Commit 6fdf02

2025-06-27 20:53:39 novaflash: -/-
Meetings/2025/2025-01-22.md ..
@@ 9,128 9,13 @@
### Current topics
- - **Closed: 2.6.x release**
- - 2.6.13 was released last week.
+ - **Closed: 2.6.x release**
+ 2.6.13 was released last week.
- - **Updated: DCO Linux upstreaming**
- - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
- - Patchset v18 sparked 2 discussions, both resolved. A v19 is expected to be sent in after net-next opens on February 3rd again.
+ - **Updated: DCO Linux upstreaming**
+ Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
+ Patchset v18 sparked 2 discussions, both resolved. A v19 is expected to be sent in after net-next opens on February 3rd again.
- - **Updated: community.openvpn.net wiki**
- - It's online now, but completely empty. Now we will look into a proper 404 page in preparation for the move.
- - We are going to move releases information, IRC meeting summaries and notes, and security advisories over first. Then we'll see further.
-
- - **DCO windows multi-peer**
- - Lev has finished the driver and userspace implementations for the iroute.
-
- - **data format v3 / epoch data keys**
- - RFC is here: [RFC Link](https://github.com/OpenVPN/openvpn-rfc/pull/5).
- - Implementation in OpenVPN3 is in review/merge stage.
- - Implementation in OpenVPN2 is almost fully merged, just one patch to go.
-
- - **multi-socket support**
- - Patchset v12 is pushed out and ready for review.
- - [Review Link](https://gerrit.openvpn.net/q/topic:%22multisocket%22)
-
- - **t_server_null improvements**
- - ovpnlwip seems to work fine on all linux platforms, based on buildbot tests.
- - Waiting for review. djpig promised to do it last week.
-
- - **new --dns option support**
- - Now in review. d12fk sent in patchset for new --dns option support.
- - [DNS Option Review](https://gerrit.openvpn.net/q/topic:%22dns+option%22)
-
- - **Release 2.7**
- - ../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.
- - Compare with wiki:CommunityMeetup2024.
- - Want to do a first preview release as soon as possible, but need to get at least one of the big patch series in, preferably multi-socket.
-
- - **OpenVPN SEO**
- - There is a request from OpenVPN whether we could exclude build.openvpn.net and gerrit.openvpn.net from search engines to not muddle search results for openvpn with developer-only resources. We will need more information about the actual problem they see before doing something like that.
-
- ### Backlog
-
- - **push_update / live route updates**
- - There have been some initial tests on a server implementation in PG.
- - There is a server-side bug that will be fixed in PG, and a request to support a few more options (keepalive options).
- - Lev will add keepalive to OpenVPN3 code.
- - Mrbff and ordex will implement the OpenVPN2 server and client support for push_update.
-
- - **TLS-exporter in mbedtls**
- - Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls.
- - Maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work.
-
- - **snapshot releases via Chocolatey software**
- - Mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.
- - Seems like the maintainer is amenable to helping us achieve that goal.
-
- - **OpenVPN community meetup 2025**
- - [Community Meetup 2025](../../Meetups/2025-Naples)
- - When: September/October ish, a poll for checking availability is here: [Poll Link](https://nuudel.digitalcourage.de/NROHeFlkfaYnoNGC)
- - Where: Napoli, Italy.
- - Meeting room: TBD.
- - Hotel: TBD.
- - Beer: Yes.
- - T-shirts: Yes.
-
- - **2.7 security audit**
- - Ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.
-
- - **forums topics**
- - Novaflash has access and is working on a PoC setup combining old and new on an Ubuntu server.
-
- - **Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)**
- - Status update on TunnelCrack mitigations:
- - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
- - Windows, OpenVPN2: merged to master, not to 2.6.x. OpenVPN3: in code review.
- - Linux, OpenVPN2: in progress. OpenVPN3: in progress.
- - macOS: to be determined.
- - iOS: to be determined.
- - Android: not vulnerable.
-
- - **run tests of 2.x against openvpn3? how?**
- - There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
- - This is in the openvpn3 repository.
-
- - **donation collection**
- - From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
- - What we can do is start out with an existing company that can collect the money and puts it to good community use. Ordex volunteers to take this on.
- - There are some options to consider. There may be existing solutions that we want to consider.
- - PayPal seems overly expensive with all their fees.
- - Stripe could be worth considering for credit card processing.
- - GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
- - Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
-
- - **Community AWS account governance**
- - Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization
- - With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.
- - Requires further discussion whether that is something we want.
-
- - **website release process**
- - Waiting for a faster way to update community downloads and security advisories on the main site.
- - Again postponed due to issues. Now planned for this week. We'll see.
-
- - **Status of SBOM**
- - There was a discussion between MaxF and djpig and others.
- - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
- - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
-
- - **Static-key mini how-to is outdated.**
- - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
- - Company will send this to tech writer to redo based on [GitHub doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
- - Having a simple guide online will help adoption.
-
- - **OpenVPN 2.6 performance results.**
- - Tests should cover: GRE, IPSec, userland, DCO
- - Linux, FreeBSD, Windows
- - Requires time to be dedicated to doing this, when time available will do it.
-
- - **What's going on with new taskbar icons?**
- - Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
- - Last update: will be picked up by Selva when he has time.
-
- - **software code signing topic**
- - Company switched EV code signing to cloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
- - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
- - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
- - Also no high priority at the moment, we have a working solution now.
\ No newline at end of file
+ - **Updated: community.openvpn.net wiki**
+ It's online now, but completely empty. Now we will look into a proper 404 page in preparation for the move.
+ We are going to move releases information, IRC meeting summaries and notes, and security advisories over first. Then we'll see further.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9