Commit 9ad98e

2025-01-29 12:45:51 Samuli Seppänen: Add more pages, fix more links Signed-off-by: Samuli Seppänen <samuli.seppanen@gmail.com>
Development/StatusOfOpenvpn27.md ..
@@ 15,11 15,11 @@
| **Task description** | **Assigned to** | **Status** | **Ticket** | **Patchwork / Gerrit** |
|----------------------|-----------------|------------|------------|------------------------|
| Switch from MSVC buildsystem to CMake for Windows builds | djpig | Done | - | [Change 266](https://gerrit.openvpn.net/c/openvpn/+/266) |
- | Remove deprecated `--no-replay` | djpig | Done | [Deprecated Options](wiki:DeprecatedOptions#Option:--no-replayStatus:RemovedinOpenVPNv2.7) | [Change 281](https://gerrit.openvpn.net/c/openvpn/+/281) |
- | Make it harder to use `--secret` | plaisthos | Done | [Deprecated Options](wiki:DeprecatedOptions#Option:--secretStatus:Deprecatedpendingremoval) | [Change 325](https://gerrit.openvpn.net/c/openvpn/+/325) |
- | Remove deprecated NTLM v1 support | djpig | Done | [Deprecated Options](wiki:DeprecatedOptions#NTLMv1authenticationsupportin--http-proxyStatus:Deprecatedpendingremoval) | [Change 379](https://gerrit.openvpn.net/c/openvpn/+/379) [Change 500](https://gerrit.openvpn.net/c/openvpn/+/500) |
+ | Remove deprecated `--no-replay` | djpig | Done | [Deprecated Options](../Pages/Deprecated%20options) |
+ | Make it harder to use `--secret` | plaisthos | Done | [Deprecated Options](../Pages/Deprecated%20options) |
+ | Remove deprecated NTLM v1 support | djpig | Done | [Deprecated Options](../Pages/Deprecated%20options) |
| Support TLS alerts | plaisthos | Done | - | [Change 449](https://gerrit.openvpn.net/c/openvpn/+/449) |
- | Change default for `--topology` to `subnet` | djpig | Done | [Deprecated Options](wiki:DeprecatedOptions#Changedefault--topologynet30tosubnetStatus:Pending) | [Change 421](https://gerrit.openvpn.net/c/openvpn/+/421) |
+ | Change default for `--topology` to `subnet` | djpig | Done | [Deprecated Options](../Pages/Deprecated%20options) |
| afunix/lwipovpn | plaisthos, cron2 | Done | - | [lwipovpn topic](https://gerrit.openvpn.net/q/topic:%22lwipovpn%22) |
| Tunnelcrack improvements for Windows | d12fk | Done | - | [Change 489](https://gerrit.openvpn.net/c/openvpn/+/489) |
@@ 50,12 50,12 @@
| dco-win multipeer (--server) | lev | WIP | - | - |
| HAProxy support | ralf_lici | Gerrit | - | [proxy-protocol topic](https://gerrit.openvpn.net/q/topic:%22proxy-protocol%22) |
| Transport plugin (primary use case: obfuscation) | giaan | WIP | - | - |
- | Remove deprecated --ns-cert-type | - | - | [Deprecated Options](wiki:DeprecatedOptions#Option:--ns-cert-typeStatus:Pendingremoval) | - |
- | Remove deprecated --tun-ipv6 | - | - | [Deprecated Options](wiki:DeprecatedOptions#Option:--tun-ipv6Status:Ignoredpendingremoval) | - |
- | Remove deprecated --max-routes | - | - | [Deprecated Options](wiki:DeprecatedOptions#Option:--max-routesStatus:Ignoredpendingremoval) | - |
- | Remove deprecated --dhcp-release | - | - | [Deprecated Options](wiki:DeprecatedOptions#Option:--dhcp-releaseStatus:Ignoredpendingremoval) | - |
- | Properly deprecate _v1 and _v2 plugin functions | - | - | [Deprecated Options](wiki:DeprecatedOptions#plugin:_v1and_v2functionsforopenandfunccallStatus:Pendingremoval) | - |
- | Deprecate NTLM v2 support | djpig | - | [Deprecated Options](wiki:DeprecatedOptions#NTLMv2authenticationsupportin--http-proxyStatus:Tobedeprecatedin2.7) | - |
+ | Remove deprecated --ns-cert-type | - | - | [Deprecated Options](../Pages/Deprecated%20options) | - |
+ | Remove deprecated --tun-ipv6 | - | - | [Deprecated Options](../Pages/Deprecated%20options) | - |
+ | Remove deprecated --max-routes | - | - | [Deprecated Options](../Pages/Deprecated%20options) | - |
+ | Remove deprecated --dhcp-release | - | - | [Deprecated Options](../Pages/Deprecated%20options) | - |
+ | Properly deprecate _v1 and _v2 plugin functions | - | - | [Deprecated Options](../Pages/Deprecated%20options) | - |
+ | Deprecate NTLM v2 support | djpig | - | [Deprecated Options](../Pages/Deprecated%20options) | - |
| Implement kqueue on MacOS | plaisthos | wip (but slower than poll()) | - | - |
| Sort out multiple-plugin auth mess | dazo, cron2 | on-going | - | [RFC patch 2327](https://patchwork.openvpn.net/patch/2327/) |
| Improve NM-OVPN integration | cron2 | trying to establish contact | - | - |
/dev/null .. Pages/Deprecated options.md
@@ 0,0 1,437 @@
+ # Deprecated Options in OpenVPN
+
+ [OpenVPN](https://openvpn.net/) is a software VPN product that has been around since [May 2001](https://en.wikipedia.org/wiki/OpenVPN). It has mostly been backwards compatible on the most important features through all these years. However, the world moves forward, security issues are discovered, and expectations of how a secure VPN should be configured have changed over the years.
