Commit 98be28

2026-01-28 16:31:18 flichtenheld: 2.7_rc6
Downloads.md ..
@@ 1,32 1,16 @@
- ## OpenVPN 2.7_rc5 -- Released 15 January 2026
- The OpenVPN community project team is proud to release OpenVPN 2.7_rc5. This is the fifth release candidate for the feature release 2.7.0.
+ ## OpenVPN 2.7_rc6 -- Released 28 January 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.7_rc6. This is the sixth release candidate for the feature release 2.7.0.
- Security fixes:
- * [CVE-2025-15497](https://www.cve.org/CVERecord?id=CVE-2025-15497): in epoch key handling (an authenticated remote system
- can send a valid OpenVPN data packet that triggers an edge case
- where a too-strict check would trigger an ASSERT(), exiting OpenVPN)
-
- Important bug fixes since 2.7_rc4:
- * remove "resolve --remote on incoming TCP connects on --tcp-server"
- code base, because that did not work in a long time (since 2.4) and
- is seen as too obscure and too complicated to rescue.
- * repair interaction between DCO and persist-tun after reconnection
- (in this case the client side would fail to set up the DCO event
- handler, and not notice further --ping timeouts - GH: #947)
- * remove ENABLE_X509ALTUSERNAME conditional, always enabling
- "configure --enable-x509-alt-username". Effectively no change in
- code size, and one less build variant to maintain and test (GH: [OpenVPN/openvpn#917](https://github.com/OpenVPN/openvpn/issues/917)).
- * require "script-security 2" when using `--dev unix:<program>`
- * socks client: fix and improve various code parts
- * configure etc: drop support for systemd 216 and older, adapt
- other checks to reflect modern systemd setups
- * fix unit test building with libcmocka 2.0+
- * fix Android build warnings about unused variables/methods
- * allow --test-crypto to run without --secret
- (prepare for removal of --secret after 2.7)
- * improve WolfSSL build compatibility
-
- For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc4...v2.7_rc5).
+ Important changes since 2.7_rc5:
+ * bugfix on restarting a p2mp server instance with SIGUSR1 (inadvertedly
+ closing fd 0, causing a crash on the next restart - GH [OpenVPN/openvpn#966](https://github.com/OpenVPN/openvpn/issues/966))
+ * prevent NULL pointer crash on suitable combination of --dns-updown
+ statements in openvpn config file (not pushable)
+ * prevent inappropriate management interface activity if a password is
+ set and --management-forget-disconnect or --management-signal are active
+ * add mbedTLS 4 support
+
+ For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc5...v2.7_rc6).
Highlights of 2.7 include:
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
@@ 49,24 33,20 @@
* PUSH_UPDATE server support (minimal)
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
* TLS 1.3 support with bleeding-edge mbedTLS versions
+ * Support for mbedTLS version 4
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc5/Changes.rst)
-
- Windows MSI changes since 2.7_rc4:
- * Built against OpenSSL 3.6.0
- * Included openvpn-gui updated to 11.61.0.0
- * Included win-dco driver updated to 2.8.0
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc6/Changes.rst)
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-amd64.msi.asc)|[OpenVPN-2.7_rc5-I013-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-arm64.msi.asc)|[OpenVPN-2.7_rc5-I013-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-x86.msi.asc)|[OpenVPN-2.7_rc5-I013-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc5.tar.gz.asc)|[openvpn-2.7_rc5.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc5.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-amd64.msi.asc)|[OpenVPN-2.7_rc6-I014-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-arm64.msi.asc)|[OpenVPN-2.7_rc6-I014-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-x86.msi.asc)|[OpenVPN-2.7_rc6-I014-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc6.tar.gz.asc)|[openvpn-2.7_rc6.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc6.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9