 13.
+ - Djpig noticed an issue with the GPG signing key.
+ - Accidentally used recently revoked key instead of new key from recent key rotation.
+ - Also, apparently the latest Debian release's GPG does not like SHA1 anymore.
+
+ ### When Going Back to Normal Operating Mode?
+ - New features and refactors in master,
+ - Bugfixes to master + release/2.6,
+ - Serious bugfixes also ported to 2.5
+ - This would hit the Selva PKCS11 unit test series first.
+
+ ### Status of PoC Using Gerrit for Code Review
+ - There's a workflow proposal here: [Proposed Gerrit Workflow](https://community.openvpn.net/openvpn/wiki/Proposed%20Gerrit%20Workflow)
+ - This was reviewed 3 weeks ago.
+ - Want to have something like this appear on the mailing list:
+ - Initial patch notification mail, daily digest mail, final patch+discussion+who acked mail.
+ - Anything new on this topic?
+
+ ### Security Assessment of OpenVPN2 Codebase
+ - What is the current status?
+ - There are 2 items not directly related to the codebase that we're arguing against putting into the report.
+ - They're both 'informational' level so not particularly worrisome, but in our opinion weird to have in the report.
+ - Dazo will send an updated version to Cron2 for review.
+
+ ### IPv6 to Community
+ - Cloudflare IPv6 compatibility is turned off on openvpn.net because the company is worried it might break something.
+ - Community wants a date when this is resolved.
+ - Novaflash working to get a date that the company will commit to.
+ - Expect to have a date when IPv6 is turned on globally on openvpn.net this week.
+
+ ## Topics on Standby
+
+ ### License Amendment for OpenVPN2 to Solve OpenSSL/MbedTLS Licensing Issues
+ - Current status is that individual contributors are being contacted, and approvals gathered.
+
+ ### Security@openvpn.net Mailing List
+ - Company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net.
+ - This seems reasonable, the company will investigate and prepare such a thing.
+
+ ### Can We Have Someone at OpenVPN Create Nicer Windows Traybar Logos (Issue #1276)?
+ - Matt is currently working on it at [OpenVPN-GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595).
+
+ ### Website Release Process Woes
+ - The website team did not deliver the solution as promised in February, then March, and it's still not delivered. Now they promise April. We will see.
+
+ ### SBOM Topic
+ - Cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ ### 2.7 Plans, if Any?
+ - Are there any features that we have in mind that will not make it into 2.6.*?
+ - Signal handling respin
+ - 2.6 refactor
+ - Bloom filter DDoS reflection protection.
+
+ ### Forums Machine on Community Infrastructure is Only Non-Linux System
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ ### OpenVPN 2.6 Performance Results
+ - We should work on an article to publish some performance results when 2.6 is out as stable. But first, the press release.
+
+ ### Management Interface Documentation on Main Website Will Be Updated
+ - Information from `doc/management-notes.txt` will be updated.
+ - Novaflash will pick this up again now that he is back.
+
+ ### [OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) Will Be Updated
+ - From `/doc/man-sections/example-fingerprint.rst` information.
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-04-26.md
@@ 0,0 1,79 @@
+ # Basic Info
+
+ - **Time:** Wednesday 26 April 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **PGP Signing Key for OpenVPN Releases:**
+ - djpig noticed an issue with the gpg signing key.
+ - Accidentally used recently revoked key instead of new key from recent key rotation.
+ - Also, the latest Debian release's gpg does not like sha1 anymore.
+
+ - **2.6.3 Build 2 Release:**
+ - Have some minor updates to release, so will do a build #2 and get that out today or tomorrow.
+
+ - **2.6.4 Release Plans:**
+ - Tentatively May 11.
+
+ - **Hackathon Arrangements:**
+ - End of September, beginning of October.
+ - Topics?
+
+ - **2.7 Plans, if any?**
+ - [Status of OpenVPN 2.7](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn27)
+
+ - **We are now back on normal operating mode, meaning:**
+ - New features and refactors in master,
+ - Bugfixes to master + release/2.6,
+ - Serious bugfixes also ported to 2.5.
+ - This would hit the selva pkcs11 unit test series first.
+
+ - **Status of PoC Using Gerrit for Code Review:**
+ - Last item discussed was buildbot and Gerrit interaction not working due to an SSL issue - when cron2 has time he'll take a look.
+
+ - **Security Assessment of OpenVPN2 Codebase:**
+ - There are 2 items not directly related to the codebase that we're arguing against putting into the report.
+ - They're both 'informational' level so not particularly worrisome, but in our opinion, weird to have in the report.
+ - Dazo will send an updated version to cron2 for review.
+
+ - **IPv6 to Community:**
+ - IPv6 is now enabled on openvpn.net.
+ - community.openvpn.net is now available on IPv4 and IPv6, both behind Cloudflare still though.
+
+ ## Topics on Standby
+
+ - **License Amendment for OpenVPN2 to Solve OpenSSL/mbedTLS Licensing Issues:**
+ - Current status is that individual contributors are being contacted, and approvals gathered.
+
+ - **security@openvpn.net Mailing List:**
+ - Company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net.
+ - This seems reasonable, company will investigate and prepare such a thing.
+
+ - **Can We Have Someone at OpenVPN Create Nicer Windows Traybar Logos (#1276)?**
+ - Matt is currently working on it in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+
+ - **Website Release Process Woes:**
+ - Website team did not deliver solution as promised in February. Then March. Still not delivered. Now they promise April. We will see.
+
+ - **SBOM Topic:**
+ - Cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ - **Forums Machine on Community Infrastructure is Only Non-Linux System:**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ - **OpenVPN 2.6 Performance Results:**
+ - We should work on an article to publish some performance results when 2.6 is out as stable. But first, press release.
+
+ - **Management Interface Documentation on Main Website will be Updated with Info from doc/management-notes.txt:**
+ - Novaflash will pick this up again now that he is back.
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be Updated from /doc/man-sections/example-fingerprint.rst Information:**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-05-03.md
@@ 0,0 1,72 @@
+ # Basic info
+
+ - **Time**: Wednesday 3 May 2023 at 13:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **PGP signing key for OpenVPN releases**
+ djpig noticed an issue with the gpg signing key.
+ accidentally used recently revoked key instead of new key from recent key rotation.
+ also apparently latest debian release's gpg does not like sha1 anymore.
+
+ - **2.6.4 release plans**
+ tentatively may 11
+
+ - **Hackathon arrangements**
+ end of september, begin of october.
+ location? topics?
+
+ - **2.7 plans, if any?**
+ [Status of OpenVPN 2.7](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn27)
+
+ - **Status of PoC using Gerrit for code review.**
+ last item discussed was buildbot and gerrit interaction not working due to an ssl issue - when cron2 has time he'll take a look.
+
+ - **Security assessment of OpenVPN2 codebase.**
+ there will be a meeting with security assessor tomorrow.
+
+ - **security@openvpn.net mailing list**
+ company is trying to get to soc2 compliance.
+ probably will need a simple nda to be signed by recipients of emails to security@openvpn.net
+ company guy took standard nda we use for contractors, suggests to use that.
+ novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ current status is approx 100 approvals, 20 relevant ones missing.
+ current status: [OpenVPN License Change](https://github.com/OpenVPN/openvpn-license-change)
+
+ ## Topics on standby
+
+ - **We are now back on normal operating mode, meaning:**
+ new features and refactors in master,
+ bugfixes to master + release/2.6,
+ serious bugfixes also ported to 2.5
+ this would hit the selva pkcs11 unit test series first
+
+ - **Can we have someone at OpenVPN create nicer windows traybar logos (#1276)?**
+ matt is currently working on it in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+
+ - **Website release process woes**
+ website team did not deliver solution as promised in february. then march. still not delivered. now they promise april. we will see.
+
+ - **SBOM topic**
+ cron2 was asked if openvpn has a software bill of materials. answer was no.
+ coincidentally, in openvpn inc a security requirement is to have an SBOM so this is on our list of things to do
+ when we pick up this task we can coordinate on it.
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
+ ecrist has looked at it but the current state of the migration is unknown.
+
+ - **OpenVPN 2.6 performance results.**
+ We should work on an article to publish some performance results when 2.6 is out as stable. but first press release.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ novaflash will pick this up at some point
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-05-10.md
@@ 0,0 1,72 @@
+ # Basic info
+
+ - **Time**: Wednesday 10 May 2023 at 13:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **PGP signing key for OpenVPN releases**
+ 'djpig noticed an issue with the gpg signing key.
+ accidentally used recently revoked key instead of new key from recent key rotation.
+ also apparently latest debian release's gpg does not like sha1 anymore.'
+
+ - **Another key signing topic**
+ 'company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ also no high priority at the moment, we have a working solution now.'
+
+ - **2.6.4 release plans**
+ 'tentatively may 11'
+
+ - **Hackathon arrangements**
+ 'end of september, begin of october.
+ location? something valencia. topics?'
+
+ - **2.7 plans, if any?**
+ '[Status of OpenVPN 2.7](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn27)'
+
+ - **Status of PoC using Gerrit for code review.**
+ 'last item discussed was buildbot and gerrit interaction not working due to an ssl issue - when cron2 has time he'll take a look.'
+
+ - **Security assessment of OpenVPN2 codebase.**
+ 'what was result of last week's meeting?'
+
+ - **security@openvpn.net mailing list**
+ 'company is trying to get to soc2 compliance.
+ probably will need a simple nda to be signed by recipients of emails to security@openvpn.net
+ company guy took standard nda we use for contractors, suggests to use that.
+ novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.'
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ 'current status is approx 105 approvals, 13 somewhat relevant ones missing.
+ current status: [OpenVPN License Change](https://github.com/OpenVPN/openvpn-license-change)'
+
+ - **Website release process woes**
+ 'website team claims their solution is 95% done. we'll see.'
+
+ ## Topics on standby
+
+ - **Can we have someone at OpenVPN create nicer windows traybar logos (#1276)?**
+ 'matt is currently working on it in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)'
+
+ - **SBOM topic**
+ 'cron2 was asked if openvpn has a software bill of materials. answer was no.
+ coincidentally, in openvpn inc a security requirement is to have an SBOM so this is on our list of things to do
+ when we pick up this task we can coordinate on it.'
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ 'mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
+ ecrist has looked at it but the current state of the migration is unknown.'
+
+ - **OpenVPN 2.6 performance results.**
+ 'We should work on an article to publish some performance results when 2.6 is out as stable. but first press release.'
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ 'novaflash will pick this up at some point'
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ 'Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ novaflash will pick this up again as time permits and other more important topics are done.'
\ No newline at end of file
/dev/null .. meetings/2023-05-17.md
@@ 0,0 1,75 @@
+ # Basic Info
+
+ - **Time**: Wednesday 17 May 2023 at 13:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on [LiberaChat](https://libera.chat/) IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **2.6.5 Release Plans**
+ - "in about 4 to 8 weeks from now so anywhere between half June and half July"
+
+ - **Hackathon Arrangements**
+ - When: [Schedule](https://nuudel.digitalcourage.de/t1hjepaHGhdpiV2P)
+ - Location: Torrevieja.
+ - Topics: Yes.
+
+ - **2.7 Plans, if Any?**
+ - [Status of OpenVPN 2.7](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn27)
+
+ - **PGP Signing Key for OpenVPN Releases**
+ - djpig noticed an issue with the GPG signing key.
+ - Accidentally used a recently revoked key instead of the new key from a recent key rotation.
+ - Also, the latest Debian release's GPG does not like SHA-1 anymore.
+
+ - **Status of PoC Using Gerrit for Code Review**
+ - cron2 took a look, hopefully it will be working now.
+
+ - **Security Assessment of OpenVPN2 Codebase**
+ - What was the result of last week's meeting?
+
+ - **security@openvpn.net Mailing List**
+ - The company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net.
+ - Company guy took the standard NDA we use for contractors, suggests using that.
+ - novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ - **License Amendment for OpenVPN2 to Solve OpenSSL/mbedTLS Licensing Issues**
+ - Current status: [GitHub License Change](https://github.com/OpenVPN/openvpn-license-change)
+ - The next step for us is to put in extra effort to try and reach those people that didn't respond or we couldn't reach yet.
+
+ - **Website Release Process Woes**
+ - The website team claims their solution is 95% done. We'll see.
+
+ ## Topics on Standby
+
+ - **Another Key Signing Topic**
+ - The company switched EV code signing to CloudHSM, which is the same cert type used for driver signing and is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key to save having to maintain two different keys.
+ - Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
+
+ - **Can We Have Someone at OpenVPN Create Nicer Windows Traybar Logos?**
+ - Matt is currently working on it in [GitHub Issue 595](https://github.com/OpenVPN/openvpn-gui/issues/595).
+
+ - **SBOM Topic**
+ - cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
+ - Coincidentally, at OpenVPN Inc., a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task, we can coordinate on it.
+
+ - **Forums Machine on Community Infrastructure is Only Non-Linux System**
+ - mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.
+ - ecrist has looked at it but the current state of the migration is unknown.
+
+ - **OpenVPN 2.6 Performance Results**
+ - We should work on an article to publish some performance results when 2.6 is out as stable, but first press release.
+
+ - **Management Interface Documentation on Main Website Will Be Updated**
+ - Information from doc/management-notes.txt will be updated.
+ - novaflash will pick this up at some point.
+
+ - **OpenVPN Quickstart on Community Resources Will Be Updated**
+ - From `/doc/man-sections/example-fingerprint.rst` information.
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-05-24.md
@@ 0,0 1,58 @@
+ # Basic Info
+
+ - **Time**: Wednesday 24 May 2023 at 13:00 CET (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **2.6.5 release plans**
+ - _"in about 3 to 7 weeks from now, so anywhere between half June and half July"_
+
+ - **Hackathon Arrangements**
+ - When: [https://nuudel.digitalcourage.de/t1hjepaHGhdpiV2P](https://nuudel.digitalcourage.de/t1hjepaHGhdpiV2P) => Probably October 6th-October 8th
+ - Location: Torrevieja. Lev looking into venue.
+ - Topics: Yes.
+
+ - **2.7 Plans, if any?**
+ - [https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn27](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn27)
+
+ - **Status of PoC using Gerrit for code review.**
+ - "Buildbot builds from Gerrit should work now for all workers. Please use!"
+
+ - **Security Assessment of OpenVPN2 Codebase.**
+ - "dazo has the final report and is reviewing. Will raise any remaining issues."
+
+ - **License Amendment for OpenVPN2 to Solve openssl/mbedtls Licensing Issues**
+ - Current status: [https://github.com/OpenVPN/openvpn-license-change](https://github.com/OpenVPN/openvpn-license-change)
+ - "The next step for us is to put in extra effort to try and reach those people that didn't respond or we couldn't reach yet. dazo wanted to look into that but didn't find time, yet."
+
+ ## Topics on Standby
+
+ - **security@openvpn.net mailing list**
+ - "Company is trying to get to SOC2 compliance. Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net. Company guy took standard NDA we use for contractors, suggests to use that. Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all."
+
+ - **Website Release Process Woes**
+ - "Website team claims their solution is 95% done. We'll see."
+
+ - **Another Key Signing Topic**
+ - "Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing. In future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys. Depends on how hard/easy it is to access company key signing thing from community infrastructure. Also, no high priority at the moment, we have a working solution now."
+
+ - **Can We Have Someone at OpenVPN Create Nicer Windows Traybar Logos (#1276)?**
+ - "Matt is currently working on it in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)"
+
+ - **SBOM Topic**
+ - "Cron2 was asked if OpenVPN has a Software Bill of Materials. Answer was no. Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do. When we pick up this task we can coordinate on it."
+
+ - **Forums Machine on Community Infrastructure is Only Non-Linux System.**
+ - "Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist. Ecrist has looked at it but the current state of the migration is unknown."
+
+ - **OpenVPN 2.6 Performance Results.**
+ - "We should work on an article to publish some performance results when 2.6 is out as stable, but first press release."
+
+ - **Management Interface Documentation on Main Website Will Be Updated with Info from doc/management-notes.txt**
+ - "Novaflash will pick this up at some point."
+
+ - **[https://openvpn.net/community-resources/openvpn-quickstart/](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - "Static-key will be deprecated and contents updated with peer-fingerprint stuff. Novaflash will pick this up again as time permits and other more important topics are done."
\ No newline at end of file
/dev/null .. meetings/2023-05-31.md
@@ 0,0 1,70 @@
+ # Basic info
+
+ - **Time:** Wednesday 31 May 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **2.6.5 release plans**
+ - *in about 2 to 6 weeks from now so anywhere between half June and half July*
+
+ - **Hackathon arrangements**
+ - *When: [Poll Link](https://nuudel.digitalcourage.de/t1hjepaHGhdpiV2P) => Probably October 6th-October 8th*
+ - *Location: Torrevieja. Lev looking into venue.*
+ - *Topics: Yes.*
+
+ - **2.7 plans, if any?**
+ - [Status of OpenVPN 2.7](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn27)
+
+ - **Status of PoC using Gerrit for code review.**
+ - *Buildbot builds from Gerrit should work now for all workers. Please use!*
+
+ - **Security assessment of OpenVPN2 codebase.**
+ - *dazo has the final report and is reviewing. Will raise any remaining issues.*
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - *Current status: [License Change](https://github.com/OpenVPN/openvpn-license-change)*
+ - *Issue with a particular contributor looks to be resolved.*
+ - *Now only 6 people remaining to approve.*
+ - *novaflash will assist plaisthos next week with trying to contact them.*
+
+ ## Topics on standby
+
+ - **security@openvpn.net mailing list**
+ - *Company is trying to get to SOC2 compliance.*
+ - *Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net*
+ - *Company guy took standard NDA we use for contractors, suggests to use that.*
+ - *novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.*
+
+ - **Website release process woes**
+ - *Website team claims their solution is 95% done. We'll see.*
+
+ - **Another key signing topic**
+ - *Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.*
+ - *In future, we could possibly switch community to that same key. Saves having to maintain 2 different keys.*
+ - *Depends on how hard/easy it is to access company key signing thing from community infrastructure.*
+ - *Also no high priority at the moment, we have a working solution now.*
+
+ - **Can we have someone at OpenVPN create nicer windows traybar logos?**
+ - *Matt is currently working on it in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)*
+
+ - **SBOM topic**
+ - *cron2 was asked if OpenVPN has a software bill of materials. Answer was no.*
+ - *Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do*
+ - *When we pick up this task we can coordinate on it.*
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - *Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.*
+ - *Ecrist has looked at it but the current state of the migration is unknown.*
+
+ - **OpenVPN 2.6 performance results.**
+ - *We should work on an article to publish some performance results when 2.6 is out as stable. but first press release.*
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - *novaflash will pick this up at some point*
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - *Static-key will be deprecated and contents updated with peer-fingerprint stuff.*
+ - *novaflash will pick this up again as time permits and other more important topics are done.*
\ No newline at end of file
/dev/null .. meetings/2023-06-07.md
@@ 0,0 1,71 @@
+ # Basic Info
+
+ - **Time:** Wednesday 7 June 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ ### 2.6.5 Release Plans
+ - Expected in about 1 to 5 weeks from now, so anywhere between half June and half July.
+
+ ### Hackathon Arrangements
+ - **When:** [Schedule](https://nuudel.digitalcourage.de/t1hjepaHGhdpiV2P) (Probably October 6th-October 8th)
+ - **Location:** Torrevieja. Lev looking into venue.
+
+ ### 2.7 Plans, If Any?
+ - [Status of OpenVPN 2.7](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn27)
+
+ ### Status of PoC Using Gerrit for Code Review
+ - Buildbot builds from Gerrit should work now for all workers. Please use!
+
+ ### Security Assessment of OpenVPN2 Codebase
+ - Dazo has the final report and is reviewing. Will raise any remaining issues.
+
+ ### License Amendment for OpenVPN2 to Solve openssl/mbedtls Licensing Issues
+ - Current status: [OpenVPN License Change](https://github.com/OpenVPN/openvpn-license-change)
+ - Issue with a particular contributor looks to be resolved.
+ - Now only 6 people remaining to approve.
+ - Novaflash will assist plaisthos next week with trying to contact them.
+
+ ## Topics on Standby
+
+ ### security@openvpn.net Mailing List
+ - Company is trying to get SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net.
+ - Company guy took standard NDA we use for contractors, suggests to use that.
+ - Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ ### Website Release Process Woes
+ - Website team claims their solution is 95% done. We'll see.
+
+ ### Another Key Signing Topic
+ - Company switched EV code signing to CloudHSM, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - In future we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
+
+ ### Can We Have Someone at OpenVPN Create Nicer Windows Traybar Logos (#1276)?
+ - Matt is currently working on it in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+
+ ### SBOM Topic
+ - Cron2 was asked if OpenVPN has a Software Bill of Materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ ### Forums Machine on Community Infrastructure Is Only Non-Linux System.
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ ### OpenVPN 2.6 Performance Results
+ - We should work on an article to publish some performance results when 2.6 is out as stable. But first press release.
+
+ ### Management Interface Documentation on Main Website Will Be Updated
+ - With info from `doc/management-notes.txt`.
+ - Novaflash will pick this up at some point.
+
+ ### [OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) Will Be Updated
+ - From `/doc/man-sections/example-fingerprint.rst` information.
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-06-14.md
@@ 0,0 1,74 @@
+ # Basic info
+
+ - **Time:** Wednesday 14 June 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **2.6.5 release plans**
+ *released 13 June*
+
+ - **2.6.6 release plans**
+ *tentatively last week of July*
+
+ - **Hackathon arrangements**
+ *See [Hackathon2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023)*
+
+ - **Status of PoC using Gerrit for code review.**
+ *Buildbot builds from Gerrit should work now for all workers. Please use!*
+
+ - **Security assessment of OpenVPN2 codebase.**
+ *this is now done.
+ novaflash will take to company to discuss publishing it.
+ ultimately francis makes the call on that.*
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ *novaflash assisting plaisthos to reach the last 6 or so relevant people.
+ we set a deadline at august 1st*
+
+ - **Website release process woes**
+ *website team launched a new CMS system to be used with a headless system.
+ they're copying community downloads stuff in there.
+ once done we can test it and then updates there can be done independently of main website releases.*
+
+ - **Teach someone other than djpig to do releases**
+ *uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases.
+ likewise dazo and djpig will share knowledge about copr/fedora releases.*
+
+ ## Topics on standby
+
+ - **security@openvpn.net mailing list**
+ *company is trying to get to soc2 compliance.
+ probably will need a simple nda to be signed by recipients of emails to security@openvpn.net
+ company guy took standard nda we use for contractors, suggests to use that.
+ novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.*
+
+ - **Another key signing topic**
+ *company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ depends on how hard or easy it is to access company key signing thingee from community infrastructure.
+ also no high priority at the moment, we have a working solution now.*
+
+ - **Can we have someone at OpenVPN create nicer windows traybar logos (#1276)?**
+ *matt is currently working on it in [OpenVPN-gui#595](https://github.com/OpenVPN/openvpn-gui/issues/595)*
+
+ - **SBOM topic**
+ *cron2 was asked if openvpn has a software bill of materials. answer was no.
+ coincidentally, in openvpn inc a security requirement is to have an SBOM so this is on our list of things to do
+ when we pick up this task we can coordinate on it.*
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ *mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
+ ecrist has looked at it but the current state of the migration is unknown.*
+
+ - **OpenVPN 2.6 performance results.**
+ *We should work on an article to publish some performance results when 2.6 is out as stable.*
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ *novaflash will pick this up at some point*
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ *Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ novaflash will pick this up again as time permits and other more important topics are done.*
\ No newline at end of file
/dev/null .. meetings/2023-06-21.md
@@ 0,0 1,52 @@
+ # Basic Info
+
+ - **Time:** Wednesday 21 June 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **2.6.6 Release Plans**
+ *Tentatively last week of July*
+
+ - **Hackathon Arrangements**
+ [See Hackathon 2023 details](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+
+ - **Security Assessment of OpenVPN2 Codebase**
+ *Company agreed to publish. Dazo and Novaflash to push this to marketing for a release on site.*
+
+ - **License Amendment for OpenVPN2 to Solve openssl/mbedtls Licensing Issues**
+ *Novaflash assisting Plaisthos to reach the last 6 or so relevant people. We set a deadline at August 1st.*
+
+ - **Website Release Process Woes**
+ *Website team is working on migrating community downloads content to new CMS system.*
+
+ - **Teach Someone Other Than Djpig to Do Releases**
+ *Uddr and Djpig will work together so they can share the responsibility/knowledge of OpenVPN2 releases. Likewise, Dazo and Djpig will share knowledge about COPR/Fedora releases.*
+
+ - **What's Going on With New Taskbar Icons?**
+ *Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)*
+
+ - **OpenVPN 2.6 Performance Results**
+ *We should work on an article to publish some performance results when 2.6 is out as stable.*
+
+ ## Topics on Standby
+
+ - **security@openvpn.net Mailing List**
+ *Company is trying to get to SOC2 compliance. Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net. Company guy took standard NDA we use for contractors, suggests to use that. Novaflash thinks we should review that first to see if it's really suitable or not, as community members are not contractors.*
+
+ - **Another Key Signing Topic**
+ *Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, also suitable for binary signing. In the future, we could possibly switch the community to that same key, saves having to maintain 2 different keys. Depends on how hard/easy it is to access company key signing thing from community infrastructure. Also, no high priority at the moment, we have a working solution now.*
+
+ - **SBOM Topic**
+ *Cron2 was asked if OpenVPN has a Software Bill of Materials (SBOM). The answer was no. Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM, so this is on our list of things to do. When we pick up this task, we can coordinate on it.*
+
+ - **Forums Machine on Community Infrastructure is Only Non-Linux System**
+ *Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist. Ecrist has looked at it, but the current state of the migration is unknown.*
+
+ - **Management Interface Documentation on Main Website Will Be Updated With Info from doc/management-notes.txt**
+ *Novaflash will pick this up at some point.*
+
+ - **[OpenVPN Quickstart Guide](https://openvpn.net/community-resources/openvpn-quickstart/) Will Be Updated from /doc/man-sections/example-fingerprint.rst Information.**
+ *Static-key will be deprecated and contents updated with peer-fingerprint stuff. Novaflash will pick this up again as time permits and other more important topics are done.*
\ No newline at end of file
/dev/null .. meetings/2023-06-28.md
@@ 0,0 1,57 @@
+ # Basic info
+
+ - **Time:** Wednesday 28 June 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ **This meeting is cancelled due to ongoing real life events.**
+
+ # Topics
+
+ ## Current topics
+
+ - **2.6.6 release plans**
+ *Tentatively last week of July.*
+
+ - **CMake work is done, need to decide if to merge that to 2.6 or not.**
+
+ - **Hackathon arrangements**
+ [See Hackathon 2023 Details](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+
+ - **Security assessment of OpenVPN2 codebase.**
+ *Company agreed to publish. Dazo and Novaflash to push this to marketing for a release on site.*
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ *Novaflash assisting Plaisthos to reach the last 6 or so relevant people. We set a deadline at August 1st.*
+ **Update:** 2 additional people reached successfully.
+
+ - **Website release process woes**
+ *Website team is working on migrating community downloads content to new CMS system.*
+
+ - **Teach someone other than djpig to do releases**
+ *Uddr and Djpig will work together so they can share the responsibility/knowledge of OpenVPN2 releases. Likewise, Dazo and Djpig will share knowledge about Copr/Fedora releases.*
+
+ - **What's going on with new taskbar icons?**
+ *Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)*
+
+ - **OpenVPN 2.6 performance results.**
+ *We should work on an article to publish some performance results when 2.6 is out as stable.*
+
+ ## Topics on standby
+
+ - **security@openvpn.net mailing list**
+ *Company is trying to get to SOC2 compliance. Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net. Company guy took standard NDA we use for contractors, suggests to use that. Novaflash thinks we should review that first to see if it's really suitable or not, as community members are not contractors after all.*
+
+ - **Another key signing topic**
+ *Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, and is also suitable for binary signing. In future, we could possibly switch community to that same key, saves having to maintain 2 different keys. Depends on how hard/easy it is to access company key signing thing from community infrastructure. Also no high priority at the moment, we have a working solution now.*
+
+ - **SBOM topic**
+ *Cron2 was asked if OpenVPN has a Software Bill of Materials. Answer was no. Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do. When we pick up this task we can coordinate on it.*
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ *Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist. Ecrist has looked at it but the current state of the migration is unknown.*
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt.**
+ *Novaflash will pick this up at some point.*
+
+ - [**OpenVPN Quickstart Guide**](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.
+ *Static-key will be deprecated and contents updated with peer-fingerprint stuff. Novaflash will pick this up again as time permits and other more important topics are done.*
\ No newline at end of file
/dev/null .. meetings/2023-07-05.md
@@ 0,0 1,78 @@
+ # Basic info
+
+ - **Time:** Wednesday 5 July 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **2.6.6 release plans**
+ - _tentatively last week of July_
+
+ - **cmake work is done, need to decide if to merge that to 2.6 or not**
+ - _djpig notes that there are some things to be ironed out before we can backport_
+
+ - **Hackathon arrangements**
+ - [See Hackathon2023 details](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+
+ - **Security assessment of OpenVPN2 codebase.**
+ - _company agreed to publish. novaflash to push this to marketing for a release on site._
+
+ - **Static-key mini how-to is outdated.**
+ - [This page is outdated badly](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - _Company will send this to tech writer to redo based on [GitHub doc info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc._
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - _we have a deadline at August 1st_
+ - **update:** _2 additional people reached successfully, currently attempting 3rd hard-to-reach person_
+
+ - **License amendment for OpenVPN2: keep old openssl exception or no?**
+ - _someone mentioned that we should remove the old exception._
+ - _we will, eventually. while we still support openssl 1.0.2 we still need it_
+ - _if someone really wants to get rid of the exception they can fork openvpn2_
+
+ - **OpenVPN 2.6 performance results.**
+ - _We should work on an article to publish some performance results when 2.6 is out as stable._
+
+ - **Website release process woes**
+ - _website team is working on migrating community downloads content to new cms system._
+
+ ## Topics on standby
+
+ - **Teach someone other than djpig to do releases**
+ - _uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases._
+ - _likewise dazo and djpig will share knowledge about copr/fedora releases._
+ - **update:** _placed on standby for now because of holidays._
+
+ - **What's going on with new taskbar icons?**
+ - _matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
+ - **update:** _will be picked up by selva when he has time_
+
+ - **security@openvpn.net mailing list**
+ - _company is trying to get to soc2 compliance._
+ - _probably will need a simple nda to be signed by recipients of emails to security@openvpn.net_
+ - _company guy took standard nda we use for contractors, suggests to use that._
+ - _novaflash thinks we should review that first to see if it's really suitable or not, as community members are not contractors._
+
+ - **Another key signing topic**
+ - _company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
+ - _in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
+ - _depends on how hard/easy it is to access company key signing thing from community infrastructure._
+ - _also no high priority at the moment, we have a working solution now._
+
+ - **SBOM topic**
+ - _cron2 was asked if openvpn has a software bill of materials. answer was no._
+ - _coincidentally, in openvpn inc a security requirement is to have an SBOM so this is on our list of things to do_
+ - _when we pick up this task we can coordinate on it._
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - _mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist._
+ - _ecrist has looked at it but the current state of the migration is unknown._
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - _novaflash will pick this up at some point_
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - _Static-key will be deprecated and contents updated with peer-fingerprint stuff._
+ - _novaflash will pick this up again as time permits and other more important topics are done._
\ No newline at end of file
/dev/null .. meetings/2023-07-12.md
@@ 0,0 1,81 @@
+ # Basic info
+
+ - **Time:** Wednesday 12 July 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Topics regarding Gerrit reviewing**
+ - **Gerrit cannot mail to mailing list.**
+ - The reason may be that the mailing list is subscriber only, and Gerrit isn't a member. Will look into adding Gerrit.
+ - **Can we ask cron2 to also push master to Gerrit as well when he updates master?**
+ - This is currently blocking putting stuff up for review because master is more up-to-date than on Gerrit.
+
+ - **An issue was brought up on the security list by Mathy Vanhoef**
+ - Should evaluate and see what could and should be done.
+
+ - **2.6.6 release plans**
+ - Tentatively last week of July.
+
+ - **CMake work is done, need to decide if to merge that to 2.6 or not**
+ - Djpig notes that there are some things to be ironed out before we can backport.
+
+ - **Hackathon arrangements**
+ - [Hackathon 2023 Information](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+
+ - **Security assessment of OpenVPN2 codebase.**
+ - Company agreed to publish. Novaflash to push this to marketing for a release on site.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static-key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - Company will send this to tech writer to redo based on [GitHub Example Fingerprint Info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - We have a deadline at August 1st.
+ - **Update:** 2 additional people reached successfully, currently attempting 3rd hard-to-reach person.
+
+ - **OpenVPN 2.6 performance results**
+ - We should work on an article to publish some performance results when 2.6 is out as stable.
+
+ - **Website release process woes**
+ - Website team is working on migrating community downloads content to new CMS system.
+
+ ## Topics on standby
+
+ - **Teach someone other than djpig to do releases**
+ - Uddr and djpig will work together so they can share the responsibility/knowledge of OpenVPN2 releases.
+ - Likewise, Dazo and djpig will share knowledge about Copr/Fedora releases.
+ - **Update:** Placed on standby for now because of holidays.
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** Will be picked up by Selva when he has time.
+
+ - **security@openvpn.net mailing list**
+ - Company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net.
+ - Company guy took standard NDA we use for contractors, suggests to use that. Novaflash thinks we should review that first to see if it's really suitable or not, as community members are not contractors.
+
+ - **Another key signing topic**
+ - Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In future we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
+
+ - **SBOM topic**
+ - Cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up at some point.
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-07-19.md
@@ 0,0 1,81 @@
+ # Basic Info
+
+ - **Time:** Wednesday 19 July 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **Topics Regarding Gerrit Reviewing**
+ - Solved the issue of Gerrit not being able to send emails.
+ - When the OpenVPN2 master is updated, Gerrit should be updated too. Requested cron2 to take care of this.
+
+ - **An Issue Was Brought Up on Security List by Mathy Vanhoef**
+ - 9:30 AM 20 July we'll discuss internally. The location will be disclosed on the security list.
+
+ - **2.6.6 Release Plans**
+ - Moved from the last week of July to tentatively the first week of August.
+
+ - **CMake Work is Done, Need to Decide if to Merge That to 2.6 or Not**
+ - All the work for this appears to be done. A backport will be made to 2.6.
+
+ - **Hackathon Arrangements**
+ - See [Hackathon2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+
+ - **Security Assessment of OpenVPN2 Codebase**
+ - The company agreed to publish. Novaflash to push this to marketing for a release on the site.
+
+ - **Static-Key Mini How-to is Outdated**
+ - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [GitHub Doc Information](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst)
+ - Also, retain a link to that GitHub doc.
+
+ - **License Amendment for OpenVPN2 to Solve OpenSSL/mbedTLS Licensing Issues**
+ - We have a deadline at August 1st.
+ - **Update:** 2 additional people reached successfully, currently attempting 3rd hard-to-reach person.
+
+ - **OpenVPN 2.6 Performance Results**
+ - Tests should cover: GRE, IPSec, userland, DCO on Linux, FreeBSD, Windows.
+
+ - **Website Release Process Woes**
+ - The website team is working on migrating community downloads content to a new CMS system.
+
+ ## Topics on Standby
+
+ - **Teach Someone Other Than Djpig to Do Releases**
+ - Uddr and Djpig will work together so they can share the responsibility/knowledge of OpenVPN2 releases.
+ - Likewise, Dazo and Djpig will share knowledge about COPR/Fedora releases.
+ - **Update:** Placed on standby for now because of holidays.
+
+ - **What's Going on with New Taskbar Icons?**
+ - Matt provided icons in [Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** Will be picked up by Selva when he has time.
+
+ - **Security@openvpn.net Mailing List**
+ - The company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - The company guy took the standard NDA we use for contractors, suggests to use that.
+ - Novaflash thinks we should review that first to see if it's really suitable or not, as community members are not contractors after all.
+
+ - **Another Key Signing Topic**
+ - The company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
+
+ - **SBOM Topic**
+ - Cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do
+ - When we pick up this task we can coordinate on it.
+
+ - **Forums Machine on Community Infrastructure is Only Non-Linux System**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Management Interface Documentation on Main Website Will Be Updated with Info From doc/management-notes.txt**
+ - Novaflash will pick this up at some point.
+
+ - **OpenVPN Quickstart Will Be Updated from /doc/man-sections/example-fingerprint.rst Information**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-07-26.md
@@ 0,0 1,64 @@
+ # Basic info
+
+ - **Time:** Wednesday 26 July 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **An issue brought up by Mathy on the security list**
+ - "This was discussed internally; at the moment it is not yet clear if this really is a CVE reportable issue. We do see that there are issues here that need to be addressed, so we acknowledge it and commit to implementing mitigations."
+
+ - **Security assessment topic raised by dazo**
+ - "TOB-OVPN-14, NTLM issues in some buffer length checks. An audit will be done on code fixes for software assessment, and this is the most relevant one requiring code changes that is left. Conclusion is that we will document that if challenge is too short, we will fill remaining bytes with zero bytes from buf2."
+
+ - **How to handle coverity scans/results discussed by djpig**
+ - "The idea was to use the company Coverity code scanner, but there may be licensing issues. Also, it turns out there is a free version (Travis CI) that we used in the past but stopped working. We should instead focus on getting that free service working again."
+
+ - **2.6.6 release plans**
+ - "Moved from last week of July to tentatively first week of August. There's not all that much new to release yet, but we could do the cmake backport in this release."
+
+ - **Hackathon arrangements**
+ - [Hackathon 2023 Information](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+
+ - **Teach someone other than djpig to do releases**
+ - "uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases. Likewise, dazo and djpig will share knowledge about copr/fedora releases. **Update:** dazo sort of back from vacation."
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - "We have a deadline at August 1st. **Update:** 2 additional people reached successfully; others could not be reached."
+
+ - **Static-key mini how-to is outdated**
+ - "This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/). The company will send this to a tech writer to redo based on [GitHub documentation](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc."
+
+ - **Website release process woes**
+ - "The website team is working on migrating community downloads content to a new CMS system."
+
+ ## Topics on standby
+
+ - **OpenVPN 2.6 performance results**
+ - "Tests should cover: gre, ipsec, userland, dco; Linux, FreeBSD, Windows. Requires time to be dedicated to doing this. When time is available, we will do it."
+
+ - **What's going on with new taskbar icons?**
+ - "Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595). **Update:** will be picked up by selva when he has time."
+
+ - **security@openvpn.net mailing list**
+ - "The company is trying to get to SOC2 compliance. Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net. The company guy took the standard NDA we use for contractors, suggests to use that. Novaflash thinks we should review that first to see if it's really suitable or not, as community members are not contractors after all."