+
+ As OpenVPN carries a lot of options (over 230), we need to clean up from time to time. The main goal is to be as backwards compatible in regards to the *configuration files* as possible. We do not recommend running any older OpenVPN releases than the [latest supported version](SupportedVersions). Whenever possible, you should always upgrade to the latest available OpenVPN release. But sometimes, we unfortunately need to remove old options as they impose a security risk to VPN configurations.
+
+ In this wiki page, we will try to keep an up-to-date list of all options we have deprecated, when they will be removed, the new alternative approach, and the reasoning behind removing the option. This wiki page summarizes the "Deprecated features" section in the [Changes.rst](https://github.com/OpenVPN/openvpn/blob/master/Changes.rst#deprecated-features) file which is distributed with the source code.
+
+ ## Remove clear-text VPN mode | **Status: Under consideration**
+ - **Status:** Under consideration
+ - **Deprecated in:** Not currently deprecated
+ - **To be removed in:** N/A
+ - **Affects:** Client and server
+ - **Result if used:** N/A
+ - **Replaced by:** Not replaced
+ - **Examples:** (N/A)
+
+ This is a placeholder for the **possible** deprecation of clear-text mode.
+
+ **Important**: OpenVPN DCO does **not** support clear-text mode.
+
+ ## Change default `--topology net30` to `subnet` | **Status: Pending**
+ - **Status:** Pending
+ - **Deprecated in:** OpenVPN v2.5
+ - **To be removed in:** TBD
+ - **Affects:** Client and server
+ - **Result if used:** N/A
+ - **Replaced by:** Not replaced
+ - **Examples:** (N/A)
+
+ [Changing from `--topology net30` to `subnet`](https://community.openvpn.net/openvpn/ticket/1288) for most simple servers, only requires the addition of `topology subnet` to the server configuration file. However, for more complex setups, there is potentially a lot more that requires changing, e.g., CCD files, etc.
+
+ **OpenVPN recommends using `topology subnet` now, so that when the default is changed, you will not be affected.**
+
+ ## Option: `--key-method` | Status: Removed in OpenVPN v2.5
+ - **Status:** Removed in OpenVPN v2.5
+ - **Deprecated in:** OpenVPN v2.4
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will not start due to unknown option
+ - **Replaced by:** Not replaced
+ - **Examples:** (N/A)
+
+ OpenVPN has used `--key-method 2` since OpenVPN v2.0 if it was not provided. Using the older `--key-method 1` was primarily present to allow OpenVPN clients running older releases than v2.0 to connect to a v2.0 server. This older key-method is not recommended as the key negotiation method is not as strong as the current default.
+
+ ## Option: `--tls-remote` | Status: Removed in OpenVPN v2.4
+ - **Status:** Removed in OpenVPN v2.4
+ - **Deprecated in:** OpenVPN v2.3
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will not start due to unknown option
+ - **Replaced by:** `--verify-x509-name`
+ - **Examples:**
+ - `--verify-x509-name 'C=KG, ST=NA, L=Bishkek, CN=Server-1'`
+ - `--verify-x509-name Server-1 name`
+ - `--verify-x509-name Server name-prefix`
+
+ ## Option: `--compat-names` | Status: Removed in OpenVPN v2.5
+ - **Status:** Removed in OpenVPN v2.5
+ - **Deprecated in:** OpenVPN v2.3
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will print an error message and **terminate**
+ - **Replaced by:** Not replaced
+ - **Examples:** (N/A)
+ - **Ref:** [mail-archive.com/openvpn-devel](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg17804.html)
+
+ OpenVPN used the former OpenSSL formatting of X.509 Subject fields. They could look like this:
+ ```
+ /C=US/L=Somewhere/CN=John Doe/emailAddress=john@example.com
+ ```
+ As of OpenVPN v2.3, this format was changed to the more widely used X.509 formatting:
+ ```
+ C=US, L=Somewhere, CN=John Doe, emailAddress=john@example.com
+ ```
+ This option would additionally add remapping of characters and render most characters outside the typical a-z/A-Z/0-9 range to be replaced by an underscore (_) - unless the `no-remapping` flag was added. This behavior would in many cases be required by older authentication plug-ins or scripts which was not able to process the newer format. As this behavior is now considered bad, it is expected that authentication plug-ins and scripts will have had enough time to get an update to handle the new X.509 Subject formatting.
