Commit 9ea8ff
2025-01-29 07:28:13 Samuli Seppänen: Import most meetup/hackaton pages Signed-off-by: Samuli Seppänen <samuli.seppanen@gmail.com>| /dev/null .. meetups/2013-munich.md | |
| @@ 0,0 1,183 @@ | |
| + | # OpenVPN Hackathon 2013 |
| + | |
| + | ## who |
| + | |
| + | This is organized by Gert Döring (cron2) and sponsored by [Spacenet AG](http://www.space.net/). |
| + | |
| + | We have space for about 10 people in the conference room I have booked so far, so I'd limit this to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". If there is overwhelming interest, I can get a larger room, but then the address listed below would change (still in Munich, but not as centrally located). |
| + | |
| + | ## who is coming? |
| + | |
| + | | Name | Topics | Arrival | Departure | |
| + | |---------------|-------------------------------------------|-----------------|-----------------| |
| + | | Gert Döring | no particular topics | Fri morning-ish | Sun, late night | |
| + | | Heiko Hund | OpenVPN Windows Interactive Service<br>General OpenVPN for Windows architecture | Fri. ~15h | Sun. ~18h | |
| + | | David Sommerseth | Maintainer <br> Plug-in API <br> GUI on Linux | Fri, 15-ish | Sun afternoon/evening | |
| + | | Arne Schwabe | OpenVPN Dual Stack <br> OpenVPN for Android | Fri noo-ish | Monday | |
| + | | Steffan Karger | PolarSSL 1.3, elliptic curve crypto | Friday noon-ish | Sunday afternoon| |
| + | | Adriaan de Jong | tbd, probably some PolarSSL/Elliptic curve work, open crypto trac tickets | Friday | Sunday | |
| + | | Samuli Seppänen | Ticket review, CLA, OpenVPN 2.4/3.0, NSIS | Friday 11:00 | Sunday 18:20 | |
| + | | James Yonan | OpenVPN 2.4/3.0 | Thursday morning| Monday morning | |
| + | |
| + | ## where? |
| + | |
| + | We'll meet in one of the office locations of Spacenet. The address is: |
| + | |
| + | ``` |
| + | SpaceNet AG |
| + | Landsberger Strasse 155 |
| + | 80687 München (Munich) |
| + | Germany |
| + | ``` |
| + | |
| + | See [google maps](https://maps.google.de/maps?q=Landsberger+Stra%C3%9Fe+155,+M%C3%BCnchen&hl=de&ie=UTF8&ll=48.139892,11.526031&spn=0.002957,0.003358&sll=48.917413,11.407993&sspn=4.216739,6.877441&oq=landsb&hnear=Landsberger+Stra%C3%9Fe+155,+Laim+80687+M%C3%BCnchen&t=h&z=18). The entrance is in the upper left corner on the inside of the "#" formed building. |
| + | |
| + | Inside the "#", there are 4 entries in each of the corners, marked as "Haus 1" to "Haus 4". Take the entry "Haus 4". There is a reception for Cable&Wireless and SpaceNet there. Tell the security guy that you want to visit SpaceNet, and he'll call me or one of my colleagues and we'll pick you up (SpaceNet is on the 1st floor of Haus 4). The guard will require some sort of deposit - ID card, driver license, etc - to ensure people properly check out at leaving. |
| + | |
| + | This location is easy to reach by car or by public transport (Tram from central station). |
| + | |
| + | Specifically: |
| + | |
| + | - if you arrive by plane, take S-Bahn S1 or S8 (it's a circle, S1 goes left, S8 goes right) and exit after about 45 minutes at "Hirschgarten" or "Donnersbergerbrücke". About 10 minutes walk from there, or take the Tram 18/19 for the remainder. |
| + | - if you end up near the central station (either arriving by train, or with the S-Bahn), exit the central station on the south side, take Tram 18 or 19 towards Willibaldplatz / Gondrellplatz (westwards), and exit at "Lokschuppen". Landsberger Strasse is the street the Tram travels, 155 is across the street next to the "Bauhaus" market |
| + | - if you come by car, parking in the vicinity is a bit problematic. You can park in the "Bauhaus" garage but that's "for their customers only", so you'd need to relocate to the SpaceNet parking garage when the SpaceNet crew has left (no guest parking there, unfortunately). We'll find something. |
| + | |
| + | If you get lost, call me: +49 177 2160221 |
| + | |
| + | ## when? |
| + | |
| + | The hackathon will take place from Nov 15 (Friday), 2013 to Nov 17 (Sunday). The room is ours for the full 3 days, and I (cron2) will be there at Friday 09:30-ish. I have no confirmed arrival dates from anyone else yet... |
| + | |
| + | ## food |
| + | |
| + | I'll sponsor soft drinks and snacks, and the conference room, and I'll sponsor a "Weisswurstfrühstück" for Saturday. |
| + | |
| + | For lunch, there's lots of nice small restaurants in the area, so we'll find something better than in Brussels. |
| + | |
| + | Dinner on Friday is international fingerfood at [Cafe Westend](http://www.cafe-westend.com/), nice TexMex food and not too loud (19:00, 8-10 persons, reservation for "Döring") |
| + | |
| + | For dinner on Saturday we booked a table at [Augustinerkeller](http://www.augustinerkeller.de) for some serious Bavarianism. |
| + | |
| + | ## what? |
| + | |
| + | So what is the goal of the Hackathon? |
| + | |
| + | - meet in person, talk about things |
| + | - contributors agreement (CLA) for OpenVPN 3 |
| + | - future development of 2.x and 3.x |
| + | - GPL violation on multiple apps on the play store |