+
+ - **Another key signing topic**
+ - "The company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing. In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys. Depends on how hard/easy it is to access company key signing thing from community infrastructure. Also, no high priority at the moment, we have a working solution now."
+
+ - **SBOM topic**
+ - "Cron2 was asked if OpenVPN has a software bill of materials. Answer was no. Coincidentally, in OpenVPN Inc, a security requirement is to have an SBOM so this is on our list of things to do. When we pick up this task, we can coordinate on it."
+
+ - **Forums machine on community infrastructure is the only non-Linux system**
+ - "Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist. Ecrist has looked at it but the current state of the migration is unknown."
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - "Novaflash will pick this up at some point."
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information**
+ - "Static-key will be deprecated and contents updated with peer-fingerprint stuff. Novaflash will pick this up again as time permits and other more important topics are done."
+
+ - **Security assessment of OpenVPN2 codebase**
+ - "Company agreed to publish. Novaflash to push this to marketing for a release on site."
\ No newline at end of file
/dev/null .. meetings/2023-08-02.md
@@ 0,0 1,65 @@
+ # Basic Info
+
+ - **Time:** Wednesday 2 August 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **An issue was brought up on security list by Mathy**
+ - This was discussed internally
+ - At the moment, it is not yet clear if this really is a CVE reportable issue
+ - We do see that there are issues here that need to be addressed, so we acknowledge it and commit to implementing mitigations
+ - We'll put together a draft here: [Cryptpad Draft](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/)
+
+ - **Security assessment topic that dazo wanted to bring up**
+ - TOB-OVPN-14, NTLM issues in some buffer length checks
+ - An audit will be done on code fixes for software assessment, and this is the most relevant one requiring code changes that is left
+ - Conclusion is that we will document that if the challenge is too short, we will fill remaining bytes with zero bytes from buf2
+
+ - **How to handle coverity scans/results by djpig**
+ - The idea was to use the company coverity code scanner but there may be licensing issues
+ - Also, it turns out there is a free version (Travis CI) that we used in the past but stopped working
+ - We should instead focus on getting that free service working again
+
+ - **2.6.6 release plans**
+ - Release date between 9 and 15 August
+ - We could do the cmake backport in this release
+ - Lev mentions a WINS patch to go into 2.6.6
+
+ - **Hackathon arrangements**
+ - See [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+
+ - **Teach someone other than djpig to do releases**
+ - Uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases
+ - Likewise, dazo and djpig will share knowledge about copr/fedora releases
+ - **Update:** Dazo sort of back from vacation
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - There are a total of 5 contributions that need to be reimplemented/removed to finalize the license change
+ - 1 item was reimplemented by plaisthos and merged already, so 4 remain
+ - One person asked if old exception could be kept for libressl, plaisthos asked for clarification
+
+ - **Static-key mini how-to is outdated**
+ - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - Company will send this to tech writer to redo based on [GitHub Doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info
+ - And also retain a link to that GitHub doc
+ - Having a simple guide online will help adoption
+
+ - **Website release process woes**
+ - Website team is working on migrating community downloads content to new CMS system
+
+ ## Topics on Standby
+
+ - **OpenVPN 2.6 performance results**
+ - Tests should cover: GRE, IPSec, userland, DCO
+ - Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this
+ - When time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** Will be picked up by Selva when he has time
+
+ [... Additional topics on standby continue ...]
\ No newline at end of file
/dev/null .. meetings/2023-08-09.md
@@ 0,0 1,92 @@
+ # Basic info
+
+ - **Time:** Wednesday 9 August 2023 at 13:00 CET (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **An issue was brought up on security list by Mathy**
+ - This was discussed internally.
+ - At the moment it is not yet clear if this really is a CVE reportable issue.
+ - We do see that there are issues here that need to be addressed so we acknowledge it and commit to implementing mitigations.
+ - We'll put together a draft here: [Draft Link](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/)
+
+ - **Security assessment topic that dazo wanted to bring up**
+ - TOB-OVPN-14, NTLM issues in some buffer length checks.
+ - An audit will be done on code fixes for software assessment and this is the most relevant one requiring code changes that is left.
+ - Conclusion is that we will document that if challenge is too short we will fill remaining bytes with zero bytes from buf2.
+
+ - **How to handle coverity scans/results by djpig**
+ - The idea was to use the company coverity code scanner but there may be licensing issues.
+ - Also it turns out there is a free version (Travis CI) that we used in the past but stopped working.
+ - We should instead focus on getting that free service working again.
+
+ - **2.6.6 release plans**
+ - Release date between 9 and 15 August.
+ - We could do the cmake backport in this release.
+ - Lev mentions a WINS patch to go into 2.6.6.
+
+ - **Hackathon arrangements**
+ - See [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+
+ - **Teach someone other than djpig to do releases**
+ - Uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases.
+ - Likewise, dazo and djpig will share knowledge about copr/fedora releases.
+ - **Update:** Dazo sort of back from vacation.
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - There are a total of 5 contributions that need to be reimplemented/removed to finalize the license change.
+ - 1 item was reimplemented by plaisthos and merged already, so 4 remain.
+ - One person asked if the old exception could be kept for libressl, plaisthos asked for clarification.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini How-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - Company will send this to tech writer to redo based on [GitHub Doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ - **Website release process woes**
+ - Website team is working on migrating community downloads content to new CMS system.
+
+ ## Topics on standby
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: GRE, IPsec, userland, DCO, Linux, FreeBSD, Windows.
+ - Requires time to be dedicated to doing this.
+ - When time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** Will be picked up by Selva when he has time.
+
+ - **security@openvpn.net mailing list**
+ - Company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net.
+ - Company guy took standard NDA we use for contractors, suggests to use that.
+ - Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ - **Another key signing topic**
+ - Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
+
+ - **SBOM topic**
+ - Cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up at some point.
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
+
+ - **Security assessment of OpenVPN2 codebase.**
+ - Company agreed to publish. Novaflash to push this to marketing for a release on site.
\ No newline at end of file
/dev/null .. meetings/2023-08-16.md
@@ 0,0 1,67 @@
+ # Basic info
+
+ - **Time:** Wednesday 16 August 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **2.6.6 was released**
+ - djpig explained release process to uddr. dazo explained copr release process to djpig. So progress on spreading release process knowledge around.
+
+ - **Tunnelcrack** published now [https://tunnelcrack.mathyvanhoef.com/](https://tunnelcrack.mathyvanhoef.com/).
+ - We do see that there are issues here that need to be addresses so we acknowledge it and commit to implementing mitigations. We'll put together a draft here [https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/). Mitigation plans should be discussed at Hackathon in October (or sooner).
+
+ - **NTLM code clarification patch has been applied (TOB-OVPN-14)**
+ - This concludes all open items from the last audit. They will now do another round of reviews on our fixes for the issues they raised.
+
+ - **NTLM feature deprecation?**
+ - dazo argues for deprecating NTLM. E.g. disabling it in 2.7 by default. Will be added as "under discussion" to DeprecatedOptions page.
+
+ - **2.5.x support status**
+ - 2.5 will be marked as "old stable" on SupportedVersions since it has been more than 6 months since 2.6.0 release.
+
+ - **Hackathon arrangements**
+ - See [Hackathon2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - There are a total of 5 contributions that need to be reimplemented/removed to finalize the license change. 1 item was reimplemented by plaisthos and merged already, so 4 remain. One person asked if old exception could be kept, for libressl, plaisthos asked for clarification. djpig volunteered to look at the original changes to describe them for people interested in reimplementing them. MaxF has volunteered to help with any mbedtls related required changes. dazo will speak to Pam to get her opinions on the contributions. plaisthos has volunteered to reimplement tls-export-cert.
+
+ - **How to handle coverity scans/results by djpig**
+ - The idea was to use the company coverity code scanner but there may be licensing issues. Also, it turns out there is a free version (Travis CI) that we used in the past but stopped working. We should instead focus on getting that free service working again. Patch is available for GHA. Just needs to be merged to master.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini HowTo](https://openvpn.net/community-resources/static-key-mini-howto/). Company will send this to tech writer to redo based on [GitHub doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc. Having a simple guide online will help adoption.
+
+ - **Website release process woes**
+ - Website team is working on migrating community downloads content to new CMS system.
+
+ ## Topics on standby
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: gre, ipsec, userland, dco, linux, freebsd, windows. Requires time to be dedicated to doing this. When time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [GitHub Issue 595](https://github.com/OpenVPN/openvpn-gui/issues/595). **Update:** will be picked up by selva when he has time.
+
+ - **security@openvpn.net mailing list**
+ - Company is trying to get to SOC2 compliance. Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net. Company guy took standard NDA we use for contractors, suggests to use that. Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ - **Another key signing topic**
+ - Company switched EV code signing to CloudHSM, this is same cert type we use for driver signing, is also suitable for binary signing. In future we could possibly switch community to that same key. Saves having to maintain 2 different keys. Depends on how hard/easy it is to access company key signing thingee from community infrastructure. Also no high priority at the moment, we have a working solution now.
+
+ - **SBOM topic**
+ - Cron2 was asked if OpenVPN has a software bill of materials. Answer was no. Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do. When we pick up this task we can coordinate on it.
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist. Ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up at some point.
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff. Novaflash will pick this up again as time permits and other more important topics are done.
+
+ - **Security assessment of OpenVPN2 codebase.**
+ - Company agreed to publish. Novaflash to push this to marketing for a release on site.
\ No newline at end of file
/dev/null .. meetings/2023-08-23.md
@@ 0,0 1,90 @@
+ # Basic info
+
+ - Time: Wednesday 23 August 2023 at 13:00 CEST (11:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **openvpn release process topics**
+ - djpig explained release process to uddr. dazo explained copr release process to djpig. So progress on spreading release process knowledge around.
+ - when 2.6.7 goes out it will be done by uddr under supervision from djpig. that way we'll be sure we have a good backup.
+ - there was also the request in [https://github.com/OpenVPN/openvpn/issues/397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
+
+ - **Tunnelcrack published now [https://tunnelcrack.mathyvanhoef.com](https://tunnelcrack.mathyvanhoef.com)**
+ - we do see that there are issues here that need to be addressed so we acknowledge it and commit to implementing mitigations
+ - we'll put together a draft here [https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/)
+ - in the company there will also be discussions about possible mitigations. any mitigation plans we can put into the draft and publish it on community side.
+ - company will then reference that document on the main website and contribute/participate in making the mitigations happen.
+
+ - **security assessment review**
+ - currently the fixes are being reviewed.
+
+ - **Hackathon arrangements**
+ - See [https://community.openvpn.net/openvpn/wiki/Hackathon2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+ - a possible topic for discussion is deprecation of NTLM and when to deprecate
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - there are a total of 5 contributions that need to be reimplemented/removed to finalize the license change.
+ - 1 item was reimplemented by plaisthos and merged already, so 4 remain
+ - one of them wanted
+ - one person asked if old exception could be kept, for libressl, plaisthos asked for clarification. djpig volunteered to look at the original changes to describe them for people interested in reimplementing them. MaxF has volunteered to help with any mbedtls related required changes. dazo will speak to Pam to get her opinions on the contributions. plaisthos has volunteered to reimplement tls-export-cert.
+
+ - **how to handle coverity scans/results by djpig**
+ - the idea was to use the company coverity code scanner but there may be licensing issues
+ - also, it turns out there is a free version (Travis CI) that we used in the past but stopped working
+ - we should instead focus on getting that free service working again.
+ - patch is available for GHA. Just needs to be merged to master.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info
+ - and also retain a link to that GitHub doc.
+ - having a simple guide online will help adoption
+
+ - **Website release process woes**
+ - website team is working on migrating community downloads content to new CMS system.
+
+ ## Topics on standby
+
+ - **OpenVPN 2.6 performance results.**
+ - tests should cover: gre, ipsec, userland, dco
+ - linux, freebsd, windows
+ - requires time to be dedicated to doing this
+ - when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **update:** will be picked up by selva when he has time
+
+ - **security@openvpn.net mailing list**
+ - company is trying to get to soc2 compliance.
+ - probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - company guy took standard NDA we use for contractors, suggests to use that.
+ - novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ - **Another key signing topic**
+ - company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ - depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - also no high priority at the moment, we have a working solution now.
+
+ - **SBOM topic**
+ - cron2 was asked if openvpn has a software bill of materials. answer was no.
+ - coincidentally, in openvpn inc a security requirement is to have an SBOM so this is on our list of things to do
+ - when we pick up this task we can coordinate on it.
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
+ - ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - novaflash will pick this up at some point
+
+ - **[https://openvpn.net/community-resources/openvpn-quickstart/](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - novaflash will pick this up again as time permits and other more important topics are done.
+
+ - **Security assessment of OpenVPN2 codebase.**
+ - company agreed to publish. novaflash to push this to marketing for a release on site.
\ No newline at end of file
/dev/null .. meetings/2023-08-30.md
@@ 0,0 1,57 @@
+ # Basic info
+
+ - **Time:** Wednesday 30 August 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ ### OpenVPN release process topics
+ - djpig explained the release process to uddr. dazo explained the copr release process to djpig. Progress on spreading release process knowledge around.
+ - When 2.6.7 is released, it will be done by uddr under supervision from djpig, ensuring a good backup.
+ - There was also a request in [OpenVPN GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig thinks it would be fairly doable to copy/paste that info to GitHub.
+
+ ### Tunnelcrack publication
+ - Published at [Tunnelcrack](https://tunnelcrack.mathyvanhoef.com).
+ - Acknowledging issues and committing to implementing mitigations.
+ - Drafting mitigations [here](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/).
+ - Company discussions about possible mitigations will reference the community document and participate in making the mitigations happen.
+
+ ### Security assessment review
+ - Currently reviewing the fixes.
+
+ ### Hackathon arrangements
+ - Details at [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023).
+ - Possible discussion topic: deprecation of NTLM and timing for it.
+
+ ### License amendment for OpenVPN2
+ - To address openssl/mbedtls licensing issues.
+ - 5 contributions need to be reimplemented/removed to finalize the license change.
+ - One item was reimplemented by plaisthos and merged. Four remain.
+ - Discussion about whether the old exception could be kept for libressl.
+ - Djpig and MaxF will assist with changes. Dazo will consult with Pam.
+
+ ### Handling coverity scans/results
+ - Consider using a free version of the service, such as Travis CI.
+ - A patch is available for GHA and just needs to be merged to master.
+
+ ### Static-key mini how-to is outdated
+ - The page at [OpenVPN Static-Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/) is outdated.
+ - A tech writer will redo it based on the information in [GitHub](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst).
+ - A simple guide online will help with adoption.
+
+ ### Website release process woes
+ - The website team is working on migrating community downloads content to a new CMS system.
+
+ ## Topics on standby
+
+ - **OpenVPN 2.6 performance results:** Testing covers various configurations. Pending dedicated time.
+ - **New taskbar icons:** Update pending time availability.
+ - **Security mailing list:** Company is moving towards SOC2 compliance; a simple NDA might be required.
+ - **Key signing topic:** Transition to cloud-based key signing is under consideration but not a priority.
+ - **SBOM topic:** No current software bill of materials; coordination will occur when task is picked up.
+ - **Forums machine on community infrastructure:** Transition to a new system is in progress.
+ - **Management interface documentation update:** Will be updated based on management-notes.txt when possible.
+ - **OpenVPN Quickstart update:** Static-key will be deprecated; update will include peer-fingerprint info when possible.
+ - **Security assessment of OpenVPN2 codebase:** Agreed to be published; pending marketing release.
\ No newline at end of file
/dev/null .. meetings/2023-09-06.md
@@ 0,0 1,87 @@
+ # Basic info
+
+ - **Time:** Wednesday 6 September 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ ### OpenVPN Release Process Topics
+ - djpig explained the release process to uddr.
+ - dazo explained the copr release process to djpig.
+ - When 2.6.7 goes out, it will be done by uddr under the supervision of djpig to ensure we have a good backup.
+ - There was also a request in [OpenVPN Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig thinks it would be fairly doable to copy/paste that info to GitHub as well.
+
+ ### Tunnelcrack Publication
+ - Published at [Tunnelcrack](https://tunnelcrack.mathyvanhoef.com).
+ - Acknowledged issues and committed to implementing mitigations.
+ - A draft is being put together [here](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/).
+ - The company will discuss possible mitigations, add them to the draft, and publish it on the community side.
+ - The main website will reference this document and contribute to making the mitigations happen.
+
+ ### Security Assessment Review
+ - Currently, the fixes are being reviewed.
+
+ ### Hackathon Arrangements
+ - See [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023).
+ - Topics include deprecation of NTLM and discussion about merchandise like t-shirts.
+
+ ### License Amendment for OpenVPN2
+ - To solve openssl/mbedtls licensing issues, there are 5 contributions that need to be reimplemented/removed.
+ - One contribution was reimplemented by plaisthos and merged already, so 4 remain.
+ - Discussion about keeping old exceptions for libressl and mbedtls related changes.
+
+ ### Handling Coverity Scans/Results
+ - The idea was to use the company's coverity code scanner, but there are licensing issues.
+ - There is a free version (Travis CI) that we used in the past but stopped working.
+ - Focus on getting the free service working again.
+ - A patch is available for GHA and just needs to be merged to master.
+
+ ### Static-Key Mini How-To is Outdated
+ - The page is badly outdated: [Static-Key Mini HowTo](https://openvpn.net/community-resources/static-key-mini-howto/).
+ - The company will send this to a tech writer to redo based on the information from [GitHub](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst).
+ - A simple guide online will help adoption.
+
+ ### Website Release Process Woes
+ - The website team is working on migrating community downloads content to a new CMS system.
+
+ ## Topics on Standby
+
+ ### OpenVPN 2.6 Performance Results
+ - Tests should cover various configurations and operating systems.
+ - Requires time to be dedicated to doing this.
+
+ ### New Taskbar Icons
+ - Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595).
+ - Update: will be picked up by Selva when he has time.
+
+ ### Security Mailing List
+ - Company is trying to get to SOC2 compliance.
+ - Might need a simple NDA to be signed by recipients of emails to security@openvpn.net.
+ - The community needs to review if the standard NDA used for contractors is suitable.
+
+ ### Another Key Signing Topic
+ - Company switched EV code signing to CloudHSM.
+ - Possible future switch for community to the same key.
+ - Depends on access ease from community infrastructure.
+
+ ### SBOM Topic
+ - OpenVPN has no SBOM currently.
+ - OpenVPN Inc. needs an SBOM for security requirements.
+
+ ### Forums Machine on Community Infrastructure
+ - New forums system runs on Rocky Linux 8.
+ - Current state of migration is unknown.
+
+ ### Management Interface Documentation
+ - Documentation on the main website will be updated with info from `doc/management-notes.txt`.
+ - Novaflash will pick this up eventually.
+
+ ### OpenVPN Quickstart Update
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will manage updates as time permits.
+
+ ### Security Assessment of OpenVPN2 Codebase
+ - Company agreed to publish.
+ - Novaflash to push this to marketing for release on site.
\ No newline at end of file
/dev/null .. meetings/2023-09-13.md
@@ 0,0 1,61 @@
+ # Basic info
+
+ - **Time**: Wednesday 13 September 2023 at 13:00 CEST (11:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Security assessment of OpenVPN2 codebase.**
+ - *update: publishing this is currently being handled, it requires some preparation and internal reviews that is ongoing.*
+
+ - **Hackathon t-shirts**
+ - *novaflash remembered just in time to arrange this. matt came up with this design: [https://crashed.computer/shirt2023.jpg](https://crashed.computer/shirt2023.jpg) back of shirt will be as usual with all previous locations.*
+
+ - **Hackathon arrangements**
+ - *See [Hackathon2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023) topics: deprecation of NTLM, dhcp-option dns option future, gerrit, live route updates, custom app control message.*
+
+ - **Tunnelcrack published now [https://tunnelcrack.mathyvanhoef.com](https://tunnelcrack.mathyvanhoef.com)**
+ - *we do see that there are issues here that need to be addressed so we acknowledge it and commit to implementing mitigations. We'll put together a draft here [https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/). In the company, there will also be discussions about possible mitigations. Any mitigation plans we can put into the draft and publish it on the community side. The company will then reference that document on the main website and contribute/participate in making the mitigations happen.*
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - *update: dazo is working to make a full overview of the 'considered trivial' patches, and will then reach out to a legal expert. There are some contributors that didn't respond, need to reimplement those items. MaxF has volunteered to help with any mbedtls related required changes. plaisthos has volunteered to reimplement tls-export-cert.*
+
+ - **How to handle coverity scans/results by djpig**
+ - *the idea was to use the company coverity code scanner but there may be licensing issues. Also, it turns out there is a free version (Travis CI) that we used in the past but stopped working. We should instead focus on getting that free service working again. Patch is available for GHA. Just needs to be merged to master.*
+
+ - **Static-key mini how-to is outdated.**
+ - *This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/) company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc. Having a simple guide online will help adoption.*
+
+ - **Website release process woes**
+ - *website team is working on migrating community downloads content to new cms system. novaflash pushed them on coming up with a firm date, getting tired of this.*
+
+ ## Topics on standby
+
+ - **Openvpn release process topics**
+ - *there was a request in [https://github.com/OpenVPN/openvpn/issues/397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on github as well. djpig seems to think it would be fairly doable to copy/paste that info to github as well. We could do this during a next release.*
+
+ - **OpenVPN 2.6 performance results.**
+ - *tests should cover: gre, ipsec, userland, dco linux, freebsd, windows requires time to be dedicated to doing this when the time available will do it.*
+
+ - **What's going on with new taskbar icons?**
+ - *matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595) update: will be picked up by selva when he has time.*
+
+ - **security@openvpn.net mailing list**
+ - *company is trying to get to soc2 compliance. Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net. Company guy took standard NDA we use for contractors, suggests to use that. novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.*
+
+ - **Another key signing topic**
+ - *company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing. In the future, we could possibly switch community to that same key. Saves having to maintain 2 different keys. Depends on how hard/easy it is to access company key signing thing from community infrastructure. Also, no high priority at the moment, we have a working solution now.*
+
+ - **SBOM topic**
+ - *cron2 was asked if openvpn has a software bill of materials. Answer was no. Coincidentally, in openvpn inc a security requirement is to have an SBOM so this is on our list of things to do. When we pick up this task we can coordinate on it.*
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - *mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist. Ecrist has looked at it but the current state of the migration is unknown.*
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - *novaflash will pick this up at some point.*
+
+ - **[https://openvpn.net/community-resources/openvpn-quickstart/](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - *Static-key will be deprecated and contents updated with peer-fingerprint stuff. novaflash will pick this up again as time permits and other more important topics are done.*
\ No newline at end of file
/dev/null .. meetings/2023-09-20.md
@@ 0,0 1,94 @@
+ # Basic info
+
+ - **Time:** Wednesday 20 September 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Security assessment of OpenVPN2 codebase.**
+ *Update: Publishing this is currently being handled, it requires some preparation and internal reviews that are ongoing.*
+
+ - **Hackathon t-shirts**
+ *Novaflash remembered just in time to arrange this. Matt came up with this design: [https://crashed.computer/shirt2023.jpg](https://crashed.computer/shirt2023.jpg)
+ Back of shirt will be as usual with all previous locations.*
+
+ - **Hackathon arrangements**
+ *See [Hackathon 2023 Info](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+ Topics collected and placed in wiki page.*
+
+ - **Tunnelcrack published now**
+ [https://tunnelcrack.mathyvanhoef.com](https://tunnelcrack.mathyvanhoef.com)
+ *We do see that there are issues here that need to be addressed so we acknowledge it and commit to implementing mitigations.
+ We'll put together a draft here [Draft Document](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/)
+ In the company, there will also be discussions about possible mitigations. Any mitigation plans we can put into the draft and publish it on the community side.
+ The company will then reference that document on the main website and contribute/participate in making the mitigations happen.*
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ *Update: Dazo is working to make a full overview of the 'considered trivial' patches, and will then reach out to a legal expert.
+ There are some contributors that didn't respond, need to reimplement those items.
+ MaxF has volunteered to help with any mbedtls related required changes.
+ Plaisthos has volunteered to reimplement tls-export-cert.
+ James Bottomley's contribution will be removed as he does not agree to the license change.*
+
+ - **How to handle coverity scans/results by djpig**
+ *The idea was to use the company coverity code scanner but there may be licensing issues.
+ Also, it turns out there is a free version (Travis CI) that we used in the past but stopped working.
+ We should instead focus on getting that free service working again.
+ Patch is available for GHA. Just needs to be merged to master.*
+
+ - **Static-key mini how-to is outdated.**
+ *This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ Company will send this to tech writer to redo based on [GitHub Doc Info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst)
+ And also retain a link to that GitHub doc.
+ Having a simple guide online will help adoption.*
+
+ - **Website release process woes**
+ *Website team is working on migrating community downloads content to new CMS system.
+ Novaflash pushed them on coming up with a firm date, getting tired of this.*
+
+ ## Topics on standby
+
+ - **OpenVPN release process topics**
+ *There was a request in [GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well.
+ Djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
+ We could do this during a next release.*
+
+ - **OpenVPN 2.6 performance results.**
+ *Tests should cover: GRE, IPSec, userland, DCO
+ Linux, FreeBSD, Windows
+ Requires time to be dedicated to doing this
+ When time available will do it*
+
+ - **What's going on with new taskbar icons?**
+ *Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ **Update:** Will be picked up by Selva when he has time.*
+
+ - **Security@openvpn.net mailing list**
+ *Company is trying to get to SOC2 compliance.
+ Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ Company guy took standard NDA we use for contractors, suggests to use that.
+ Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.*
+
+ - **Another key signing topic**
+ *Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ In the future, we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ Also no high priority at the moment, we have a working solution now.*
+
+ - **SBOM topic**
+ *Cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
+ Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ When we pick up this task we can coordinate on it.*
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ *Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
+ Ecrist has looked at it but the current state of the migration is unknown.*
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ *Novaflash will pick this up at some point.*
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ *Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ Novaflash will pick this up again as time permits and other more important topics are done.*
\ No newline at end of file
/dev/null .. meetings/2023-09-27.md
@@ 0,0 1,89 @@
+ # Basic info
+
+ - **Time:** Wednesday 27 September 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ **Note:** Next week's meeting cancelled because of hackathon meeting next week.
+
+ # Topics
+
+ ## Current topics
+
+ - **Security assessment of OpenVPN2 codebase.**
+ - *Update:* Publishing this is currently being handled, it requires some preparation and internal reviews that is ongoing.
+
+ - **Hackathon t-shirts**
+ - *Update:* Shirts arrived. [View Shirt](https://crashed.computer/shirt2023.jpg)
+ - Back of shirt will be as usual with all previous locations.
+
+ - **Hackathon arrangements**
+ - See [Hackathon 2023 Wiki](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
+ - Topics collected and placed in wiki page.
+
+ - **Tunnelcrack published now** [Tunnelcrack](https://tunnelcrack.mathyvanhoef.com)
+ - We acknowledge issues and commit to implementing mitigations.
+ - We'll put together a draft [here](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/)
+ - Discussions about possible mitigations are ongoing within the company. Any mitigation plans will be added to the draft and published on the community side. The company will then reference that document on the main website and contribute/participate in making the mitigations happen.
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - *Update:* Dazo is working to make a full overview of the 'considered trivial' patches, and will then reach out to a legal expert.
+ - There are some contributors that didn't respond; need to reimplement those items.
+ - MaxF has volunteered to help with any mbedtls related required changes.
+ - Plaisthos has volunteered to reimplement tls-export-cert.
+ - James Bottomley's contribution will be removed as he does not agree to the license change.
+
+ - **How to handle coverity scans/results**
+ - Free coverity open source code scanner now working on OpenVPN2 codebase again.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - Company will send this to tech writer to redo based on [GitHub Doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ - **Website release process woes**
+ - Website team is working on migrating community downloads content to new CMS system.
+ - Novaflash pushed them on coming up with a firm date, getting tired of this.
+
+ ## Topics on standby
+
+ - **OpenVPN release process topics**
+ - There was a request in [GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well.
+ - Djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
+ - We could do this during the next release.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: GRE, IPSec, userland, DCO, Linux, FreeBSD, Windows.
+ - Requires time to be dedicated to doing this.
+ - When time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** Will be picked up by Selva when he has time.
+
+ - **security@openvpn.net mailing list**
+ - Company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net.
+ - Company guy took standard NDA we use for contractors, suggests to use that.
+ - Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ - **Another key signing topic**
+ - Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In future we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
+
+ - **SBOM topic**
+ - Cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up at some point.
+
+ - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-10-11.md
@@ 0,0 1,91 @@
+ # Basic info
+
+ - **Time**: Wednesday 11 October 2023 at 13:00 CEST (11:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ ### OpenVPN 2.6.7 release
+ - CMake backport is in.
+ - Some small bugfixes waiting to merge.
+ - Planned release date: 18 October.
+
+ ### Hackathon 2023 meeting summary
+ - See [wiki:Hackathon2023](https://wiki.openvpn.net/Hackathon2023)
+
+ ### Hackathon 2024 planning
+ - When? Not sure but we should do a date range of about 3 weeks so we can do availability polling.
+ - Where? In last discussion Karlsruhe was mentioned.
+ - Who? We should compile a more comprehensive list and send initial availability polling early.
+ - Shirts!
+
+ ### Weekly meeting summaries
+ - It was decided novaflash will do meeting summaries on wiki and send a copy to the devel mailing list.
+ - So novaflash will join the devel list and do the needful starting next week.
+
+ ### Security assessment of OpenVPN2 codebase
+ - Update 27 September: publishing this is currently being handled, it requires some preparation and internal reviews that is ongoing.
+
+ ### Tunnelcrack published now [Tunnelcrack](https://tunnelcrack.mathyvanhoef.com)
+ - A post was published at TunnelCrack
+ - More details are in the [wiki:Hackathon2023 meeting summary](https://wiki.openvpn.net/Hackathon2023).
+
+ ### License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues
+ - Update 11 October: we want dazo to review things so we can decide if we can finalize this.
+ - One of the tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary.
+
+ ### Static-key mini how-to is outdated.
+ - This page is outdated badly: [Static Key Mini Howto](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [GitHub info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ ### Website release process woes
+ - Update 11 October: website team reports they've migrated existing content to a new CMS.
+ - Apparently, this week is planned for release.
+
+ ## Topics on standby
+
+ ### OpenVPN release process topics
+ - There was a request on [GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well.
+ - Djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
+ - We could do this during a next release.
+
+ ### OpenVPN 2.6 performance results
+ - Tests should cover: GRE, IPSec, userland, DCO
+ - Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this
+ - When time available will do it
+
+ ### What's going on with new taskbar icons?
+ - Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** will be picked up by Selva when he has time
+
+ ### security@openvpn.net mailing list
+ - The company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - The company guy took the standard NDA we use for contractors, suggests using that.
+ - Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ ### Another key signing topic
+ - The company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
+
+ ### SBOM topic
+ - Cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ ### Forums machine on community infrastructure is only non-Linux system
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ ### Management interface documentation on main website will be updated with info from doc/management-notes.txt
+ - Novaflash will pick this up at some point
+
+ ### [OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - Novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-10-18.md
@@ 0,0 1,93 @@
+ # Basic info
+
+ - **Time:** Wednesday 18 October 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Closed: Community Hackathon 2023 meeting**
+ - This was held in Orihuela Costa 6-8 October.
+ - For a summary see [Hackathon 2023](wiki:Hackathon2023)
+
+ - **Closed: Weekly meeting summaries by email**
+ - It was decided novaflash will do meeting summaries on wiki and send a copy to the devel mailing list.
+ - novaflash has joined the openvpn-devel mailing list and will send out these meeting summaries.
+
+ - **Updated: Website release process woes**
+ - There is actual movement on this now, they're moving the Community Downloads content now to another CMS.
+ - They will also move Security Advisories to this other CMS as well so both can be updated independently from website updates.
+
+ - **Updated: OpenVPN 2.6.7 release**
+ - CMake backport is in.
+ - Originally planned for 18 October, but it will be postponed a little but still expected to go out in October.
+ - Reason: there are a number of outstanding issues ready to be merged that we want to get in, this takes a bit more time.
+ - Also, there is a div-by-zero bug we want to get out soon so we'd rather delay 2.6.7 slightly to get it in.
+
+ - **Updated: License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - A new version of James Bottomley's patch is needed as it broke openssl 1.0.2 and libressl. Plaisthos will look into this.
+ - Then dazo can review things so we can decide if we can finalize this.
+ - One of the tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary.
+
+ - **Updated: OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ - **Security assessment of OpenVPN2 codebase.**
+ - Update 27 September: publishing this is currently being handled, it requires some preparation and internal reviews that are ongoing.
+
+ - **Tunnelcrack published now [https://tunnelcrack.mathyvanhoef.com](https://tunnelcrack.mathyvanhoef.com)**
+ - A post was published at [TunnelCrack community wiki article](wiki:TunnelCrack)
+ - More details are in the Hackathon2023 meeting summary.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [GitHub doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ - **openvpn release process topics**
+ - There was a request on [GitHub issue](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well.
+ - djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
+ - We could do this during a next release.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: gre, ipsec, userland, dco
+ - Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this
+ - When time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [GitHub issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** will be picked up by selva when he has time
+
+ - **security@openvpn.net mailing list**
+ - The company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - Company guy took the standard NDA we use for contractors, suggests to use that.
+ - novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ - **Another key signing topic**
+ - Company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
+
+ - **SBOM topic**
+ - cron2 was asked if openvpn has a software bill of materials. The answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do
+ - When we pick up this task we can coordinate on it.
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
+ - ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - novaflash will pick this up at some point
+
+ - **[https://openvpn.net/community-resources/openvpn-quickstart/](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
+ - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
+ - novaflash will pick this up again as time permits and other more important topics are done.
\ No newline at end of file
/dev/null .. meetings/2023-10-25.md
@@ 0,0 1,85 @@
+ # Basic Info
+
+ - **Time:** Wednesday 25 October 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **Updated: Publish security assessment of OpenVPN2 codebase on main website.**
+ - Approvals and preparations are done for this.
+ - Marketing decided to make it a larger topic and include past security assessments.
+ - Expected to be published within the next 3 weeks.
+
+ - **Updated: License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - The OpenSSL James Bottomley stuff is resolved now.
+ - The --tls-export-cert feature needs to be removed by dazo and reimplemented by plaisthos.
+ - Then it is up to dazo to review things so we can work on finalizing this.
+ - One of the tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary.
+ - For new contributions the new license already applies so maxf is unblocked to implement mbedtls3 support on master.
+ - maxf mentioned he will look into how much work it is to backport mbedtls3 to 2.6.
+
+ - **Updated: OpenVPN 2.6.7 release**
+ - CMake backport is in.
+ - We are working on some outstanding patches that we are working to get in.
+ - Also there is a div-by-zero bug we want to get out soon so we're waiting until that is in.
+
+ - **Tunnelcrack published now [https://tunnelcrack.mathyvanhoef.com](https://tunnelcrack.mathyvanhoef.com)**
+ - A post was published at [TunnelCrack community wiki article](https://wiki.openvpn.net/TunnelCrack)
+ - More details are in the Hackathon2023 meeting summary.
+
+ - **OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ - **Website release process woes**
+ - There is actual movement on this now, they're moving the Community Downloads content now to another CMS.
+ - They will also move Security Advisories to this other CMS as well so both can be updated independently from website updates.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - Company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ - **OpenVPN release process topics**
+ - There was a request in [https://github.com/OpenVPN/openvpn/issues/397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well.
+ - Djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
+ - We could do this during a next release.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: GRE, IPSec, userland, DCO
+ - Platforms: Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this
+ - When time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** will be picked up by Selva when he has time.
+
+ - **security@openvpn.net mailing list**
+ - Company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - Company guy took standard NDA we use for contractors, suggests using that.
+ - Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ - **Another key signing topic**
+ - Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In future, we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
+
+ - **SBOM topic**
+ - Cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do
+ - When we pick up this task we can coordinate on it.
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up at some point.
\ No newline at end of file
/dev/null .. meetings/2023-11-01.md
@@ 0,0 1,87 @@
+ # Basic Info
+
+ - **Time:** Wednesday 1 November 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ ### Updated: OpenVPN 2.6.7 Release
+ - CMake backport is in.
+ - We are working on some outstanding patches that we are working to get in.
+ - Also, there is a div-by-zero bug and a critical bug we want to get out soon so we're waiting until that is in.
+ - The patch for it is on the security mailing list and being reviewed by dazo and df12k.
+
+ ### Updated: Publish Security Assessment of OpenVPN2 Codebase on Main Website
+ - Approvals and preparations are done for this.
+ - Marketing sent a draft over internally, which was reviewed by novaflash and dazo and looks almost reasonable.
+ - Expected to be published within the next 2 weeks.
+
+ ### Updated: Tunnelcrack Published Now
+ - A post was published at [TunnelCrack Community Wiki Article](https://tunnelcrack.mathyvanhoef.com)
+ - More details are in the wiki:Hackathon2023 meeting summary.
+ - A security advisory went up on the main website [OpenVPN Security Advisories](https://openvpn.net/security-advisories/)
+
+ ### License Amendment for OpenVPN2 to Solve OpenSSL/mbedTLS Licensing Issues
+ - The OpenSSL James Bottomley stuff is resolved now.
+ - The --tls-export-cert feature needs to be removed by dazo and reimplemented by plaisthos.
+ - Then it is up to dazo to review things so we can work on finalizing this.
+ - One of the tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary.
+ - For new contributions, the new license already applies so maxf is unblocked to implement mbedTLS3 support on master.
+ - maxf mentioned he will look into how much work it is to backport mbedTLS3 to 2.6.
+
+ ### OpenVPN Community Meetup 2024
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ ### Website Release Process Woes
+ - There is actual movement on this now, they're moving the Community Downloads content now to another CMS.
+ - They will also move Security Advisories to this other CMS as well so both can be updated independently from website updates.
+
+ ### Static-Key Mini How-To is Outdated
+ - This page is outdated badly: [Static Key Mini HowTo](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [GitHub Doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) information and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ ### OpenVPN Release Process Topics
+ - There was a request on [GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well.
+ - djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
+ - We could do this during a next release.
+
+ ### OpenVPN 2.6 Performance Results
+ - Tests should cover: gre, ipsec, userland, dco
+ - Platforms: Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this.
+ - When time is available, we will do it.
+
+ ### What's Going on with New Taskbar Icons?
+ - matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** will be picked up by selva when he has time.
+
+ ### security@openvpn.net Mailing List
+ - The company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - Company guy took the standard NDA we use for contractors, suggests using that.
+ - novaflash thinks we should review that first to see if it's really suitable or not, as community members are not contractors after all.
+
+ ### Another Key Signing Topic
+ - Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
+
+ ### SBOM Topic
+ - cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM, so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ ### Forums Machine on Community Infrastructure is Only Non-Linux System
+ - mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.
+ - ecrist has looked at it, but the current state of the migration is unknown.