+
+ ## Option: `--no-name-remapping` | Status: Removed in OpenVPN v2.5
+ - **Status:** Removed in OpenVPN v2.5
+ - **Deprecated in:** OpenVPN v2.3
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will print an error message and **terminate**
+ - **Replaced by:** Not replaced
+ - **Examples:** (N/A)
+ - **Ref:** [mail-archive.com/openvpn-devel](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg17804.html)
+
+ This is essentially just an alias for `--compat-names no-remapping`. This option would avoid the character remapping of characters being outside the typical a-z/A-Z/0-9 range in the X.509 Subject identifiers.
+
+ ## Option: `--no-iv` | Status: Removed in OpenVPN v2.5
+ - **Status:** Removed in OpenVPN v2.5
+ - **Deprecated in:** OpenVPN v2.4
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will not start due to unknown option
+ - **Replaced by:** Not replaced
+ - **Examples:** (N/A)
+
+ This option will disable OpenVPN's use of the cipher initialization vector (IV). This is considered very harmful on today's ciphers and will severely reduce the security of VPN tunnels. As the use cases for `--no-iv` are few and mostly obscure, it was decided to remove this option to ensure the tunnels' security cannot be deliberately reduced.
+
+ ## Option: `--no-replay` | Status: Removed in OpenVPN v2.7
+ - **Status:** Removed in OpenVPN v2.7
+ - **Deprecated in:** OpenVPN v2.4
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will refuse the option and provide an error message that the option is no longer supported
+ - **Replaced by:** Not replaced
+ - **Examples:** (N/A)
+
+ This option will disable OpenVPN's use of replay protection. This slightly reduces the overhead (8 bytes per packet for static keyed setups, 4 bytes for TLS with CBC mode, 0 bytes for TLS with GCM/OFB/CFB mode). The overhead reduction in CBC mode can better be achieved by switching to GCM mode. The remaining benefit for static key mode does not warrant keeping this option around. The added code complexity adds attack surface and increases the chance of users reducing their security more than they realize.
+
+ ## Policy: Removal of insecure ciphers | **Status: To be decided**
+ Ciphers with cipher block-size less than 128 bits; Most commonly `BF`, `DES`, `CAST5`, `IDEA`, and `RC2`.
+ - **Status:** Pending removal
+ - **Deprecated in:** OpenVPN v2.4
+ - **To be removed in:** TBD
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will not start due to incorrect cipher being used
+ - **Replaced by:** Replaced by stronger ciphers, most commonly AES-256-GCM
+ - **Examples:** (N/A)
+
+ After the discovery of the [SWEET32 Birthday attacks on 64-bit block ciphers](https://sweet32.info), any cipher using a cipher block length smaller than 128 bits is considered insecure and prone to be successfully attacked. The cipher block length is *not* an indication of the cipher *key* length.
+
+ For now, we will not officially remove them and focus on educating users. Maybe at some point, the SSL libraries will start dropping them.
+
+ ## Policy: Migrate away from deprecated ciphers. **Status: In progress**
+ With the OpenVPN v2.4 release, a new feature was introduced, Negotiated Cipher Protocol (NCP). This allows users to seamlessly migrate away from deprecated ciphers without much extra work. If both client and server run OpenVPN v2.4, the tunnel will automatically be upgraded to `AES-256-GCM`. If the environment also uses clients older than OpenVPN v2.4, the server can deploy:
+ ```
+ --data-ciphers AES-256-GCM:AES-256-CBC:BF-CBC
+ ```
+ This will allow older clients to add or change `--cipher` to use `AES-256-CBC` instead of the default `BF-CBC` or any other cipher enlisted. This can be done on client configuration files on a one-by-one approach. Unmodified clients will be able to connect as before. Once all clients have been updated to OpenVPN v2.4 or later (preferred) or have their configuration altered, the `--data-ciphers` list can be modified to remove `BF-CBC`.
+
+ **WARNING:** This migration approach **will not** work after the release of OpenVPN v2.7. As of that release, `BF-CBC`, `CAST`, or `RC2` ciphers **will not** be accepted anymore.
+
+ ## Option: `--keysize` | Status: Removed in OpenVPN v2.6
+ - **Status:** Removed in OpenVPN v2.6
+ - **Deprecated in:** OpenVPN v2.4
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will not start due to unknown option
+ - **Replaced by:** Not replaced
+ - **Examples:** (N/A)
+
+ The `--keysize` option was only useful to change the key length when using the `BF`, `CAST6`, or `RC2` ciphers. For all other ciphers, the key size is fixed with the chosen cipher. As OpenVPN v2.6 will no longer support any of these variable length ciphers, this option will be removed as well to avoid confusion.