| + | - hack on the 2.4 codebase - there's a number of "large" things we could try to tackle |
| + | - dual-stack patches |
| + | - openvpn interactive service |
| + | - work on open trac issues |
| + | - lots of things to review and bugs to fix |
| + | |
| + | I'm all open for additions here - I think the meetings in Brussels have shown that "just being able to sit together and hack" is a useful exercise. Add reasonable food, air condition, etc. and things should be even better. |
| + | |
| + | ## Internet |
| + | |
| + | Of course, there will be free WiFi available, and for bandwidth junkies, wired Internet as well :-) - Spacenet is an Internet service provider, and that's one of their core locations, connected with multiple 10Gbit links to the world... |
| + | |
| + | ## accommodation |
| + | |
| + | - "Motel One Munich City West" has been recommended as "being close, reasonably priced, and generally OK" |
| + | |
| + | ## results |
| + | |
| + | This is just a sort of unordered list of things we agree on, to avoid thoughts getting lost |
| + | |
| + | - push-peer-info of IV_OPENVPN_GUI_VERSION -> go there in the core, gui writers can add --setenv line if they want. Format for the content = "<gui_identifier><space><version>" |
| + | - GPL violations - "we should go after them, to strengthen the GPL" - but making money out of GPL software means you have to accept that people will use your software without paying for it |
| + | - don't go for DCMA/cease-and-desist letters (bad press) |
| + | - be open about it - "we have contacted these people for this-and-that reason, and are waiting for a response" |
| + | - use help (templates?) from gpl-violations.org people? |
| + | |
| + | - --float with TLS HMAC |
| + | - the code looks good (syzzer), but it opens the server for CPU usage DoS attacks (walking a potentially long list of clients for each unknown packet) |
| + | - put a big warning label there |
| + | - plaisthos: if we do that, send a notice to the client that the server can do it, so a mobile client can handle network changes "floating" instead of "full reconnect" |
| + | |
| + | - OpenVPN 3 |
| + | - it's proven itself as a mobile client |
| + | - more work is needed for desktop client |
| + | - even more work needed for server |
| + | - it's the base for the iOS client, which **must** have a closed license (Apple requirement), so a contributor agreement is needed to enable dual-license distribution |
| + | - what to do with "occasional contributors" that do not want to sign the agreement? |
| + | - dazo needs to check with redhat whether he can sign such a CLA |
| + | - formal text not yet finalized, James looking at stuff like the Google Android code agreement for guidance |
| + | - process for android: sign and scan an e-mail, or sign electronically on a web page |
| + | - would dual-license GPL/BSD work? |
| + | - what to do about zealots that will not accept closed license? are we in a risk of forking the project? can we **do** anything about it, if we accept the need to have an iOS client? (cron2 says "no") |
| + | - separate openvpn 3 into "core" (dual-licensed, with CLA) and "users of the core" (GPLed, like platform-specific for non-apple platforms, authentication related, crypto library interfaces, etc.)? "**that sounds like a plan (and it sends the right signals to the community etc)**" :-) - more work is needed to make good APIs for that |
| + | - mattock: timeline for releasing a git repo of 3? james: "I'll publish a git repo in the next few weeks", it's a good time, the code has been fairly quietly recently |
| + | |
| + | - plan for the technical development of 2.4 and 3? |
| + | - "we will have 2.x around for quite a while, at least for the server" |
| + | - 3 will eventually be "a general client", and we might remove "client-only bits" from 2.x |
| + | - move over to 3 will take a while... |
| + | - dazo: linux, network manager, talking to openvpn 3 as a client would be a great thing - james: that's what the 3 core is good at, being API driven |
| + | - james: openvpn 3 is really meant to be used as a library, not so much as a command line client (even if it exists) |
| + | - 2.4: d12fk: the interactive service should be in. It's being shipped in the Astaro UTM provided client for a while, and works good for IPv4 routes today, but some bits are still being added (DNS, winbind, IPv6, ...) |
| + | - 2.4: dual stack cleanup (plaisthos) |
| + | - behaviour about as openvpn 3 does regarding talk to dual-stack servers |
| + | - well-tested in the android client, still needs review |
| + | - as a side note: socket.c in 3 replaced by boost ASIO library "which is brilliant and bug free" |
| + | - 2.4: handshake crypto parameters? |
| + | - "what is the best way to go there"? |
| + | - we have TLS handshaking - use that to define data-link cipher? |
| + | - reason for independent TLS and data layer crypto: SSL library might not expose symmetric crypto algorithms that are used for SSL/TLS handshake inside the library |
| + | - client pushes list of supported ciphers+hmac digest, server picks, pushes back? |