+
+ ### Management Interface Documentation on Main Website Will Be Updated with Info from doc/management-notes.txt
+ - novaflash will pick this up at some point.
\ No newline at end of file
/dev/null .. meetings/2023-11-08.md
@@ 0,0 1,85 @@
+ # Basic Info
+
+ - Time: Wednesday 8 November 2023 at 13:00 CEST (11:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ ### Updated: OpenVPN 2.6.7 Release
+ - There is a div-by-zero bug and a critical bug we were waiting to get fixed before proceeding.
+ - The patch for fixing both is on the security mailing list and has acks so will go in now.
+ - The release is expected to happen today.
+
+ ### Updated: Publish Security Assessment of OpenVPN2 Codebase on Main Website
+ - Expected to be published either this or next week.
+
+ ### Tunnelcrack Published Now
+ - A post was published at [TunnelCrack community wiki article](https://tunnelcrack.mathyvanhoef.com)
+ - More details are in the [Hackathon2023 meeting summary](https://wiki:TunnelCrack).
+ - A security advisory went up on the main website [OpenVPN Security Advisories](https://openvpn.net/security-advisories/)
+ - Current status: when mitigations start appearing we will mention them in meeting notes.
+
+ ### License Amendment for OpenVPN2 to Solve OpenSSL/MBedTLS Licensing Issues
+ - The OpenSSL James Bottomley stuff is resolved now.
+ - The `--tls-export-cert` feature needs to be removed by dazo and reimplemented by plaisthos.
+ - Then it is up to dazo to review things so we can work on finalizing this.
+ - One of the tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary.
+ - For new contributions, the new license already applies so maxf is unblocked to implement mbedtls3 support on master.
+ - maxf mentioned he will look into how much work it is to backport mbedtls3 to 2.6.
+
+ ### OpenVPN Community Meetup 2024
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ ### Website Release Process Woes
+ - There is actual movement on this now, they're moving the Community Downloads content now to another CMS.
+ - They will also move Security Advisories to this other CMS as well so both can be updated independently from website updates.
+
+ ### Static-Key Mini How-to is Outdated
+ - This page is badly outdated: [Static Key Mini How-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on info from the [GitHub Doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ ### OpenVPN Release Process Topics
+ - There was a request on [GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well.
+ - djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
+ - We could do this during a next release.
+
+ ### OpenVPN 2.6 Performance Results
+ - Tests should cover: GRE, IPSec, userland, DCO
+ - Platforms: Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this
+ - When time available will do it.
+
+ ### What's Going on with New Taskbar Icons?
+ - matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** will be picked up by selva when he has time.
+
+ ### Security@openvpn.net Mailing List
+ - The company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - The company guy took the standard NDA we use for contractors, suggests to use that.
+ - novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ ### Another Key Signing Topic
+ - The company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
+
+ ### SBOM Topic
+ - cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do
+ - When we pick up this task we can coordinate on it.
+
+ ### Forums Machine on Community Infrastructure is Only Non-Linux System
+ - mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.
+ - ecrist has looked at it but the current state of the migration is unknown.
+
+ ### Management Interface Documentation on Main Website Will Be Updated with Info from doc/management-notes.txt
+ - novaflash will pick this up at some point.
\ No newline at end of file
/dev/null .. meetings/2023-11-15.md
@@ 0,0 1,96 @@
+ # Basic info
+
+ - **Time:** Wednesday 15 November 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ ### Updated: OpenVPN 2.6.7 release
+ - The 2.6.7 release was made last week on November 9th 2023.
+ - There was a segfault crash reported that points to double check buffer leak code.
+ - There was a mention of fragment 0 not working anymore (since 2.6.1). This was from documentation 12 years old. But we can still look into handling this case better.
+ - There was a question from glcox on whether copr can hold older versions as well to rollback to. There are of course always options like using packages.openvpn.net for this or upstreaming to EPEL repos or such. But unfortunately copr has the limitation that it only can have one build. So there is no easy solution here with copr. The effort involved to get another solution is stopping us at this moment to implement a solution. dazo does mention that perhaps modules or streams for various versions on EPEL could be a solution. Ideally we'd have someone from EPEL repository to collaborate with.
+
+ ### New: OpenVPN 2.6.8 release
+ - There is a fix available for the crash in 2.6.7. We will put this into 2.6.8 and release soon.
+ - There are 2 patches from lev that will go in as well.
+ - Intention is to get this out this week (Friday likely).
+
+ ### New: donations for OpenVPN community
+ - There is currently no place to donate money to the community.
+ - The question is, do we want to allow donations? The answer is yes.
+ - We need to figure out how to deal with that legally, and what payment methods to accept and how.
+ - Probably credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions.
+ - We definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way.
+ - Random things yelled out (to investigate): legal entity? stripe? paypal? credit card? open collective? github sponsors? linux foundation? sf conservancy?
+
+ ### Updated: Publish security assessment of OpenVPN2 codebase on main website.
+ - Expected to be published this week.
+
+ ### Tunnelcrack progress [TunnelCrack community wiki article](wiki:TunnelCrack)
+ - Current status: when mitigations start appearing we will mention them in meeting notes.
+
+ ### License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues
+ - The OpenSSL James Bottomley stuff is resolved now.
+ - The --tls-export-cert feature needs to be removed by dazo and reimplemented by plaisthos.
+ - Then it is up to dazo to review things so we can work on finalizing this.
+ - One of the tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary.
+ - For new contributions the new license already applies so maxf is unblocked to implement mbedtls3 support on master.
+ - maxf mentioned he will look into how much work it is to backport mbedtls3 it to 2.6.
+
+ ### OpenVPN community meetup 2024
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ ### Website release process woes
+ - There is actual movement on this now, they're moving the Community Downloads content now to another CMS.
+ - They will also move Security Advisories to this other CMS as well so both can be updated independently from website updates.
+
+ ### Static-key mini how-to is outdated
+ - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [GitHub doc info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption
+
+ ### OpenVPN release process topics
+ - There was a request in [GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well.
+ - djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
+ - We could do this during a next release.
+
+ ### OpenVPN 2.6 performance results
+ - Tests should cover: GRE, IPsec, userland, DCO
+ - Platforms: Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this
+ - When time available will do it
+
+ ### What's going on with new taskbar icons?
+ - matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** will be picked up by selva when he has time
+
+ ### security@openvpn.net mailing list
+ - The company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - Company guy took standard NDA we use for contractors, suggests to use that.
+ - novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ ### Another key signing topic
+ - Company switched EV code signing to cloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In future we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
+
+ ### SBOM topic
+ - cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do
+ - When we pick up this task we can coordinate on it.
+
+ ### Forums machine on community infrastructure is only non-Linux system.
+ - mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
+ - ecrist has looked at it but the current state of the migration is unknown.
+
+ ### Management interface documentation on main website will be updated with info from doc/management-notes.txt
+ - novaflash will pick this up at some point
\ No newline at end of file
/dev/null .. meetings/2023-11-22.md
@@ 0,0 1,95 @@
+ # Basic info
+
+ - **Time:** Wednesday 22 November 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Closed: OpenVPN 2.6.7 release**
+ - 2.6.7 was released, and followed up with 2.6.8.
+
+ - **Closed: OpenVPN 2.6.8 release**
+ - 2.6.8 was released on Friday 17 November.
+
+ - **Updated: Publish security assessment of OpenVPN2 on main website.**
+ - Trail of Bits security audit of OpenVPN2 published: [https://openvpn.net/blog/trail-of-bits/](https://openvpn.net/blog/trail-of-bits/)
+
+ - **Updated: Website release process woes**
+ - Website team reports they are going to publish the new CMS for community downloads and security advisories next week.
+
+ - **New: TLS 1.0 PRF problem**
+ - OpenVPN has used a scheme based on the TLS 1.0 PRF with MD5+SHA1 in the past. Since OpenVPN 2.6.0+ and 3.6.0+ using Keying Material Exporters (RFC 5705) is preferred as a modern alternative to that.
+ - If one or both sides are older versions of OpenVPN like 2.5 and use the older method of making key material, there can be a problem.
+ - For example, on platforms like RHEL9 with FIPS enabled, you cannot use TLS 1.0 PRF with MD5+SHA1. So even for these special cases, MD5 has become impossible in this particular situation.
+ - As a practical example, this means OpenVPN 2.5 on RHEL9 with FIPS enabled cannot work at all. But 2.6 does work because it uses TLS export, but only if the other side supports TLS export too.
+ - We should first of all document this. But second, having a self-test in OpenVPN that warns of this situation can be beneficial.
+
+ - **Updated: License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - For new contributions the new license already applies.
+ - The --tls-export-cert option needs to be removed, and reimplemented. dazo sent in the patch to remove it, plaisthos will reimplement it.
+ - Then it is up to dazo to review things so we can work on finalizing this.
+ - One of the last tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary.
+
+ - **Donations for OpenVPN community**
+ - There is currently no place to donate money to the community.
+ - The question is, do we want to allow donations? The answer is yes.
+ - We need to figure out how to deal with that legally, and what payment methods to accept and how.
+ - Probably credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions.
+ - We definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way.
+ - Random things yelled out (to investigate): legal entity? Stripe? PayPal? Credit card? Open Collective? GitHub Sponsors? Linux Foundation? SF Conservancy?
+
+ - **Tunnelcrack progress**
+ - Current status: when mitigations start appearing we will mention them in meeting notes.
+ - [TunnelCrack community wiki article](wiki:TunnelCrack)
+
+ - **OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [this GitHub document](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc. Having a simple guide online will help adoption.
+
+ - **Openvpn release process topics**
+ - There was a request in [GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well.
+ - djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
+ - We could do this during a next release.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: GRE, IPSec, userland, DCO
+ - Platforms: Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this
+ - When time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - **Update:** will be picked up by Selva when he has time.
+
+ - **security@openvpn.net mailing list**
+ - The company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - Company guy took standard NDA we use for contractors, suggests to use that.
+ - Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ - **Another key signing topic**
+ - Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In future, we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
+
+ - **SBOM topic**
+ - cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ - **Forums machine on community infrastructure is the only non-Linux system.**
+ - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.
+ - Ecrist has looked at it but the current state of the migration is unknown.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up at some point.
\ No newline at end of file
/dev/null .. meetings/2023-11-29.md
@@ 0,0 1,89 @@
+ # Basic info
+
+ - **Time:** Wednesday 29 November 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **Meeting today cancelled due to lack of attendance**
+
+ - **Publish security assessment of OpenVPN2 on main website.**
+ _Trail of Bits security audit of OpenVPN2 published:_ [https://openvpn.net/blog/trail-of-bits/](https://openvpn.net/blog/trail-of-bits/)
+
+ - **Website release process woes**
+ _Website team reports they are going to publish the new CMS for community downloads and security advisories next week._
+
+ - **TLS 1.0 PRF problem**
+ _OpenVPN has used a scheme based on the TLS 1.0 PRF with MD5+SHA1 in the past. Since OpenVPN 2.6.0+ and 3.6.0+ using Keying Material Exporters (RFC 5705) is preferred as modern alternative to that._
+ _If one or both sides are older versions of OpenVPN like 2.5 and use the older method of making key material, there can be a problem._
+ _For example, on platforms like RHEL9 with FIPS enabled, you cannot use TLS 1.0 PRF with MD5+SHA1. So even for these special cases MD5 has become impossible in this particular situation._
+ _As a practical example, this means OpenVPN 2.5 on RHEL9 with FIPS enabled cannot work at all. But 2.6 does work because it uses TLS export, but only if the other side supports TLS export too._
+ _We should first of all document this. But second, having a self-test in OpenVPN that warns of this situation can be beneficial._
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ _For new contributions the new license already applies._
+ _The --tls-export-cert option needs to be removed, and reimplemented. dazo sent in the patch to remove it, plaisthos will reimplement it._
+ _Then it is up to dazo to review things so we can work on finalizing this._
+ _One of the last tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary._
+
+ - **Donations for OpenVPN community**
+ _There is currently no place to donate money to the community._
+ _The question is, do we want to allow donations? The answer is yes._
+ _We need to figure out how to deal with that legally, and what payment methods to accept and how._
+ _Probably credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions._
+ _We definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way._
+ _Random things yelled out (to investigate): legal entity? stripe? PayPal? credit card? open collective? GitHub sponsors? Linux foundation? sf conservancy?_
+
+ - **Tunnelcrack progress** [TunnelCrack community wiki article](/wiki/TunnelCrack)
+ _Current status: when mitigations start appearing we will mention them in meeting notes._
+
+ - **OpenVPN community meetup 2024**
+ _Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome._
+ _Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged._
+ _When: At the moment tentatively set to 20-22 September 2024._
+ _Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest._
+ _Shirts: There is plenty of time still to prepare a shirt design._
+
+ - **Static-key mini how-to is outdated.**
+ _This page is outdated badly:_ [Static Key Mini How-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ _Company will send this to tech writer to redo based on [GitHub Example Fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc._
+ _Having a simple guide online will help adoption._
+
+ - **OpenVPN release process topics**
+ _There was a request in [GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well. We could do this during a next release._
+
+ - **OpenVPN 2.6 performance results.**
+ _Tests should cover: GRE, IPSec, userland, DCO
+ Linux, FreeBSD, Windows
+ Requires time to be dedicated to doing this
+ When time available will do it._
+
+ - **What's going on with new taskbar icons?**
+ _Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
+ _**Update:** will be picked up by Selva when he has time._
+
+ - **security@openvpn.net mailing list**
+ _Company is trying to get to SOC2 compliance._
+ _Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net._
+ _Company guy took standard NDA we use for contractors, suggests to use that._
+ _Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all._
+
+ - **Another key signing topic**
+ _Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing._
+ _In future, we could possibly switch community to that same key. Saves having to maintain 2 different keys._
+ _Depends on how hard/easy it is to access company key signing thing from community infrastructure._
+ _Also no high priority at the moment, we have a working solution now._
+
+ - **SBOM topic**
+ _Cron2 was asked if OpenVPN has a software bill of materials. Answer was no._
+ _Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do._
+ _When we pick up this task we can coordinate on it._
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ _Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist._
+ _Ecrist has looked at it but the current state of the migration is unknown._
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ _Novaflash will pick this up at some point._
\ No newline at end of file
/dev/null .. meetings/2023-12-06.md
@@ 0,0 1,85 @@
+ # Basic info
+
+ - **Time:** Wednesday 6 December 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **New: spam on forums.**
+ - "It just keeps coming. We need a solution."
+ - "Asked pippin_ if he could maybe get attention from ecrist to try and solve this."
+
+ - **Updated: Website release process woes**
+ - "Website team continues to report that they are on the verge of launching the new stuff."
+ - "But there is a release freeze planned for last weeks of December so we may not actually get it this year."
+
+ - **Updated: TLS 1.0 PRF problem**
+ - "A patch for this has been created and it needs reviews."
+
+ - **Updated: License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - "For new contributions the new license already applies."
+ - "The --tls-export-cert code was removed, and plaisthos will reimplement it."
+ - "Then it is up to dazo to review things so we can work on finalizing this."
+ - "One of the last tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary."
+
+ - **New: OpenVPN 2.6.9 release**
+ - "After --export-peer-cert/--tls-export-cert issue is clarified and code merged, we feel we're ready for a new release."
+ - "Tentatively next week."
+
+ - **Donations for OpenVPN community**
+ - "There is currently no place to donate money to the community."
+ - "The question is, do we want to allow donations? The answer is yes."
+ - "We need to figure out how to deal with that legally, and what payment methods to accept and how."
+ - "Probably credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions."
+ - "We definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way."
+ - "Random things yelled out (to investigate): legal entity? stripe? PayPal? credit card? open collective? GitHub sponsors? Linux foundation? sf conservancy?"
+
+ - **Tunnelcrack progress** [TunnelCrack community wiki article](https://openvpn.net/wiki/TunnelCrack)
+ - "Current status: when mitigations start appearing we will mention them in meeting notes."
+
+ - **OpenVPN community meetup 2024**
+ - "Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome."
+ - "Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged."
+ - "When: At the moment tentatively set to 20-22 September 2024."
+ - "Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest."
+ - "Shirts: There is plenty of time still to prepare a shirt design."
+
+ - **Static-key mini how-to is outdated.**
+ - "This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)"
+ - "Company will send this to tech writer to redo based on [GitHub doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc."
+ - "Having a simple guide online will help adoption."
+
+ - **OpenVPN 2.6 performance results.**
+ - "Tests should cover: GRE, IPSec, userland, DCO, Linux, FreeBSD, Windows."
+ - "Requires time to be dedicated to doing this."
+ - "When time available will do it."
+
+ - **What's going on with new taskbar icons?**
+ - "Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)"
+ - "**Update:** will be picked up by selva when he has time."
+
+ - **security@openvpn.net mailing list**
+ - "Company is trying to get to SOC2 compliance."
+ - "Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net."
+ - "Company guy took standard NDA we use for contractors, suggests to use that."
+ - "Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all."
+
+ - **Another key signing topic**
+ - "Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing."
+ - "In future we could possibly switch community to that same key. Saves having to maintain 2 different keys."
+ - "Depends on how hard/easy it is to access company key signing thing from community infrastructure."
+ - "Also no high priority at the moment, we have a working solution now."
+
+ - **SBOM topic**
+ - "Cron2 was asked if OpenVPN has a software bill of materials. Answer was no."
+ - "Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do."
+ - "When we pick up this task we can coordinate on it."
+
+ - **Forums machine on community infrastructure is only non-Linux system.**
+ - "Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist."
+ - "Ecrist has looked at it but the current state of the migration is unknown."
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - "Novaflash will pick this up at some point."
\ No newline at end of file
/dev/null .. meetings/2023-12-13.md
@@ 0,0 1,91 @@
+ # Basic info
+
+ - **Time:** Wednesday 13 December 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ ### **Updated: OpenVPN 2.6.9 release**
+ In discussion with community members looks like next week would be a good time for a 2.6.9 release.
+
+ ### **Updated: forums topics**
+ - Pippin_ and novaflash reported lots of spam on the forums. rob0 got into contact with ecrist, looks like anti-spam module had expired. It was renewed.
+ - ecrist suggests to decouple authentication system for forums from community PWM. Almost all forum users never use other community resources, so it makes sense.
+ - There is the pending migration from BSD to Linux for the forums machine.
+ - In collaboration with ecrist, we'll look into arranging for OpenVPN Inc. to provide a new VM and a license for vBulletin. ecrist can then convert the existing forums content.
+ - Regarding CloudFlare; currently not enabled on forums, but we will enable it on the new VM.
+
+ ### **New: community funding**
+ - ordex has an initiative he wants to bring up regarding dev resources to be added to community.
+ - This may tie into the donations topic.
+ - In short ordex convinced OTF (Open Tech Fund) to provide a "test FOSS funding scheme" to OpenVPN.
+ - This would for example allow to pay for allocated hours for mattock and cron2 to work on OpenVPN community tasks.
+ - This is to be worked out more and in collaboration between OpenVPN Community, OpenVPN Inc., and OTF.
+
+ ### **Updated: Donations for OpenVPN community**
+ - There is currently no place to donate money to the community, and we do want to allow that.
+ - We need to figure out how to deal with that legally, and what payment methods to accept and how.
+ - Probably credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions.
+ - We definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way.
+ - Random things yelled out (to investigate): legal entity? stripe? PayPal? credit card? open collective? GitHub sponsors? Linux foundation? sf conservancy?
+ - ordex suggested that he will take a look in January to figure out what legalities etc. are involved in getting a legal entity for OpenVPN community.
+
+ ### **Website release process woes**
+ - Website team continues to report that they are on the verge of launching the new stuff.
+ - But there is a release freeze planned for last weeks of December so we may not actually get it this year.
+
+ ### **TLS 1.0 PRF problem**
+ A patch for this has been created and it needs reviews.
+
+ ### **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - For new contributions the new license already applies.
+ - The --tls-export-cert code was removed, and plaisthos will reimplement it.
+ - Then it is up to dazo to review things so we can work on finalizing this.
+ - One of the last tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary.
+
+ ### **Tunnelcrack progress**
+ Current status: when mitigations start appearing we will mention them in meeting notes. [TunnelCrack community wiki article](wiki:TunnelCrack)
+
+ ### **OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ ### **Static-key mini how-to is outdated.**
+ This page is outdated badly: [Static-key mini how-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [GitHub document](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) information and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ ### **OpenVPN 2.6 performance results.**
+ - Tests should cover: GRE, IPSec, userland, DCO
+ - Platforms: Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this
+ - When time available will do it.
+
+ ### **What's going on with new taskbar icons?**
+ - Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time.
+
+ ### **Security mailing list**
+ - The company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - Company guy took the standard NDA we use for contractors, suggests to use that.
+ - Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ ### **Another key signing topic**
+ - Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In future, we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
+
+ ### **SBOM topic**
+ - Cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ ### **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up at some point.
\ No newline at end of file
/dev/null .. meetings/2023-12-20.md
@@ 0,0 1,117 @@
+ # Basic Info
+
+ - **Time:** Wednesday 20 December 2023 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ ### New: No Meeting on 27th December or 3 January
+ - Normal meetings to resume on January 10, 2024.
+
+ ### Updated: OpenVPN 2.6.9 Release
+ - Given that we're close to the end of the year, we'll push this to next year.
+ - The --tls-export-cert PR needs a little love first.
+ - Tentative new release date is January 10.
+
+ ### Updated: Forums Topics
+ - There has been a lot of spam. An antispam module had expired. We fixed that, but there's still the occasional bit of spam.
+ - We agreed in the last meeting to commit to getting a new VM and switch to vBulletin and disconnecting from community LDAP logins.
+ - The new VM is delivered, the license should be delivered this week too, so then ecrist can get to work.
+ - Regarding CloudFlare, currently not enabled on forums, but we will enable it at some point on the new VM.
+
+ ### New: Status of Trac/Wiki
+ - ordex wanted to discuss the state of trac/wiki. Do we move to something else? Do we update existing?
+ - mattock has been volunteered to look into alternatives.
+ - It must be open source. Self-hosted or hosted open-source both fine.
+ - There is no hard requirement for LDAP capability.
+ - Should have access controls so only approved members can edit.
+
+ ### New: Status of Community LDAP Sign-in Solution
+ - We use it currently for forums, wiki, gerrit, patchwork. We are seriously considering getting rid of it.
+ - The reality is that 99.99% of forums users do not interact with the other tools.
+ - And that the small group of contributors to wiki and gerrit does not justify the need for an LDAP sign-in solution.
+ - So we're inclined to disconnect from LDAP. For the forums, we already intend to do that now.
+ - No final decision reached at this time. Considering our options.
+
+ ### New: Packet Header Order
+ - plaisthos wanted to get a consensus/decision on whether we do that as part of the rekeying improvements.
+ - Generally in favor of adding a new negotiable packet format, so long as plaisthos and syzzer are in agreement.
+
+ ### New: Plan to Improve Server Side Testing
+ - mattock posted a plan to improve server-side testing. mattock would like to get eyes on this and feedback.
+
+ ### Updated: TLS 1.0 PRF Problem
+ - Patches for this have been created and are in review, have not made it in yet.
+
+ ### Community Funding
+ - ordex has an initiative he wants to bring up regarding dev resources to be added to the community.
+ - This may tie into the donations topic.
+ - In short, ordex convinced OTF (Open Tech Fund) to provide a "test FOSS funding scheme" to OpenVPN.
+ - This would, for example, allow paying for allocated hours for mattock and cron2 to work on OpenVPN community tasks.
+ - This is to be worked out more and in collaboration between OpenVPN Community, OpenVPN Inc., and OTF.
+
+ ### Donations for OpenVPN Community
+ - There is currently no place to donate money to the community, and we do want to allow that.
+ - We need to figure out how to deal with that legally, and what payment methods to accept and how.
+ - Probably, a credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions.
+ - We definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way.
+ - Random things yelled out (to investigate): legal entity? stripe? PayPal? credit card? open collective? GitHub sponsors? Linux foundation? sf conservancy?
+ - ordex suggested that he will take a look in January to figure out what legalities etc. are involved in getting a legal entity for OpenVPN community.
+
+ ### Website Release Process Woes
+ - Website team continues to report that they are on the verge of launching the new stuff.
+ - But there is a release freeze planned for the last weeks of December, so we may not actually get it this year.
+
+ ### License Amendment for OpenVPN2 to Solve OpenSSL/mbedTLS Licensing Issues
+ - For new contributions, the new license already applies.
+ - The --tls-export-cert code was removed, and plaisthos will reimplement it.
+ - Then it is up to dazo to review things so we can work on finalizing this.
+ - One of the last tasks is reviewing if remaining items are trivial patches and maybe get legal advice on those if necessary.
+
+ ### Tunnelcrack Progress
+ - Current status: when mitigations start appearing, we will mention them in meeting notes.
+
+ ### OpenVPN Community Meetup 2024
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to the openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ ### Static-key Mini How-to is Outdated
+ - This page is outdated badly: [Static Key Mini Howto](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on info from [GitHub doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ ### OpenVPN 2.6 Performance Results
+ - Tests should cover: GRE, IPSec, userland, DCO
+ - Platforms: Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this
+ - When time is available will do it.
+
+ ### What's Going on with New Taskbar Icons?
+ - matt provided icons in this [GitHub issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time.
+
+ ### Security Email List
+ - Company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - Company guy took the standard NDA we use for contractors, suggests to use that.
+ - novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ ### Another Key Signing Topic
+ - Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
+
+ ### SBOM Topic
+ - cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
+ - Coincidentally, in OpenVPN Inc, a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task, we can coordinate on it.
+
+ ### Management Interface Documentation on Main Website Will Be Updated
+ - Information from doc/management-notes.txt will be updated.
+ - novaflash will pick this up at some point.
\ No newline at end of file
/dev/null .. meetings/2024-01-10.md
@@ 0,0 1,132 @@
+ # Basic info
+
+ - **Time**: Wednesday 10 January 2024 at 13:00 CEST (11:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ - **New: small security issue reported in OpenVPN GUI**
+ - *lev is looking into this.*
+ - *dazo will work with lev to arrange a CVE report.*
+
+ - **Mattock needs things to do**
+ - [TracWikiReplacements](https://community.openvpn.net/openvpn/wiki/TracWikiReplacements)
+ - There are a couple of potential Wiki alternatives in that list
+ - More research or deploy something to get some experience on the options?
+ - [ServerSideTestingImprovementPlan](https://community.openvpn.net/openvpn/wiki/ServerSideTestingImprovementPlan)
+ - Do we want to start doing some improvements on this front? If so, which would be a priority?
+ - Buildbot
+ - Mattock set up Buildbot master successfully on Ubuntu 20.04 (current production instance?) as well as Ubuntu 22.04 and Ubuntu 23.10
+ - Any buildbot-related improvement we could do?
+ - Maybe building snapshot packages (deb/rpm) in buildbot and publishing them automatically?
+ - The pragmatic way would be to use FPM instead of "official" packaging tools
+ - Cloudfront + S3 + aptly might be a good solution for public repos with minimal/non-existent management overhead
+
+ - **Closed: No meeting on 27th December or 3 January.**
+ - *Normal meetings to resume on January 10 2024.*
+
+ - **OpenVPN 2.6.9 release**
+ - *Given that we're so close to end of year, we'll push this to next year.*
+ - *The --tls-export-cert PR needs a little love first.*
+ - *Tentative new release date is January 10.*
+
+ - **Forums topics**
+ - *There has been a lot of spam. An antispam module had expired. We fixed that. But there's still the occasional bit of spam.*
+ - *We agreed in last meeting to commit to a path to get a new VM and switch to vBulletin and disconnect from community LDAP logins.*
+ - *The new VM is delivered, the license should be delivered this week too, so then ecrist can get to work.*
+ - *Regarding CloudFlare, currently not enabled on forums, but we will enable it at some point on the new VM.*
+
+ - **Status of trac/wiki**
+ - *ordex wanted to discuss state of trac/wiki. Do we move to something else? Do we update existing?*
+ - *mattock has been volunteered to look into alternatives.*
+ - *It must be open source. Self-hosted or hosted open-source both fine.*
+ - *There is no hard requirement for LDAP capability.*
+ - *Should have access controls so only approved members can edit.*
+
+ - **Status of community LDAP sign-in solution**
+ - *We use it currently for forums, wiki, gerrit, patchwork. We are seriously considering getting rid of it.*
+ - *The reality is that 99.99% of forums users do not interact with the other tools.*
+ - *And that the small group of contributors to wiki and gerrit does not justify the need for an LDAP sign-in solution.*
+ - *So we're inclined to disconnect from LDAP. For the forums we already intend to do that now.*
+ - *No final decision reached at this time. Considering our options.*
+
+ - **Packet header order**
+ - *plaisthos wanted to get consensus/decision on whether we do that as part of the rekeying improvements.*
+ - *Generally in favor of adding a new negotiable packet format, so long as plaisthos and syzzer are in agreement.*
+
+ - **Plan to improve server side testing**
+ - *mattock posted a plan to improve server side testing. mattock would like to get eyes on this and feedback.*
+
+ - **TLS 1.0 PRF problem**
+ - *Patches for this have been created and are in review, have not made it in yet.*
+
+ - **Community funding**
+ - *ordex has an initiative he wants to bring up regarding dev resources to be added to community.*
+ - *This may tie into the donations topic.*
+ - *In short ordex convinced OTF (Open Tech Fund) to provide a "test FOSS funding scheme" to OpenVPN.*
+ - *This would for example allow to pay for allocated hours for mattock and cron2 to work on OpenVPN community tasks.*
+ - *This is to be worked out more and in collaboration between OpenVPN Community, OpenVPN Inc., and OTF.*
+
+ - **Donations for OpenVPN community**
+ - *There is currently no place to donate money to the community, and we do want to allow that.*
+ - *We need to figure out how to deal with that legally, and what payment methods to accept and how.*
+ - *Probably credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions.*
+ - *We definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way.*
+ - *Random things yelled out (to investigate): legal entity? Stripe? PayPal? Credit card? Open Collective? GitHub Sponsors? Linux Foundation? SF Conservancy?*
+ - *ordex suggested that he will take a look in January to figure out what legalities etc are involved in getting a legal entity for OpenVPN community.*
+
+ - **Website release process woes**
+ - *Website team continues to report that they are on the verge of launching the new stuff.*
+ - *But there is a release freeze planned for last weeks of December so we may not actually get it this year.*
+
+ - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - *For new contributions the new license already applies.*
+ - *The --tls-export-cert code was removed, and plaisthos will reimplement it.*
+ - *Then it is up to dazo to review things so we can work on finalizing this.*
+ - *One of the last tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary.*
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)**
+ - *Current status: when mitigations start appearing we will mention them in meeting notes.*
+
+ - **OpenVPN community meetup 2024**
+ - *Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.*
+ - *Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.*
+ - *When: At the moment tentatively set to 20-22 September 2024.*
+ - *Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.*
+ - *Shirts: There is plenty of time still to prepare a shirt design.*
+
+ - **Static-key mini how-to is outdated.**
+ - *This page is outdated badly: [Static-key mini how-to](https://openvpn.net/community-resources/static-key-mini-howto/)*
+ - *Company will send this to tech writer to redo based on [example-fingerprint information](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.*
+ - *Having a simple guide online will help adoption.*
+
+ - **OpenVPN 2.6 performance results.**
+ - *Tests should cover: GRE, IPSec, userland, DCO; Linux, FreeBSD, Windows.*
+ - *Requires time to be dedicated to doing this.*
+ - *When time available will do it.*
+
+ - **What's going on with new taskbar icons?**
+ - *Matt provided icons in [GitHub issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595).*
+ - *Last update: will be picked up by selva when he has time.*
+
+ - **security@openvpn.net mailing list**
+ - *Company is trying to get to SOC2 compliance.*
+ - *Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net.*
+ - *Company guy took standard NDA we use for contractors, suggests to use that.*
+ - *Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.*
+
+ - **Another key signing topic**
+ - *Company switched EV code signing to CloudHSM, this is same cert type we use for driver signing, is also suitable for binary signing.*
+ - *In future we could possibly switch community to that same key. Saves having to maintain 2 different keys.*
+ - *Depends on how hard/easy it is to access company key signing thingee from community infrastructure.*
+ - *Also no high priority at the moment, we have a working solution now.*
+
+ - **SBOM topic**
+ - *Cron2 was asked if OpenVPN has a software bill of materials. Answer was no.*
+ - *Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.*
+ - *When we pick up this task we can coordinate on it.*
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - *Novaflash will pick this up at some point.*
\ No newline at end of file
/dev/null .. meetings/2024-01-17.md
@@ 0,0 1,135 @@
+ # Basic info
+
+ - **Time:** Wednesday 17 January 2024 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ ### New: small security issue reported in OpenVPN GUI
+ - lev is looking into this.
+ - dazo will work with lev to arrange a CVE report.
+
+ ### Mattock needs things to do
+ - [TracWikiReplacements](TracWikiReplacements)
+ - There are a couple of potential Wiki alternatives in that list
+ - More research or deploy something to get some experience on the options?
+ - [ServerSideTestingImprovementPlan](ServerSideTestingImprovementPlan)
+ - Do we want to start doing some improvements on this front? If so, which would be a priority?
+ - Buildbot
+ - Mattock set up Buildbot master successfully on Ubuntu 20.04 (current production instance?) as well as Ubuntu 22.04 and Ubuntu 23.10
+ - Any buildbot-related improvement we could do?
+ - Maybe building snapshot packages (deb/rpm) in buildbot and publishing them automatically?
+ - The pragmatic way would be to use FPM instead of "official" packaging tools
+ - Cloudfront + S3 + aptly might be a good solution for public repos with minimal/non-existent management overhead
+
+ ### Closed: No meeting on 27th December or 3 January.
+ - Normal meetings to resume on January 10 2024.
+
+ ### OpenVPN 2.6.9 release
+ - Given that we're so close to the end of the year, we'll push this to next year.
+ - The --tls-export-cert PR needs a little love first.
+ - Tentative new release date is January 10.
+
+ ### Forums topics
+ - There has been a lot of spam. An antispam module had expired. We fixed that. But there's still the occasional bit of spam.
+ - We agreed in the last meeting to commit to a path to get a new VM and switch to vBulletin and disconnect from community LDAP logins.
+ - The new VM is delivered, the license should be delivered this week too, so then ecrist can get to work.
+ - Regarding CloudFlare, currently not enabled on forums, but we will enable it at some point on the new VM.
+
+ ### Status of Trac/Wiki
+ - ordex wanted to discuss the state of Trac/Wiki. Do we move to something else? Do we update existing?
+ - mattock has been volunteered to look into alternatives.
+ - It must be open source. Self-hosted or hosted open-source both fine.
+ - There is no hard requirement for LDAP capability.
+ - Should have access controls so only approved members can edit.
+
+ ### Status of community LDAP sign-in solution
+ - We use it currently for forums, wiki, gerrit, patchwork. We are seriously considering getting rid of it.
+ - The reality is that 99.99% of forums users do not interact with the other tools.
+ - And that the small group of contributors to wiki and gerrit does not justify the need for an LDAP sign-in solution.
+ - So we're inclined to disconnect from LDAP. For the forums, we already intend to do that now.
+ - No final decision reached at this time. Considering our options.
+
+ ### Packet header order
+ - plaisthos wanted to get consensus/decision on whether we do that as part of the rekeying improvements.
+ - Generally in favor of adding a new negotiable packet format, so long as plaisthos and syzzer are in agreement.
+
+ ### Plan to improve server-side testing
+ - mattock posted [ServerSideTestingImprovementPlan](https://community.openvpn.net/openvpn/wiki/ServerSideTestingImprovementPlan#no1)
+ - It's a plan to improve server-side testing. mattock would like to get eyes on this and feedback.
+
+ ### TLS 1.0 PRF problem
+ - Patches for this have been created and are in review, have not made it in yet.
+
+ ### Community funding
+ - ordex has an initiative he wants to bring up regarding dev resources to be added to the community.
+ - This may tie into the donations topic.
+ - In short, ordex convinced OTF (Open Tech Fund) to provide a "test FOSS funding scheme" to OpenVPN.
+ - This would for example allow paying for allocated hours for mattock and cron2 to work on OpenVPN community tasks.
+ - This is to be worked out more and in collaboration between OpenVPN Community, OpenVPN Inc., and OTF.
+
+ ### Donations for OpenVPN community
+ - There is currently no place to donate money to the community, and we do want to allow that.
+ - We need to figure out how to deal with that legally, and what payment methods to accept and how.
+ - Probably plastic-money is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions.
+ - We definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way.
+ - Random things yelled out (to investigate): legal entity? stripe? paypal? plastic-money? open collective? GitHub sponsors? Linux foundation? sf conservancy?
+ - ordex suggested that he will take a look in January to figure out what legalities etc are involved in getting a legal entity for OpenVPN community.
+
+ ### Website release process woes
+ - Website team continues to report that they are on the verge of launching the new stuff.
+ - But there is a release freeze planned for the last weeks of December so we may not actually get it this year.
+
+ ### License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues
+ - For new contributions, the new license already applies.
+ - The --tls-export-cert code was removed, and plaisthos will reimplement it.
+ - Then it is up to dazo to review things so we can work on finalizing this.
+ - One of the last tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary.
+
+ ### Tunnelcrack progress
+ - [TunnelCrack community wiki article](wiki:TunnelCrack)
+ - Current status: when mitigations start appearing, we will mention them in meeting notes.
+
+ ### OpenVPN community meetup 2024
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to the openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ ### Static-key mini how-to is outdated.
+ - This page is outdated badly: [Static-key mini how-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [GitHub documentation](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ ### OpenVPN 2.6 performance results.
+ - Tests should cover: gre, ipsec, userland, dco
+ - Platforms: linux, freebsd, windows
+ - Requires time to be dedicated to doing this
+ - When time available will do it
+
+ ### What's going on with new taskbar icons?
+ - matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time
+
+ ### security@openvpn.net mailing list
+ - The company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - The company guy took the standard NDA we use for contractors, suggests using that.
+ - novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ ### Another key signing topic
+ - The company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access the company key signing thingee from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
+
+ ### SBOM topic
+ - cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do
+ - When we pick up this task, we can coordinate on it.
+
+ ### Management interface documentation on main website will be updated with info from doc/management-notes.txt
+ - novaflash will pick this up at some point.
\ No newline at end of file
/dev/null .. meetings/2024-01-24.md
@@ 0,0 1,134 @@
+ # Basic Info
+
+ - **Time:** Wednesday 24 January 2024 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current Topics
+
+ - **Closed: License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
+ - All work on this is now completed.
+
+ - **New: security mailing list procedure can stand improvement**
+ - To be discussed in more detail later.
+
+ - **Updated: tasks related to build processes (Mattock)**
+ - Buildbot can now skip builds that don't touch irrelevant files ([PR #31](https://github.com/OpenVPN/openvpn-buildbot/pull/31))
+ - Which file and/or directory changes should trigger the buildbot builds?