+
+ ## Option: `--comp-lzo` | **Status: Pending removal**
+ - **Status:** Currently not planned for removal, see description for details
+ - **Deprecated in:** OpenVPN v2.4
+ - **To be removed in:** (not decided)
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will ignore the option and provide a warning
+ - **Replaced by:** Not replaced
+ - **Examples:** (N/A)
+
+ Compression is not recommended and is a feature users should avoid using. See `--compress` for more details.
+
+ ## Option: `--comp-noadapt` | **Status: Pending removal**
+ - **Status:** Currently not planned for removal, see description for details
+ - **Deprecated in:** OpenVPN v2.4
+ - **To be removed in:** (not decided)
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will ignore the option and provide a warning
+ - **Replaced by:** Not replaced
+ - **Examples:** (N/A)
+
+ Compression is not recommended and is a feature users should avoid using. See `--compress` for more details.
+
+ ## Option: `--compress` | **Status: Pending removal**
+ - **Status:** Currently not planned for removal, see description for details
+ - **Deprecated in:** OpenVPN v2.5
+ - **To be removed in:** (not decided)
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will ignore the option and provide a warning
+ - **Replaced by:** Not replaced
+ - **Examples:** (N/A)
+
+ Compression is not recommended and is a feature users should avoid using. To signal this clearly, `--comp-lzo` and `--compress` are discouraged and considered deprecated features. Beginning with 2.5, these options will no longer enable compression, just enable the compression framing to be able to receive compressed packets.
+
+ ## Option: `--ifconfig-pool-linear` | Status: Removed in OpenVPN v2.5
+ - **Status:** Removed in OpenVPN v2.5
+ - **Deprecated in:** OpenVPN v2.1
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will not start due to unknown option
+ - **Replaced by:** `--topology`
+ - **Examples:** `--topology p2p`
+
+ This option will not work with Windows-based clients. Since the `--topology p2p` mode is equivalent to `--ifconfig-pool-linear` and works with Windows, this option will be removed.
+
+ ## Option: `--client-cert-not-required` | Status: Removed in OpenVPN v2.5
+ - **Status:** Removed in OpenVPN v2.5
+ - **Deprecated in:** OpenVPN v2.4
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will print an error message and **terminate**
+ - **Replaced by:** `--verify-client-cert`
+ - **Examples:**
+ - `--verify-client-cert none`
+ - `--verify-client-cert optional`
+ - `--verify-client-cert require`
+
+ The replacement option allows a far more fine-grained control of authentication methods and can allow a combination of only username/password authentication, only certificate-based authentication, or a combination. This would not be possible with the old `--client-cert-not-required` option.
+
+ ## Option: `--ns-cert-type` | **Status: Pending removal**
+ - **Status:** Pending removal
+ - **Deprecated in:** OpenVPN v2.4 and v2.3.18
+ - **To be removed in:** TBD
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will complain and remap to replacement option
+ - **Replaced by:** `--remote-cert-tls`
+ - **Examples:**
+ - `--remote-cert-tls server`
+ - `--remote-cert-tls client`
+
+ As of OpenSSL v1.1, the nsCertType extension in X.509 certificates is no longer supported. This extension is old and has been deprecated for a long time. The replacement option, `--remote-cert-tls`, is a macro that sets the `--remote-cert-ku` and `--remote-cert-eku` to appropriate values, depending on whether you want to check if the remote-provided certificate is a server certificate or client certificate. As the extended key usage extension is far more commonly used today, this is effectively the equivalent of `--ns-cert-type`. For the time being, if `--ns-cert-type` is used in OpenVPN v2.5 or later, it will currently be re-mapped to `--remote-cert-tls` and complain about a deprecated option being used. (FIXME: the remapping doesn't actually seem to be implemented?)
+
+ This cannot be turned into a "hard error" due to compatibility issues with OpenVPN AS and commercial upgrade cycles.
+
+ In OpenVPN v2.7, support for this option was dropped when compiling OpenVPN with mbedTLS.
+
+ ## Option: `--tun-ipv6` | **Status: Ignored, pending removal**
+ - **Status:** Ignored since in OpenVPN 2.4l
+ - **Deprecated in:** OpenVPN v2.4
+ - **To be removed in:** OpenVPN v2.7
+ - **Affects:** Client and server
+ - **Result if used:** OpenVPN will complain and ignore the option
+ - **Replaced by:** Not replaced
+ - **Examples:**
+
+ This option was useful when IPv6 tun support was non-standard and was an internal/user-specified flag that tracked the IPv6 capability of the tun device.
+
+ Today, all supported OS support IPv6 and indicating explicit support is not needed anymore. Also, tun-ipv6 is pushable by the remote so not putting tun-ipv6 does not forbid IPv6 addresses.
