"configure --enable-x509-alt-username". Effectively no change in
-
code size, and one less build variant to maintain and test (GH: [OpenVPN/openvpn#917](https://github.com/OpenVPN/openvpn/issues/917)).
-
* require "script-security 2" when using `--dev unix:<program>`
-
* socks client: fix and improve various code parts
-
* configure etc: drop support for systemd 216 and older, adapt
-
other checks to reflect modern systemd setups
-
* fix unit test building with libcmocka 2.0+
-
* fix Android build warnings about unused variables/methods
-
* allow --test-crypto to run without --secret
-
(prepare for removal of --secret after 2.7)
-
* improve WolfSSL build compatibility
-
-
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc4...v2.7_rc5).
+
Important changes since 2.7_rc5:
+
* bugfix on restarting a p2mp server instance with SIGUSR1 (inadvertedly
+
closing fd 0, causing a crash on the next restart - GH [OpenVPN/openvpn#966](https://github.com/OpenVPN/openvpn/issues/966))
+
* prevent NULL pointer crash on suitable combination of --dns-updown
+
statements in openvpn config file (not pushable)
+
* prevent inappropriate management interface activity if a password is
+
set and --management-forget-disconnect or --management-signal are active
+
* add mbedTLS 4 support
+
+
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc5...v2.7_rc6).
Highlights of 2.7 include:
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
@@ 49,24 33,20 @@
* PUSH_UPDATE server support (minimal)
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
* TLS 1.3 support with bleeding-edge mbedTLS versions
+
* Support for mbedTLS version 4
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
-
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc5/Changes.rst)
-
-
Windows MSI changes since 2.7_rc4:
-
* Built against OpenSSL 3.6.0
-
* Included openvpn-gui updated to 11.61.0.0
-
* Included win-dco driver updated to 2.8.0
+
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc6/Changes.rst)
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.