Commit 7e6afc
2025-06-18 11:42:52 novaflash: -/-| /dev/null .. Meetings/2025/2025-06-18.md | |
| @@ 0,0 1,84 @@ | |
| + | # Basic info |
| + | |
| + | * Time: Wednesday 18 June 2025 at 14:00 CEST (12:00 UTC) |
| + | * Place: #openvpn-meeting channel on !LiberaChat IRC network |
| + | |
| + | # Topics |
| + | |
| + | ## Current topics |
| + | |
| + | * **Updated, closed: (embargo) security issue**\ |
| + | CVE ID CVE-2025-50054 reserved for this security issue.\ |
| + | For OpenVPN 2.6 the Windows installer will be updated.\ |
| + | For OpenVPN 2.7 a new alpha2 release will be made.\ |
| + | Estimated delivery date 18 june 2025. |
| + | |
| + | * **Updated: Release 2.7**\ |
| + | OpenVPN 2.7 alpha2 expected 18 june 2025 (includes embargoed security issue fix).\ |
| + | For the DNS related changes, the macOS DNS script and the compatibility code is yet to be merged.\ |
| + | For the DCO related changes, Windows server support is done, epoch data keys being worked on in both Linux and Windows.\ |
| + | For the live route updates changes, it is likely that this will not make it into 2.7. |
| + | |
| + | * **Updated: push_update / live route updates**\ |
| + | For client-side support, company did QA on it against the current only server implementation (cloudconnexa) and it works as expected.\ |
| + | Server-side support patch is up and requires review and is a bit more involved, company QA will test it. |
| + | |
| + | * **OpenVPN community meetup 2025**\ |
| + | https://community.openvpn.net/openvpn/wiki/CommunityMeetup2025 \ |
| + | When: weekend of 25 and 26 october.\ |
| + | Where: Napoli, Italy.\ |
| + | Meeting room: giaan found a location, pricing to be determined/approved.\ |
| + | Hotel: giaan will take a look into this.\ |
| + | Beer: yes.\ |
| + | T-shirts: yes. |
| + | |
| + | --- |
| + | |
| + | ## Backlog |
| + | |
| + | * **Changes to community pages on main website**\ |
| + | Company is finetuning new design together with lev, ordex, and novaflash.\ |
| + | Expected to be published in the next few weeks.\ |
| + | Rough idea (not updated with latest adjustments) is visible here https://crashed.computer/new.png |
| + | |
| + | * **forums situation**\ |
| + | The current forums are not maintained, not working well, and flooded with spam.\ |
| + | We have a contributor (minx) with web development experience willing to set up something new, but migrate the old forum contents.\ |
| + | To the question where the instance should be hosted, community indicates it should be under the community AWS infrastructure.\ |
| + | To the question what authentication system should be used, community indicates it should just be the built-in system from the forum solution itself. |
| + | |
| + | * **snapshot releases via Chocolatey software**\ |
| + | mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.\ |
| + | Seems like the maintainer is amenable to helping us achieve that goal. |
| + | |
| + | * **2.7 security audit**\ |
| + | ''ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code. |
| + | |
| + | * **Tunnelcrack progress (see TunnelCrack community wiki article)\ |
| + | ''Status update on TunnelCrack mitigations:''\ |
| + | ''The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.''\ |
| + | ''Windows, openvpn2: block-local merged to master, not to 2.6.x. openvpn3: in code review.''\ |
| + | ''Linux, openvpn2: in progress. openvpn3: in progress.''\ |
| + | ''macOS: to be determined.''\ |
| + | ''iOS: to be determined.''\ |
| + | ''Android: not vulnerable.'' |
| + | |
| + | * **donation collection**\ |
| + | ''From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.''\ |
| + | ''What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.''\ |
| + | ''There are some options to consider. There may be existing solutions that we want to consider.''\ |
| + | ''PayPal seems overly expensive with all their fees.''\ |
| + | ''Stripe could be worth considering for credit card processing.''\ |
| + | ''GitHub Sponsors was mentioned as a possible solution, this is worth investigating.''\ |
| + | ''Open Collective was also mentioned, that needs some investigating how that exactly would work for us.'' |
| + | |
| + | * **Status of SBOM**\ |
| + | There was a discussion between MaxF and djpig and others.\ |
| + | For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.\ |
| + | The interesting use-case for an SBOM is really the OpenVPN Windows GUI client. |
| + | |
| + | * **Static-key mini how-to is outdated.**\ |
| + | This page is outdated badly: https://openvpn.net/community-resources/static-key-mini-howto/ \ |
| + | company will send this to tech writer to redo based on https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst info\ |
| + | and also retain a link to that github doc.\ |
| + | having a simple guide online will help adoption |