+
+ ## Policy: Automatic Up-casing of X509 Certificate field names | Status: Completed in OpenVPN 2.5
+ - **Status:** Planned for removal
+ - **Deprecated in:** OpenVPN v2.3
+ - **To be removed in:**
+ - **Affects:** Server
+ - **Result if used:** n/a (Always used)
+ - **Replaced by:** Not replaced
+ - **Examples:** This feature converts an all-lowercase field name to uppercase characters, e.g., ou -> OU
+
+ See --x509-username-field in [Openvpn24ManPage](https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage) for a detailed explanation.
+
+ ## Option: `--max-routes` | **Status: Ignored, pending removal**
+ - **Status:** Planned for removal
+ - **Deprecated in:** OpenVPN v2.4
+ - **To be removed in:**
+ - **Affects:**
+ - **Result if used:** OpenVPN warns and ignores the option
+ - **Replaced by:** N/A
+ - **Examples:**
+
+ ## Option: `--dhcp-release` | **Status: Ignored, pending removal**
+ - **Status:** Enabled by default
+ - **Deprecated in:** OpenVPN v2.4
+ - **To be removed in:**
+ - **Affects:**
+ - **Result if used:** OpenVPN warns and ignores the option
+ - **Replaced by:** N/A
+ - **Examples:**
+ - **Notes:** Windows only
+
+ ## Option: `--route-nopull` | **Status: To be decided**
+ - **Status:** Disabled by default
+ - **Deprecated in:** Deprecation is under discussion
+ - **To be removed in:**
+ - **Affects:** Client routing, dhcp-options, and Windows firewall
+ - **Result if used:** See the manual
+ - **Replaced by:** `--pull-filter`
+ - **Examples:**
+ - **Notes:** Openvpn devs would like to know if you use this option
+
+ To emulate `--route-nopull` with `--pull-filter`:
+ - `--pull-filter ignore redirect-private redirect-gateway block-ipv6 client-nat route route-ipv6 route-metric ip-win32 dhcp-option dhcp-renew register-dns tap-sleep block-outside-dns`
+ - Optionally, also `ignore`: `route-gateway## Option: `--genkey --secret` | **Status: Deprecated, pending removal**
+
+ | **Status** | Warning |
+ |---|---|
+ | **Deprecated in** | OpenVPN v2.4 |
+ | **To be removed in** | **OpenVPN v2.8** |
+ | **Affects** | `--genkey` |
+ | **Result if used** | User Warning printed |
+ | **Replaced by** | `secret` (No leading double dash) |
+ | **Examples** | Use `--genkey secret filename` |
+ | **Notes** | |
+
+ ## Option: `--secret` | **Status: Deprecated, pending removal**
+
+ | **Status** | Warning in OpenVPN 2.6, error in OpenVPN 2.7 (can be overridden with `--allow-deprecated-insecure-static-crypto`) |
+ |---|---|
+ | **Deprecated in** | OpenVPN v2.6 |
+ | **To be removed in** | **OpenVPN v2.8** |
+ | **Affects** | `--secret` |
+ | **Result if used** | User Warning printed |
+ | **Replaced by** | `--peer-fingerprint` |
+ | **Examples** | See `man 5 openvpn-examples` |
+ | **Notes** | Static key mode (non-TLS) is no longer considered "good and secure enough" for today's requirements. Use TLS mode instead. If deploying a PKI CA is considered "too complicated", using `--peer-fingerprint` makes TLS mode about as easy as using `--secret`. This mode can still be enabled by using `--allow-deprecated-insecure-static-crypto` but will be removed in OpenVPN 2.8. |
+
+ ## Option: `--ncp-disable` | Status: Removed in OpenVPN v2.6
+
+ | **Status** | **Removed in OpenVPN v2.6** |
+ |---|---|
+ | **Deprecated in** | OpenVPN v2.5 |
+ | **Affects** | |
+ | **Result if used** | OpenVPN will not start due to unknown option |
+ | **Replaced by** | |
+ | **Examples** | |
+ | **Notes** | `ncp-disable` was mainly a debug option that allowed disabling NCP if there were problems with dynamic cipher negotiation. With the current status of NCP, this option is no longer necessary. |
+
+ ## plugin: `_v1 and _v2 functions for open and func call` | **Status: Pending removal**
+
+ | **Status** | Planned for removal |
+ |---|---|
+ | **Deprecated in** | OpenVPN v2.5 (**to be done**) |
+ | **To be removed in** | OpenVPN v2.7 |
+ | **Affects** | plugins still use the old API |
+ | **Result if used** | User Warning printed, later: refuse to load plugin |
+ | **Replaced by** | _v3 functions |
+ | **Examples** | |
+ | **Notes** | The _v3 API functions can do everything _v1 and _v2 can do, and the existence of the old functions mostly confuses everyone |