+ - Do we want the skipped builds to show up on the build state page? Or to be (almost) completely invisible to buildbot?
+ - We do not have answers right now to these questions but the fact that we can now skip irrelevant things is great.
+ - Extending the above: Have different Builders and build steps for different types of files
+ - We can have more than one Scheduler per project (e.g. openvpn)
+ - Each Scheduler can have a different Change Filters for builds that are relevant for that type of build
+ - Each Scheduler links to a set of Builders
+ - Each Builder runs different commands on the Worker (e.g. "autoreconf -vi && ./configure ..." or "do-something-else")
+ - Example Schedulers:
+ - **openvpn-default** Scheduler (=what we have now) would:
+ - Trigger normal builds on all builders
+ - No build would be triggered on documentation changes
+ - **openvpn-rst** Scheduler would:
+ - Trigger RST sanity check on one builder when .rst file changes
+
+ - **Updated: OpenVPN 2.6.9 release**
+ - There is a small security issue reported in OpenVPN for Windows installer.
+ - Once this is resolved we can make the 2.6.9 release.
+ - lev, selva, and d12fk, are looking into this at the moment.
+ - dazo will work with lev to arrange a CVE report.
+
+ - **Updated: forums topics**
+ - There has been a lot of spam. An antispam module had expired. We fixed that. But there's still the occasional bit of spam.
+ - ecrist looked into setting up a new forum. Discovered that migrating data is not possible.
+ - Suggested approach is to run both old and new side-by-side and let people finish discussions on old forums while new is up. Then after some time make the old forum read-only.
+ - Regarding CloudFlare, currently not enabled on forums, but we will enable it at some point on the new VM.
+
+ - **packet header order**
+ - plaisthos wanted to get consensus/decision on whether we do that as part of the rekeying improvements.
+ - Generally in favor of adding a new negotiable packet format, so long as plaisthos and syzzer are in agreement.
+ - Currently this is still in progress/discussion.
+
+ - **status of trac/wiki**
+ - ordex wanted to discuss state of trac/wiki. Do we move to something else? Do we update existing?
+ - mattock has been volunteered to look into alternatives.
+ - It must be open source. Self-hosted or hosted open-source both fine.
+ - There is no hard requirement for LDAP capability.
+ - Should have access controls so only approved members can edit.
+
+ - **status of community LDAP sign-in solution**
+ - We use it currently for forums, wiki, gerrit, patchwork. We are seriously considering getting rid of it.
+ - The reality is that 99.99% of forums users do not interact with the other tools.
+ - And that the small group of contributors to wiki and gerrit does not justify the need for an LDAP sign-in solution.
+ - So we're inclined to disconnect from LDAP. For the forums we already intend to do that now.
+ - No final decision reached at this time. Considering our options.
+
+ - **plan to improve server side testing**
+ - mattock posted a [plan to improve server side testing](https://community.openvpn.net/openvpn/wiki/ServerSideTestingImprovementPlan#no1).
+ - mattock would like to get eyes on this and feedback.
+
+ - **TLS 1.0 PRF problem**
+ - Patches for this have been created and are in review, have not made it in yet.
+
+ - **community funding**
+ - ordex has an initiative he wants to bring up regarding dev resources to be added to community.
+ - This may tie into the donations topic.
+ - In short ordex convinced OTF (Open Tech Fund) to provide a "test FOSS funding scheme" to OpenVPN.
+ - This would for example allow to pay for allocated hours for mattock and cron2 to work on OpenVPN community tasks.
+ - This is to be worked out more and in collaboration between OpenVPN Community, OpenVPN Inc., and OTF.
+
+ - **Donations for OpenVPN community**
+ - There is currently no place to donate money to the community, and we do want to allow that.
+ - We need to figure out how to deal with that legally, and what payment methods to accept and how.
+ - Probably plastic-money is a must. Maybe Paypal as well. Bitcoin seems to encounter some resistance in the discussions.
+ - We definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way.
+ - Random things yelled out (to investigate): legal entity? stripe? paypal? plastic-money? open collective? github sponsors? linux foundation? sf conservancy?
+ - ordex suggested that he will take a look in January to figure out what legalities etc are involved in getting a legal entity for OpenVPN community.
+
+ - **Website release process woes**
+ - Website team continues to report that they are on the verge of launching the new stuff.
+ - But there is a release freeze planned for last weeks of December so we may not actually get it this year.
+
+ - **Tunnelcrack progress**
+ - Current status: when mitigations start appearing we will mention them in meeting notes.
+ - [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)
+
+ - **OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - Company will send this to tech writer to redo based on [example fingerprint info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: GRE, IPsec, userland, DCO
+ - Platforms: Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this
+ - When time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time.
+
+ - **security@openvpn.net mailing list**
+ - Company is trying to get to SOC2 compliance.
+ - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
+ - Company guy took standard NDA we use for contractors, suggests to use that.
+ - novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
+
+ - **Another key signing topic**
+ - Company switched EV code signing to CloudHSM, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - In future we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
+
+ - **SBOM topic**
+ - cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
+ - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
+ - When we pick up this task we can coordinate on it.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - novaflash will pick this up at some point.
\ No newline at end of file
/dev/null .. meetings/2024-01-31.md
@@ 0,0 1,133 @@
+ # Basic info
+
+ - **Time:** Wednesday 31 January 2024 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ # Topics
+
+ ## Current topics
+
+ ### Closed: License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues
+ _All work on this is now completed._
+
+ ### New: security mailing list procedure can stand improvement
+ _To be discussed in more detail later._
+
+ ### Updated: tasks related to build processes (Mattock)
+ - Buildbot can now skip builds that don't touch irrelevant files ([PR #31](https://github.com/OpenVPN/openvpn-buildbot/pull/31))
+ - Which file and/or directory changes should trigger the buildbot builds?
+ - Do we want the skipped builds to show up on the build state page? Or to be (almost) completely invisible to buildbot?
+ - We do not have answers right now to these questions but the fact that we can now skip irrelevant things is great.
+ - Extending the above: Have different Builders and build steps for different types of files
+ - We can have more than one Scheduler per project (e.g. openvpn)
+ - Each Scheduler can have a different Change Filters for builds that are relevant for that type of build
+ - Each Scheduler links to a set of Builders
+ - Each Builder runs different commands on the Worker (e.g. "autoreconf -vi && ./configure ..." or "do-something-else")
+ - Example Schedulers:
+ - **openvpn-default** Scheduler (=what we have now) would:
+ - Trigger normal builds on all builders
+ - No build would be triggered on documentation changes
+ - **openvpn-rst** Scheduler would:
+ - Trigger RST sanity check on one builder when `.rst` file changes
+
+ ### Updated: OpenVPN 2.6.9 release
+ _There is a small security issue reported in OpenVPN for Windows installer._
+ _Once this is resolved we can make the 2.6.9 release._
+ _lev, selva, and d12fk, are looking into this at the moment._
+ _dazo will work with lev to arrange a CVE report._
+
+ ### Updated: forums topics
+ _There has been a lot of spam. An antispam module had expired. We fixed that. But there's still the occasional bit of spam._
+ _ecrist looked into setting up a new forum. Discovered that migrating data is not possible._
+ _Suggested approach is to run both old and new side-by-side and let people finish discussions on old forums while new is up. Then after some time make the old forum read-only._
+ _Regarding CloudFlare, currently not enabled on forums, but we will enable it at some point on the new VM._
+
+ ### packet header order
+ _plaisthos wanted to get consensus/decision on whether we do that as part of the rekeying improvements._
+ _Generally in favor of adding a new negotiable packet format, so long as plaisthos and syzzer are in agreement._
+ _Currently this is still in progress/discussion._
+
+ ### status of trac/wiki
+ _ordex wanted to discuss state of trac/wiki. Do we move to something else? Do we update existing?_
+ _mattock has been volunteered to look into alternatives._
+ _It must be open source. Self-hosted or hosted open-source both fine._
+ _There is no hard requirement for LDAP capability._
+ _Should have access controls so only approved members can edit._
+
+ ### status of community LDAP sign-in solution
+ _We use it currently for forums, wiki, gerrit, patchwork. We are seriously considering getting rid of it._
+ _The reality is that 99.99% of forums users do not interact with the other tools._
+ _And that the small group of contributors to wiki and gerrit does not justify the need for an LDAP sign-in solution._
+ _So we're inclined to disconnect from LDAP. For the forums we already intend to do that now._
+ _No final decision reached at this time. Considering our options._
+
+ ### plan to improve server side testing
+ _mattock posted [Server Side Testing Improvement Plan](https://community.openvpn.net/openvpn/wiki/ServerSideTestingImprovementPlan#no1)_
+ _It's a plan to improve server side testing. mattock would like to get eyes on this and feedback._
+
+ ### TLS 1.0 PRF problem
+ _Patches for this have been created and are in review, have not made it in yet._
+
+ ### community funding
+ _ordex has an initiative he wants to bring up regarding dev resources to be added to community._
+ _This may tie into the donations topic._
+ _In short ordex convinced OTF (Open Tech Fund) to provide a "test FOSS funding scheme" to OpenVPN._
+ _This would for example allow to pay for allocated hours for mattock and cron2 to work on OpenVPN community tasks._
+ _This is to be worked out more and in collaboration between OpenVPN Community, OpenVPN Inc., and OTF._
+
+ ### Donations for OpenVPN community
+ _There is currently no place to donate money to the community, and we do want to allow that._
+ _We need to figure out how to deal with that legally, and what payment methods to accept and how._
+ _Probably plastic-money is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions._
+ _We definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way._
+ _Random things yelled out (to investigate): legal entity? stripe? paypal? plastic-money? open collective? github sponsors? linux foundation? sf conservancy?_
+ _ordex suggested that he will take a look in January to figure out what legalities etc are involved in getting a legal entity for OpenVPN community._
+
+ ### Website release process woes
+ _Website team continues to report that they are on the verge of launching the new stuff._
+ _But there is a release freeze planned for last weeks of December so we may not actually get it this year._
+
+ ### Tunnelcrack progress
+ _Current status: when mitigations start appearing we will mention them in meeting notes._
+
+ ### OpenVPN community meetup 2024
+ _Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome._
+ _Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged._
+ _When: At the moment tentatively set to 20-22 September 2024._
+ _Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest._
+ _Shirts: There is plenty of time still to prepare a shirt design._
+
+ ### Static-key mini how-to is outdated.
+ _This page is outdated badly: [Static Key Mini How-to](https://openvpn.net/community-resources/static-key-mini-howto/)_
+ _company will send this to tech writer to redo based on [GitHub Info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc._
+ _having a simple guide online will help adoption_
+
+ ### OpenVPN 2.6 performance results.
+ _tests should cover: gre, ipsec, userland, dco_
+ _linux, freebsd, windows_
+ _requires time to be dedicated to doing this_
+ _when time available will do it_
+
+ ### What's going on with new taskbar icons?
+ _matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
+ _last update: will be picked up by selva when he has time_
+
+ ### security@openvpn.net mailing list
+ _company is trying to get to soc2 compliance._
+ _probably will need a simple nda to be signed by recipients of emails to security@openvpn.net_
+ _company guy took standard nda we use for contractors, suggests to use that._
+ _novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all._
+
+ ### Another key signing topic
+ _company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
+ _in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
+ _depends on how hard/easy it is to access company key signing thingee from community infrastructure._
+ _also no high priority at the moment, we have a working solution now._
+
+ ### SBOM topic
+ _cron2 was asked if openvpn has a software bill of materials. answer was no._
+ _coincidentally, in openvpn inc a security requirement is to have an SBOM so this is on our list of things to do_
+ _when we pick up this task we can coordinate on it._
+
+ ### Management interface documentation on main website will be updated with info from doc/management-notes.txt
+ _novaflash will pick this up at some point_
\ No newline at end of file
/dev/null .. meetings/2024-02-07.md
@@ 0,0 1,44 @@
+ * Adding explicit license for [openvpn-buildbot](https://github.com/OpenVPN/openvpn-buildbot)
+ * It should be clear under which terms the code can be used.
+ * Use GPLv2 or BSD-2-Clause and be done with it?
+
+ * Discussion: BSD-2 should be fine, mattock will prepare PR
+
+ * Pending Buildbot PRs
+ * [Only build openvpn when changing source code or build files](https://github.com/OpenVPN/openvpn-buildbot/pull/31)
+ * Which file changes should trigger a build? Current list is available [here](https://github.com/OpenVPN/openvpn-buildbot/pull/31/files#diff-15a627861a52f2d01f1aaa5969a64cfc8dd59803a9773b668a7c09c68a490535R510).
+ * Do we want to show skipped builds on the Buildbot status page or not?
+ * Even if not, we will still see the Changes (Git commits that could have triggered a build) in "Last changes" view.
+ * [Buildbot: do not run the full test suite if smoketests fail](https://github.com/OpenVPN/openvpn-buildbot/pull/32)
+ * Assumes that smoketests run on one or more *NIX-like workers without any configure flags
+ * Is this a fair assumption?
+
+ * Discussion:
+ * djpig has reviewed PR 32 and is working on deploying it
+ * PR 31 still needs review
+
+ * Wiki migration
+ * Xwiki and Wiki.js have been running for a few weeks now
+ * Can we move on to the next step?
+ * Pick one of the wikis now?
+ * Do more research on the wiki(s)?
+ * Decide to do nothing for now?
+
+ * Discussion:
+ * mattock will provide current links to replacement PoCs (see TracWikiReplacements) and we will revisit the topic next week
+
+ * Server-side testing
+ * We agreed to schedule a separate meeting to discuss server-side testing
+ * What would be a good time?
+
+ * Discussion:
+ * Need cron2 for agreeing on a time, but he wasn't in the meeting today, so let's try to discuss in #openvpn-devel when he is online
+
+ * 2.6.9 release
+ * Working on an easy-rsa fix on Windows 11. Not a regression, also openvpn-build only
+ * FreeBSD DCO fix merged today
+ * Windows security fix ready, openvpn-build only
+ * Tag openvpn on Monday?
+
+ * SBOM
+ * Fox IT would like to discuss SBOMs. MaxF will set up a meeting with djpig and uddr and a colleague. Tuesday 13th at 11:00 CET.
\ No newline at end of file
/dev/null .. meetings/2024-02-14.md
@@ 0,0 1,43 @@
+ # IrcMeetings
+
+ ## Pending Buildbot PRs
+ - [Add license file (BSD-2-Clause)](https://github.com/OpenVPN/openvpn-buildbot/pull/33)
+ - [Only build openvpn when changing source code or build files](https://github.com/OpenVPN/openvpn-buildbot/pull/31)
+ - The same mechanism can be used to do "special builds" like "only do documentation linting/validation documentation changes"
+ - [Buildbot: do not run the full test suite if smoketests fail](https://github.com/OpenVPN/openvpn-buildbot/pull/32)
+ - djpig's and mattock's tests indicate that it may be necessary to remove the buildmaster sqlite database (safe, but we lose history) when this change is merged - otherwise smoke tests would not run first
+
+ ## Buildbot
+ - Debian packaging is "ready" since a long time ago, but packages are not published anywhere
+ - Discussion:
+ - Mattock will resume work on this
+ - Mattock will do a PoC of [aptly](https://www.aptly.info/)
+ - Test if aptly would be better than freight which we have on build.openvpn.net for buildbot apt repos and/or official releases
+ - Agreed that using the same GPG signing key as on build.openvpn.net makes sense
+
+ ## Wiki migration
+ - Xwiki and Wiki.js have been running for a few weeks now
+ - Can we move on to the next step?
+ - Pick one of the wikis now?
+ - Do more research on the wiki(s)?
+ - Decide to do nothing for now?
+ - Discussion:
+ - Wiki.js seemed to be everyone's favorite
+ - Mattock will move forward with Wiki.js (unless somebody strongly objects by next community meeting)
+ - A new server is required eventually, but for now Samuli can use OTF AWS account for Wiki.js testing
+
+ ## Server-side testing
+ - We agreed to schedule a separate meeting to think about server-side testing
+ - What would be a good time?
+ - Discussion:
+ - cron2 wasn't in the meeting, again.
+
+ ## Easy-rsa in Windows installers
+ - easy-rsa has included pre-built Windows binaries for a long time. But with Windows 11 they do not seem to work correctly anymore in some cases. There is a plan to switch to a current version of busybox.exe instead. But the required changes to the Windows installer raise the question whether it is actually worth the effort. Does anyone use the included easy-rsa on Windows?
+ - Discussion:
+ - Decided to ask on openvpn-users ml and forums if people really care about easy-rsa in the Windows installers
+ - Depending on feedback we might drop it from the installer
+ - One alternative is to use "Windows Subsystem for Linux" which enables users to run easy-rsa in a Linux environment on Windows
+
+ ## 2.6.9
+ - Release was done on Monday
\ No newline at end of file
/dev/null .. meetings/2024-02-21.md
@@ 0,0 1,21 @@
+ # IrcMeetings
+
+ ## Pending Buildbot PRs
+ - [ChangeFilter according to touched files PR still pending](https://github.com/OpenVPN/openvpn-buildbot/pull/31)
+
+ ## Discussion:
+ - Plan to roll out the branch on buildbot-host-staging and test, especially against Gerrit. We can use the test "fake-ovpn" repository for this purpose.
+ - uddr proposed to extend the filter for Gerrit with additional checks, which should happen in a separate PR.
+
+ ## Server-side testing
+ - **Discussion:** Meeting time agreed for next Tuesday at 14:00 CET
+
+ ## Easy-rsa in Windows installers
+ - Request for feedback was posted on the -user mailing list and in the forum.
+
+ ## Discussion:
+ - Feedback indicates that easy-rsa is used on Windows, not necessarily for OpenVPN, but generally for managing PKI.
+ - It might be feasible to unbundle easy-rsa from the OpenVPN installer, though there is demand for a Windows version of it.
+ - For version 2.6.x, we should replace the old bundled executables with a recent version of busybox.exe. djpig will investigate whether to trust pre-compiled binaries (e.g., [frippery.org/busybox](https://frippery.org/busybox)) or build our own from source.
+ - For version 2.7, we could consider unbundling and creating a separate installer for easy-rsa. Further discussion needed on how this would be implemented.
+ - Some suggest using WSL (versions 1 and 2) as a solution for users, but there's skepticism about its feasibility for users not already using it.
\ No newline at end of file
/dev/null .. meetings/2024-02-28.md
@@ 0,0 1,19 @@
+ # IrcMeetings
+
+ ## Server-side testing
+ - Discussion: Meeting happened yesterday, some highlights:
+ - `cron2` will try to clean up his server-side testing infrastructure code and make it available publicly, probably at [GitHub OpenVPN Tests](https://github.com/OpenVPN/openvpn-tests)
+ - `mattock` will look into setting up some `--dev null` test suite which can run inside `make check` on UNIXy platforms
+ - `plaisthos` will look into enhancing `--dev null` with some lightweight IP stack so that it can simulate more things for testing
+ - Will review progress in next week's community meeting and decide whether another dedicated meeting is required
+
+ ## Wiki replacement
+ - Discussion: We decided to go with Wiki.js, but `mattock` has not had time to work on it yet
+
+ ## Publishing debian package snapshots
+ - Discussion: `mattock` says he made good progress on aptly PoC, will move ahead with that
+
+ ## Pending Buildbot PRs
+ - [ChangeFilter according to touched files PR](https://github.com/OpenVPN/openvpn-buildbot/pull/31) still pending
+ - Discussion:
+ - No activity this week
\ No newline at end of file
/dev/null .. meetings/2024-03-06.md
@@ 0,0 1,113 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 6 March 2024 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **New: openvpn 2.6.10 release**
+ - *There are some Windows related issues to be resolved in this release.*
+ - *Tentatively planned for end of next week.*
+
+ - **Updated: server-side testing status and next meeting**
+ - mattock has created a PoC of `--dev null` "does a client connect" check
+ - client config has `--dev null` and `ifconfig-noexec`
+ - uses an "up" script to stop the parent (openvpn) process gracefully soon after connection initialization
+ - the "up" script almost certainly includes some Linux-specifisms
+ - example usage:
+ - `openvpn --config client.conf | grep "Initialization Sequence Completed"`
+ - integration with "make check", buildbot, etc. is still missing
+ - next steps:
+ - integrate the PoC with "make check"
+ - make the script portable
+ - buildbot integration (if required separately)
+ - *We want to continue on this topic once a bit more progress has been made.*
+
+ - **Updated: forums topics**
+ - *A new forum is under construction. But already spammers have found it.*
+ - *Suggestion is to give openvpn_inc user novaflash and Pippin_ full admin rights so they can help find a solution and help maintain the forums.*
+ - *To be discussed with ecrist.*
+ - *Layout and categories look ok?*
+ - *Access for Mod to delete users that put spam url in profile and never post a message, currently I cannot discover a way to delete those(1)*
+ - *Related to above, Access for Mod to edit user profiles (asks for AdminCP password)(1)*
+ - *Mod guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)*
+ - *Access for mods to logs so one can see what others did*
+ - *Email confirmation on register?*
+ - *[Forgot password or user name?](https://forums-new.openvpn.net/lostpw) and [Contact](https://forums-new.openvpn.net/contact-us)?*
+ - *Considering some existing platform to do discussions next to forum?*
+ - *(1) May not be necessary if enough admin available*
+
+ - **Updated: website release process**
+ - *Finally they have come up with a solution that they will run by novaflash this week.*
+
+ - **New: breaking DCO changes, how to approach?**
+ - *This topic appeared but we do not have details on what this entails exactly.*
+ - *Perhaps ordex can provide details on what this is about, so we can have a meaningful discussion.*
+
+ - **Updated: Status of SBOM**
+ - *There was a discussion between MaxF and djpig and others.*
+ - *For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.*
+ - *The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.*
+
+ - **Updated: Debian and Ubuntu snapshot packages and buildbot**
+ - Cloudfront + S3 + aptly PoC is complete and seems to work fine
+ - Cloudfront caches need to be invalidated when new packages are added or removed, or the apt repository will end up in an inconsistent state almost immediately
+ - If we use swupdate.openvpn.net to publish the snapshots we will have to deal with cloudfront + cloudflare.
+ - We can choose to just publish snapshots on build.openvpn.net. This seems the preferred option.
+ - Alternatively, a new S3 bucket + cloudfront can be done. Whatever people like best.
+ - Buildbot integration is missing, but should be fairly straightforward
+ - This will probably have to wait until `--dev null` is done
+
+ - **status of trac/wiki**
+ - *No progress since last meeting.*
+ - *This will probably have to wait until `--dev null` is done*
+ - *Should have access controls so only approved members can edit.*
+
+ - **Security mailing list procedure can stand improvement**
+ - *To be discussed in more detail later.*
+
+ - **community funding**
+ - *ordex has an initiative he wants to bring up regarding dev resources to be added to community.*
+ - *This may tie into the donations topic.*
+ - *In short ordex convinced OTF (Open Tech Fund) to provide a "test FOSS funding scheme" to OpenVPN.*
+ - *This would for example allow to pay for allocated hours for mattock and cron2 to work on OpenVPN community tasks.*
+ - *This is to be worked out more and in collaboration between OpenVPN Community, OpenVPN Inc., and OTF.*
+
+ - **donation collection**
+ - *what are the options?*
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](wiki:TunnelCrack)**
+ - *Current status: when mitigations start appearing we will mention them in meeting notes.*
+
+ - **OpenVPN community meetup 2024**
+ - *Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.*
+ - *Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.*
+ - *When: At the moment tentatively set to 20-22 September 2024.*
+ - *Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.*
+ - *Shirts: There is plenty of time still to prepare a shirt design.*
+
+ - **Static-key mini how-to is outdated.**
+ - *This page is outdated badly: [Static Key Mini Howto](https://openvpn.net/community-resources/static-key-mini-howto/)*
+ - *company will send this to tech writer to redo based on [example fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc. Having a simple guide online will help adoption.*
+
+ - **OpenVPN 2.6 performance results.**
+ - *tests should cover: gre, ipsec, userland, dco*
+ - *linux, freebsd, windows*
+ - *requires time to be dedicated to doing this, when time available will do it*
+
+ - **What's going on with new taskbar icons?**
+ - *matt provided icons in [Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)*
+ - *last update: will be picked up by selva when he has time*
+
+ - **software code signing topic**
+ - *company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.*
+ - *in future we could possibly switch community to that same key. saves having to maintain 2 different keys.*
+ - *depends on how hard/easy it is to access company key signing thingee from community infrastructure.*
+ - *also no high priority at the moment, we have a working solution now.*
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - *novaflash will pick this up at some point*
\ No newline at end of file
/dev/null .. meetings/2024-03-13.md
@@ 0,0 1,128 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 13 March 2024 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **New: topic from an OpenVPN Inc contributor to community (illia)**
+ - Would like to discuss the `--inactive` option that disconnects a VPN when it is not sending/receiving more than the set seconds timeout.
+ - One part of it is that openvpn2 only counts outgoing packets and openvpn3 counts incoming and outgoing. Which is correct?
+ - Another part is the type of packets to count - this is all not so clear.
+ - For now, we are counting any packets and ICMP spam from the router resets inactive timeout very often for openvpn3 so it disconnects later than 2.
+ - Current proposal: count also incoming packets for openvpn2 and do not reset inactive timeout on ICMP packets for both ovpn3 and ovpn2.
+ - There was an argument made that "this is how it has been in openvpn2 forever and we had no complaints" but oddly the documentation claims incoming and outgoing is counted.
+ - After looking into this a bit some screwiness was found with tracking the data in openvpn2 that could use fixing, and illia will work on it.
+ - There is some voodoo happening in openvpn2 that skips inactive reset packets and similar magic is missing in ovpn3, so illia will work on that too.
+
+ - **New: breaking DCO changes, how to approach?**
+ - During the upstreaming process to the Linux kernel, some alterations had to be made.
+ - This made the updated implementation different enough from ovpn-dco-v2 that OpenVPN 2.6 won't work with it anymore.
+ - The plan is to adjust OpenVPN 2.6 so it can support the ovpn-dco-v2 delivered as out-of-tree kernel module, and the in-tree new kernel module.
+ - We can then update the out-of-tree kernel module to work in the new way and have a graceful transition period.
+ - So when it goes upstream and is in the Linux kernel, or DCO is installed out-of-tree, it will work the same.
+ - We can later decide on when to drop the support for ovpn-dco-v2 old methods.
+
+ - **Updated: openvpn 2.6.10 release**
+ - There are some Windows related issues to be resolved in this release.
+ - Was planned for this week - pushed to begin next week.
+
+ - **Updated: website release process**
+ - Next week a website release is planned that will enable a new way for updating Community Downloads page.
+ - The new way has a much faster release method separate from the rest of the website's release schedule.
+
+ - **Server-side testing status and next meeting**
+ - Mattock has created a PoC of `--dev null` "does a client connect" check.
+ - Client config has `--dev null` and `ifconfig-noexec`.
+ - Uses an "up" script to stop the parent (openvpn) process gracefully soon after connection initialization.
+ - The "up" script almost certainly includes some Linux-specifics.
+ - Example usage:
+ - `openvpn --config client.conf | grep "Initialization Sequence Completed"`
+ - Integration with `make check`, buildbot, etc. is still missing.
+ - Next steps:
+ - Integrate the PoC with `make check`.
+ - Make the script portable.
+ - Buildbot integration (if required separately).
+ - We want to continue on this topic once a bit more progress has been made.
+
+ - **Forums topics**
+ - A new forum is under construction. But already spammers have found it.
+ - Suggestion is to give openvpn_inc user novaflash and Pippin_ full admin rights so they can help find a solution and help maintain the forums.
+ - To be discussed with ecrist.
+ - Layout and categories look ok?
+ - Access for Mod to delete users that put spam URL in profile and never post a message.
+ - Related to above, Access for Mod to edit user profiles (asks for AdminCP password).
+ - Mod guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic).
+ - Access for mods to logs so one can see what others did.
+ - Email confirmation on register?
+ - [Forgot password or user name?](https://forums-new.openvpn.net/lostpw) and [Contact](https://forums-new.openvpn.net/contact-us).
+ - Considering some existing platform to do discussions next to the forum.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Debian and Ubuntu snapshot packages and buildbot**
+ - Cloudfront + S3 + aptly PoC is complete and seems to work fine.
+ - Cloudfront caches need to be invalidated when new packages are added or removed, or the apt repository will end up in an inconsistent state almost immediately.
+ - If we use swupdate.openvpn.net to publish the snapshots, we will have to deal with cloudfront + cloudflare.
+ - We can choose to just publish snapshots on build.openvpn.net. This seems the preferred option.
+ - Alternatively, a new S3 bucket + cloudfront can be done. Whatever people like best.
+ - Buildbot integration is missing, but should be fairly straightforward.
+ - This will probably have to wait until `--dev null` is done.
+
+ - **Status of trac/wiki**
+ - No progress since the last meeting.
+ - This will probably have to wait until `--dev null` is done.
+ - Should have access controls so only approved members can edit.
+
+ - **Security mailing list procedure can stand improvement**
+ - To be discussed in more detail later.
+
+ - **Community funding**
+ - Ordex has an initiative he wants to bring up regarding dev resources to be added to the community.
+ - This may tie into the donations topic.
+ - In short, ordex convinced OTF (Open Tech Fund) to provide a "test FOSS funding scheme" to OpenVPN.
+ - This would, for example, allow paying for allocated hours for mattock and cron2 to work on OpenVPN community tasks.
+ - This is to be worked out more and in collaboration between OpenVPN Community, OpenVPN Inc., and OTF.
+
+ - **Donation collection**
+ - What are the options?
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](wiki:TunnelCrack)**
+ - Current status: when mitigations start appearing, we will mention them in meeting notes.
+
+ - **OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [GitHub doc info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: gre, ipsec, userland, dco.
+ - Linux, FreeBSD, Windows.
+ - Requires time to be dedicated to doing this, when time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time.
+
+ - **Software code signing topic**
+ - The company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
+
+ - **Management interface documentation on the main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up at some point.
\ No newline at end of file
/dev/null .. meetings/2024-03-20.md
@@ 0,0 1,160 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 20 March 2024 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: openvpn 2.6.10 release**
+ - _This release should go out today._
+ - _It contains a number of security fixes focused on Windows._
+
+ - **OpenVPN 2.5.10 release**
+ - _According to our SupportedVersions guidelines we should do a release with the CVE fixes from 2.6._
+ - _But we don't promise Windows installers there. Given that these issues are all focused around Windows, we will do a best effort attempt to deliver it anyway._
+ - _This is something we'll pick up right after 2.6.10._
+
+ - **New: tunnelblick and sophos UTM**
+ - _Need to investigate this issue. Possibly a client side fix._
+
+ - **Updated: website release process**
+ - _This week a website release is planned that will enable a new way for updating Community Downloads page._
+ - _The new way has a much faster release method separate from the rest of the website's release schedule._
+ - _For today's release however the usual annoying method will be used to get it published on the main site._
+
+ - **Updated: forums topics**
+ - _ecrist has gone ahead and launched the new forums and locked the old forums._
+ - _The idea is that people and conversations migrate over to the new forums._
+ - _There are still some issues with the new forums that should be resolved._
+ - _The current situation is that old forums is new topics locked, and new forums has issues._
+ - _Discussed and agreed to ask ecrist to either fix new forums quickly or unlock new topics on old forums until we fix things._
+ - _email delivery seems not to be working. Email confirmation on registration was suggested._
+ - _Spammers found the new forums - but an anti-spam module was installed so that should solve this in theory._
+ - _Access to admin interface seems broken. Have to find out where the problem is exactly and solve it._
+ - _We still need to work on having some other people with some admin or high mod access._
+ - _Mod guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)_
+ - _Access for mods to logs so one can see what others did_
+
+ - **Updated: Security mailing list procedure can stand improvement**
+ - _dazo and novaflash will start discussing this internally in openvpn inc._
+ - _Goal of discussions is to work out a better internal procedure to connect security mailing list better with company product responsible people._
+
+ - **Updated: mattock topics**
+ - _Talked about mattock's --dev null server testing implementation._
+ - _Agreed that testing TCP and UDP servers and matching clients is a good start._
+ - _Mattock will also check if t_client.sh could be used and/or adapted to do the client-side of this equation._
+
+ - **community funding**
+ - _ordex has an initiative he wants to bring up regarding dev resources to be added to community._
+ - _This may tie into the donations topic._
+ - _In short ordex convinced OTF (Open Tech Fund) to provide a "test FOSS funding scheme" to OpenVPN._
+ - _This would for example allow to pay for allocated hours for mattock and cron2 to work on OpenVPN community tasks._
+ - _This is to be worked out more and in collaboration between OpenVPN Community, OpenVPN Inc., and OTF._
+
+ - **Updated: donation collection**
+ - _ordex consulted an expert and it looks like doing a legal entity does not make sense when you're just starting out._
+ - _The tricky part here is that only if we get a lot of donations and a lot of money does it make sense to have that kind of overhead._
+ - _What we can do is start out with a company that collects the money and puts it to good community use. ordex volunteers to take this on._
+ - _We want the donations to be collected in one place, and expenses made from that one place, so we are accountable._
+ - _We need to figure out how to deal with that legally, and what payment methods to accept and how._
+ - _Probably credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions._
+ - _And a reminder; we definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way._
+
+ - **inactive setting data counter in openvpn2 and openvpn3**
+ - _It looks like openvpn2 and openvpn3 handle the counting of traffic for this differently._
+ - _After some discussion it was decided illia will submit some suggested fixes._
+
+ - **Status of SBOM**
+ - _There was a discussion between MaxF and djpig and others._
+ - _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
+ - _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
+
+ - **status of trac/wiki**
+ - _No progress since last meeting._
+ - _This will probably have to wait until "--dev null" is done_
+ - _Should have access controls so only approved members can edit._
+
+ - **Tunnelcrack progress**
+ - _Current status: when mitigations start appearing we will mention them in meeting notes._
+
+ - **OpenVPN community meetup 2024**
+ - _Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome._
+ - _Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged._
+ - _When: At the moment tentatively set to 20-22 September 2024._
+ - _Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest._
+ - _Shirts: There is plenty of time still to prepare a shirt design._
+
+ - **Static-key mini how-to is outdated.**
+ - _This page is outdated badly: [Static-key Mini How-to](https://openvpn.net/community-resources/static-key-mini-howto/)_
+ - _The company will send this to tech writer to redo based on [Example Fingerprint doc on GitHub](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc._
+ - _Having a simple guide online will help adoption._
+
+ - **OpenVPN 2.6 performance results.**
+ - _Tests should cover: GRE, IPSec, userland, DCO_
+ - _Linux, FreeBSD, Windows_
+ - _Requires time to be dedicated to doing this, when time available will do it._
+
+ - **What's going on with new taskbar icons?**
+ - _Matt provided icons in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
+ - _Last update: will be picked up by Selva when he has time._
+
+ - **Software code signing topic**
+ - _The company switched EV code signing to cloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing._
+ - _In future we could possibly switch community to that same key. Saves having to maintain 2 different keys._
+ - _Depends on how hard/easy it is to access the company key signing thing from community infrastructure._
+ - _Also no high priority at the moment, we have a working solution now._
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - _Novaflash will pick this up at some point._
+
+ ### Mattock topics
+
+ #### --dev null server testing
+
+ Mattock has implemented the first version of the so-called "--dev null server testing" and integrated it with "make check". The features are:
+
+ - Does what it says on the tin (more on that later)
+ - Mostly operating system agnostic
+ - Should be POSIX shell compliant
+ - Uses the sample certificates and keys
+ - Supports running directly as root and with sudo
+ - Supports using different OpenVPN client versions
+ - The "current" (just compiled) version
+ - Any other OpenVPN versions (must be present on the filesystem)
+ - Support testing for success as well as failure
+ - Server configuration is currently static (i.e. no support for multiple server configurations yet)
+
+ Here's how it works:
+
+ 1. **make check**
+ 1. **t_server_null.sh**
+ 1. **t_server_null_server.sh**
+ - Launches the compiled OpenVPN as root (if necessary with sudo)
+ - OpenVPN server exits when all clients have been disconnected for ten seconds, based on its status file
+ 1. **t_server_null_client.sh**
+ - Launches each individual client test
+ - Client kills itself after some delay using an "--up" script
+
+ Current PoC code is available in mattock's "dev_null" branch. A good starting point is [t_server_null.sh](https://github.com/mattock/openvpn/blob/dev_null/tests/t_server_null.sh).
+
+ What should be the next steps?
+
+ - Basic approach ok?
+ - Is starting with a single server configuration ok?
+ - Which server configurations should we test against?
+ - Which client configurations should we test (success or failure)?
+ - Which operating systems do we want to support in this context? Linux and BSDs? Something more esoteric?
+ - Which OpenVPN client versions should we run?
+
+ #### Debian/Ubuntu snapshot publishing
+
+ - In the last meeting we agreed to publish snapshot Debian/Ubuntu packages on *build.openvpn.net*
+ - The tool to use to publish is [aptly](https://www.aptly.info/)
+ - aptly does not have direct support for running commands (e.g. rsync, scp) after publishing packages, e.g. to a local filesystem on the buildmaster
+ - _Option 1 (hacky):_ use _inotifywait_ with _rsync_ or _scp_ to copy the published repo to build.openvpn.net
+ - _Option 2 (less hacky):_ use _NFS_ to publish "directly" to build.openvpn.net
+ - Both options require a fair amount of tinkering
\ No newline at end of file
/dev/null .. meetings/2024-03-27.md
@@ 0,0 1,168 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 27 March 2024 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **New: when to deprecate weak ciphers**
+ - Weak ciphers like 3DES and BF-CBC - what to do with them and when?
+ - Originally it looks like it was planned to remove in 2.7 but that may be too soon.
+ - For example, OpenVPN Inc. still sees customers with 10+ year old installations fairly regularly.
+ - A proposal to consider may be to deprecate it when crypto libraries deprecate it.
+ - Weighing the expected complaints versus the low cost of just maintaining weak ciphers until crypto libraries deprecate them - the choice seems obvious.
+ - For now, we'll stick with letting weak ciphers stay in unless there is some convincing reason to remove it.
+
+ - **Closed: OpenVPN 2.6.10 release**
+ - This was released on 20th of March.
+
+ - **Closed: OpenVPN 2.5.10 release**
+ - This was released on 21st of March, including new Windows installers.
+
+ - **Closed: community funding initiative**
+ - ordex convinced OTF (Open Tech Fund) to let OpenVPN join the "FOSS sustainability funding pilot run."
+ - This allows paying for allocated hours for mattock and cron2 to work on OpenVPN community tasks.
+ - Some ongoing tasks are listed under 'Mattock Topics' in the meeting notes and have already been ongoing for a while.
+ - This topic is therefore considered closed for now.
