Commit 74ed4f

2025-12-17 19:04:57 uddr: OpenVPN-2.7_rc4-I012
Downloads.md ..
@@ 1,43 1,42 @@
- ## OpenVPN 2.7_rc3 -- Released 28 November 2025
- The OpenVPN community project team is proud to release OpenVPN 2.7_rc3. This is the third release candidate for the feature release 2.7.0.
-
- Security fixes:
- * [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix bug where the interactive service would error-exit in
- certain error conditions instead of just logging the fact and
- continuing. After the error-exit, OpenVPN connections will no
- longer work until the service is restarted (or the system rebooted).
- This can be triggered by any authenticated local user, and has
- thus been classified as a "local denial of service" attack.
-
- Important bug fixes since 2.7_rc2:
- * Windows/Interactive Service bugfixes:
- many small bugfixes to registry-related DNS domain handling
- * Windows/Interactive Service: harden service pipe handling
- close a small race condition, and add restrictive ACLs
- * more type conversion related warnings have been fixed
- * --multihome behaviour regarding egress interface selection has been
- changed. See Changes.rst and manpage for details.
- * cleanup dead code in event handling code (leftover of the multisocket
- patch set)
- * add new feature, --tls-crypt-v2-max-age n. See Changes.rst and
- manpage for details.
- * improve documentation to point out the pitfalls of case-insensitive
- filesystems and --client-config-dir
- * split default gateway query logic in two:
- * for --redirect-gateway functionality, query for the gateway towards
- the actual IP address of the VPN server connecting to
- * for the "net_gateway" special destination for --route, and the
- corresponding environment variable, always query for 0.0.0.0 / ::
- (this will only make a difference in certain scenarios using a local
- proxy, or on a system with multiple interfaces, not using the "default
- route" for the VPN connection * see github#890)
- * upgrade embedded pkcs11-helper vcpkg + pkcs11-uri patch to 1.31
- * CMake / autoconf cleanup wrt unused checks, outdated old-Linux checks,
- Windows oddities
- * DCO (primarily Linux): improve handling of bulk notifications from
- kernel (do not lose notifications, do not crash) ([github#900](https://github.com/OpenVPN/openvpn/issues/900))
-
- For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc2...v2.7_rc3).
+ ## OpenVPN 2.7_rc4 -- Released 17 December 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.7_rc4. This is the fourth release candidate for the feature release 2.7.0.
+
+ Important bug fixes since 2.7_rc3:
+ * Windows interactive service: do not configure adapter DNS if
+ there are no search-domains but there are resolve-domains (which
+ get resolved via NRPT rules) - GH: [OpenVPN/openvpn#473](https://github.com/OpenVPN/openvpn/issues/473)
+ * improve documentation and error messages for a number of deprecated
+ options
+ * improve documentation for not-really-deprecated-yet ``--ns-cert-type``
+ * Windows IPv4 configuration with netsh.exe: ensure addresses are added
+ with "store=active" (ensure proper cleanup) - GH: [OpenVPN/openvpn#915](https://github.com/OpenVPN/openvpn/issues/915)
+ * Windows: set UTF8 code page in openvpn.exe manifest, to make cert/key
+ loading work again for files with non-ASCII characters in their file
+ name (GH: [OpenVPN/openvpn#920](https://github.com/OpenVPN/openvpn/issues/920))
+ * tun.c: unify read_tun()/write_tun() functions for all BSD platforms
+ * more type conversion related cleanups
+ * add NULL check before freeaddrinfo() call, which might lead to a
+ crash on OpenBSD (GH: [OpenVPN/openvpn#930](https://github.com/OpenVPN/openvpn/issues/930))
+ * add NULL check to mbedtls handling of external and inline certificates
+ * add check for auth none / cipher none on FreeBSD DCO
+ * add CAP_SYS_NICE to positive list in Linux systemd unit files
+ (GH: [OpenVPN/openvpn#834](https://github.com/OpenVPN/openvpn/issues/834))
+ * drop mbedtls 2.x support (which is end of life, and work on mbedtls 4
+ is much simplified by not having to take care of 2.x compat as well)
+ * PUSH_UPDATE: bugfix for the client side where split/continued messages
+ (due to large number of "route" statements) would not correctly handle
+ the full set of routes. Add unit test. (GH: [OpenVPN/openvpn#925](https://github.com/OpenVPN/openvpn/issues/925))
+ * new unit test module for mbuf handling
+ * deprecate --fast-io option (it got partially broken by the multisocket
+ implementation, and the benefits of the existing implementation did
+ not outweigh the extra code complexity to make it work again)
+ * change the ssl_ctx in struct tls_options to be a pointer - this is
+ a shared data structure between various contexts, but previously it
+ was shallow-copied, leading to needless CRL reloading - and when
+ working on implementing the new OpenSSL CRL API, to segfaults
+ (the existing code works, as these new APIs are not used yet).
+
+ For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc3...v2.7_rc4).
Highlights of 2.7 include:
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
@@ 65,21 64,20 @@
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc3/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc4/Changes.rst)
- Windows MSI changes since 2.7_rc2:
+ Windows MSI changes since 2.7_rc3:
* Built against OpenSSL 3.6.0
- * Included openvpn-gui updated to 11.59.0.0
- * Authorize config before opening the service pipe
- * Remove dependence on pathcch.dll not in Windows 7
+ * Included openvpn-gui updated to 11.60.0.0
+ * Update copyright year in About dialog
* Included win-dco driver updated to 2.8.0
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-amd64.msi.asc)|[OpenVPN-2.7_rc3-I010-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-arm64.msi.asc)|[OpenVPN-2.7_rc3-I010-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-x86.msi.asc)|[OpenVPN-2.7_rc3-I010-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc3.tar.gz.asc)|[openvpn-2.7_rc3.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc3.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-amd64.msi.asc)|[OpenVPN-2.7_rc4-I012-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-arm64.msi.asc)|[OpenVPN-2.7_rc4-I012-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-x86.msi.asc)|[OpenVPN-2.7_rc4-I012-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc4.tar.gz.asc)|[openvpn-2.7_rc4.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc4.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9