+
+ ## Option: `--inetd` | Status: Removed in OpenVPN v2.6
+
+ | **Status** | **Removed in OpenVPN v2.6** |
+ |---|---|
+ | **Deprecated in** | OpenVPN v2.5 |
+ | **Affects** | `--inetd` |
+ | **Result if used** | OpenVPN will not start due to unknown option |
+ | **Replaced by** | |
+ | **Examples** | |
+ | **Notes** | This is a very limited and not-well-tested way to run OpenVPN, on TCP and TAP mode only, which complicates the code quite a bit for little gain. |
+
+ ## Windows: `openvpn-legacy-service` | Status: Removed
+
+ | **Status** | Gone |
+ |---|---|
+ | **Deprecated in** | A Galaxy a long time ago .. |
+ | **To be removed in** | It's Gone MacREADY! |
+ | **Affects** | Windows only |
+ | **Result if used** | Service is not configured and cannot be used: See #1344 |
+ | **Replaced by** | `openvpnserv2.exe` Windows Service: `OpenVPNService` |
+ | **Examples** | n/a |
+ | **Notes** | To use `openvpnserv2.exe` see `C:\Program Files\Openvpn\config-auto\readme.txt` |
+
+ ## Option: `--persist-key` | **Status: To be decided**
+
+ | **Status** | TBD |
+ |---|---|
+ | **Deprecated in** | TBD |
+ | **To be removed in** | TBD |
+ | **Affects** | ALL |
+ | **Result if used** | Nothing, always enabled: See #1405 |
+ | **Replaced by** | Nothing |
+ | **Examples** | n/a |
+ | **Notes** | `--persist-key` will be always enabled |
+
+ ## Option: `--verify-hash` | **Status: Pending removal**
+
+ | **Status** | Deprecated |
+ |---|---|
+ | **Deprecated in** | OpenVPN v2.6 |
+ | **To be removed in** | TBD |
+ | **Affects** | Client and Server |
+ | **Result if used** | Warns about deprecation |
+ | **Replaced by** | Nothing, potential alternatives are specifying an intermediate CA as `--ca`, using a `--tls-verify` script, or `--peer-fingerprint` |
+ | **Examples** | |
+ | **Notes** | |
+
+ ## Option: `--link-mtu` | **Status: Pending Deprecation**
+
+ | **Status** | TBD |
+ |---|---|
+ | **Deprecated in** | TBD |
+ | **To be removed in** | TBD |
+ | **Affects** | ALL |
+ | **Result if used** | n/a |
+ | **Replaced by** | Nothing |
+ | **Examples** | n/a |
+ | **Notes** | n/a |
+
+ ## Option: `--management-client-pf` | Status: Removed in OpenVPN v2.6
+
+ | **Status** | **Removed in OpenVPN v2.6** |
+ |---|---|
+ | **Deprecated in** | OpenVPN v2.5 |
+ | **Affects** | Server and Client |
+ | **Result if used** | OpenVPN will not start due to unknown option |
+ | **Replaced by** | Nothing |
+ | **Examples** | n/a |
+ | **Notes** | n/a |
+
+ ## Option: `--prng` | **Status: Ignored, pending removal**
+
+ | **Status** | Ignored in OpenVPN 2.6 |
+ |---|---|
+ | **Deprecated in** | OpenVPN v2.5 |
+ | **Affects** | ALL |
+ | **Result if used** | OpenVPN warns and ignores the option |
+ | **Replaced by** | SSL library |
+ | **Examples** | n/a |
+ | **Notes** | OpenVPN used to implement its own PRNG based on a hash. However, implementing a PRNG is better left to a crypto library. So we use the PRNG of the used SSL library now.
+
+ ## Option: `--opt-verify` | **Status: Deprecated, pending removal**
+
+ | **Status** | Warns about deprecation |
+ |---|---|
+ | **Deprecated in** | OpenVPN v2.6 |
+ | **Affects** | ALL |
+ | **Result if used** | OpenVPN warns |
+ | **Replaced by** | n/a |
+ | **Examples** | n/a |
+ | **Notes** | n/a |
+
+ ## Option: `--disable-occ` | **Status: Deprecated, pending removal**
+
+ | **Status** | Warns about deprecation |
+ |---|---|
+ | **Deprecated in** | OpenVPN v2.6 |
+ | **Affects** | ALL |
+ | **Result if used** | OpenVPN warns |
+ | **Replaced by** | n/a |
+ | **Examples** | n/a |
+ | **Notes** | n/a |
+
+ ## NTLM v1 authentication support in `--http-proxy` | **Status: Deprecated, pending removal**
+
+ | **Status** | Deprecated in 2.6. To be removed in 2.7 |
+ |---|---|
+ | **Deprecated in** | OpenVPN v2.6 |
+ | **Affects** | `--http-proxy` |
+ | **Result if used** | Currently warns about deprecation. In 2.7 will try NTLM v2 instead. |
+ | **Replaced by** | basic auth |
+ | **Examples** | n/a |
+ | **Notes** | Generally considered insecure. If you don't care about that, just use basic auth.