+
+ - **Closed: inactive setting data counter in openvpn2 and openvpn3**
+ - It looks like openvpn2 and openvpn3 handle the counting of traffic differently.
+ - After some discussion, it was decided illia will submit some suggested fixes.
+ - This will now follow standard procedure for patch submission and review. Closing topic.
+
+ - **Closed: tunnelblick and sophos UTM**
+ - Looks like Tunnelblick implemented a fix on their end.
+ - [OpenVPN Issue #525](https://github.com/OpenVPN/openvpn/issues/525)
+
+ - **Updated: website release process**
+ - Last week a website release was planned that would enable a new way for updating the Community Downloads page.
+ - Postponed to this week. We'll see.
+
+ - **Updated: forums topics**
+ - ecrist still working on forums. Admin access issue looks resolved. Email issue looks resolved.
+ - Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address.
+ - Email confirmation on registration was suggested.
+ - We still need to work on having some other people with some admin or high mod access.
+ - Mod guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)
+ - Access for mods to logs so one can see what others did.
+
+ - **Updated: DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex will prepare a v3 patchset soon based on feedback received.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **Updated: mattock topics**
+ - Made it so --dev null tests can run arbitrary numbers of servers concurrently, and have arbitrary amount of clients run in parallel to these servers.
+ - Will probably look into separating the --dev null test data (test cases) from the test scripts.
+ - Also started on debian snapshot publishing but didn't get very far there yet.
+
+ - **Security mailing list procedure can stand improvement**
+ - dazo and novaflash will start discussing this internally in openvpn inc.
+ - Goal of discussions is to work out a better internal procedure to connect security mailing list better with company product responsible people.
+
+ - **Donation collection**
+ - ordex consulted an expert and it looks like doing a legal entity does not make sense when you're just starting out.
+ - The tricky part here is that only if we get a lot of donations and a lot of money does it make sense to have that kind of overhead.
+ - What we can do is start out with a company that collects the money and puts it to good community use. ordex volunteers to take this on.
+ - We want the donations to be collected in one place, and expenses made from that one place, so we are accountable.
+ - We need to figure out how to deal with that legally, and what payment methods to accept and how.
+ - Probably credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions.
+ - And a reminder; we definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Status of trac/wiki**
+ - No progress since last meeting.
+ - This will probably have to wait until "--dev null" is done
+ - Should have access controls so only approved members can edit.
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://openvpn.net/community-resources/tunnelcrack)**
+ - Current status: when mitigations start appearing we will mention them in meeting notes.
+
+ - **OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static-key mini how-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - Company will send this to a tech writer to redo based on [example-fingerprint info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: GRE, IPSec, userland, DCO
+ - Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time
+
+ - **Software code signing topic**
+ - Company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In future, we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up at some point
+
+ ## Mattock topics
+
+ ### --dev null server testing
+
+ Mattock has implemented the first version of the so-called "--dev null server testing" and integrated it with "make check". The features are:
+
+ - Does what it says on the tin (more on that later)
+ - Mostly operating-system agnostic
+ - Should be POSIX shell compliant
+ - Uses the sample certificates and keys
+ - Supports running directly as root and with sudo
+ - Supports using different OpenVPN client versions
+ - The "current" (just compiled) version
+ - Any other OpenVPN versions (must be present on the filesystem)
+ - Support testing for success as well as failure
+ - Server configuration is currently static (i.e. no support for multiple server configurations yet)
+ - How would we go about running OpenVPN 2.4, 2.5, 2.6, etc. clients against the "--dev null server"
+
+ Here's how it works:
+
+ 1. **make check**
+ 1. **t_server_null.sh**
+ 1. **t_server_null_server.sh**
+ - Launches the compiled OpenVPN as root (if necessary with sudo)
+ - OpenVPN server exits when all clients have been disconnected for ten seconds, based on its status file
+ 1. **t_server_null_client.sh**
+ - Launches each individual client test
+ - Client kills itself after some delay using an "--up" script
+
+ Current PoC code is available in mattock's "dev_null" branch. A good starting point is [t_server_null.sh](https://github.com/mattock/openvpn/blob/dev_null/tests/t_server_null.sh).
+
+ What should be the next steps?
+
+ - Basic approach ok?
+ - Is starting with a single server configuration ok?
+ - Which server configuration(s) should we test against?
+ - Which client configurations should we test (success or failure)?
+ - Which operating systems do we want to support in this context? Linux and BSDs? Something more esoteric?
+ - Which OpenVPN client versions should we run?
+
+ ### Debian/Ubuntu snapshot publishing
+
+ - In the last meeting we agreed to publish snapshot Debian/Ubuntu packages on *build.openvpn.net*
+ - The tool to use to publish is [aptly](https://www.aptly.info/)
+ - Aptly does not have direct support for running commands (e.g. rsync, scp) after publishing packages, e.g. to a local filesystem on the buildmaster
+ - **Option 1 (hacky):** use inotifywait with rsync or scp to copy the published repo to build.openvpn.net
+ - **Option 2 (less hacky):** use NFS to publish "directly" to build.openvpn.net
+ - Both options require a fair amount of tinkering
\ No newline at end of file
/dev/null .. meetings/2024-04-03.md
@@ 0,0 1,148 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 3 April 2024 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **New: live route update feature**
+ - A client implementation will be added to OpenVPN3 core soonish.
+ - Obviously we'll need a spec that can be agreed on for this feature.
+ - And ideally also an openvpn2 implementation (client+server).
+ - lev will put together a spec proposal for next meeting.
+
+ - **Updated: website release process**
+ - Waiting for a faster way to update community downloads and security advisories on the main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Updated: forums topics**
+ - ecrist still working on forums. A DNS record for the future archive address will be added, rob0 is doing this.
+ - Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address.
+ - Email confirmation on registration was suggested.
+ - We still need to work on having some other people with some admin or high mod access.
+ - Mod guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)
+ - Access for mods to logs so one can see what others did.
+
+ - **Updated: mattock topics**
+ - Separated test data from code in --dev null tests.
+ - Also started on debian snapshot publishing but didn't get very far there yet.
+ - Will next look at remove sudo root requirement from --dev null server-side.
+ - Figure out if reliability can be increased further (i.e. why did it fail 4 out of 500 times).
+
+ - **Closed: when to deprecate weak ciphers**
+ - Weak ciphers like 3DES and BF-CBC - what to do with them and when?
+ - Originally it looks like it was planned to remove in 2.7 but that may be too soon.
+ - For example, OpenVPN Inc. still sees customers with 10+ year old installations fairly regularly.
+ - A proposal to consider may be to deprecate it when crypto libraries deprecate it.
+ - Weighing the expected complaints versus the low cost of just maintaining weak ciphers until crypto libraries deprecate them - the choice seems obvious.
+ - For now, we'll stick with letting weak ciphers stay in unless there is some convincing reason to remove it.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex will prepare a v3 patchset soon based on feedback received.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **Security mailing list procedure can stand improvement**
+ - dazo and novaflash will start discussing this internally in openvpn inc.
+ - The goal of discussions is to work out a better internal procedure to connect the security mailing list better with company product responsible people.
+
+ - **Donation collection**
+ - ordex consulted an expert and it looks like doing a legal entity does not make sense when you're just starting out.
+ - The tricky part here is that only if we get a lot of donations and a lot of money does it make sense to have that kind of overhead.
+ - What we can do is start out with a company that collects the money and puts it to good community use. ordex volunteers to take this on.
+ - We want the donations to be collected in one place, and expenses made from that one place, so we are accountable.
+ - We need to figure out how to deal with that legally, and what payment methods to accept and how.
+ - Probably credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions.
+ - And a reminder; we definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Status of trac/wiki**
+ - No progress since the last meeting.
+ - This will probably have to wait until "--dev null" is done
+ - Should have access controls so only approved members can edit.
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](wiki:TunnelCrack)**
+ - Current status: when mitigations start appearing we will mention them in meeting notes.
+
+ - **OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
+ - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to the openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: gre, ipsec, userland, dco
+ - Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time
+
+ - **Software code signing topic**
+ - The company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
+
+ - **Management interface documentation on the main website will be updated with info from doc/management-notes.txt**
+ - Novaflash will pick this up at some point
+
+ ## Mattock topics
+
+ ### --dev null server testing
+
+ Mattock has improved so-called "--dev null server testing" and integrated it with "make check". The features are:
+
+ - Does what it says on the tin
+ - Mostly operating-system agnostic
+ - Should be POSIX shell compliant but uses Bash now
+ - Uses the sample certificates and keys
+ - Supports running directly as root and with sudo
+ - Supports using different OpenVPN client versions
+ - The "current" (just compiled) version
+ - Any other OpenVPN versions (must be present on the filesystem)
+ - Support testing for success as well as failure
+ - Test cases (client configurations) and server setups (server configurations) are stored in a configuration file, i.e. data and code have been separated
+ - Configuration file format is nearly identical to t_client.rc configuration
+
+ Here's how it works:
+
+ 1. **make check**
+ 1. **t_server_null.sh**
+ 1. **t_server_null_server.sh**
+ - Launches the compiled OpenVPN server instances as root (if necessary with sudo)
+ - OpenVPN servers exit when all clients have disconnected from all servers
+ 1. **t_server_null_client.sh**
+ - Launches each individual client test
+ - The client kills itself after some delay using an "--up" script
+
+ Current PoC code is available in mattock's "dev_null" branch. A good starting point is [t_server_null.sh](https://github.com/mattock/openvpn/blob/dev_null/tests/t_server_null.sh).
+
+ Mattock is improving test success rates now. When servers (due to a bug) did not exit in between stress tests reliability was 100%. However, with that bug fixed, the best reliability so far was 99%. As normal "make check" will involve spinning up new servers, the 99% reliability number is the number we should be looking at. It seems that the connection failures are caused by clients who try to connect to a server that is not yet up and/or when it is no longer running. Better synchronization between clients and servers is needed. Checking for the presence of server pid files may or may not help there.
+
+ ### Debian/Ubuntu snapshot publishing
+
+ - In the last meeting, we agreed to publish snapshot Debian/Ubuntu packages on build.openvpn.net.
+ - The tool to use to publish is [aptly](https://www.aptly.info/)
+ - Aptly does not have direct support for running commands (e.g. rsync, scp) after publishing packages, e.g. to a local filesystem on the buildmaster
+ - **Option 1 (hacky):** use inotifywait with rsync or scp to copy the published repo to build.openvpn.net
+ - **Option 2 (less hacky):** use NFS to publish "directly" to build.openvpn.net
+ - Both options require a fair amount of tinkering
+ - Mattock moved this forward a bit at the buildbot end (get the files out from workers).
\ No newline at end of file
/dev/null .. meetings/2024-04-10.md
@@ 0,0 1,141 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time**: Wednesday 10 April 2024 at 13:00 CEST (11:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: live route update feature**
+ - In short, the ability to update routes, DNS, ifconfig options, live, without having to do a full reconnect.
+ - One example where this solves an issue is when 1000 users are connected to a server, and you change a route that applies to all. You'd end up temporarily almost DDoS-ing yourself.
+ - As discussed last week, Lev has put together a proposal from which we can build a specification.
+ - The plan is to get approval for the specification first. Then CloudConnexa/openvpn3 will get this implemented.
+ - In discussion with ordex it seems he and giaan can take on creating the OpenVPN2 server and client implementations.
+ - Proposal here: [https://cryptpad.fr/pad/#/2/pad/edit/w1SE-ttFQphTrgZALaG8o8YE/](https://cryptpad.fr/pad/#/2/pad/edit/w1SE-ttFQphTrgZALaG8o8YE/)
+ - DYNAMIC_ROUTES message name is too limited to just routes, we instead prefer PUSH_UPDATE.
+ - Initially PUSH_UPDATE will support routes, DNS, and ifconfig options, to update network related settings on the client. This could be expanded in the future.
+
+ - **Updated: forums topics**
+ - ecrist still working on forums. DNS record for archive of old forums was finally correctly created.
+ - Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address.
+ - - email confirmation on registration was suggested.
+ - - we still need to work on having some other people with some admin or high mod access.
+ - - mod guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)
+ - - access for mods to logs so one can see what others did
+
+ - **Updated: OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it.
+ - Where: Karlsruhe, Germany. Meeting room location to be determined.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+ - There's a wiki page up now where we can coordinate: [https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+
+ - **mattock topics**
+ - Separated test data from code in --dev null tests.
+ - Also started on debian snapshot publishing but didn't get very far there yet.
+ - Will next look at remove sudo root requirement from --dev null server-side.
+ - Figure out if reliability can be increased further (i.e. why did it fail 4 out of 500 times).
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex will prepare a v3 patchset soon based on feedback received.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **website release process**
+ - Waiting for a faster way to update community downloads and security advisories on the main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Security mailing list procedure can stand improvement**
+ - dazo and novaflash will start discussing this internally in openvpn inc.
+ - The goal of discussions is to work out a better internal procedure to connect the security mailing list better with company product responsible people.
+
+ - **donation collection**
+ - ordex consulted an expert and it looks like doing a legal entity does not make sense when you're just starting out.
+ - The tricky part here is that only if we get a lot of donations and a lot of money does it make sense to have that kind of overhead.
+ - What we can do is start out with a company that collects the money and puts it to good community use. ordex volunteers to take this on.
+ - We want the donations to be collected in one place, and expenses made from that one place, so we are accountable.
+ - We need to figure out how to deal with that legally, and what payment methods to accept and how.
+ - Probably credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions.
+ - And a reminder; we definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **status of trac/wiki**
+ - No progress since last meeting.
+ - This will probably have to wait until "--dev null" is done
+ - Should have access controls so only approved members can edit.
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)**
+ - Current status: when mitigations start appearing we will mention them in meeting notes.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc. Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ - tests should cover: gre, ipsec, userland, dco
+ - linux, freebsd, windows
+ - requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ - company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - in the future, we could possibly switch the community to that same key. saves having to maintain 2 different keys.
+ - depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - also no high priority at the moment, we have a working solution now.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - novaflash will pick this up at some point
+
+ ## Mattock topics
+
+ ### --dev null server testing
+
+ Mattock has improved the so-called "--dev null server testing" and integrated it with "make check". The features are:
+
+ - Does what it says on the tin
+ - Mostly operating-system agnostic
+ - Should be POSIX shell compliant but uses Bash now
+ - Uses the sample certificates and keys
+ - Supports running directly as root and with sudo
+ - Supports using different OpenVPN client versions
+ - The "current" (just compiled) version
+ - Any other OpenVPN versions (must be present on the filesystem)
+ - Support testing for success as well as failure
+ - Test cases (client configurations) and server setups (server configurations) are stored in a configuration file, i.e. data and code have been separated
+ - Configuration file format is nearly identical to t_client.rc configuration
+
+ Here's how it works:
+ 1. **make check**
+ 1. **t_server_null.sh**
+ 1. **t_server_null_server.sh**
+ - Launches the compiled OpenVPN server instances as root (if necessary with sudo)
+ - OpenVPN servers exit when all clients have disconnected from all servers
+ 1. **t_server_null_client.sh**
+ - Launches each individual client test
+ - Client kills itself after some delay using an "--up" script
+
+ Current PoC code is available in mattock's "dev_null" branch. A good starting point is [t_server_null.sh](https://github.com/mattock/openvpn/blob/dev_null/tests/t_server_null.sh).
+
+ ### Debian/Ubuntu snapshot publishing
+
+ - In the last meeting we agreed to publish snapshot Debian/Ubuntu packages on build.openvpn.net
+ - The tool to use to publish is [aptly](https://www.aptly.info/)
+ - aptly does not have direct support for running commands (e.g. rsync, scp) after publishing packages, e.g., to a local filesystem on the buildmaster
+ - **Option 1 (hacky)**: use inotifywait with rsync or scp to copy the published repo to build.openvpn.net
+ - **Option 2 (less hacky)**: use NFS to publish "directly" to build.openvpn.net
+ - Both options require a fair amount of tinkering
+ - Mattock moved this forward a bit at the buildbot end (get the files out from workers)
\ No newline at end of file
/dev/null .. meetings/2024-04-17.md
@@ 0,0 1,128 @@
+ # IrcMeetings
+
+ ## Basic Info
+
+ - **Time**: Wednesday 17 April 2024 at 13:00 CEST (11:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current Topics
+
+ - **New: updated 2.6.10 with new MSI installers**
+ - _There is a new Windows DCO driver that should handle coming back from hibernation better/faster, as it doesn't wait for keepalive timeout after hibernation._
+
+ - **New: --topology directive**
+ - _We changed the default for this to be 'subnet' as this is the most commonly used setup and has been for ages (used to be net30)._
+ - _This is however breaking things by default for peer to peer setups. We could limit the change to just --server mode._
+ - _djpig will propose a patch and it can be discussed further there._
+
+ - **Closed: live route update feature**
+ - _In short, the ability to update routes, DNS, ifconfig options, live, without having to do a full reconnect._
+ - _After discussing last week seems like a path forward is clear._
+
+ - **Updated: Security mailing list procedure can stand improvement**
+ - _company will improve process on picking up tasks from security mailing list in the next week or so._
+ - _The idea being that community guys will continue doing their thing as usual, and company guys monitor the list for company related items and follow up on those._
+ - _The idea of an NDA is also revived. But it was made clear internally that we need like a one-page simple NDA for community members, not the unnecessarily restrictive one originally suggested by legal guys._
+
+ - **Updated: DCO and Linux upstreaming, API change**
+ - _Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._
+ - _ordex will send a patchset v3 based on feedback received today._
+ - _There will be an API change that makes it incompatible with the current implementation._
+ - _A graceful solution to that was already discussed and in motion. giaan will be working on this._
+
+ - **Updated: donation collection**
+ - _From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._
+ - _What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on._
+ - _There are some options to consider. There may be existing solutions that we want to consider._
+ - _PayPal seems overly expensive with all their fees._
+ - _Stripe could be worth considering for credit card processing._
+ - _GitHub Sponsors was mentioned as a possible solution, this is worth investigating._
+ - _Open Collective was also mentioned, that needs some investigating how that exactly would work for us._
+
+ - **Updated: forums topics**
+ - _ecrist still working on forums. waiting on ecrist to move things around._
+ - _Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address._
+ - _email confirmation on registration was suggested._
+ - _mod guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)_
+ - _access for mods to logs so one can see what others did_
+
+ - **Updated: mattock topics**
+ - _Managed to make tests run reliably now, the occassional failures seem resolved now._
+ - _Documentation here: [https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst)_
+ - _Will submit a patch soon._
+
+ - **OpenVPN community meetup 2024**
+ - _Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it._
+ - _Where: Karlsruhe, Germany. Meeting room location to be determined._
+ - _When: At the moment tentatively set to 20-22 September 2024._
+ - _Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest._
+ - _Shirts: There is plenty of time still to prepare a shirt design._
+ - _There's a wiki page up now where we can coordinate: [https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)_
+
+ - **Website release process**
+ - _Waiting for faster way to update community downloads and security advisories on main site._
+ - _Again postponed due to issues. Now planned for this week. We'll see._
+
+ - **Status of SBOM**
+ - _There was a discussion between MaxF and djpig and others._
+ - _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
+ - _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
+
+ - **Status of trac/wiki**
+ - _No progress since last meeting._
+ - _This will probably have to wait until "--dev null" is done_
+ - _Should have access controls so only approved members can edit._
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)**
+ - _Current status: when mitigations start appearing we will mention them in meeting notes._
+
+ - **Static-key mini how-to is outdated.**
+ - _This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)_
+ - _company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc._
+ - _having a simple guide online will help adoption_
+
+ - **OpenVPN 2.6 performance results.**
+ - _tests should cover: gre, ipsec, userland, dco_
+ - _linux, freebsd, windows_
+ - _requires time to be dedicated to doing this, when time available will do it_
+
+ - **What's going on with new taskbar icons?**
+ - _matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
+ - _last update: will be picked up by selva when he has time_
+
+ - **Software code signing topic**
+ - _company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
+ - _in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
+ - _depends on how hard/easy it is to access company key signing thingee from community infrastructure._
+ - _also no high priority at the moment, we have a working solution now._
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - _novaflash will pick this up at some point_
+
+ ## Mattock Topics
+
+ ### --dev null server testing
+
+ Latest status in [ServerSideTestingImprovementPlan](https://github.com/mattock/openvpn/blob/dev_null/doc/server-side-testing-improvement-plan.rst). Additional details in [https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst). Current PoC code is available in mattock's "dev_null" branch. A good starting point is [t_server_null.sh](https://github.com/mattock/openvpn/blob/dev_null/tests/t_server_null.sh).
+
+ Potential next steps:
+
+ - Expand the test suite
+ - Integrate into Buildbot (i.e. get to production)
+ - Support multiple client versions (depends on Buildbot integration)
+
+ Git commit history needs to be cleaned up and there may be other small fixes / improvements here and there to be done:
+
+ - Enable disabling the test suite (requires root so we can't run it by default)
+
+ ### Debian/Ubuntu snapshot publishing
+
+ - In the last meeting we agreed to publish snapshot Debian/Ubuntu packages on *build.openvpn.net*
+ - The tool to use to publish is [aptly](https://www.aptly.info/)
+ - Aptly does not have direct support for running commands (e.g. rsync, scp) after publishing packages, e.g. to a local filesystem on the buildmaster
+ - **Option 1 (hacky)**: use **inotifywait** with **rsync** or **scp** to copy the published repo to build.openvpn.net
+ - **Option 2 (less hacky)**: use **NFS** to publish "directly" to build.openvpn.net
+ - Both options require a fair amount of tinkering
+ - Mattock moved this forward a bit at the buildbot end (get the files out from workers)
\ No newline at end of file
/dev/null .. meetings/2024-04-24.md
@@ 0,0 1,127 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time**: Wednesday 24 April 2024 at 13:00 CEST (11:00 UTC)
+ - **Place**: `#openvpn-meeting` channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **New, closed: OpenSSL 1.0.2 removal from OpenVPN 2.7**
+ - Currently plaisthos is still supporting OpenSSL 1.0.2 because of Access Server still releasing on CentOS7/Red Hat7.
+ - Since we are dropping those platforms on Access Server, there appears to be no reason to keep supporting it.
+ - There were no objections to removing openssl 1.0.2 support from OpenVPN 2.7.
+
+ - **New: Discussion related to DNS IV flag**
+ - The implementation of the dns option deviates somewhat from the original specification.
+ - d12fk wants to discuss a possible solution using another IV flag.
+ - A flag such as IV_PROTO_DNS_OPTION_V2 would be acceptable, as of OpenVPN 2.6.11.
+ - IV_PROTO_DNS_OPTION could be renamed to IV_PROTO_DNS_OPTION_OLD and marked as 'do not send'.
+
+ - **Updated: forums topics**
+ - ecrist still working on forums. waiting on ecrist to move things around.
+ - ecrist requests that cloudflare be removed again. that's not really something that we want to do as we lose a lot of protection.
+ - rob0 and novaflash would like to assist in solving this problem. they would need root access to the VM. perhaps djpig can arrange this?
+ - Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address.
+ - email confirmation on registration was suggested.
+ - mod permissions, guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)
+ - access for mods to logs so one can see what others did.
+
+ - **Updated: mattock topics**
+ - PR created for the --dev null test suite. Fixed some issues based on feedback in #openvpn-devel.
+ - Documentation here: [dev-null-test-suite](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst)
+
+ - **Security mailing list procedure can stand improvement**
+ - company will improve process on picking up tasks from security mailing list in the next week or so.
+ - The idea being that community guys will continue doing their thing as usual, and company guys monitor the list for company-related items and follow up on those.
+ - The idea of an NDA is also revived. But it was made clear internally that we need like a one-page simple NDA for community members, not the unnecessarily restrictive one originally suggested by legal guys.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex will send a patchset v3 based on feedback received today.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it.
+ - Where: Karlsruhe, Germany. Meeting room location to be determined.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+ - There's a wiki page up now where we can coordinate: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+
+ - **website release process**
+ - Waiting for faster way to update community downloads and security advisories on main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **status of trac/wiki**
+ - No progress since last meeting.
+ - This will probably have to wait until "--dev null" is done
+ - Should have access controls so only approved members can edit.
+
+ - **Tunnelcrack progress**
+ - Current status: when mitigations start appearing we will mention them in meeting notes.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static-key mini how-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - company will send this to tech writer to redo based on [example-fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ - tests should cover: gre, ipsec, userland, dco
+ - linux, freebsd, windows
+ - requires time to be dedicated to doing this, when time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [openvpn-gui issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - last update: will be picked up by selva when he has time.
+
+ - **software code signing topic**
+ - company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ - depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - also no high priority at the moment, we have a working solution now.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - novaflash will pick this up at some point.
+
+ ## Mattock topics
+
+ ### --dev null server testing
+
+ Latest status in [ServerSideTestingImprovementPlan]. Additional details in [dev-null-test-suite](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst). Current PoC code is available in mattock's "dev_null" branch. A good starting point is [t_server_null.sh](https://github.com/mattock/openvpn/blob/dev_null/tests/t_server_null.sh).
+
+ Potential next steps:
+ - Expand the test suite
+ - Integrate into Buildbot (i.e. get to production)
+ - Support multiple client versions (depends on Buildbot integration)
+
+ Git commit history needs to be cleaned up and there may be other small fixes / improvements here and there to be done:
+ - Enable disabling the test suite (requires root so we can't run it by default)
+
+ ### Debian/Ubuntu snapshot publishing
+
+ - In a previous meeting we agreed to publish snapshot Debian/Ubuntu packages on *build.openvpn.net*
+ - The tool to use to publish is [aptly](https://www.aptly.info/)
+ - aptly does not have direct support for running commands (e.g. rsync, scp) after publishing packages, e.g. to a local filesystem on the buildmaster
+ - **Option 1 (hacky)**: use `inotifywait` with `rsync` or `scp` to copy the published repo to build.openvpn.net
+ - **Option 2 (less hacky)**: use `NFS` to publish "directly" to build.openvpn.net
+ - Both options require a fair amount of tinkering
+ - Mattock moved this forward a bit at the buildbot end (get the files out from workers)
\ No newline at end of file
/dev/null .. meetings/2024-05-01.md
@@ 0,0 1,1 @@
+ No meeting due to international holiday.
\ No newline at end of file
/dev/null .. meetings/2024-05-08.md
@@ 0,0 1,141 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 8 May 2024 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Closed: Discussion related to DNS IV flag**
+ *This was done with a IV_PROTO_DNS_OPTION_V2 proto flag.*
+
+ - **New, closed: TunnelVision vulnerability.**
+ *This looks to be basically the same as the TunnelCrack vulnerability.*
+ *Mitigations for TunnelCrack are underway but take time to deliver as the implementation is different on each platform.*
+ *What we'll do is add a wiki article for TunnelVision that redirects to TunnelCrack statement already present on our wiki.*
+ *We'll add a section there specific to the TunnelVision aspect of this.*
+
+ - **Updated: Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)**
+ *Status update on TunnelCrack mitigations:*
+ *Windows, openvpn2: ready to merge. openvpn3: in code review.*
+ *Linux, openvpn2: in progress. openvpn3: in progress.*
+ *macOS: to be determined.*
+ *iOS: to be determined.*
+ *Android: not vulnerable.*
+
+ - **New: BlackHat announcement regarding 'OVPNX'.**
+ *BlackHat announced a presentation about OVPNX vulnerabilities that lead to privilege escalation.*
+ *This is by the same guy, Vladimir Tokarev, that reported these issues to us that we then solved.*
+ *The problem is they are announcing it as zero-day vulnerabilities, which is simply not true.*
+ *These were responsibly disclosed and in cooperation were fixed and published with the OpenVPN 2.6.10 and 2.5.10 releases.*
+ *We did reach out to clarify things but haven't had a response yet.*
+ *A security advisory and a blog post will be posted in the next day or so on the main website, and it will be added to the company newsletter as well.*
+ *These will set the record straight that it's not zero-day, and furthermore point out that this is not that critical of an issue as you need privileges anyways to exploit it.*
+ *Also this only affects OpenVPN2 GUI on Windows.*
+
+ - **Updated: forums topics**
+ *rob0 and novaflash volunteered to take a look at the web server config to make it work correctly.*
+ *However due to other ongoing things, didn't have time yet, but will be able to spend time on it soonish.*
+ *Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address.*
+ *- email confirmation on registration was suggested.*
+ *- mod permissions, guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)*
+ *- access for mods to logs so one can see what others did*
+
+ - **Updated: mattock topics**
+ *PR created to add t_server_null tests to buildbot.*
+ *There's a parallelism issue to fix between t_server_null.sh and t_client.sh - will work on that.*
+
+ - **Security mailing list procedure can stand improvement**
+ *company will improve process on picking up tasks from security mailing list in the next week or so.*
+ *The idea being that community guys will continue doing their thing as usual, and company guys monitor the list for company related items and follow up on those.*
+ *The idea of an NDA is also revived. But it was made clear internally that we need like a one-page simple NDA for community members, not the unnecessarily restrictive one originally suggested by legal guys.*
+
+ - **DCO and Linux upstreaming, API change**
+ *Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.*
+ *ordex will send a patchset v3 based on feedback received today.*
+ *There will be an API change that makes it incompatible with the current implementation.*
+ *A graceful solution to that was already discussed and in motion. giaan will be working on this.*
+ *(in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)*
+
+ - **donation collection**
+ *From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.*
+ *What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.*
+ *There are some options to consider. There may be existing solutions that we want to consider.*
+ *PayPal seems overly expensive with all their fees.*
+ *Stripe could be worth considering for credit card processing.*
+ *GitHub Sponsors was mentioned as a possible solution, this is worth investigating.*
+ *Open Collective was also mentioned, that needs some investigating how that exactly would work for us.*
+
+ - **OpenVPN community meetup 2024**
+ *Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it.*
+ *Where: Karlsruhe, Germany. Meeting room location to be determined.*
+ *When: At the moment tentatively set to 20-22 September 2024.*
+ *Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.*
+ *Shirts: There is plenty of time still to prepare a shirt design.*
+ *There's a wiki page up now where we can coordinate: [Community Meetup 2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)*
+
+ - **website release process**
+ *Waiting for faster way to update community downloads and security advisories on main site.*
+ *Again postponed due to issues. Now planned for this week. We'll see.*
+
+ - **Status of SBOM**
+ *There was a discussion between MaxF and djpig and others.*
+ *For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.*
+ *The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.*
+
+ - **status of trac/wiki**
+ *No progress since last meeting.*
+ *This will probably have to wait until "--dev null" is done*
+ *Should have access controls so only approved members can edit.*
+
+ - **Static-key mini how-to is outdated.**
+ *This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)*
+ *company will send this to tech writer to redo based on [this GitHub document](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.*
+ *having a simple guide online will help adoption*
+
+ - **OpenVPN 2.6 performance results.**
+ *tests should cover: gre, ipsec, userland, dco*
+ *linux, freebsd, windows*
+ *requires time to be dedicated to doing this, when time available will do it*
+
+ - **What's going on with new taskbar icons?**
+ *matt provided icons in [this GitHub issue](https://github.com/OpenVPN/openvpn-gui/issues/595)*
+ *last update: will be picked up by selva when he has time*
+
+ - **software code signing topic**
+ *company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.*
+ *in future we could possibly switch community to that same key. saves having to maintain 2 different keys.*
+ *depends on how hard/easy it is to access company key signing thingee from community infrastructure.*
+ *also no high priority at the moment, we have a working solution now.*
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ *novaflash will pick this up at some point*
+
+ ## Mattock topics
+
+ ### --dev null server testing
+
+ Latest status in [Server Side Testing Improvement Plan](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst). Additional details in [GitHub document](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst). Current PoC code is available in mattock's "dev_null" branch. A good starting point is [t_server_null.sh](https://github.com/mattock/openvpn/blob/dev_null/tests/t_server_null.sh).
+
+ Potential next steps:
+
+ - Expand the test suite
+ - Integrate into Buildbot (i.e., get to production)
+ - Support multiple client versions (depends on Buildbot integration)
+
+ Git commit history needs to be cleaned up and there may be other small fixes/improvements here and there to be done:
+
+ - Enable disabling the test suite (requires root so we can't run it by default)
+
+ ### Debian/Ubuntu snapshot publishing
+
+ - In a previous meeting, we agreed to publish snapshot Debian/Ubuntu packages on *build.openvpn.net*
+ - The tool to use to publish is [aptly](https://www.aptly.info/)
+ - aptly does not have direct support for running commands (e.g., rsync, scp) after publishing packages, e.g., to a local filesystem on the buildmaster
+ - **Option 1 (hacky):** use `inotifywait` with `rsync` or `scp` to copy the published repo to build.openvpn.net
+ - **Option 2 (less hacky):** use `NFS` to publish "directly" to build.openvpn.net
+ - Both options require a fair amount of tinkering
+ - Mattock moved this forward a bit at the buildbot end (get the files out from workers)
\ No newline at end of file
/dev/null .. meetings/2024-05-15.md
@@ 0,0 1,131 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 15 May 2024 at 13:00 CEST (11:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated, closed: change time of community meeting to one hour later**
+ - In general, it seemed most people are okay with this.
+ - For the next few weeks, community meetings will be at 2PM CEST/CET instead of 1PM.
+ - For real this time.
+
+ - **Updated: release openvpn 2.6.11**
+ - It seems like it makes sense to do a 2.6.11 release after Windows tunnelcrack mitigations are merged.
+ - From the looks of it, this isn't a major disruptive change so could be merged and released in 2.6.
+ - For the proposed Linux tunnelcrack mitigations, going for policy routing and such, it may need to go to 2.7 and it's quite a big change.
+ - Waiting for cron2 to do a review/merge pass on Windows tunnelcrack patch.
+
+ - **Updated: forums topics**
+ - rob0 and novaflash will work to get access and then find some time to look at solving the cloudflare related issue.
+ - Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address.
+ - Email confirmation on registration was suggested.
+ - Mod permissions, guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)
+ - Access for mods to logs so one can see what others did
+
+ - **Updated: Security mailing list procedures**
+ - We unfortunately let the key expire last week and had to quickly issue a renewed key.
+ - This was done and the renewed key has been distributed.
+
+ - **mattock topics**
+ - PR created to add t_server_null tests to buildbot.
+ - There's a parallelism issue to fix between t_server_null.sh and t_client.sh - will work on that.
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)**
+ - Status update on TunnelCrack mitigations:
+ - Windows, openvpn2: ready to merge. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex will send a patchset v3 based on feedback received today.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **donation collection**
+ - From earlier exploration, it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it.
+ - Where: Karlsruhe, Germany. Meeting room location to be determined.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+ - There's a wiki page up now where we can coordinate: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+
+ - **website release process**
+ - Waiting for a faster way to update community downloads and security advisories on the main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **status of trac/wiki**
+ - No progress since last meeting.
+ - This will probably have to wait until "--dev null" is done
+ - Should have access controls so only approved members can edit.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini Howto](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [example-fingerprint info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: gre, ipsec, userland, dco
+ - Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this, when time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time.
+
+ - **software code signing topic**
+ - Company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
+
+ - **Management interface documentation on the main website will be updated with info from doc/management-notes.txt**
+ - novaflash will pick this up at some point.
+
+ ## Mattock topics
+
+ ### --dev null server testing
+
+ Latest status in [ServerSideTestingImprovementPlan](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst). Additional details in [dev-null test suite](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst). Current PoC code is available in mattock's "dev_null" branch. A good starting point is [t_server_null.sh](https://github.com/mattock/openvpn/blob/dev_null/tests/t_server_null.sh).
+
+ Potential next steps:
+
+ - Expand the test suite
+ - Integrate into Buildbot (i.e., get to production)
+ - Support multiple client versions (depends on Buildbot integration)
+
+ Git commit history needs to be cleaned up and there may be other small fixes/improvements here and there to be done:
+
+ - Enable disabling the test suite (requires root so we can't run it by default)
+
+ ### Debian/Ubuntu snapshot publishing
+
+ - In a previous meeting, we agreed to publish snapshot Debian/Ubuntu packages on *build.openvpn.net*
+ - The tool to use to publish is [aptly](https://www.aptly.info/)
+ - aptly does not have direct support for running commands (e.g., rsync, scp) after publishing packages, e.g., to a local filesystem on the buildmaster
+ - **Option 1 (hacky):** use `inotifywait` with `rsync` or `scp` to copy the published repo to build.openvpn.net
+ - **Option 2 (less hacky):** use `NFS` to publish "directly" to build.openvpn.net
+ - Both options require a fair amount of tinkering
+ - Mattock moved this forward a bit at the buildbot end (get the files out from workers)
\ No newline at end of file
/dev/null .. meetings/2024-05-22.md
@@ 0,0 1,137 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 22 May 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **New: DCO-win update needed**
+ - There was a responsible disclosure report made regarding DCO windows driver. Details are currently under embargo.
+ - A new Windows installer release will be made available shortly and details will be published then.
+ - This will be an I002 Windows installer release for 2.6.10.
+
+ - **New: community.openvpn.net server maintenance**
+ - There was some downtime here and after looking into it, the conclusion is that the software is out-of-date and needs love.
+ - We were already planning to migrate to another wiki solution, so this has provided an impetus to accelerate this.
+ - mattock will do a PoC of wiki.js and outline and we will make a decision once those are up, and then go for it.
+
+ - **Updated: Security mailing list**
+ - It was proposed to add df12k to the security mailing list. If no objections this will be done.
+ - No objections. He will be added.
+
+ - **Updated: forums topics**
+ - rob0 and novaflash will work to get access and then find some time to look at solving the cloudflare related issue.
+ - Unfortunately the past weeks were difficult to find time - holidays and travel and such. Will find time and push this forward.
+ - Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address.
+ - Email confirmation on registration was suggested.
+ - Mod permissions, guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)
+ - Access for mods to logs so one can see what others did
+
+ - **Updated: mattock topics**
+ - There is code waiting for review/merging but one of the reviewers is on vacation.
+ - Will in the meantime tackle the community.openvpn.net / wiki topic.
+
+ - **Release openvpn 2.6.11**
+ - It seems like it makes sense to do a 2.6.11 release after Windows tunnelcrack mitigations are merged.
+ - From the looks of it this isn't a major disruptive change so could be merged and released in 2.6.
+ - For the proposed Linux tunnelcrack mitigations, going for policy routing and such, it may need to go to 2.7 and it's quite a big change.
+ - Waiting for cron2 to do a review/merge pass on Windows tunnelcrack patch.
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)**
+ - Status update on TunnelCrack mitigations:
+ - Windows, openvpn2: ready to merge. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex will send a patchset v3 based on feedback received today.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - In a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API.
+
+ - **Donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **OpenVPN community meetup 2024**
+ - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it.
+ - Where: Karlsruhe, Germany. Meeting room location to be determined.
+ - When: At the moment tentatively set to 20-22 September 2024.
+ - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
+ - Shirts: There is plenty of time still to prepare a shirt design.