+
+ ## NTLM v2 authentication support in `--http-proxy` | Status: To be deprecated in 2.7
+
+ | **Status** | Considered to be declared deprecated in 2.7 |
+ |---|---|
+ | **Deprecated in** | TBD |
+ | **Affects** | `--http-proxy` |
+ | **Result if used** | TBD |
+ | **Replaced by** | basic auth |
+ | **Examples** | n/a |
+ | **Notes** | Weak crypto. If you don't care about that, just use basic auth.
\ No newline at end of file
/dev/null .. Pages/OpenVPN software repos.md
@@ 0,0 1,147 @@
+ # Introduction
+
+ This page contains instructions for using the OpenVPN project's own software repositories. For a list of unofficial repositories, please refer to the [Unofficial OpenVPN software repositories](wiki:UnofficialOpenvpnSoftwareRepos) page.
+
+ For OpenVPN 3 Linux, see the dedicated [OpenVPN 3 Linux](wiki:OpenVPN3Linux) page.
+
+ The latest OpenVPN releases are available in the OpenVPN project's apt repositories. This allows you to use a more up-to-date version of OpenVPN than what is typically available in your distribution's repositories. Please note that all commands listed below have to be run as root, e.g. using `sudo` or `su`.
+
+ Pre-built Linux binaries are only available for Debian and Ubuntu for the following reasons:
+
+ - Official Debian and Ubuntu repositories tend to have fairly old OpenVPN versions available.
+ - Fedora and Fedora EPEL provide fairly up-to-date OpenVPN releases for supported Fedora and Red Hat Enterprise Linux (including clones such as CentOS, Scientific Linux) releases.
+
+ All packages are available in `amd64/x86_64` flavors. Additionally, `arm64/aarch64` flavors might be available for newer distributions and `i386` flavor might be available for older distributions. Even if a package is built on a particular OS, it does not mean it won't work on older and/or newer versions of the same distro, or even on a different operating system. If you encounter any issues with the package, please file a new [bug report](wiki:TesterDocumentation#Reportingbugs).
+
+ ## CentOS / Fedora / Red Hat Enterprise Linux
+
+ There are two alternatives here for OpenVPN packages. Fedora carries a reasonably up-to-date release in the main repositories. For CentOS and Red Hat Enterprise Linux (RHEL), the [Fedora EPEL](https://fedoraproject.org/wiki/EPEL) repositories contain the last OpenVPN releases when the distribution was released. All of these packages are considered to be stable for enterprise usage and will essentially just get bug and security fixes during the lifetime of the distribution. OpenVPN major releases will only be added to the next Fedora release.
+
+ ### Using Fedora EPEL (CentOS / RHEL)
+
+ Ensure you have the Fedora EPEL repository enabled. CentOS users may do this easily by installing the `epel-release` package via `yum install`. Red Hat Enterprise Linux users need to install this package manually, as described in the [Fedora EPEL wiki page](https://fedoraproject.org/wiki/EPEL). Then just run:
+
+ ```bash
+ yum install openvpn
+ ```
+
+ ### Using Fedora Copr
+
+ CentOS/RHEL users: Ensure you have the `yum-plugin-copr` package installed (can be installed via `yum`).
+
+ Then run these commands:
+
+ ```bash
+ yum copr enable dsommers/openvpn-release-2.6 # for OpenVPN 2.6 releases
+ yum copr enable dsommers/openvpn-release # for OpenVPN 2.5 releases
+ ...
+ yum install openvpn
+ ```
+
+ The [dsommers/openvpn-release-2.6 Copr repository](https://copr.fedorainfracloud.org/coprs/dsommers/openvpn-release-2.6/) currently contains the latest stable OpenVPN release.
+
+ The [dsommers/openvpn-release Copr repository](https://copr.fedorainfracloud.org/coprs/dsommers/openvpn-release/) contains the latest 2.5.x OpenVPN release. For new installations, it is recommended to use the 2.6.x release, 2.5.x releases are only provided for a short period to give users some time to migrate to 2.6. For details see SupportedVersions.
+
+ To test OpenVPN beta releases, the [dsommers/openvpn-beta Copr repository](https://copr.fedorainfracloud.org/coprs/dsommers/openvpn-beta/) contains builds for all recent Fedora, Red hat Enterprise Linux, and CentOS/CentOS Stream releases.
+
+ There are also nightly builds of the master branch available in the [dsommers/openvpn-git Copr repository](https://copr.fedorainfracloud.org/coprs/dsommers/openvpn-git/). Testing is welcome but not intended for production use!
+
+ If you have OpenVPN already installed, it will be upgraded to the latest available version.
+
+ #### Data Channel Offload support (DCO)
+
+ The Data Channel Offload support is available in OpenVPN 2.6 beta releases and newer and in [OpenVPN 3 Linux](https://community.openvpn.net/openvpn/wiki/OpenVPN3Linux). The needed Linux kernel module is available for Fedora and Red Hat Enterprise Linux 8 and newer. To get the needed `kmod-ovpn-dco` package, the `dsommers/openvpn3` Copr repository needs to be enabled as well.
+
+ ## Debian / Ubuntu: Using OpenVPN apt repositories
+
+ We maintain several OpenVPN (OSS) software repositories. To set up the repositories, you need to change to the root user. Typically this is done using `sudo`:
+
+ ```bash
+ sudo -s
+ ```
+
+ Then import the public GPG key that is used to sign the packages:
+
+ ```bash
+ mkdir -p /etc/apt/keyrings # directory does not exist on older releases
+ curl -fsSL https://swupdate.openvpn.net/repos/repo-public.gpg | gpg --dearmor > /etc/apt/keyrings/openvpn-repo-public.gpg
+ ```
+
+ Next, you need to create a sources.list fragment (as root) so that apt can find the new OpenVPN packages. One way to do it is this:
+
+ ```bash
+ echo "deb [arch=<arch> signed-by=/etc/apt/keyrings/openvpn-repo-public.gpg] https://build.openvpn.net/debian/openvpn/<version> <osrelease> main" > /etc/apt/sources.list.d/openvpn-aptrepo.list
+ ```
+
+ Where `<arch>` can be one of:
+ 1. `amd64`
+ 1. `arm64`
+
+ Where `<version>` can be one of:
+ 1. `stable`: stable releases only - no alphas, betas, or RCs
+ 1. `testing`: latest releases, including alphas/betas/RCs
+ 1. `release/2.3`: OpenVPN 2.3 releases
+ 1. `release/2.4`: OpenVPN 2.4 releases, including alphas/betas/RCs
+ 1. `release/2.5`: OpenVPN 2.5 releases, including alphas/betas/RCs
+ 1. `release/2.6`: OpenVPN 2.6 releases, including alphas/betas/RCs
+
+ and `<osrelease>` depends on your distribution:
+ * `buster` (Debian 10.x)
+ * `bullseye` (Debian 11.x)
+ * `bookworm` (Debian 12.x)
+ * `focal` (Ubuntu 20.04 LTS)
+ * `jammy` (Ubuntu 22.04 LTS)
+ * `noble` (Ubuntu 24.04 LTS)
+ * `oracular` (Ubuntu 24.10)
+
+ This list may be incomplete. Please check the [repository web page](http://build.openvpn.net/debian/openvpn/release/) for the complete list of releases.
+
+ Examples:
+
+ ```bash
+ # Always get the latest package, even Beta versions
+ echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/openvpn-repo-public.gpg] http://build.openvpn.net/debian/openvpn/testing jammy main" > /etc/apt/sources.list.d/openvpn-aptrepo.list
+ # Only get a specific version, do not upgrade to newer major version automatically
+ echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/openvpn-repo-public.gpg] http://build.openvpn.net/debian/openvpn/release/2.6 bullseye main" > /etc/apt/sources.list.d/openvpn-aptrepo.list
+ ```
+
+ Now you're set for installing OpenVPN. Note that packages built for older operating system releases might work just fine on a newer release of the same operating system.
+
+ ### Installing OpenVPN
+
+ On Debian/Ubuntu use:
+
+ ```bash
+ apt-get update && apt-get install openvpn
+ ```
+
+ To additionally install the DCO kernel driver use:
+
+ ```bash
+ apt-get install openvpn-dco-dkms
+ ```
+
+ ### Notes on expired keys
+
+ If the apt signing key expires, apt will complain when refreshing the package cache (e.g. `apt-get update`). In that case, just download the key again as described above.
+
+ ### Debian Snapshot Builds
+
+ Debian snapshot development builds are available as well. To use them:
+
+ ```bash
+ mkdir -p /etc/apt/keyrings # directory does not exist on older Debian/Ubuntu releases
+ curl -fsSL https://build.openvpn.net/debian/snapshots/snapshots-key.asc > /etc/apt/keyrings/openvpn-repo-snapshots.asc
+ echo "deb [signed-by=/etc/apt/keyrings/openvpn-repo-snapshots.asc] https://build.openvpn.net/debian/snapshots/<osrelease> <osrelease> main" > /etc/apt/sources.list.d/openvpn-snapshots.list
+ apt-get install openvpn
+ ```
+
+ To test a specific build with a specific patch, you might need to install a specific snapshot build. You can do this with apt by providing the exact version to install:
+
+ ```bash
+ apt-get install openvpn=2.7-1719406367
+ ```
+
+ See [https://build.openvpn.net/debian/snapshots/](https://build.openvpn.net/debian/snapshots/) for a current list of valid `osrelease` values. Only `amd64` snapshot builds are available currently.
+
+ Note that these are intended to provide an easy way to test patches or the latest master, **not for production use**. If you notice any problems, let us know!
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9