+ - There's a wiki page up now where we can coordinate: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+
+ - **Website release process**
+ - Waiting for a faster way to update community downloads and security advisories on the main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Status of trac/wiki**
+ - No progress since last meeting.
+ - This will probably have to wait until "--dev null" is done
+ - Should have access controls so only approved members can edit.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini Howto](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: gre, ipsec, userland, dco
+ - Linux, FreeBSD, windows
+ - Requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time
+
+ - **Software code signing topic**
+ - The company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - novaflash will pick this up at some point
+
+ ## Mattock topics
+
+ ### --dev null server testing
+
+ Latest status in [Server Side Testing Improvement Plan](https://github.com/mattock/openvpn/blob/dev_null/doc/ServerSideTestingImprovementPlan.rst). Additional details in [dev-null-test-suite.rst](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst). Current PoC code is available in mattock's "dev_null" branch. A good starting point is [t_server_null.sh](https://github.com/mattock/openvpn/blob/dev_null/tests/t_server_null.sh).
+
+ Potential next steps:
+
+ - Expand the test suite
+ - Integrate into Buildbot (i.e., get to production)
+ - Support multiple client versions (depends on Buildbot integration)
+
+ Git commit history needs to be cleaned up and there may be other small fixes/improvements here and there to be done:
+
+ - Enable disabling the test suite (requires root so we can't run it by default)
+
+ ### Debian/Ubuntu snapshot publishing
+
+ - In a previous meeting, we agreed to publish snapshot Debian/Ubuntu packages on build.openvpn.net
+ - The tool to use to publish is [aptly](https://www.aptly.info/)
+ - Aptly does not have direct support for running commands (e.g., rsync, scp) after publishing packages, e.g., to a local filesystem on the buildmaster
+ - **Option 1 (hacky):** use inotifywait with rsync or scp to copy the published repo to build.openvpn.net
+ - **Option 2 (less hacky):** use NFS to publish "directly" to build.openvpn.net
+ - Both options require a fair amount of tinkering
+ - Mattock moved this forward a bit at the buildbot end (get the files out from workers)
\ No newline at end of file
/dev/null .. meetings/2024-05-29.md
@@ 0,0 1,129 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 29 May 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** `#openvpn-meeting` channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Closed: DCO-win update needed**
+ - There was a responsible disclosure report made regarding DCO windows driver.
+ - This was fixed and released in the I003 Windows installer release for 2.6.10.
+
+ - **Updated: community.openvpn.net trac wiki**
+ - There was some downtime here and after looking into it, the conclusion is that the software is out-of-date and needs love.
+ - We were already planning to migrate to another wiki solution, so this has provided an impetus to accelerate this.
+ - mattock will look into putting a PoC of wiki.js and outline after debian/ubuntu snapshot task is done.
+
+ - **Updated: release openvpn 2.6.11**
+ - Waiting to complete review/merge process of Windows tunnelcrack mitigations.
+ - For the proposed Linux tunnelcrack mitigations, going for policy routing and such, it may need to go to 2.7 and it's quite a big change.
+ - There's an item reported by reynir that we'll likely want to get into this release as well.
+
+ - **Updated: OpenVPN community meetup 2024**
+ - There's a wiki page up now where we can coordinate: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ - We're basically at the point where we can prepare a mailing and send out invites to people.
+ - Where: Karlsruhe, Germany. Exact details of meeting room to be determined.
+ - When: Set to 20-22 September 2024.
+ - Shirts: novaflash will talk to matt about this.
+
+ - **Updated: mattock topics**
+ - There is code waiting for review/merging but one of the reviewers is on vacation.
+ - Will in the meantime tackle the community.openvpn.net / wiki topic.
+ - Wrapping up debian/ubuntu snapshot building. It already works but wants to clean things up and make a PR.
+
+ - **forums topics**
+ - rob0 and novaflash will work to get access and then find some time to look at solving the cloudflare related issue.
+ - Unfortunately the past weeks were difficult to find time - holidays and travel and such. Will find time and push this forward.
+ - Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address.
+ - - email confirmation on registration was suggested.
+ - - mod permissions, guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)
+ - - access for mods to logs so one can see what others did
+
+ - **Tunnelcrack progress**
+ - Status update on TunnelCrack mitigations:
+ - Windows, openvpn2: ready to merge. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex will send a patchset v3 based on feedback received today.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **website release process**
+ - Waiting for faster way to update community downloads and security advisories on main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static-key mini how-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - company will send this to tech writer to redo based on [Github example-fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info
+ - and also retain a link to that github doc.
+ - having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ - tests should cover: gre, ipsec, userland, dco
+ - linux, freebsd, windows
+ - requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [OpenVPN GUI issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ - company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ - depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - also no high priority at this moment, we have a working solution now.
+
+ - **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
+ - novaflash will pick this up at some point
+
+ ## Mattock topics
+
+ ### --dev null server testing
+
+ Latest status in [ServerSideTestingImprovementPlan](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst). Additional details in [dev-null-test-suite](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst). Current PoC code is available in mattock's "dev_null" branch. A good starting point is [t_server_null.sh](https://github.com/mattock/openvpn/blob/dev_null/tests/t_server_null.sh).
+
+ Potential next steps:
+
+ - Expand the test suite
+ - Integrate into Buildbot (i.e. get to production)
+ - Support multiple client versions (depends on Buildbot integration)
+
+ Git commit history needs to be cleaned up and there may be other small fixes / improvements here and there to be done:
+
+ - Enable disabling the test suite (requires root so we can't run it by default)
+
+ ### Debian/Ubuntu snapshot publishing
+
+ - In a previous meeting we agreed to publish snapshot Debian/Ubuntu packages on *build.openvpn.net*
+ - The tool to use to publish is [aptly](https://www.aptly.info/)
+ - aptly does not have direct support for running commands (e.g. rsync, scp) after publishing packages, e.g. to a local filesystem on the buildmaster
+ - **Option 1 (hacky):** use `inotifywait` with `rsync` or `scp` to copy the published repo to build.openvpn.net
+ - **Option 2 (less hacky):** use `NFS` to publish "directly" to build.openvpn.net
+ - Both options require a fair amount of tinkering
+ - Mattock moved this forward a bit at the buildbot end (get the files out from workers)
\ No newline at end of file
/dev/null .. meetings/2024-06-05.md
@@ 0,0 1,98 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 5 June 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** `#openvpn-meeting` channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **New, closed: no community meeting on 12 June 2024**
+ Due to an event that a large amount of people will attend, this particular day will be inconvenient to do a meeting.
+ Meetings will resume the week after on 19 June 2024.
+
+ - **Updated: Buildbot and t_server null**
+ Builds were failing because worker containers have not been rebuilt.
+ This issue was resolved between mattock and djpig.
+
+ - **Updated: community.openvpn.net trac wiki**
+ It turned out that outline is not really open source, it has BSL 1.1 license. Not suitable for us.
+ Wiki.js still seems at the moment the direction we want to go. To be sure leoossa will present some workflows to test.
+ Based on the results of those tests we can then see where the limitations of wiki.js are, and then we can see if those are dealbreakers or not.
+
+ - **Updated: release openvpn 2.6.11**
+ Waiting to complete review/merge process of Windows tunnelcrack mitigations.
+ Waiting to complete review/merge process of item reported by reynir.
+ Once those items are in we'll prepare for a release, tentatively in 2 weeks from now.
+
+ - **Updated: DCO and Linux upstreaming, API change**
+ Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ ordex will send a **patchset v4** based on feedback received over the past days.
+ There will be an API change that makes it incompatible with the current implementation.
+ A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **OpenVPN community meetup 2024**
+ There's a wiki page up now where we can coordinate: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ We're basically at the point where we can prepare a mailing and send out invites to people.
+ Where: Karlsruhe, Germany. Exact details of meeting room to be determined.
+ When: Set to 20-22 September 2024.
+ Shirts: novaflash will talk to matt about this.
+
+ - **forums topics**
+ rob0 and novaflash will work to get access and then find some time to look at solving the cloudflare related issue.
+ Unfortunately the past weeks were difficult to find time - holidays and travel and such. Will find time and push this forward.
+ Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address.
+ - email confirmation on registration was suggested.
+ - mod permissions, guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)
+ - access for mods to logs so one can see what others did
+
+ - **Tunnelcrack progress**
+ Status update on TunnelCrack mitigations:
+ Windows, openvpn2: ready to merge. openvpn3: in code review.
+ Linux, openvpn2: in progress. openvpn3: in progress.
+ macOS: to be determined.
+ iOS: to be determined.
+ Android: not vulnerable.
+
+ - **donation collection**
+ From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ There are some options to consider. There may be existing solutions that we want to consider.
+ PayPal seems overly expensive with all their fees.
+ Stripe could be worth considering for credit card processing.
+ GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **website release process**
+ Waiting for faster way to update community downloads and security advisories on main site.
+ Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ There was a discussion between MaxF and djpig and others.
+ For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ This page is outdated badly: [Static Key Mini How-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ company will send this to tech writer to redo based on [example fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc.
+ having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ tests should cover: gre, ipsec, userland, dco
+ linux, freebsd, windows
+ requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-06-19.md
@@ 0,0 1,120 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - Time: Wednesday 19 June 2024 at 14:00 CEST (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: release openvpn 2.6.11**
+ There is a security issue reported by reynir that is resolved, and we want to get that out in 2.6.11 tomorrow.
+ The tunnelcrack mitigations for Windows are held back because we have had absolutely no response on the mailing lists for testing these and confirming that it doesn't break things.
+ If someone can contribute to testing this we can follow up with a 2.6.12 release in a few weeks that contains the tunnelcrack mitigations for Windows.
+
+ - **New: buildbot PRs need attention**
+ Getting these merged soonish would help avoid nasty merge conflicts down the line
+ [Allow skipping build types](https://github.com/OpenVPN/openvpn-buildbot/pull/50)
+ [Add smoketest builds for openvpn3, openvpn3-linux and ovpn-dco](https://github.com/OpenVPN/openvpn-buildbot/pull/51)
+ [PR 48](https://github.com/OpenVPN/openvpn-buildbot/pull/48)
+ Developers have been pinged in the meeting about these, so they'll take a look when they can.
+
+ - **New: fixing openvpn3-linux builds in Buildbot**
+ Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing.
+ As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process.
+ Next step is a 'regular' OpenVPN3 Linux v23 release again.
+
+ - **New: Linux arm64 buildbot workers**
+ Mattock has done initial research.
+ Docker seems to support (QEMU) emulated non-native containers, but Buildbot might be missing the glue to make it work.
+ Patching Buildbot should not be *that* difficult.
+ External (arm64) Docker host might be a more performant alternative option.
+
+ - **New: how to proceed with lzo2.pc**
+ pc file suggests "all includes should be done without `lzo/` prefix" - which is generally not a bad idea, but needs code changes beyond configure (right?)
+ There are some options to make changes here. For now we'll just keep working around this issue.
+ One thing seems clear; it would be too early to rip it out, it would most likely affect too many people still using it despite the fact that they shouldn't.
+ An option we have is to use the OpenVPN3 implementation of lzo and port that to OpenVPN2, to solve this.
+ This is a topic that will be moved to the OpenVPN community meetup 2024.
+
+ - **New: run tests of 2.x against openvpn3? how?**
+ There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ This is in the openvpn3 repository.
+
+ - **Updated: community.openvpn.net trac wiki**
+ Wiki.js felt quite awkward and counterintuitive in practical tests done by mattock. It seems to focus on bling rather than usability.
+ Xwiki felt quite bulky and enterprisey (a.k.a. full of "stuff") in the practical tests by mattock. It seems an overkill for our simple use-case.
+ Mediawiki no longer feels as nasty as it once did :)
+ Maybe some Git-based wiki-type solution would be ok?
+
+ - **DCO and Linux upstreaming, API change**
+ Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ ordex will send a **patchset v4** based on feedback received over the past days.
+ There will be an API change that makes it incompatible with the current implementation.
+ A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **OpenVPN community meetup 2024**
+ There's a wiki page up now where we can coordinate: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ We're basically at the point where we can prepare a mailing and send out invites to people.
+ Where: Karlsruhe, Germany. Exact details of meeting room to be determined.
+ When: Set to 20-22 September 2024.
+ Shirts: novaflash will talk to matt about this.
+
+ - **forums topics**
+ rob0 and novaflash will work to get access and then find some time to look at solving the cloudflare related issue.
+ Unfortunately the past weeks were difficult to find time - holidays and travel and such. Will find time and push this forward.
+ Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address.
+ - email confirmation on registration was suggested.
+ - mod permissions, guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)
+ - access for mods to logs so one can see what others did
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)**
+ Status update on TunnelCrack mitigations:
+ Windows, openvpn2: ready to merge. openvpn3: in code review.
+ Linux, openvpn2: in progress. openvpn3: in progress.
+ macOS: to be determined.
+ iOS: to be determined.
+ Android: not vulnerable.
+
+ - **donation collection**
+ From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ There are some options to consider. There may be existing solutions that we want to consider.
+ PayPal seems overly expensive with all their fees.
+ Stripe could be worth considering for credit card processing.
+ GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **website release process**
+ Waiting for faster way to update community downloads and security advisories on main site.
+ Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ There was a discussion between MaxF and djpig and others.
+ For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ This page is outdated badly: [Static-key mini how-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ company will send this to tech writer to redo based on [example-fingerprint info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that github doc.
+ having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ tests should cover: gre, ipsec, userland, dco
+ linux, freebsd, windows
+ requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ matt provided icons in [issue 595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-06-26.md
@@ 0,0 1,120 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 26 June 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ #### **New: release openvpn 2.6.12**
+ _The security issue addressed in 2.6.11 has the known issue that it breaks certain setups with backend scripts that produce custom auth_failed messages. This will be addressed in the upcoming 2.6.12 release. An improvement in the area of the LZO library is also in the works._
+
+ #### **Updated: release openvpn 2.6.11**
+ _This release was done last week on June 20th. We have a fix for a reported issue with localized versions of Windows and a custom installation path of OpenVPN GUI. Looks like we can update to I002 for the Windows installer. This will likely go out today. The tunnelcrack mitigations for Windows are held back because we have had absolutely no response on the mailing lists for testing these and confirming that it doesn't break things. If someone can contribute to testing this we can follow up with a 2.6.12 release in a few weeks that contains the tunnelcrack mitigations for Windows. Otherwise, it goes to 2.7._
+
+ #### **Updated: DCO and Linux upstreaming, API change**
+ _Upstreaming DCO to Linux is proceeding, it is in the review stage at the moment. ordex has sent in **patchset version 4**. There will be an API change that makes it incompatible with the current implementation. A graceful solution to that was already discussed and in motion. giaan will be working on this._
+
+ #### **Updated: Tunnelcrack progress**
+ _Status update on TunnelCrack mitigations:_\
+ _The tunnelcrack mitigation for Windows has gone in master, which will go to the 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this._
+ _Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review._
+ _Linux, openvpn2: in progress. openvpn3: in progress._
+ _macOS: to be determined._
+ _iOS: to be determined._
+ _Android: not vulnerable._
+
+ #### **Updated: OpenVPN community meetup 2024**
+ _Wiki coordination page: [Community Meetup 2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)_
+ _Where: Karlsruhe, Germany. Meeting room found, need to find out how many participants roughly._
+ _When: Set to 20-22 September 2024._
+ _Shirts: novaflash spoke to matt - he will get us some design in august._
+ _We need to know how many participants will show. To that end, it makes sense if we put together an invite mail and send it out._
+ _novaflash put together a suggested mail; [invite draft](https://cryptpad.fr/pad/#/2/pad/edit/UEzTg-cbReVteh9zR9CQD-Tt/)_
+ _This will be sent out as an official invite to openvpn-devel and to some special guests._
+
+ #### **buildbot PRs need attention**
+ _Getting these merged soonish would help avoid nasty merge conflicts down the line_\
+ [Allow skipping build types](https://github.com/OpenVPN/openvpn-buildbot/pull/50)\
+ [Add smoketest builds for openvpn3, openvpn3-linux and ovpn-dco](https://github.com/OpenVPN/openvpn-buildbot/pull/51)\
+ [PR #48](https://github.com/OpenVPN/openvpn-buildbot/pull/48)\
+ _Developers have been pinged in the meeting about these, so they'll take a look when they can._
+
+ #### **fixing openvpn3-linux builds in Buildbot**
+ _Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing._
+ _As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process._
+ _Next step is a 'regular' OpenVPN3 Linux v23 release again._
+
+ #### **Linux arm64 buildbot workers**
+ _Mattock has done initial research._
+ _Docker seems to support (QEMU) emulated non-native containers, but Buildbot might be missing the glue to make it work._
+ _Patching Buildbot should not be *that* difficult._
+ _External (arm64) Docker host might be a more performant alternative option._
+
+ #### **how to proceed with lzo2.pc**
+ _pc file suggests "all includes should be done without `lzo/` prefix" - which is generally not a bad idea, but needs code changes beyond configure (right?)_
+ _There are some options to make changes here. For now, we'll just keep working around this issue._
+ _One thing seems clear; it would be too early to rip it out, it would most likely affect too many people still using it despite the fact that they shouldn't._
+ _An option we have is to use the OpenVPN3 implementation of lzo and port that to OpenVPN2, to solve this._
+ _This is a topic that will be moved to the OpenVPN community meetup 2024._
+
+ #### **run tests of 2.x against openvpn3? how?**
+ _There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes._
+ _This is in the openvpn3 repository._
+
+ #### **community.openvpn.net trac wiki**
+ _Wiki.js felt quite awkward and counterintuitive in practical tests done by mattock. It seems to focus on bling rather than usability._
+ _Xwiki felt quite bulky and enterprisey (a.k.a. full of "stuff") in the practical tests by mattock. It seems an overkill for our simple use-case._
+ _Mediawiki no longer feels as nasty as it once did :)_
+ _Maybe some Git-based wiki-type solution would be ok?_
+
+ #### **forums topics**
+ _rob0 and novaflash will work to get access and then find some time to look at solving the cloudflare related issue._
+ _Unfortunately the past weeks were difficult to find time - holidays and travel and such. Will find time and push this forward._
+ _Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address._
+ _- email confirmation on registration was suggested._
+ _- mod permissions, guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)_
+ _- access for mods to logs so one can see what others did_
+
+ #### **donation collection**
+ _From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._
+ _What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on._
+ _There are some options to consider. There may be existing solutions that we want to consider._
+ _PayPal seems overly expensive with all their fees._
+ _Stripe could be worth considering for credit card processing._
+ _GitHub Sponsors was mentioned as a possible solution, this is worth investigating._
+ _Open Collective was also mentioned, that needs some investigating how that exactly would work for us._
+
+ #### **website release process**
+ _Waiting for faster way to update community downloads and security advisories on main site._
+ _Again postponed due to issues. Now planned for this week. We'll see._
+
+ #### **Status of SBOM**
+ _There was a discussion between MaxF and djpig and others._
+ _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
+ _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
+
+ #### **Security mailing list**
+
+ #### **Static-key mini how-to is outdated.**
+ _This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)_
+ _company will send this to tech writer to redo based on [example fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc._
+ _having a simple guide online will help adoption_
+
+ #### **OpenVPN 2.6 performance results.**
+ _tests should cover: gre, ipsec, userland, dco_
+ _linux, freebsd, windows_
+ _requires time to be dedicated to doing this, when time available will do it_
+
+ #### **What's going on with new taskbar icons?**
+ _matt provided icons in [Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
+ _last update: will be picked up by selva when he has time_
+
+ #### **software code signing topic**
+ _company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
+ _in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
+ _depends on how hard/easy it is to access company key signing thingee from community infrastructure._
+ _also no high priority at the moment, we have a working solution now._
\ No newline at end of file
/dev/null .. meetings/2024-07-03.md
@@ 0,0 1,117 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 3 July 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated, closed: release openvpn 2.6.11**
+ - The original release was done on June 20th. A Windows installer update was done last week to solve an issue with localization and custom installation path (I002).
+
+ - **Updated: forums topics**
+ - novaflash finally has time to look into this topic. But has no access. Who can get novaflash access?
+ - looks like mattock, djpig or uddr35 - will poke uddr35 about this.
+
+ - **Updated: buildbot PRs need attention**
+ - 2 out of 3 PRs got merged, 3rd one is still up
+ - [Add smoketest builds for openvpn3, openvpn3-linux and ovpn-dco](https://github.com/OpenVPN/openvpn-buildbot/pull/51)
+
+ - **Updated: DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex has sent in **patchset version 5**.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **Updated: OpenVPN community meetup 2024**
+ - Invitation was sent, waiting to gather responses.
+ - Perhaps we can do a guesstimate on number of people expected.
+ - Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ - Where: Karlsruhe, Germany. Meeting room found, need to find out how many participants roughly.
+ - When: Set to 20-22 September 2024.
+ - Shirts: novaflash spoke to matt - he will get us some design in august.
+
+ - **Updated: community.openvpn.net trac wiki**
+ - We keep running into stupid limitations and bad suckiness with wiki solutions.
+ - So we're going back to requirements and lining up candidates: [NewWiki](https://community.openvpn.net/openvpn/wiki/NewWiki)
+
+ - **release openvpn 2.6.12**
+ - The security issue addressed in 2.6.11 has the known issue that it breaks certain setups with backend scripts that produce custom auth_failed messages.
+ - This will be addressed in the upcoming 2.6.12 release.
+ - An improvement in the area of the LZO library is also in the works.
+
+ - **Tunnelcrack progress**
+ - [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **fixing openvpn3-linux builds in Buildbot**
+ - Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing.
+ - As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process.
+ - Next step is a 'regular' OpenVPN3 Linux v23 release again.
+
+ - **Linux arm64 buildbot workers**
+ - Mattock has done initial research.
+ - Docker seems to support (QEMU) emulated non-native containers, but Buildbot might be missing the glue to make it work.
+ - Patching Buildbot should not be *that* difficult.
+ - External (arm64) Docker host might be a more performant alternative option.
+
+ - **how to proceed with lzo2.pc**
+ - pc file suggests "all includes should be done without `lzo/` prefix" - which is generally not a bad idea, but needs code changes beyond configure (right?)
+ - There are some options to make changes here. For now we'll just keep working around this issue.
+ - One thing seems clear; it would be too early to rip it out, it would most likely affect too many people still using it despite the fact that they shouldn't.
+ - An option we have is to use the OpenVPN3 implementation of lzo and port that to OpenVPN2, to solve this.
+ - This is a topic that will be moved to the OpenVPN community meetup 2024.
+
+ - **run tests of 2.x against openvpn3? how?**
+ - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **website release process**
+ - Waiting for faster way to update community downloads and security advisories on main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini Howto](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - company will send this to tech writer to redo based on [example-fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc.
+ - having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ - tests should cover: gre, ipsec, userland, dco
+ - linux, freebsd, windows
+ - requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ - company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ - depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-07-10.md
@@ 0,0 1,109 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time**: Wednesday 10 July 2024 at 14:00 CEST (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: forums topics**
+ - novaflash got access just last week, will look into the forums situation and set up a new PoC server.
+
+ - **Updated: OpenVPN community meetup 2024**
+ - Determined that venue will be at SteamWork, Karlsruhe. Details will be added to the wiki.
+ - Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ - Where: Karlsruhe, Germany. Meeting room found, need to find out how many participants roughly.
+ - When: Set to 20-22 September 2024.
+ - Shirts: novaflash spoke to matt - he will get us some design in August.
+
+ - **Updated: community.openvpn.net trac wiki**
+ - novaflash tried out a few things and updated: [NewWiki](https://community.openvpn.net/openvpn/wiki/NewWiki)
+ - The search continues.
+ - The security level on community.openvpn.net was lowered by one notch. Immediately attacks happened again.
+ - Turns out trac has a reflection attack vulnerability and this was mitigated. Let's see how it runs now.
+ - We know we need to replace this but need to find a solution that fits our needs first.
+
+ - **Updated: release openvpn 2.6.12**
+ - This should address the slightly-too-aggressive security fix in 2.6.11 that could affect people sending custom messages with trailing newline characters.
+ - Tentatively we will release this version next week.
+
+ - **Tunnelcrack progress**
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex has sent in **patchset version 5**.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **Fixing openvpn3-linux builds in Buildbot**
+ - Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing.
+ - As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process.
+ - Next step is a 'regular' OpenVPN3 Linux v23 release again.
+
+ - **Linux arm64 buildbot workers**
+ - Mattock has done initial research.
+ - Docker seems to support (QEMU) emulated non-native containers, but Buildbot might be missing the glue to make it work.
+ - Patching Buildbot should not be *that* difficult.
+ - External (arm64) Docker host might be a more performant alternative option.
+
+ - **How to proceed with lzo2.pc**
+ - pc file suggests "all includes should be done without `lzo/` prefix" - which is generally not a bad idea, but needs code changes beyond configure (right?)
+ - There are some options to make changes here. For now we'll just keep working around this issue.
+ - One thing seems clear; it would be too early to rip it out, it would most likely affect too many people still using it despite the fact that they shouldn't.
+ - An option we have is to use the OpenVPN3 implementation of lzo and port that to OpenVPN2, to solve this.
+ - This is a topic that will be moved to the OpenVPN community meetup 2024.
+
+ - **Run tests of 2.x against openvpn3? How?**
+ - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **Donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **Website release process**
+ - Waiting for a faster way to update community downloads and security advisories on the main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini Howto](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [this GitHub document](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: gre, ipsec, userland, dco
+ - Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this, when time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [this issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time.
+
+ - **Software code signing topic**
+ - The company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-07-17.md
@@ 0,0 1,103 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 17 July 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: release openvpn 2.6.12**
+ _This should address the slightly-too-aggressive security fix in 2.6.11 that could affect people sending custom messages with trailing newline characters._
+ _Should be a release tomorrow on 18 July._
+
+ - **Updated: OpenVPN community meetup 2024**
+ _Hotel recommendation added; Hotel Santo in Karlsruhe._
+ _Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)_
+ _Where: Karlsruhe, Germany. SteamWork, Karlsruhe._
+ _When: Set to 20-22 September 2024._
+ _Shirts: novaflash spoke to matt - he will get us some design in August._
+
+ - **community.openvpn.net trac wiki**
+ _novaflash tried out a few things and updated: [NewWiki](https://community.openvpn.net/openvpn/wiki/NewWiki)_
+ _the search continues._
+ _the security level on community.openvpn.net was lowered by one notch. immediately attacks happened again._
+ _turns out trac has a reflection attack vulnerability and this was mitigated. let's see how it runs now._
+ _we know we need to replace this but need to find a solution that fits our needs first._
+
+ - **forums topics**
+ _novaflash has access and is working on a PoC setup combining old and new on an ubuntu server._
+
+ - **Tunnelcrack progress**
+ _Status update on TunnelCrack mitigations:_
+ _The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this._
+ _Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review._
+ _Linux, openvpn2: in progress. openvpn3: in progress._
+ _macOS: to be determined._
+ _iOS: to be determined._
+ _Android: not vulnerable._
+
+ - **DCO and Linux upstreaming, API change**
+ _Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._
+ _ordex has sent in **patchset version 5**._
+ _There will be an API change that makes it incompatible with the current implementation._
+ _A graceful solution to that was already discussed and in motion. giaan will be working on this._
+ _(in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)_
+
+ - **fixing openvpn3-linux builds in Buildbot**
+ _Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing._
+ _As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process._
+ _Next step is a 'regular' OpenVPN3 Linux v23 release again._
+
+ - **Linux arm64 buildbot workers**
+ _Mattock has done initial research._
+ _Docker seems to support (QEMU) emulated non-native containers, but Buildbot might be missing the glue to make it work._
+ _Patching Buildbot should not be *that* difficult._
+ _External (arm64) Docker host might be a more performant alternative option._
+
+ - **run tests of 2.x against openvpn3? how?**
+ _There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes._
+ _This is in the openvpn3 repository._
+
+ - **donation collection**
+ _From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._
+ _What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on._
+ _There are some options to consider. There may be existing solutions that we want to consider._
+ _PayPal seems overly expensive with all their fees._
+ _Stripe could be worth considering for credit card processing._
+ _GitHub Sponsors was mentioned as a possible solution, this is worth investigating._
+ _Open Collective was also mentioned, that needs some investigating how that exactly would work for us._
+
+ - **website release process**
+ _Waiting for faster way to update community downloads and security advisories on main site._
+ _Again postponed due to issues. Now planned for this week. We'll see._
+
+ - **Status of SBOM**
+ _There was a discussion between MaxF and djpig and others._
+ _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
+ _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ _This page is outdated badly: [Static-key mini how-to](https://openvpn.net/community-resources/static-key-mini-howto/)_
+ _company will send this to tech writer to redo based on [this GitHub document](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst)_
+ _and also retain a link to that GitHub doc._
+ _having a simple guide online will help adoption_
+
+ - **OpenVPN 2.6 performance results.**
+ _tests should cover: gre, ipsec, userland, dco_
+ _linux, freebsd, windows_
+ _requires time to be dedicated to doing this, when time available will do it_
+
+ - **What's going on with new taskbar icons?**
+ _matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
+ _last update: will be picked up by selva when he has time_
+
+ - **software code signing topic**
+ _company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
+ _in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
+ _depends on how hard/easy it is to access company key signing thingee from community infrastructure._
+ _also no high priority at the moment, we have a working solution now._
\ No newline at end of file
/dev/null .. meetings/2024-07-24.md
@@ 0,0 1,104 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 24 July 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: release openvpn 2.6.12**
+ _This was released on July 18th._
+
+ - **New: live route updates**
+ _lev has a proposal to go through, to see if the approach is acceptable to community members._
+
+ - **OpenVPN community meetup 2024**
+ _Hotel recommendation added; Hotel Santo in Karlsruhe._
+ _Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)_
+ _Where: Karlsruhe, Germany. SteamWork, Karlsruhe._
+ _When: Set to 20-22 September 2024._
+ _Shirts: novaflash spoke to matt - he will get us some design in August._
+
+ - **community.openvpn.net trac wiki**
+ _novaflash tried out a few things and updated: [NewWiki](https://community.openvpn.net/openvpn/wiki/NewWiki)_
+ _the search continues._
+ _the security level on community.openvpn.net was lowered by one notch. Immediately attacks happened again._
+ _turns out trac has a reflection attack vulnerability and this was mitigated. Let's see how it runs now._
+ _We know we need to replace this but need to find a solution that fits our needs first._
+
+ - **forums topics**
+ _novaflash has access and is working on a PoC setup combining old and new on an ubuntu server._
+
+ - **Tunnelcrack progress**
+ _Status update on TunnelCrack mitigations:_
+ _The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this._
+ _Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review._
+ _Linux, openvpn2: in progress. openvpn3: in progress._
+ _macOS: to be determined._
+ _iOS: to be determined._
+ _Android: not vulnerable._
+
+ - **DCO and Linux upstreaming, API change**
+ _Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._
+ _ordex has sent in **patchset version 5**._
+ _There will be an API change that makes it incompatible with the current implementation._
+ _A graceful solution to that was already discussed and in motion. giaan will be working on this._
+ _(in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)_
+
+ - **fixing openvpn3-linux builds in Buildbot**
+ _Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing._
+ _As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process._
+ _Next step is a 'regular' OpenVPN3 Linux v23 release again._
+
+ - **Linux arm64 buildbot workers**
+ _Mattock has done initial research._
+ _Docker seems to support (QEMU) emulated non-native containers, but Buildbot might be missing the glue to make it work._
+ _Patching Buildbot should not be *that* difficult._
+ _External (arm64) Docker host might be a more performant alternative option._
+
+ - **run tests of 2.x against openvpn3? how?**
+ _There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes._
+ _This is in the openvpn3 repository._
+
+ - **donation collection**
+ _From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._
+ _What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on._
+ _There are some options to consider. There may be existing solutions that we want to consider._
+ _PayPal seems overly expensive with all their fees._
+ _Stripe could be worth considering for credit card processing._
+ _GitHub Sponsors was mentioned as a possible solution, this is worth investigating._
+ _Open Collective was also mentioned, that needs some investigating how that exactly would work for us._
+
+ - **website release process**
+ _Waiting for faster way to update community downloads and security advisories on main site._
+ _Again postponed due to issues. Now planned for this week. We'll see._
+
+ - **Status of SBOM**
+ _There was a discussion between MaxF and djpig and others._
+ _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
+ _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ _This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)_
+ _Company will send this to tech writer to redo based on [GitHub example](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc._
+ _Having a simple guide online will help adoption._
+
+ - **OpenVPN 2.6 performance results.**
+ _Tests should cover: gre, ipsec, userland, dco_
+ _Linux, FreeBSD, Windows_
+ _Requires time to be dedicated to doing this, when time available will do it._
+
+ - **What's going on with new taskbar icons?**
+ _Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
+ _Last update: will be picked up by Selva when he has time._
+
+ - **software code signing topic**
+ _Company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing._
+ _In future we could possibly switch community to that same key. Saves having to maintain 2 different keys._
+ _Depends on how hard/easy it is to access company key signing thingee from community infrastructure._
+ _Also, no high priority at the moment, we have a working solution now._
\ No newline at end of file
/dev/null .. meetings/2024-07-31.md
@@ 0,0 1,107 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 31 July 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: OpenVPN community meetup 2024**
+ - Hotel recommendation added; Hotel Santo in Karlsruhe.
+ - Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ - Where: Karlsruhe, Germany. SteamWork, Karlsruhe.
+ - When: Set to 20-22 September 2024.
+ - Shirts: matt gave us 2 t-shirt designs and we reviewed them in the meeting.
+ - We love the cartoon version, so if we can only have one, we'll do that. But if possible, getting the minimalistic one too would be cool.
+
+ - **Updated: live route updates**
+ - lev has a proposal to go through, to see if the approach is acceptable to community members.
+ - cron2 hasn't had time to read through it yet.
+ - So far it seems we are good with optional/mandatory options concept, and by default all options are mandatory.
+ - Optional are prefixed with a question mark (?). The idea here is that if a client does not support updating that parameter live it can ignore it.
+ - Whereas without such a prefix, it is mandatory, so if a client cannot update it live, it will do a normal reconnect to ensure changes are implemented.
+
+ - **community.openvpn.net trac wiki**
+ - novaflash tried out a few things and updated: [NewWiki](https://community.openvpn.net/openvpn/wiki/NewWiki)
+ - the search continues.
+ - the security level on community.openvpn.net was lowered by one notch. immediately attacks happened again.
+ - turns out trac has a reflection attack vulnerability and this was mitigated. let's see how it runs now.
+ - we know we need to replace this but need to find a solution that fits our needs first.
+
+ - **forums topics**
+ - novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress**
+ - [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex has sent in **patchset version 5**.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **fixing openvpn3-linux builds in Buildbot**
+ - Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing.
+ - As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process.
+ - Next step is a 'regular' OpenVPN3 Linux v23 release again.
+
+ - **Linux arm64 buildbot workers**
+ - Mattock has done initial research.
+ - Docker seems to support (QEMU) emulated non-native containers, but Buildbot might be missing the glue to make it work.
+ - Patching Buildbot should not be *that* difficult.
+ - External (arm64) Docker host might be a more performant alternative option.
+
+ - **run tests of 2.x against openvpn3? how?**
+ - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **website release process**
+ - Waiting for faster way to update community downloads and security advisories on main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - company will send this to tech writer to redo based on information from [GitHub](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that github doc.
+ - having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ - tests should cover: gre, ipsec, userland, dco
+ - linux, freebsd, windows
+ - requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ - company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ - depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-08-07.md
@@ 0,0 1,106 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time**: Wednesday 07 August 2024 at 14:00 CEST (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **OpenVPN community meetup 2024**
+ - Hotel recommendation added; Hotel Santo in Karlsruhe.
+ - Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ - Where: Karlsruhe, Germany. SteamWork, Karlsruhe.
+ - When: Set to 20-22 September 2024.
+ - Shirts: matt gave us 2 t-shirt designs and we reviewed them in the meeting.
+ - We love the cartoon version, so if we can only have one, we'll do that. But if possible, getting the minimalistic one too would be cool.
+
+ - **Live route updates**
+ - lev has a proposal to go through, to see if the approach is acceptable to community members.
+ - cron2 hasn't had time to read through it yet.
+ - So far it seems we are good with optional/mandatory options concept, and by default all options are mandatory.
+ - Optional are prefixed with a question mark (?). The idea here is that if a client does not support updating that parameter live it can ignore it.
+ - Whereas without such a prefix, it is mandatory, so if a client cannot update it live, it will do a normal reconnect to ensure changes are implemented.
+
+ - **community.openvpn.net trac wiki**
+ - novaflash tried out a few things and updated: [NewWiki](https://community.openvpn.net/openvpn/wiki/NewWiki)
+ - the search continues.
+ - the security level on community.openvpn.net was lowered by one notch. immediately attacks happened again.
+ - turns out trac has a reflection attack vulnerability and this was mitigated. let's see how it runs now.
+ - we know we need to replace this but need to find a solution that fits our needs first.
+
+ - **Forums topics**
+ - novaflash has access and is working on a PoC setup combining old and new on an Ubuntu server.
+
+ - **TunnelCrack progress** ([TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack))
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex has sent in **patchset version 5**.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **Fixing openvpn3-linux builds in Buildbot**
+ - Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing.
+ - As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process.
+ - Next step is a 'regular' OpenVPN3 Linux v23 release again.
+
+ - **Linux arm64 buildbot workers**
+ - Mattock has done initial research.
+ - Docker seems to support (QEMU) emulated non-native containers, but Buildbot might be missing the glue to make it work.
+ - Patching Buildbot should not be *that* difficult.
+ - External (arm64) Docker host might be a more performant alternative option.
+
+ - **Run tests of 2.x against openvpn3? how?**
+ - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **Donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **Website release process**
+ - Waiting for faster way to update community downloads and security advisories on main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini Howto](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - company will send this to tech writer to redo based on [GitHub doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ - tests should cover: gre, ipsec, userland, dco
+ - linux, freebsd, windows
+ - requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - last update: will be picked up by selva when he has time
+
+ - **Software code signing topic**
+ - company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ - depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-08-14.md
@@ 0,0 1,103 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 14 August 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: OpenVPN community meetup 2024**
+ - Hotel recommendation added; Hotel Santo in Karlsruhe.
+ - Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ - Where: Karlsruhe, Germany. SteamWork, Karlsruhe.
+ - When: Set to 20-22 September 2024.
+ - Shirts: matt gave us 2 t-shirt designs and we reviewed them in the meeting.
+ - T-shirts are being ordered, there will be enough to provide the list of people on the wiki page.
+
+ - **Updated: community.openvpn.net trac wiki**
+ - novaflash and mattock tried out a few things and updated: [NewWiki](https://community.openvpn.net/openvpn/wiki/NewWiki)
+ - We found otterwiki and this checks the must have boxes and a nice-to-have "commit to git backend" function. So we'll PoC that.
+ - Collaborative editing seems to only be possible with paid products currently.
+
+ - **Updated: Linux arm64 buildbot workers**
+ - There's a "docker host" now that is essentially a buildbot environment that can run arm64 containers.
+ - In theory pointing our existing buildmaster to it should work. This is untested but should work.
+ - When mattock has time he'll work further on this.
+
+ - **live route updates**
+ - Lev has a proposal to go through, to see if the approach is acceptable to community members.
+ - cron2 hasn't had time to read through it yet.
+ - So far it seems we are good with optional/mandatory options concept, and by default all options are mandatory.
+ - Optional are prefixed with a question mark (?). The idea here is that if a client does not support updating that parameter live it can ignore it.
+ - Whereas without such a prefix, it is mandatory, so if a client cannot update it live, it will do a normal reconnect to ensure changes are implemented.
+
+ - **forums topics**
+ - Novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress** ([TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack))
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex has sent in **patchset version 5**.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **fixing openvpn3-linux builds in Buildbot**
+ - Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing.
+ - As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process.
+ - Next step is a 'regular' OpenVPN3 Linux v23 release again.
+
+ - **run tests of 2.x against openvpn3? how?**
+ - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **website release process**
+ - Waiting for faster way to update community downloads and security advisories on main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - Company will send this to tech writer to redo based on information from [GitHub](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: gre, ipsec, userland, dco
+ - Platforms: Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this, when time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time.
+
+ - **software code signing topic**
+ - Company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - In future we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-08-21.md
@@ 0,0 1,103 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 21 August 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **OpenVPN community meetup 2024**
+ - Hotel recommendation added: Hotel Santo in Karlsruhe.
+ - Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ - Where: Karlsruhe, Germany. SteamWork, Karlsruhe.
+ - When: Set to 20-22 September 2024.
+ - Shirts: matt gave us 2 t-shirt designs and we reviewed them in the meeting.
+ - T-shirt are being ordered, there will be enough to provide the list of people on the wiki page.
+
+ - **community.openvpn.net trac wiki**
+ - novaflash and mattock tried out a few things and updated: [NewWiki](https://community.openvpn.net/openvpn/wiki/NewWiki)
+ - we found otterwiki and this checks the must have boxes and a nice-to-have "commit to git backend" function. So we'll PoC that.
+ - Collaborative editing seems to only be possible with paid products currently.
+
+ - **Linux arm64 buildbot workers**
+ - There's a "docker host" now that is essentially a buildbot environment that can run arm64 containers.
+ - In theory pointing our existing buildmaster to it should work. This is untested but should work.
+ - When mattock has time he'll work further on this.
+
+ - **live route updates**
+ - lev has a proposal to go through, to see if the approach is acceptable to community members.
+ - cron2 hasn't had time to read through it yet.
+ - So far it seems we are good with optional/mandatory options concept, and by default all options are mandatory.
+ - Optional are prefixed with a question mark (?). The idea here is that if a client does not support updating that parameter live it can ignore it.
+ - Whereas without such a prefix, it is mandatory, so if a client cannot update it live, it will do a normal reconnect to ensure changes are implemented.
+
+ - **forums topics**
+ - novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress** ([TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack))
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex has sent in **patchset version 5**.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **fixing openvpn3-linux builds in Buildbot**
+ - Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing.
+ - As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process.
+ - Next step is a 'regular' OpenVPN3 Linux v23 release again.
+
+ - **run tests of 2.x against openvpn3? how?**
+ - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **website release process**
+ - Waiting for faster way to update community downloads and security advisories on main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static-key mini-howto](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - company will send this to tech writer to redo based on [this GitHub document](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ - tests should cover: gre, ipsec, userland, dco
+ - linux, freebsd, windows
+ - requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [this GitHub issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ - company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ - depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-08-28.md
@@ 0,0 1,104 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - Time: Wednesday 28 August 2024 at 14:00 CEST (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **OpenVPN community meetup 2024**
+ - Hotel recommendation added; Hotel Santo in Karlsruhe.
+ - Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ - Where: Karlsruhe, Germany. SteamWork, Karlsruhe.
+ - When: Set to 20-22 September 2024.
+ - Shirts: matt gave us 2 t-shirt designs and we reviewed them in the meeting.
+ - T-shirts are being ordered, there will be enough to provide the list of people on the wiki page.
+
+ - **community.openvpn.net trac wiki**
+ - novaflash and mattock tried out a few things and updated: [NewWiki](https://community.openvpn.net/openvpn/wiki/NewWiki)
+ - We found otterwiki and this checks the must-have boxes and a nice-to-have "commit to git backend" function. So we'll PoC that.
+ - Collaborative editing seems to only be possible with paid products currently.
+
+ - **Linux arm64 buildbot workers**
+ - There's a "docker host" now that is essentially a buildbot environment that can run arm64 containers.
+ - In theory pointing our existing buildmaster to it should work. This is untested but should work.
+ - When mattock has time he'll work further on this.
+
+ - **live route updates**
+ - lev has a proposal to go through, to see if the approach is acceptable to community members.
+ - cron2 hasn't had time to read through it yet.
+ - So far it seems we are good with optional/mandatory options concept, and by default all options are mandatory.
+ - Optional are prefixed with a question mark (?). The idea here is that if a client does not support updating that parameter live it can ignore it.
+ - Whereas without such a prefix, it is mandatory, so if a client cannot update it live, it will do a normal reconnect to ensure changes are implemented.
+
+ - **forums topics**
+ - novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress**
+ - [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex has sent in **patchset version 5**.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **fixing openvpn3-linux builds in Buildbot**
+ - Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing.
+ - As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process.
+ - Next step is a 'regular' OpenVPN3 Linux v23 release again.
+
+ - **run tests of 2.x against openvpn3? how?**
+ - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **website release process**
+ - Waiting for a faster way to update community downloads and security advisories on the main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini Howto](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - company will send this to tech writer to redo based on [example fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc.
+ - having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ - tests should cover: gre, ipsec, userland, dco
+ - linux, freebsd, windows
+ - requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [OpenVPN GUI Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ - company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ - depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-09-04.md
@@ 0,0 1,100 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time**: Wednesday 4 September 2024 at 14:00 CEST (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: OpenVPN community meetup 2024**
+ - Hotel recommendation added; Hotel Santo in Karlsruhe.
+ - Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ - Where: Karlsruhe, Germany. SteamWork, Karlsruhe.
+ - When: Set to 20-22 September 2024.
+ - Shirts: T-shirts have been ordered.
+
+ - **Updated: community.openvpn.net trac wiki**
+ - mattock is working on getting otterwiki working in a reasonable production configuration.
+
+ - **Linux arm64 buildbot workers**
+ - There's a "docker host" now that is essentially a buildbot environment that can run arm64 containers.
+ - In theory pointing our existing buildmaster to it should work. This is untested but should work.
+ - When mattock has time he'll work further on this.
+
+ - **live route updates**
+ - lev has a proposal to go through, to see if the approach is acceptable to community members.
+ - cron2 hasn't had time to read through it yet.
+ - So far it seems we are good with optional/mandatory options concept, and by default all options are mandatory.
+ - Optional are prefixed with a question mark (?). The idea here is that if a client does not support updating that parameter live it can ignore it.
+ - Whereas without such a prefix, it is mandatory, so if a client cannot update it live, it will do a normal reconnect to ensure changes are implemented.
+
+ - **forums topics**
+ - novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress** [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex has sent in **patchset version 5**.
+ - There will be an API change that makes it incompatible with the current implementation.
+ - A graceful solution to that was already discussed and in motion. giaan will be working on this.
+ - (in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)
+
+ - **fixing openvpn3-linux builds in Buildbot**
+ - Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing.
+ - As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process.
+ - Next step is a 'regular' OpenVPN3 Linux v23 release again.
+
+ - **run tests of 2.x against openvpn3? how?**
+ - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **website release process**
+ - Waiting for faster way to update community downloads and security advisories on main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static-key mini how-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - company will send this to tech writer to redo based on [this GitHub doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc.
+ - having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ - tests should cover: gre, ipsec, userland, dco
+ - linux, freebsd, windows
+ - requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [this GitHub issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ - company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ - depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-09-11.md
@@ 0,0 1,98 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time**: Wednesday 11 September 2024 at 14:00 CEST (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: OpenVPN community meetup 2024**
+ - Hotel recommendation added; Hotel Santo in Karlsruhe.
+ - Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ - Where: Karlsruhe, Germany. SteamWork, Karlsruhe.
+ - When: Set to 20-22 September 2024.
+ - Shirts: T-shirts are on their way, expected to arrive this week.
+
+ - **Updated: community.openvpn.net trac wiki**
+ - Mattock is working on getting otterwiki working in a reasonable production configuration.
+ - Hit a bug in otterwiki, reported it, it got fixed, moving on...
+ - Basically working on setting up postgresql, separating uwsgi. After that, let's see if we can copy content.
+
+ - **Updated: DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex has sent in **patchset version 6**. and v7 is on the way.
+ - There will be an API change that makes it incompatible with the current implementation.
+
+ - **Closed: Linux arm64 buildbot workers**
+ - Mattock almost finished the work on this - a small fix that djpig requested is pending, but it's all working now.
+
+ - **Closed: fixing openvpn3-linux builds in Buildbot**
+ - Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing.
+ - As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process.
+ - Next step is a 'regular' OpenVPN3 Linux v23 release again.
+
+ - **live route updates**
+ - lev has a proposal to go through, to see if the approach is acceptable to community members.
+ - cron2 hasn't had time to read through it yet.
+ - So far it seems we are good with optional/mandatory options concept, and by default all options are mandatory.
+ - Optional are prefixed with a question mark (?). The idea here is that if a client does not support updating that parameter live it can ignore it.
+ - Whereas without such a prefix, it is mandatory, so if a client cannot update it live, it will do a normal reconnect to ensure changes are implemented.
+
+ - **forums topics**
+ - novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress** [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **run tests of 2.x against openvpn3? how?**
+ - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **website release process**
+ - Waiting for faster way to update community downloads and security advisories on main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini-Howto](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - Company will send this to tech writer to redo based on [example fingerprint info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: gre, ipsec, userland, dco
+ - Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by Selva when he has time
+
+ - **software code signing topic**
+ - Company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - In future we could possibly switch community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-09-18.md
@@ 0,0 1,86 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - Time: Wednesday 18 September 2024 at 14:00 CEST (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: OpenVPN community meetup 2024**
+ - Hotel recommendation added; Hotel Santo in Karlsruhe.
+ - Wiki coordination page: [https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)
+ - Where: Karlsruhe, Germany. SteamWork, Karlsruhe.
+ - When: 20-22 September 2024.
+ - Shirts: T-shirts are in d12fk's possession in Karlsruhe now.
+
+ - **Updated: DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex has sent in **patchset version 7**. Awaiting review again.
+
+ - **Updated: community.openvpn.net trac wiki**
+ - Seems mattock managed to get it into a reasonable shape ready for production.
+ - Next step is looking at migrating data from old to new.
+
+ - **Updated: live route updates**
+ - There's a PR up on GitHub openvpn-rfc for the live route updates proposal.
+ - So far it seems we are good with optional/mandatory options concept, and by default all options are mandatory.
+ - Optional are prefixed with a question mark (?). The idea here is that if a client does not support updating that parameter live it can ignore it.
+ - Whereas without such a prefix, it is mandatory, so if a client cannot update it live, it will do a normal reconnect to ensure changes are implemented.
+
+ - **forums topics**
+ - novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress**
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **run tests of 2.x against openvpn3? how?**
+ - There is a 'null client' variant of ovpncli that allows making VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **donation collection**
+ - From earlier exploration, it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **website release process**
+ - Waiting for a faster way to update community downloads and security advisories on the main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc. Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: gre, ipsec, userland, dco
+ - Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this, when time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time.
+
+ - **software code signing topic**
+ - The company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
/dev/null .. meetings/2024-09-25.md
@@ 0,0 1,100 @@
+ # IrcMeetings
+
+ ## Basic Info
+
+ - **Time:** Wednesday 25 September 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current Topics
+
+ - **Done: OpenVPN Community Meetup 2024**
+ - Meetup was concluded. 13 persons in attendance.
+ - Much time was spent planning the 2.7 release. Planned for January 2025. (Not yet reflected on wiki:StatusOfOpenvpn27)
+ - Meeting notes: [https://cryptpad.fr/pad/#/2/pad/edit/KPJKt7RSPrvC9grrvQ0KhbwE/](https://cryptpad.fr/pad/#/2/pad/edit/KPJKt7RSPrvC9grrvQ0KhbwE/)
+
+ - **New: --dns Patch Review Upcoming**
+ - DNS patches were discussed during Meetup. d12fk will provide them for review real soon.
+
+ - **Updated: DCO and Linux Upstreaming, API Change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex is collecting feedback on **patchset version 7**. Plan is to send v8 by end of month.
+ - During meetup, it was discussed that if the patchset does not make it into the kernel before 2.7, we should update the out-of-tree module to match the new API anyway, so that 2.7 supports the new API and we need no or minimal further changes to work with the eventual in-tree version.
+
+ - **Updated: community.openvpn.net Trac Wiki**
+ - Seems mattock managed to get it into a reasonable shape ready for production.
+ - Some required changes to otterwiki have been submitted upstream.
+ - Next step is looking at migrating data from old to new.
+ - Also, djpig needs to provide an EC2 instance in the community account for hosting production.
+
+ - **New: Community AWS Account Governance**
+ - Currently, the Community AWS account is part of the OpenVPN, Inc. AWS organization.
+ - With the OTF founding, there would be an opportunity to move to a separate AWS account that is not under the corporate umbrella.
+ - Requires further discussion whether that is something we want.
+
+ - **Updated: Live Route Updates**
+ - PR to RFC was merged. [https://github.com/OpenVPN/openvpn-rfc/pull/4](https://github.com/OpenVPN/openvpn-rfc/pull/4)
+ - Now we need to complete the actual implementations.
+ - Implementation for OpenVPN v2 will be looked at by ordex and his team.
+ - lev is working on (client-side) implementation in OpenVPN 3.
+
+ ---
+
+ ### Backlog
+
+ - **Forums Topics**
+ - novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack Progress**
+ - [TunnelCrack Community Wiki Article](wiki:TunnelCrack)
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **Run Tests of 2.x against Openvpn3? How?**
+ - There is a 'null client' variant of ovpncli that allows making VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **Donation Collection**
+ - From earlier exploration, it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution; this is worth investigating.
+ - Open Collective was also mentioned; that needs some investigating how that exactly would work for us.
+
+ - **Website Release Process**
+ - Waiting for faster way to update community downloads and security advisories on the main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security Mailing List**
+
+ - **Static-Key Mini How-To is Outdated**
+ - This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - The company will send this to a tech writer to redo based on information from [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc. Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 Performance Results**
+ - Tests should cover: gre, ipsec, userland, dco
+ - Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this; when time is available, will do it.
+
+ - **What's Going on with New Taskbar Icons?**
+ - Matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by selva when he has time.
+
+ - **Software Code Signing Topic**
+ - The company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
+ - Also, no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-10-02.md
@@ 0,0 1,118 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time**: Wednesday 2nd October 2024 at 14:00 CEST (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Release 2.7**
+ [StatusOfOpenvpn27](wiki:StatusOfOpenvpn27) was updated with the results from Karlsruhe meetup.
+ Compare [CommunityMeetup2024](wiki:CommunityMeetup2024).
+ Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right.
+
+ - **Updated: multi-socket patch series**
+ New version of the patch series is posted. Reviews welcome :)
+
+ - **Updated: DATA_V3 patch**
+ plaisthos has written a new draft for new key handling for the data channel based on discussions in Karlsruhe.
+ See [DATA_V3 patch PR](https://github.com/OpenVPN/openvpn-rfc/pull/5). Feedback welcome :)
+
+ - **Updated: buildbot improvements**
+ mattock has a patch to split the mails for different project to different mail addresses.
+ The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore.
+ Instead, we could create a openvpn3-builds@ ML. djpig will look into that.
+
+ - **Updated: t_server_null improvements**
+ mattock plans to work on improving stability of the test first. At the moment, if the test fails to clean up it can easily leave the worker in a state where all future tests fail.
+ Next feature plans are to add more cross-version tests. E.g. have a test for release/2.6 <-> master in buildbot.
+
+ - **New: 2.7 security audit**
+ ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.
+
+ ---
+
+ ### Backlog
+
+ - **--dns patch review upcoming**
+ DNS patches were discussed during Meetup. d12fk will provide them for review real soon.
+
+ - **DCO and Linux upstreaming, API change**
+ Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ ordex is collecting feedback on **patchset version 7**. Plan is to send v8 by end of month.
+ During meetup it was discussed that if the patchset does not make it into the kernel before 2.7 we should update the out-of-tree module to match the new API anyway. So that 2.7 supports the new API and we need no or minimal further changes to work with the eventual in-tree version.
+
+ - **live route updates**
+ PR to RFC was merged. [Live route updates PR](https://github.com/OpenVPN/openvpn-rfc/pull/4)
+ Now we need to complete the actual implementations.
+ Implementation for OpenVPN v2 will be looked at by ordex and his team.
+ lev is working on (client-side) implementation in OpenVPN 3.
+
+ - **community.openvpn.net trac wiki**
+ Seems mattock managed to get it into a reasonable shape ready for production.
+ Some required changes to otterwiki have been submitted upstream.
+ Next step is looking at migrating data from old to new.
+ Also, djpig needs to provide an EC2 instance in the community account for hosting production.
+
+ - **forums topics**
+ novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](wiki:TunnelCrack)**
+ Status update on TunnelCrack mitigations:
+ The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ Linux, openvpn2: in progress. openvpn3: in progress.
+ macOS: to be determined.
+ iOS: to be determined.
+ Android: not vulnerable.
+
+ - **run tests of 2.x against openvpn3? how?**
+ There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ This is in the openvpn3 repository.
+
+ - **donation collection**
+ From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ There are some options to consider. There may be existing solutions that we want to consider.
+ PayPal seems overly expensive with all their fees.
+ Stripe could be worth considering for credit card processing.
+ GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **Community AWS account governance**
+ Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization.
+ With the OTF founding, there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.
+ Requires further discussion whether that is something we want.
+
+ - **website release process**
+ Waiting for a faster way to update community downloads and security advisories on the main site.
+ Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ There was a discussion between MaxF and djpig and others.
+ For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ The company will send this to a tech writer to redo based on [Example Fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc. Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ Tests should cover: gre, ipsec, userland, dco
+ Linux, FreeBSD, Windows
+ Requires time to be dedicated to doing this, when time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ Matt provided icons in [Taskbar Icons Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ Last update: will be picked up by selva when he has time.
+
+ - **Software code signing topic**
+ Company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ In the future, we could possibly switch community to that same key. Saves having to maintain two different keys.
+ Depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ Also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-10-09.md
@@ 0,0 1,117 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time**: Wednesday 9th October 2024 at 14:00 CEST (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: DCO and Linux upstreaming, API change**
+ _Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._
+ _ordex is collecting feedback on **patchset version 8**. Plan is to send v9 after collecting feedback._
+ _During meetup it was discussed that if the patchset does not make it into the kernel before 2.7 we should update the out-of-tree module to match the new API anyway. So that 2.7 supports the new API and we need no or minimal further changes to work with the eventual in-tree version._
+
+ - **Updated: buildbot improvements**
+ _djpig reports that the first arm64 architecture buildbot agent now works. We can add more workers as required._
+ _mattock has a patch to split the mails for different project to different mail addresses._
+ _The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore._
+ _Instead we could create a openvpn3-builds@ ML. djpig will look into that._
+
+ - **Updated: t_server_null improvements**
+ _The tests against latest git master server against older openvpn client versions are almost done._
+
+ - **Release 2.7**
+ _[StatusOfOpenvpn27](wiki:StatusOfOpenvpn27) was updated with the results from Karlsruhe meetup._
+ _compare [CommunityMeetup2024](wiki:CommunityMeetup2024)._
+ _Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right._
+
+ - **multi-socket patch series**
+ _New version of the patch series is posted. Reviews welcome :)_
+
+ - **DATA_V3 patch**
+ _plaisthos has written a new draft for new key handling for the data channel based on discussions in Karlsruhe._
+ _See [https://github.com/OpenVPN/openvpn-rfc/pull/5](https://github.com/OpenVPN/openvpn-rfc/pull/5). Feedback welcome :)_
+
+ - **2.7 security audit**
+ _ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code._
+
+ ### Backlog
+
+ - **--dns patch review upcoming**
+ _DNS patches were discussed during Meetup. d12fk will provide them for review real soon._
+
+ - **live route updates**
+ _PR to RFC was merged. ([https://github.com/OpenVPN/openvpn-rfc/pull/4](https://github.com/OpenVPN/openvpn-rfc/pull/4))_
+ _Now we need to complete the actual implementations._
+ _Implementation for OpenVPN v2 will be looked at by ordex and his team._
+ _lev is working on (client-side) implementation in OpenVPN 3._
+
+ - **community.openvpn.net trac wiki**
+ _Seems mattock managed to get it into a reasonable shape ready for production._
+ _Some required changes to otterwiki have been submitted upstream._
+ _Next step is looking at migrating data from old to new._
+ _Also djpig needs to provide an EC2 instance in the community account for hosting production._
+
+ - **forums topics**
+ _novaflash has access and is working on a PoC setup combining old and new on an ubuntu server._
+
+ - **Tunnelcrack progress**
+ _Status update on TunnelCrack mitigations:_
+ _The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this._
+ _Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review._
+ _Linux, openvpn2: in progress. openvpn3: in progress._
+ _macOS: to be determined._
+ _iOS: to be determined._
+ _Android: not vulnerable._
+
+ - **run tests of 2.x against openvpn3? how?**
+ _There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes._
+ _This is in the openvpn3 repository._
+
+ - **donation collection**
+ _From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._
+ _What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on._
+ _There are some options to consider. There may be existing solutions that we want to consider._
+ _PayPal seems overly expensive with all their fees._
+ _Stripe could be worth considering for credit card processing._
+ _GitHub Sponsors was mentioned as a possible solution, this is worth investigating._
+ _Open Collective was also mentioned, that needs some investigating how that exactly would work for us._
+
+ - **Community AWS account governance**
+ _Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization_
+ _With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella._
+ _Requires further discussion whether that is something we want._
+
+ - **website release process**
+ _Waiting for faster way to update community downloads and security advisories on main site._
+ _Again postponed due to issues. Now planned for this week. We'll see._
+
+ - **Status of SBOM**
+ _There was a discussion between MaxF and djpig and others._
+ _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
+ _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
+
+ - **Security mailing list**
+
+ - **Static-key mini how-to is outdated.**
+ _This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)_
+ _company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc._
+ _having a simple guide online will help adoption_
+
+ - **OpenVPN 2.6 performance results.**
+ _tests should cover: gre, ipsec, userland, dco_
+ _linux, freebsd, windows_
+ _requires time to be dedicated to doing this, when time available will do it_
+
+ - **What's going on with new taskbar icons?**
+ _matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
+ _last update: will be picked up by selva when he has time_
+
+ - **software code signing topic**
+ _company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
+ _in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
+ _depends on how hard/easy it is to access company key signing thingee from community infrastructure._
+ _also no high priority at the moment, we have a working solution now._
\ No newline at end of file
/dev/null .. meetings/2024-10-16.md
@@ 0,0 1,126 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 16th October 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: DCO and Linux upstreaming, API change**
+ *Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.*
+ *ordex sent in **patchset version 9**. Current status seems to be that discussion about DCO internals are over, and it's now about API stuff.*
+ *During meetup it was discussed that if the patchset does not make it into the kernel before 2.7 we should update the out-of-tree module to match the new API anyway. So that 2.7 supports the new API and we need no or minimal further changes to work with the eventual in-tree version.*
+
+ - **Updated: DCO windows multi-peer**
+ *Got two peers talking to each other with parallel iperf sessions.*
+ *Need to implement userspace parts, a few more ioctls (set and delete). But there's progress.*
+
+ - **Updated: multi-socket patch series**
+ *4 preparation work patches are acked and waiting merge process.*
+ *Patchset v5 will be sent in soon.*
+
+ - **New: where next community meeting**
+ *Italy or Spain have been mentioned.*
+ *Beer: yes.*
+ *T-shirts: yes.*
+
+ - **buildbot improvements**
+ *djpig reports that the first arm64 architecture buildbot agent now works. We can add more workers as required.*
+ *mattock has a patch to split the mails for different project to different mail addresses.*
+ *The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore.*
+ *Instead we could create a openvpn3-builds@ ML. djpig will look into that.*
+
+ - **t_server_null improvements**
+ *The tests against latest git master server against older openvpn client versions are almost done.*
+
+ - **Release 2.7**
+ *wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.*
+ *compare wiki:CommunityMeetup2024.*
+ *Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right.*
+
+ - **DATA_V3 patch**
+ *plaisthos has written a new draft for new key handling for the data channel based on discussions in Karlsruhe.*
+ *See https://github.com/OpenVPN/openvpn-rfc/pull/5. Feedback welcome :)*
+
+ - **2.7 security audit**
+ *ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.*
+
+ ### Backlog
+
+ - **--dns patch review upcoming**
+ *DNS patches were discussed during Meetup. d12fk will provide them for review real soon.*
+
+ - **live route updates**
+ *PR to RFC was merged. (https://github.com/OpenVPN/openvpn-rfc/pull/4)*
+ *Now we need to complete the actual implementations.*
+ *Implementation for OpenVPN v2 will be looked at by ordex and his team.*
+ *lev is working on (client-side) implementation in OpenVPN 3.*
+
+ - **community.openvpn.net trac wiki**
+ *Seems mattock managed to get it into a reasonable shape ready for production.*
+ *Some required changes to otterwiki have been submitted upstream.*
+ *Next step is looking at migrating data from old to new.*
+ *Also djpig needs to provide an EC2 instance in the community account for hosting production.*
+
+ - **forums topics**
+ *novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.*
+
+ - **Tunnelcrack progress [wiki:TunnelCrack TunnelCrack community wiki article]**
+ *Status update on TunnelCrack mitigations:*
+ *The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.*
+ *Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.*
+ *Linux, openvpn2: in progress. openvpn3: in progress.*
+ *macOS: to be determined.*
+ *iOS: to be determined.*
+ *Android: not vulnerable.*
+
+ - **run tests of 2.x against openvpn3? how?**
+ *There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.*
+ *This is in the openvpn3 repository.*
+
+ - **donation collection**
+ *From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.*
+ *What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.*
+ *There are some options to consider. There may be existing solutions that we want to consider.*
+ *PayPal seems overly expensive with all their fees.*
+ *Stripe could be worth considering for credit card processing.*
+ *GitHub Sponsors was mentioned as a possible solution, this is worth investigating.*
+ *Open Collective was also mentioned, that needs some investigating how that exactly would work for us.*
+
+ - **Community AWS account governance**
+ *Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization*
+ *With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.*
+ *Requires further discussion whether that is something we want.*
+
+ - **website release process**
+ *Waiting for faster way to update community downloads and security advisories on main site.*
+ *Again postponed due to issues. Now planned for this week. We'll see.*
+
+ - **Status of SBOM**
+ *There was a discussion between MaxF and djpig and others.*
+ *For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.*
+ *The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.*
+
+ - **Static-key mini how-to is outdated.**
+ *This page is outdated badly: https://openvpn.net/community-resources/static-key-mini-howto/*
+ *company will send this to tech writer to redo based on https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst info*
+ *and also retain a link to that github doc.*
+ *having a simple guide online will help adoption*
+
+ - **OpenVPN 2.6 performance results.**
+ *tests should cover: gre, ipsec, userland, dco*
+ *linux, freebsd, windows*
+ *requires time to be dedicated to doing this, when time available will do it*
+
+ - **What's going on with new taskbar icons?**
+ *matt provided icons in https://github.com/OpenVPN/openvpn-gui/issues/595*
+ *last update: will be picked up by selva when he has time*
+
+ - **software code signing topic**
+ *company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.*
+ *in future we could possibly switch community to that same key. saves having to maintain 2 different keys.*
+ *depends on how hard/easy it is to access company key signing thingee from community infrastructure.*
+ *also no high priority at the moment, we have a working solution now.*
\ No newline at end of file
/dev/null .. meetings/2024-10-23.md
@@ 0,0 1,122 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 23 October 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** `#openvpn-meeting` channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: data format v3 / epoch data keys**
+ - plaisthos has written a new draft for new key handling for the data channel based on discussions in Karlsruhe.
+ - See [GitHub PR](https://github.com/OpenVPN/openvpn-rfc/pull/5).
+ - Requesting feedback from community to review.
+
+ - **Updated: DCO and Linux upstreaming, API change**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - ordex sent in **patchset version 9**. Got some small feedback, a v10 will be sent in this week.
+
+ - **Updated: buildbot improvements**
+ - cron2 requests that we pretty please have a mingw build in gerrit. djpig indicates next week should be possible.
+ - mattock has a patch to split the mails for different project to different mail addresses. The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore.
+ - Instead we could create a openvpn3-builds@ ML. djpig will look into that.
+
+ - **Updated: DCO windows multi-peer**
+ - Getting closer - kernel side stuff seems to be getting near to completion. Will look at user-space part next.
+
+ - **Updated: multi-socket patch series**
+ - There were some issues building on Windows and some buildbot failures pointed out by djpig when merging the preparation work patches.
+ - These will be addressed in follow-up patches that are underway now.
+ - And then we'll move on to the real patch series.
+
+ - **Updated: push_update / live route updates**
+ - There were some clarification questions which resulted in the decision we should add a few clarifying words to the RFC.
+ - Implementation for OpenVPN v2 will be looked at by ordex and his team.
+
+ - **where next community meeting**
+ - Italy or Spain have been mentioned.
+ - Beer: yes.
+ - T-shirts: yes.
+
+ - **t_server_null improvements**
+ - The tests against latest git master server against older openvpn client versions are almost done.
+
+ - **Release 2.7**
+ - wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.
+ - compare wiki:CommunityMeetup2024.
+ - Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right.
+
+ - **2.7 security audit**
+ - ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.
+
+ ### Backlog
+
+ - **--dns patch review upcoming**
+ - DNS patches were discussed during Meetup. d12fk will provide them for review real soon.
+
+ - **community.openvpn.net trac wiki**
+ - Seems mattock managed to get it into a reasonable shape ready for production.
+ - Some required changes to otterwiki have been submitted upstream.
+ - Next step is looking at migrating data from old to new.
+ - Also djpig needs to provide an EC2 instance in the community account for hosting production.
+
+ - **forums topics**
+ - novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](wiki:TunnelCrack)**
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ - Linux, openvpn2: in progress. openvpn3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **run tests of 2.x against openvpn3? how?**
+ - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **Community AWS account governance**
+ - Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization
+ - With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.
+ - Requires further discussion whether that is something we want.
+
+ - **website release process**
+ - Waiting for faster way to update community downloads and security advisories on main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static-key mini-howto](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - company will send this to tech writer to redo based on [GitHub doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc.
+ - having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ - tests should cover: gre, ipsec, userland, dco
+ - linux, freebsd, windows
+ - requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ - matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ - company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ - in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ - depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ - also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-10-30.md
@@ 0,0 1,120 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - Time: Wednesday 30 October 2024 at 14:00 CEST (12:00 UTC)
+ - Place: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: DCO and Linux upstreaming, API change**
+ _Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._
+ _ordex sent in **patchset version 11**. Awaiting feedback._
+
+ - **Updated: DCO windows multi-peer**
+ _Kernel-side stuff looks to be mostly done. Currently look into user-space stuff and some proper locking and memory management (refcounters etc)._
+
+ - **Updated: multi-socket patch series**
+ _4 preparation work patches were merged. Now it's on to the real patch series._
+
+ - **Updated: data format v3 / epoch data keys**
+ _plaisthos has written a new draft for new key handling for the data channel based on discussions in Karlsruhe._
+ _See <https://github.com/OpenVPN/openvpn-rfc/pull/5>._
+ _The current state is that the work for it is done but not yet sent in - plaisthos indicates he wants to test and implement it with openvpn3 before submitting it to openvpn2._
+
+ - **buildbot improvements**
+ _cron2 requests that we pretty please have a mingw build in gerrit. djpig indicates next week should be possible._
+ _mattock has a patch to split the mails for different project to different mail addresses. The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore._
+ _Instead we could create a openvpn3-builds@ ML. djpig will look into that._
+
+ - **push_update / live route updates**
+ _There were some clarification questions which resulted in the decision we should add a few clarifying words to the RFC._
+ _Implementation for OpenVPN v2 will be looked at by ordex and his team._
+
+ - **where next community meeting**
+ _Italy or Spain have been mentioned._
+ _Beer: yes._
+ _T-shirts: yes._
+
+ - **t_server_null improvements**
+ _The tests against latest git master server against older openvpn client versions are almost done._
+
+ - **Release 2.7**
+ _wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup._
+ _compare wiki:CommunityMeetup2024._
+ _Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right._
+
+ - **2.7 security audit**
+ _ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code._
+
+ ### Backlog
+
+ - **--dns patch review upcoming**
+ _DNS patches were discussed during Meetup. d12fk will provide them for review real soon._
+
+ - **community.openvpn.net trac wiki**
+ _Seems mattock managed to get it into a reasonable shape ready for production._
+ _Some required changes to otterwiki have been submitted upstream._
+ _Next step is looking at migrating data from old to new._
+ _Also djpig needs to provide an EC2 instance in the community account for hosting production._
+
+ - **forums topics**
+ _novaflash has access and is working on a PoC setup combining old and new on an ubuntu server._
+
+ - **Tunnelcrack progress**
+ _Status update on TunnelCrack mitigations:_
+ _The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this._
+ _Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review._
+ _Linux, openvpn2: in progress. openvpn3: in progress._
+ _macOS: to be determined._
+ _iOS: to be determined._
+ _Android: not vulnerable._
+
+ - **run tests of 2.x against openvpn3? how?**
+ _There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes._
+ _This is in the openvpn3 repository._
+
+ - **donation collection**
+ _From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._
+ _What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on._
+ _There are some options to consider. There may be existing solutions that we want to consider._
+ _PayPal seems overly expensive with all their fees._
+ _Stripe could be worth considering for credit card processing._
+ _GitHub Sponsors was mentioned as a possible solution, this is worth investigating._
+ _Open Collective was also mentioned, that needs some investigating how that exactly would work for us._
+
+ - **Community AWS account governance**
+ _Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization_
+ _With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella._
+ _Requires further discussion whether that is something we want._
+
+ - **website release process**
+ _Waiting for faster way to update community downloads and security advisories on main site._
+ _Again postponed due to issues. Now planned for this week. We'll see._
+
+ - **Status of SBOM**
+ _There was a discussion between MaxF and djpig and others._
+ _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
+ _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
+
+ - **Static-key mini how-to is outdated.**
+ _This page is outdated badly: <https://openvpn.net/community-resources/static-key-mini-howto/>_
+ _company will send this to tech writer to redo based on <https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst> info and also retain a link to that github doc._
+ _having a simple guide online will help adoption_
+
+ - **OpenVPN 2.6 performance results.**
+ _tests should cover: gre, ipsec, userland, dco_
+ _linux, freebsd, windows_
+ _requires time to be dedicated to doing this, when time available will do it_
+
+ - **What's going on with new taskbar icons?**
+ _matt provided icons in <https://github.com/OpenVPN/openvpn-gui/issues/595>_
+ _last update: will be picked up by selva when he has time_
+
+ - **software code signing topic**
+ _company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
+ _in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
+ _depends on how hard/easy it is to access company key signing thingee from community infrastructure._
+ _also no high priority at the moment, we have a working solution now._
\ No newline at end of file
/dev/null .. meetings/2024-11-06.md
@@ 0,0 1,124 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 6 November 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: DCO windows multi-peer**
+ _Kernelspace looks done, now working on userspace stuff. It listens for incoming clients and attempts handshake. Still a bit of work to do._
+
+ - **Updated: multi-socket patch series**
+ _This has been rebased and comments addressed, waiting for another review._
+
+ - **Updated: data format v3 / epoch data keys**
+ _Some comments from syzzer came in and were addressed on the RFC addition for epoch keys:_
+ _See [RFC Pull Request #5](https://github.com/OpenVPN/openvpn-rfc/pull/5)._
+ _plaisthos is working to implement it in openvpn3 first._
+
+ - **Updated: push_update / live route updates**
+ _Lev added some clarifying comments to the push_update section in the RFC, as per popular demand._
+ _Implementation of push_update for OpenVPN v2 will be looked at by ordex and his team._
+
+ - **New: TLS-exporter in mbedtls**
+ _Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls._
+ _maxf reports he's making some progress on implementing this._
+
+ - **DCO and Linux upstreaming, API change**
+ _Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._
+ _ordex sent in **patchset version 11**. Awaiting feedback._
+
+ - **buildbot improvements**
+ _cron2 requests that we pretty please have a mingw build in gerrit. djpig indicates next week should be possible._
+ _mattock has a patch to split the mails for different project to different mail addresses. The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore._
+ _Instead we could create a openvpn3-builds@ ML. djpig will look into that._
+
+ - **where next community meeting**
+ _Italy or Spain have been mentioned._
+ _Beer: yes._
+ _T-shirts: yes._
+
+ - **t_server_null improvements**
+ _The tests against latest git master server against older openvpn client versions are almost done._
+
+ - **Release 2.7**
+ _wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup._
+ _compare wiki:CommunityMeetup2024._
+ _Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right._
+
+ ### Backlog
+
+ - **2.7 security audit**
+ _ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code._
+
+ - **--dns patch review upcoming**
+ _DNS patches were discussed during Meetup. d12fk will provide them for review real soon._
+
+ - **community.openvpn.net trac wiki**
+ _Seems mattock managed to get it into a reasonable shape ready for production._
+ _Some required changes to otterwiki have been submitted upstream._
+ _Next step is looking at migrating data from old to new._
+ _Also djpig needs to provide an EC2 instance in the community account for hosting production._
+
+ - **forums topics**
+ _novaflash has access and is working on a PoC setup combining old and new on an ubuntu server._
+
+ - **Tunnelcrack progress**
+ _Status update on TunnelCrack mitigations:_
+ _The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this._
+ _Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review._
+ _Linux, openvpn2: in progress. openvpn3: in progress._
+ _macOS: to be determined._
+ _iOS: to be determined._
+ _Android: not vulnerable._
+
+ - **run tests of 2.x against openvpn3? how?**
+ _There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes._
+ _This is in the openvpn3 repository._
+
+ - **donation collection**
+ _From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._
+ _What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on._
+ _There are some options to consider. There may be existing solutions that we want to consider._
+ _PayPal seems overly expensive with all their fees._
+ _Stripe could be worth considering for credit card processing._
+ _GitHub Sponsors was mentioned as a possible solution, this is worth investigating._
+ _Open Collective was also mentioned, that needs some investigating how that exactly would work for us._
+
+ - **Community AWS account governance**
+ _Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization_
+ _With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella._
+ _Requires further discussion whether that is something we want._
+
+ - **website release process**
+ _Waiting for faster way to update community downloads and security advisories on main site._
+ _Again postponed due to issues. Now planned for this week. We'll see._
+
+ - **Status of SBOM**
+ _There was a discussion between MaxF and djpig and others._
+ _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
+ _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
+
+ - **Static-key mini how-to is outdated.**
+ _This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)_
+ _company will send this to tech writer to redo based on [GitHub Info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that github doc._
+ _having a simple guide online will help adoption._
+
+ - **OpenVPN 2.6 performance results.**
+ _tests should cover: gre, ipsec, userland, dco_
+ _linux, freebsd, windows_
+ _requires time to be dedicated to doing this, when time available will do it._
+
+ - **What's going on with new taskbar icons?**
+ _matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
+ _last update: will be picked up by selva when he has time._
+
+ - **software code signing topic**
+ _company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
+ _in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
+ _depends on how hard/easy it is to access company key signing thingee from community infrastructure._
+ _also no high priority at the moment, we have a working solution now._
\ No newline at end of file
/dev/null .. meetings/2024-11-13.md
@@ 0,0 1,129 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 13 November 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** `#openvpn-meeting` channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: DCO Linux upstreaming**
+ Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ ordex will send out **patchset v12** later this week.
+
+ - **Updated: DCO windows multi-peer**
+ Kernelspace and userspace now look to be working.
+ Ran gremlin tests for 30 minutes with up to 1000 connections and it all worked as it should.
+ Will prepare to send in patches for review.
+
+ - **Updated: multi-socket patch series**
+ This has been rebased and comments addressed - now in review.
+ Two minor refactoring patches handled. Continuing work on this.
+
+ - **Updated: data format v3 / epoch data keys**
+ RFC is here: [https://github.com/OpenVPN/openvpn-rfc/pull/5](https://github.com/OpenVPN/openvpn-rfc/pull/5).
+ plaisthos is working to implement it in openvpn3 first.
+ MaxF will review the RFC. And comments/questions he will pass to plaisthos so he can handle updating the RFC if needed.
+
+ - **Updated: push_update / live route updates**
+ There have been some initial tests on a server implementation in PG.
+ There is a server-side bug that will be fixed in PG, and a request to support a few more options (keepalive options).
+ lev__ will add keepalive to OpenVPN3 code.
+ mrbff and ordex will implement the openvpn2 server and client support for push_update.
+
+ - **Updated: TLS-exporter in mbedtls**
+ Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls.
+ maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work.
+
+ - **Updated: --dns patch review upcoming**
+ d12fk patches are being made ready for gerrit review now.
+
+ - **buildbot improvements**
+ cron2 requests that we pretty please have a mingw build in gerrit. djpig indicates next week should be possible.
+ mattock has a patch to split the mails for different project to different mail addresses. The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore.
+ Instead we could create a openvpn3-builds@ ML. djpig will look into that.
+
+ - **where next community meeting**
+ Italy or Spain have been mentioned.
+ Beer: yes.
+ T-shirts: yes.
+
+ - **t_server_null improvements**
+ The tests against latest git master server against older openvpn client versions are almost done.
+
+ - **Release 2.7**
+ wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.
+ compare wiki:CommunityMeetup2024.
+ Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right.
+
+ ### Backlog
+
+ - **2.7 security audit**
+ ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.
+
+ - **community.openvpn.net trac wiki**
+ Seems mattock managed to get it into a reasonable shape ready for production.
+ Some required changes to otterwiki have been submitted upstream.
+ Next step is looking at migrating data from old to new.
+ Also djpig needs to provide an EC2 instance in the community account for hosting production.
+
+ - **forums topics**
+ novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/TunnelCrack)**
+ Status update on TunnelCrack mitigations:
+ The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ Linux, openvpn2: in progress. openvpn3: in progress.
+ macOS: to be determined.
+ iOS: to be determined.
+ Android: not vulnerable.
+
+ - **run tests of 2.x against openvpn3? how?**
+ There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ This is in the openvpn3 repository.
+
+ - **donation collection**
+ From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ There are some options to consider. There may be existing solutions that we want to consider.
+ PayPal seems overly expensive with all their fees.
+ Stripe could be worth considering for credit card processing.
+ GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **Community AWS account governance**
+ Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization.
+ With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.
+ Requires further discussion whether that is something we want.
+
+ - **website release process**
+ Waiting for faster way to update community downloads and security advisories on main site.
+ Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ There was a discussion between MaxF and djpig and others.
+ For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Static-key mini how-to is outdated.**
+ This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
+ company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc.
+ having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ tests should cover: gre, ipsec, userland, dco
+ linux, freebsd, windows
+ requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-11-20.md
@@ 0,0 1,135 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 20 November 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Updated: DCO Linux upstreaming**
+ Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ ordex intended to send out patchset v12 but was delayed due to illness. Now expected this week.
+
+ - **Updated: data format v3 / epoch data keys**
+ RFC is here: [https://github.com/OpenVPN/openvpn-rfc/pull/5](https://github.com/OpenVPN/openvpn-rfc/pull/5).
+ plaisthos is working to implement it in openvpn3 first.
+ MaxF reviewed the RFC and commented that it looks good.
+
+ - **Updated: DCO windows multi-peer**
+ Preparing patchset for the userspace implementation.
+
+ - **Updated: t_server_null improvements**
+ The LWIP ping testing in t_server_null.sh is somewhat working.
+ It is a bit tricky to get it right but then it seems to be working.
+ mattock will prepare a patch.
+
+ - **Updated: community.openvpn.net wiki**
+ A more suitable production deployment schema for otterwiki has been submitted upstream. That does not block us however.
+ mattock is ready to proceed and needs an EC2 instance in the community account for hosting production.
+ This instance can have some new address so we can start setting it up and migrating content.
+ After migrating data we can then remove the old wiki and put the new wiki on the address of the old one.
+ djpig or uddr35 can help to provide the instance and give mattock full access to it so he can then deploy the necessary otterwiki deployment on it.
+
+ - **New: snapshot releases via Chocolatey software**
+ mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.
+ Seems like the maintainer is amenable to helping us achieve that goal.
+
+ - **Updated: --dns patch review upcoming**
+ d12fk patches are being made ready for gerrit review now - should arrive before next meeting.
+
+ - **multi-socket patch series**
+ Now in review.
+
+ - **push_update / live route updates**
+ There have been some initial tests on a server implementation in PG.
+ There is a server-side bug that will be fixed in PG, and a request to support a few more options (keepalive options).
+ lev__ will add keepalive to OpenVPN3 code.
+ mrbff and ordex will implement the openvpn2 server and client support for push_update.
+
+ - **TLS-exporter in mbedtls**
+ Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls.
+ maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work.
+
+ - **buildbot improvements**
+ cron2 requests that we pretty please have a mingw build in gerrit. djpig indicates next week should be possible.
+ mattock has a patch to split the mails for different project to different mail addresses. The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore.
+ Instead we could create a openvpn3-builds@ ML. djpig will look into that.
+
+ - **where next community meeting**
+ Italy or Spain have been mentioned.
+ Beer: yes.
+ T-shirts: yes.
+
+ - **Release 2.7**
+ wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.
+ compare wiki:CommunityMeetup2024.
+ Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right.
+
+ ---
+
+ ### Backlog
+
+ - **2.7 security audit**
+ ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.
+
+ - **forums topics**
+ novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://openvpn.net/community-resources/tunnelcrack)**
+ Status update on TunnelCrack mitigations:
+ The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ Linux, openvpn2: in progress. openvpn3: in progress.
+ macOS: to be determined.
+ iOS: to be determined.
+ Android: not vulnerable.
+
+ - **run tests of 2.x against openvpn3? how?**
+ There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ This is in the openvpn3 repository.
+
+ - **donation collection**
+ From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ There are some options to consider. There may be existing solutions that we want to consider.
+ PayPal seems overly expensive with all their fees.
+ Stripe could be worth considering for credit card processing.
+ GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **Community AWS account governance**
+ Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization.
+ With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.
+ Requires further discussion whether that is something we want.
+
+ - **website release process**
+ Waiting for faster way to update community downloads and security advisories on main site.
+ Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ There was a discussion between MaxF and djpig and others.
+ For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Static-key mini how-to is outdated.**
+ This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
+ company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc.
+ having a simple guide online will help adoption
+
+ - **OpenVPN 2.6 performance results.**
+ tests should cover: gre, ipsec, userland, dco
+ linux, freebsd, windows
+ requires time to be dedicated to doing this, when time available will do it
+
+ - **What's going on with new taskbar icons?**
+ matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ last update: will be picked up by selva when he has time
+
+ - **software code signing topic**
+ company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
+ in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
+ depends on how hard/easy it is to access company key signing thingee from community infrastructure.
+ also no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2024-11-27.md
@@ 0,0 1,140 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 27 November 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **New: swupdate.openvpn.net/org cleanup**
+ - *Basically, this has become a dumping ground for just about everything. We're cleaning it up.*
+ - *Need to discuss how to handle community files that are on there.*
+ - *A priority is to ensure no interruptions to existing content/links.*
+ - *The plan we want to propose to OpenVPN Inc. is to get all proprietary stuff moved off of swupdate.openvpn.net, which seems to already be ongoing anyhow.*
+ - *And then keep swupdate.openvpn.net purely for community and move the s3 bucket to community AWS account and reduce the amount of caching layers to just one.*
+ - *Will relay this plan to OpenVPN Inc. and see what they say.*
+
+ - **Updated: DCO Linux upstreaming**
+ - *Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.*
+ - *patchset v12 had 2 weeks delay, hoping to get it out this week now. Main reason is having to deal with someone with a lot of comments to make.*
+
+ - **Updated: community.openvpn.net wiki**
+ - *A more suitable production deployment schema for otterwiki has been submitted upstream. That does not block us however.*
+ - *uddr35 has arranged a node for mattock to use and the DNS record for it should be ready today.*
+ - *That means mattock will have access to a node to set things up on in the next few hours or so.*
+
+ - **Updated: t_server_null improvements**
+ - *The LWIP ping testing in t_server_null.sh is working and a PR is up.*
+
+ - **Updated: OpenVPN community meetup 2025**
+ - *When: September/October-ish, a poll will be made soonish to gather people's availabilities.*
+ - *Where: Napoli, Italy.*
+ - *Meeting room: TBD.*
+ - *Hotel: TBD.*
+ - *Beer: Yes.*
+ - *T-shirts: Yes.*
+
+ - **data format v3 / epoch data keys**
+ - *RFC is here: [RFC Pull Request](https://github.com/OpenVPN/openvpn-rfc/pull/5).*
+ - *plaisthos is working to implement it in openvpn3 first.*
+ - *MaxF reviewed the RFC and commented that it looks good.*
+
+ - **DCO windows multi-peer**
+ - *Preparing patchset for the userspace implementation.*
+
+ - **snapshot releases via Chocolatey software**
+ - *mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.*
+ - *Seems like the maintainer is amenable to helping us achieve that goal.*
+
+ - **dns patch review upcoming**
+ - *d12fk patches are being made ready for gerrit review now - should arrive before next meeting.*
+
+ - **multi-socket patch series**
+ - *Now in review.*
+
+ - **push_update / live route updates**
+ - *There have been some initial tests on a server implementation in PG.*
+ - *There is a server-side bug that will be fixed in PG, and a request to support a few more options (keepalive options).*
+ - *lev__ will add keepalive to OpenVPN3 code.*
+ - *mrbff and ordex will implement the openvpn2 server and client support for push_update.*
+
+ - **TLS-exporter in mbedtls**
+ - *Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls.*
+ - *maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work.*
+
+ - **buildbot improvements**
+ - *cron2 requests that we pretty please have a mingw build in gerrit. djpig indicates next week should be possible.*
+ - *mattock has a patch to split the mails for different project to different mail addresses. The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore.*
+ - *Instead, we could create an openvpn3-builds@ ML. djpig will look into that.*
+
+ - **Release 2.7**
+ - *wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.*
+ - *compare wiki:CommunityMeetup2024.*
+ - *Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right.*
+
+ ### Backlog
+
+ - **2.7 security audit**
+ - *ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.*
+
+ - **forums topics**
+ - *novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.*
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://openvpn.net/community-resources/tunnelcrack)**
+ - *Status update on TunnelCrack mitigations:*
+ - *The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.*
+ - *Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.*
+ - *Linux, openvpn2: in progress. openvpn3: in progress.*
+ - *macOS: to be determined.*
+ - *iOS: to be determined.*
+ - *Android: not vulnerable.*
+
+ - **run tests of 2.x against openvpn3? how?**
+ - *There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.*
+ - *This is in the openvpn3 repository.*
+
+ - **donation collection**
+ - *From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.*
+ - *What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.*
+ - *There are some options to consider. There may be existing solutions that we want to consider.*
+ - *PayPal seems overly expensive with all their fees.*
+ - *Stripe could be worth considering for credit card processing.*
+ - *GitHub Sponsors was mentioned as a possible solution, this is worth investigating.*
+ - *Open Collective was also mentioned, that needs some investigating how that exactly would work for us.*
+
+ - **Community AWS account governance**
+ - *Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization*
+ - *With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.*
+ - *Requires further discussion whether that is something we want.*
+
+ - **website release process**
+ - *Waiting for a faster way to update community downloads and security advisories on the main site.*
+ - *Again postponed due to issues. Now planned for this week. We'll see.*
+
+ - **Status of SBOM**
+ - *There was a discussion between MaxF and djpig and others.*
+ - *For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.*
+ - *The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.*
+
+ - **Static-key mini how-to is outdated.**
+ - *This page is outdated badly: [Static Key Mini Howto](https://openvpn.net/community-resources/static-key-mini-howto/)*
+ - *company will send this to tech writer to redo based on [Example Fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.*
+ - *having a simple guide online will help adoption*
+
+ - **OpenVPN 2.6 performance results.**
+ - *tests should cover: gre, ipsec, userland, dco*
+ - *linux, freebsd, windows*
+ - *requires time to be dedicated to doing this, when time available will do it*
+
+ - **What's going on with new taskbar icons?**
+ - *matt provided icons in [Taskbar Icons Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)*
+ - *last update: will be picked up by selva when he has time*
+
+ - **software code signing topic**
+ - *company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.*
+ - *in the future, we could possibly switch community to that same key. saves having to maintain 2 different keys.*
+ - *depends on how hard/easy it is to access company key signing thingee from community infrastructure.*
+ - *also no high priority at the moment, we have a working solution now.*
\ No newline at end of file
/dev/null .. meetings/2024-12-04.md
@@ 0,0 1,140 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 4 December 2024 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **New: no meetings on 25th of December, 1st of January**
+ *For obvious reasons.*
+
+ - **Updated: swupdate.openvpn.net/org cleanup**
+ *Basic idea is agreed; set up a new S3 bucket in AWS community account, keep only community stuff there, move swupdate.openvpn.net/org domains there, have only 1 caching layer (not 2 like now).*
+ *There will be some redirects for some of the company stuff that go to packages.openvpn.net.*
+
+ - **Updated: DCO Linux upstreaming**
+ *Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.*
+ *Patchset v12 has gone out and is under review.*
+ *ordex reports that some of the test framework has been merged so it looks like there is some movement.*
+
+ - **Updated: t_server_null improvements**
+ *ovpnlwip seems to work fine on all linux platforms, based on buildbot tests.*
+ *Waiting review.*
+
+ - **Updated: buildbot improvements**
+ *cron2 requests that we pretty please have a mingw build in gerrit. this has in the meantime materialized.*
+ *mattock is looking into adding ubu24.04 clang+asan build.*
+
+ - **Updated: multi-socket support**
+ *Now in review. Patchset v8 should be going out this week.*
+
+ - **Updated: new --dns option support**
+ *Now in review. d12fk sent in patchset for new --dns option support.*
+
+ - **community.openvpn.net wiki**
+ *A more suitable production deployment schema for otterwiki has been submitted upstream. That does not block us however.*
+ *uddr35 has arranged a node for mattock to use and the DNS record for it should be ready today.*
+ *That means mattock will have access to a node to set things up on in the next few hours or so.*
+
+ - **OpenVPN community meetup 2025**
+ *When: september/october ish, a poll will be made soonish to gather people's availabilities.*
+ *Where: Napoli, Italy.*
+ *Meeting room: tbd.*
+ *Hotel: tbd.*
+ *Beer: yes.*
+ *T-shirts: yes.*
+
+ - **data format v3 / epoch data keys**
+ *RFC is here: [https://github.com/OpenVPN/openvpn-rfc/pull/5](https://github.com/OpenVPN/openvpn-rfc/pull/5).*
+ *plaisthos is working to implement it in openvpn3 first.*
+ *MaxF reviewed the RFC and commented that it looks good.*
+
+ - **DCO windows multi-peer**
+ *Preparing patchset for the userspace implementation.*
+
+ - **snapshot releases via Chocolatey software**
+ *mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.*
+ *Seems like the maintainer is amenable to helping us achieve that goal.*
+
+ - **push_update / live route updates**
+ *There have been some initial tests on a server implementation in PG.*
+ *There is a server-side bug that will be fixed in PG, and a request to support a few more options (keepalive options).*
+ *lev__ will add keepalive to OpenVPN3 code.*
+ *mrbff and ordex will implement the openvpn2 server and client support for push_update.*
+
+ - **TLS-exporter in mbedtls**
+ *Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls.*
+ *maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work.*
+
+ - **Release 2.7**
+ *wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.*
+ *compare wiki:CommunityMeetup2024.*
+ *Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right.*
+
+ ### Backlog
+
+ - **2.7 security audit**
+ *ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.*
+
+ - **forums topics**
+ *novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.*
+
+ - **Tunnelcrack progress**
+ *Status update on TunnelCrack mitigations:*
+ *The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.*
+ *Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.*
+ *Linux, openvpn2: in progress. openvpn3: in progress.*
+ *macOS: to be determined.*
+ *iOS: to be determined.*
+ *Android: not vulnerable.*
+
+ - **run tests of 2.x against openvpn3? how?**
+ *There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.*
+ *This is in the openvpn3 repository.*
+
+ - **donation collection**
+ *From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.*
+ *What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.*
+ *There are some options to consider. There may be existing solutions that we want to consider.*
+ *PayPal seems overly expensive with all their fees.*
+ *Stripe could be worth considering for credit card processing.*
+ *GitHub Sponsors was mentioned as a possible solution, this is worth investigating.*
+ *Open Collective was also mentioned, that needs some investigating how that exactly would work for us.*
+
+ - **Community AWS account governance**
+ *Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization*
+ *With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.*
+ *Requires further discussion whether that is something we want.*
+
+ - **website release process**
+ *Waiting for faster way to update community downloads and security advisories on main site.*
+ *Again postponed due to issues. Now planned for this week. We'll see.*
+
+ - **Status of SBOM**
+ *There was a discussion between MaxF and djpig and others.*
+ *For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.*
+ *The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.*
+
+ - **Static-key mini how-to is outdated.**
+ *This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)*
+ *company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc.*
+ *having a simple guide online will help adoption*
+
+ - **OpenVPN 2.6 performance results.**
+ *tests should cover: gre, ipsec, userland, dco*
+ *linux, freebsd, windows*
+ *requires time to be dedicated to doing this, when time available will do it*
+
+ - **What's going on with new taskbar icons?**
+ *matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)*
+ *last update: will be picked up by selva when he has time*
+
+ - **software code signing topic**
+ *company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.*
+ *in future we could possibly switch community to that same key. saves having to maintain 2 different keys.*
+ *depends on how hard/easy it is to access company key signing thingee from community infrastructure.*
+ *also no high priority at the moment, we have a working solution now.*
\ No newline at end of file
/dev/null .. meetings/2024-12-11.md
@@ 0,0 1,141 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time**: Wednesday 11 December 2024 at 14:00 CEST (12:00 UTC)
+ - **Place**: #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Reminder: no meetings on 25th of December, 1st of January**
+ _For obvious reasons._
+
+ - **Updated: DCO Linux upstreaming**
+ _Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._
+ _Patchset v13 and v14 followed really fast and v14 is now under review._
+ _Interesting news article appeared on the webs: [Phoronix News](https://www.phoronix.com/news/OpenVPN-Data-Channel-DCO-Soon)_
+
+ - **Updated: OpenVPN community meetup 2025**
+ [OpenVPN Community Meetup 2025](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2025)
+ _When: September/October-ish, a poll for checking availability is here: [Poll](https://nuudel.digitalcourage.de/NROHeFlkfaYnoNGC)_
+ _Where: Napoli, Italy._
+ _Meeting room: TBD._
+ _Hotel: TBD._
+ _Beer: Yes._
+ _T-shirts: Yes._
+
+ - **swupdate.openvpn.net/org cleanup**
+ _Basic idea is agreed; set up a new S3 bucket in AWS community account, keep only community stuff there, move swupdate.openvpn.net/org domains there, have only 1 caching layer (not 2 like now)._
+ _There will be some redirects for some of the company stuff that go to packages.openvpn.net._
+
+ - **t_server_null improvements**
+ _ovpnlwip seems to work fine on all Linux platforms, based on buildbot tests._
+ _Waiting review._
+
+ - **buildbot improvements**
+ _cron2 requests that we pretty please have a mingw build in gerrit. This has in the meantime materialized._
+ _mattock is looking into adding ubu24.04 clang+asan build._
+
+ - **multi-socket support**
+ _Now in review. Patchset v8 should be going out this week._
+
+ - **new --dns option support**
+ _Now in review. d12fk sent in patchset for new --dns option support._
+
+ - **community.openvpn.net wiki**
+ _A more suitable production deployment schema for otterwiki has been submitted upstream. That does not block us however._
+ _uddr35 has arranged a node for mattock to use and the DNS record for it should be ready today._
+ _That means mattock will have access to a node to set things up on in the next few hours or so._
+
+ - **data format v3 / epoch data keys**
+ _RFC is here: [GitHub RFC](https://github.com/OpenVPN/openvpn-rfc/pull/5)._
+ _plaisthos is working to implement it in openvpn3 first._
+ _MaxF reviewed the RFC and commented that it looks good._
+
+ - **DCO windows multi-peer**
+ _Preparing patchset for the userspace implementation._
+
+ - **snapshot releases via Chocolatey software**
+ _mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well._
+ _Seems like the maintainer is amenable to helping us achieve that goal._
+
+ - **push_update / live route updates**
+ _There have been some initial tests on a server implementation in PG._
+ _There is a server-side bug that will be fixed in PG, and a request to support a few more options (keepalive options)._
+ _lev__ will add keepalive to OpenVPN3 code._
+ _mrbff and ordex will implement the openvpn2 server and client support for push_update._
+
+ - **TLS-exporter in mbedtls**
+ _Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls._
+ _maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work._
+
+ - **Release 2.7**
+ _wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup._
+ _compare wiki:CommunityMeetup2024._
+ _Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right._
+
+ ### Backlog
+
+ - **2.7 security audit**
+ _ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code._
+
+ - **forums topics**
+ _novaflash has access and is working on a PoC setup combining old and new on an ubuntu server._
+
+ - **Tunnelcrack progress**
+ _Status update on TunnelCrack mitigations:_
+ _The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this._
+ _Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review._
+ _Linux, openvpn2: in progress. openvpn3: in progress._
+ _macOS: to be determined._
+ _iOS: to be determined._
+ _Android: not vulnerable._
+
+ - **run tests of 2.x against openvpn3? how?**
+ _There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes._
+ _This is in the openvpn3 repository._
+
+ - **donation collection**
+ _From earlier exploration, it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._
+ _What we can do is start out with an existing company that can collect the money and puts it to good community use. Ordex volunteers to take this on._
+ _There are some options to consider. There may be existing solutions that we want to consider._
+ _PayPal seems overly expensive with all their fees._
+ _Stripe could be worth considering for credit card processing._
+ _GitHub Sponsors was mentioned as a possible solution, this is worth investigating._
+ _Open Collective was also mentioned, that needs some investigating how that exactly would work for us._
+
+ - **Community AWS account governance**
+ _Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization_
+ _With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella._
+ _Requires further discussion whether that is something we want._
+
+ - **website release process**
+ _Waiting for faster way to update community downloads and security advisories on main site._
+ _Again postponed due to issues. Now planned for this week. We'll see._
+
+ - **Status of SBOM**
+ _There was a discussion between MaxF and djpig and others._
+ _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
+ _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
+
+ - **Static-key mini how-to is outdated.**
+ _This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)_
+ _Company will send this to tech writer to redo based on [GitHub Example](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc._
+ _Having a simple guide online will help adoption._
+
+ - **OpenVPN 2.6 performance results.**
+ _Tests should cover: GRE, IPsec, userland, DCO_
+ _Linux, FreeBSD, Windows_
+ _Requires time to be dedicated to doing this, when time available will do it._
+
+ - **What's going on with new taskbar icons?**
+ _Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)_
+ _Last update: will be picked up by Selva when he has time._
+
+ - **Software code signing topic**
+ _Company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
+ _In future, we could possibly switch community to that same key. Saves having to maintain 2 different keys._
+ _Depends on how hard/easy it is to access company key signing thing from community infrastructure._
+ _Also no high priority at the moment, we have a working solution now._
\ No newline at end of file
/dev/null .. meetings/2025-01-08.md
@@ 0,0 1,145 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 8 January 2025 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **New: 2.6.x release**
+ Plan to do a 2.6.13 next Wednesday with the assorted patches that are in release/2.6.
+
+ - **Updated: DCO Linux upstreaming**
+ Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ Patchset v13 and v14 followed really fast and v14 is now under review.
+ Interesting news article appeared on the webs: [Phoronix News on OpenVPN DCO](https://www.phoronix.com/news/OpenVPN-Data-Channel-DCO-Soon)
+
+ - **Reminder: t_server_null improvements**
+ ovpnlwip seems to work fine on all linux platforms, based on buildbot tests.
+ Waiting review. djpig promises to do it today.
+
+ - **Updated: multi-socket support**
+ Now in review. Patchset v11 should be going out this week.
+ Parts of the Patchset have been merged. Work ongoing
+ [Gerrit multisocket](https://gerrit.openvpn.net/q/topic:%22multisocket%22)
+
+ - **Updated: new --dns option support**
+ Now in review. d12fk sent in patchset for new --dns option support.
+ [Gerrit DNS Option Support](https://gerrit.openvpn.net/q/topic:%22dns+option%22)
+
+ - **Updated: community.openvpn.net wiki**
+ A more suitable production deployment schema for otterwiki has been submitted upstream. That does not block us however.
+ mattock has prepared some Puppet code to deploy otterwiki and says it should be ready. He asks for a reset of the host
+ since he had some invasive changes (e.g. switch from docker to podman) and starting from scratch is easier and cleaner.
+ uddr35 will assists with that.
+
+ - **Updated: data format v3 / epoch data keys**
+ RFC is here: [GitHub RFC Pull Request](https://github.com/OpenVPN/openvpn-rfc/pull/5).
+ plaisthos is working to implement it in openvpn3 first.
+ MaxF reviewed the RFC and commented that it looks good.
+ Patchset is in Gerrit: [Gerrit Epoch Data](https://gerrit.openvpn.net/q/topic:%22epoch%22)
+
+ - **Updated: DCO windows multi-peer**
+ lev has submitted patchset for the userspace implementation.
+ [Gerrit DCO Windows Multi-peer](https://gerrit.openvpn.net/c/openvpn/+/815)
+
+ - **Updated: Release 2.7**
+ wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.
+ compare wiki:CommunityMeetup2024.
+ Want to do a first preview release as soon as possible, but need to get at least one of the big patch series in, preferably multi-socket.
+
+ - **New: OpenVPN SEO**
+ There is a request from OpenVPN whether we could exclude build.openvpn.net and gerrit.openvpn.net from search engines to not muddle search
+ results for openvpn with developer-only resources. We will need more information about the actual problem they see before doing something like that.
+
+ ----
+
+ ### Backlog
+
+ - **push_update / live route updates**
+ There have been some initial tests on a server implementation in PG.
+ There is a server-side bug that will be fixed in PG, and a request to support a few more options (keepalive options).
+ lev will add keepalive to OpenVPN3 code.
+ mrbff and ordex will implement the openvpn2 server and client support for push_update.
+
+ - **TLS-exporter in mbedtls**
+ Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls.
+ maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work.
+
+ - **snapshot releases via Chocolatey software**
+ mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.
+ Seems like the maintainer is amenable to helping us achieve that goal.
+
+ - **OpenVPN community meetup 2025**
+ [Community Meetup 2025](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2025)
+ When: september/october ish, a poll for checking availibity is here: [Nuudel Poll](https://nuudel.digitalcourage.de/NROHeFlkfaYnoNGC)
+ Where: Napoli, Italy.
+ Meeting room: tbd.
+ Hotel: tbd.
+ Beer: yes.
+ T-shirts: yes.
+
+ - **2.7 security audit**
+ ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.
+
+ - **forums topics**
+ novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)**
+ Status update on TunnelCrack mitigations:
+ The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
+ Linux, openvpn2: in progress. openvpn3: in progress.
+ macOS: to be determined.
+ iOS: to be determined.
+ Android: not vulnerable.
+
+ - **run tests of 2.x against openvpn3? how?**
+ There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ This is in the openvpn3 repository.
+
+ - **donation collection**
+ From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
+ There are some options to consider. There may be existing solutions that we want to consider.
+ PayPal seems overly expensive with all their fees.
+ Stripe could be worth considering for credit card processing.
+ GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **Community AWS account governance**
+ Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization
+ With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.
+ Requires further discussion whether that is something we want.
+
+ - **website release process**
+ Waiting for a faster way to update community downloads and security advisories on the main site.
+ Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ There was a discussion between MaxF and djpig and others.
+ For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Static-key mini how-to is outdated.**
+ This page is outdated badly: [Static Key Mini How-to](https://openvpn.net/community-resources/static-key-mini-howto/)
+ The company will send this to a tech writer to redo based on [GitHub Example Fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ Tests should cover: gre, ipsec, userland, dco
+ Linux, FreeBSD, Windows
+ Requires time to be dedicated to doing this, when time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ Last update: will be picked up by selva when he has time.
+
+ - **Software code signing topic**
+ The company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
+ Also, no high priority at the moment, we have a working solution now.
\ No newline at end of file
/dev/null .. meetings/2025-01-15.md
@@ 0,0 1,78 @@
+ ## IrcMeetings
+
+ ### Basic info
+
+ - **Time:** Wednesday 15 January 2025 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ### Topics
+
+ #### Current topics
+
+ - **Updated: 2.6.x release**
+ Plan to start the 2.6.13 release process today with the assorted patches that are in release/2.6.
+
+ - **Updated: DCO Linux upstreaming**
+ Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ Patchset v17 and v18 followed really fast and v18 is now under review.
+
+ - **Updated: DCO windows multi-peer**
+ lev has finished the driver and userspace implementations for the iroute.
+
+ - **Updated: data format v3 / epoch data keys**
+ RFC is here: [RFC Pull Request](https://github.com/OpenVPN/openvpn-rfc/pull/5).
+ Implementation in OpenVPN3 is in review/merge stage.
+ Implementation in OpenVPN2 is almost fully merged, just one patch to go.
+
+ - **Updated: multi-socket support**
+ Patchset v12 is pushed out and ready for review.
+ [Multi-socket gerrit link](https://gerrit.openvpn.net/q/topic:%22multisocket%22)
+
+ - **Updated: community.openvpn.net wiki**
+ mattock converted the setup to podman which is what we tend to use nowadays in our infrastructure.
+ mattock will try to finish the work this week so we can plan for deploying it.
+
+ - **t_server_null improvements**
+ ovpnlwip seems to work fine on all linux platforms, based on buildbot tests.
+ Waiting review. djpig promised to do it last week.
+
+ - **new --dns option support**
+ Now in review. d12fk sent in patchset for new --dns option support.
+ [DNS option gerrit link](https://gerrit.openvpn.net/q/topic:%22dns+option%22)
+
+ - **Release 2.7**
+ wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.
+ compare wiki:CommunityMeetup2024.
+ Want to do a first preview release as soon as possible, but need to get at least one of the big patch series in, preferably multi-socket.
+
+ - **OpenVPN SEO**
+ There is a request from OpenVPN whether we could exclude build.openvpn.net and gerrit.openvpn.net from search engines to not muddle search
+ results for openvpn with developer-only resources. We will need more information about the actual problem they see before doing something like that.
+
+ #### Backlog
+
+ - **push_update / live route updates**
+ There have been some initial tests on a server implementation in PG.
+ There is a server-side bug that will be fixed in PG, and a request to support a few more options (keepalive options).
+ lev will add keepalive to OpenVPN3 code.
+ mrbff and ordex will implement the openvpn2 server and client support for push_update.
+
+ - **TLS-exporter in mbedtls**
+ Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls.
+ maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work.
+
+ - **snapshot releases via Chocolatey software**
+ mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.
+ Seems like the maintainer is amenable to helping us achieve that goal.
+
+ - **OpenVPN community meetup 2025**
+ [Community Meetup 2025](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2025)
+ When: September/October ish, a poll for checking availability is here: [Availability Poll](https://nuudel.digitalcourage.de/NROHeFlkfaYnoNGC)
+ Where: Napoli, Italy.
+ Meeting room: TBD.
+ Hotel: TBD.
+ Beer: Yes.
+ T-shirts: Yes.
+
+ - **2.7 security audit**
+ ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.
\ No newline at end of file
/dev/null .. meetings/2025-01-22.md
@@ 0,0 1,136 @@
+ # IrcMeetings
+
+ ## Basic info
+
+ - **Time:** Wednesday 22 January 2025 at 14:00 CEST (12:00 UTC)
+ - **Place:** #openvpn-meeting channel on LiberaChat IRC network
+
+ ## Topics
+
+ ### Current topics
+
+ - **Closed: 2.6.x release**
+ - 2.6.13 was released last week.
+
+ - **Updated: DCO Linux upstreaming**
+ - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ - Patchset v18 sparked 2 discussions, both resolved. A v19 is expected to be sent in after net-next opens on February 3rd again.
+
+ - **Updated: community.openvpn.net wiki**
+ - It's online now, but completely empty. Now we will look into a proper 404 page in preparation for the move.
+ - We are going to move releases information, IRC meeting summaries and notes, and security advisories over first. Then we'll see further.
+
+ - **DCO windows multi-peer**
+ - Lev has finished the driver and userspace implementations for the iroute.
+
+ - **data format v3 / epoch data keys**
+ - RFC is here: [RFC Link](https://github.com/OpenVPN/openvpn-rfc/pull/5).
+ - Implementation in OpenVPN3 is in review/merge stage.
+ - Implementation in OpenVPN2 is almost fully merged, just one patch to go.
+
+ - **multi-socket support**
+ - Patchset v12 is pushed out and ready for review.
+ - [Review Link](https://gerrit.openvpn.net/q/topic:%22multisocket%22)
+
+ - **t_server_null improvements**
+ - ovpnlwip seems to work fine on all linux platforms, based on buildbot tests.
+ - Waiting for review. djpig promised to do it last week.
+
+ - **new --dns option support**
+ - Now in review. d12fk sent in patchset for new --dns option support.
+ - [DNS Option Review](https://gerrit.openvpn.net/q/topic:%22dns+option%22)
+
+ - **Release 2.7**
+ - wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.
+ - Compare with wiki:CommunityMeetup2024.
+ - Want to do a first preview release as soon as possible, but need to get at least one of the big patch series in, preferably multi-socket.
+
+ - **OpenVPN SEO**
+ - There is a request from OpenVPN whether we could exclude build.openvpn.net and gerrit.openvpn.net from search engines to not muddle search results for openvpn with developer-only resources. We will need more information about the actual problem they see before doing something like that.
+
+ ### Backlog
+
+ - **push_update / live route updates**
+ - There have been some initial tests on a server implementation in PG.
+ - There is a server-side bug that will be fixed in PG, and a request to support a few more options (keepalive options).
+ - Lev will add keepalive to OpenVPN3 code.
+ - Mrbff and ordex will implement the OpenVPN2 server and client support for push_update.
+
+ - **TLS-exporter in mbedtls**
+ - Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls.
+ - Maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work.
+
+ - **snapshot releases via Chocolatey software**
+ - Mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.
+ - Seems like the maintainer is amenable to helping us achieve that goal.
+
+ - **OpenVPN community meetup 2025**
+ - [Community Meetup 2025](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2025)
+ - When: September/October ish, a poll for checking availability is here: [Poll Link](https://nuudel.digitalcourage.de/NROHeFlkfaYnoNGC)
+ - Where: Napoli, Italy.
+ - Meeting room: TBD.
+ - Hotel: TBD.
+ - Beer: Yes.
+ - T-shirts: Yes.
+
+ - **2.7 security audit**
+ - Ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.
+
+ - **forums topics**
+ - Novaflash has access and is working on a PoC setup combining old and new on an Ubuntu server.
+
+ - **Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)**
+ - Status update on TunnelCrack mitigations:
+ - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
+ - Windows, OpenVPN2: merged to master, not to 2.6.x. OpenVPN3: in code review.
+ - Linux, OpenVPN2: in progress. OpenVPN3: in progress.
+ - macOS: to be determined.
+ - iOS: to be determined.
+ - Android: not vulnerable.
+
+ - **run tests of 2.x against openvpn3? how?**
+ - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
+ - This is in the openvpn3 repository.
+
+ - **donation collection**
+ - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
+ - What we can do is start out with an existing company that can collect the money and puts it to good community use. Ordex volunteers to take this on.
+ - There are some options to consider. There may be existing solutions that we want to consider.
+ - PayPal seems overly expensive with all their fees.
+ - Stripe could be worth considering for credit card processing.
+ - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
+ - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
+
+ - **Community AWS account governance**
+ - Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization
+ - With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.
+ - Requires further discussion whether that is something we want.
+
+ - **website release process**
+ - Waiting for a faster way to update community downloads and security advisories on the main site.
+ - Again postponed due to issues. Now planned for this week. We'll see.
+
+ - **Status of SBOM**
+ - There was a discussion between MaxF and djpig and others.
+ - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
+ - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
+
+ - **Static-key mini how-to is outdated.**
+ - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
+ - Company will send this to tech writer to redo based on [GitHub doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
+ - Having a simple guide online will help adoption.
+
+ - **OpenVPN 2.6 performance results.**
+ - Tests should cover: GRE, IPSec, userland, DCO
+ - Linux, FreeBSD, Windows
+ - Requires time to be dedicated to doing this, when time available will do it.
+
+ - **What's going on with new taskbar icons?**
+ - Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
+ - Last update: will be picked up by Selva when he has time.
+
+ - **software code signing topic**
+ - Company switched EV code signing to cloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
+ - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
+ - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
+ - Also no high priority at the moment, we have a working solution now.
\ No newline at end of file
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9