| + | - GOAL: reduce extent of incompatibilities in config file settings ("1000 clients that use MD5 and you want to switch to SHA2 on the server side") |
| + | - for //compression// handshake: client sends "flags" (IV_LZO=1, IV_SNAPPY=1, ...) in the TLS control channel (at authentication phase), server decides via mgmt interface or client-connect script |
| + | - we can not use DTLS - it's a different on-the-wire protocol, and there are issues with it - not recommended anyway |
| + | - 2.x code currently will not handle per-client cipher and HMACs yet, because the code assumes that cipher/HMAC is known at connection time, and not changing later on - so it cannot be pushed server->client, and the server will not handle different ciphers either. TBD ("historic design defect"). OpenVPN 3 does it right. |
| + | - so 1st step: handle per-client cipher on server and pushable cipher on client |
| + | - 2nd step: handle negotiation |
| + | |
| + | - 2.4 (cron2): IPv6 enhancements |
| + | - handle overlapping IPv6 server address and pushed IPv6 routes ("2001:608::/32 and server inside 2001:608::/32 -> recursive routing"). This is done for IPv4 but not IPv6 yet. Ask OS for default gateway, install route to OpenVPN server to that gateway, then install pushed routes. Cleanup on exit. |
| + | - --block-ipv6 for mobile clients (blocking inside OpenVPN) |
| + | |
| + | - windows and the interactive service |
| + | - privileged service running |
| + | - GUI talks to service, service runs openvpn process with user rights, but restricted permissions against access from elsewhere |
| + | - routes get installed by having openvpn signal the service that routes should be installed/removed/... |
| + | - gain: users do not need to run gui with admin rights, and openvpn process does not run with admin rights |
| + | - remaining attack angle: install unauthorized routes |
| + | - it can be locked down by only permitting .ovpn profiles from a given non-user-writeable path (registry setting at installation) |
| + | - on XP, this is actually not needed (only Vista and up), so the installer could decide to not install the service at all, as network programming on XP needs "netsh" while Vista and up have a decent API for that. |
| + | - "do not put any extra effort on XP, but do not break it on purpose" |
| + | - james: why not do the service in a way that it implements a "VPN API", as on Android, iOS, ...? That would nicely adapt itself to OpenVPN 3 |
| + | - access control to VPN API? |
| + | - end result: while not in full agreement on details, we'll go forward with what d12fk already has ("working code" trumps "perfect world"). |
| + | |
| + | - dual-stack patches |
| + | - agree on: use all addresses returned by getaddrinfo() in the order the OS gives it to us, making a separate connection block out of each |
| + | - timeout handling will be reworked to be identical for tcp and udp connections |
| + | - --proto udp will mean "v4+v6" from now on, "--proto udp4" will mean "only ipv4", "--proto upd6" will mean "only ipv6" |
| + | - OCC etc. will have "udp", not "udp4" or "udp6" |
| + | - same for TCP |
| + | - plaisthos will rework patches and re-send to list |
| + | - for the server side and "proto udp" (no AF specified) |
| + | - without --bind, we bind to "AF_INET6" and "INADDR_ANY" (and use setsockopt() to enable a dual-stack socket <- code needs to be written) |
| + | - **with** --bind, if the hostname resolves to a single IPv4/IPv6 address, we use that. If it resolves to multiple addresses, we fail with a clear error message "we can not handle that, specify a single address" |
| + | - for the record: on windows: use setsockopt() IPV6_ONLY = 0 |
| + | - --ip-remote-hint stays **in**, as there is usage in certain GUIs environments ("I have a profile that has DNS lookups in, but I need to force a certain hosts on a certain IP address"). |
| + | - new feature: --presolve-ipaddress --> resolve addrinfo() right away, before connecting, because after tun establishment DNS might no longer work, with an optional parameter "ip" that is "use resolve everything to *that* address" |
| + | - implementation-wise, --ip-remote-hint would be an alias to --presolve-ipaddress, so UIs would not have to adapt |
| + | |
| + | - window elevated privileges patch (manifest patch from pekster) |
| + | - d12fk is worried that people might upgrade to 2.4 and then have a gui running as "administrator" which would defeat the whole interactive service approach |
| + | |
| + | - packet format and alignment (James/--tls-float patch) |
| + | - HMAC and encrypted data is not 32bit aligned today due to the opcode |
| + | - propose to byte-swap the opcode with the last byte in the packet, so after swapping back the HMAC is 32bit aligned |
| + | - can be done by sending IV_PROTO=<supported max version> by the client (server can then immediately turn it on) and pushing "wire-proto <x>" from the server to the client (and then the client can immediately turn it on) |
| + | - slightly related: include session ID in the data packet, "if you feel like it might be needed"? (to handle --float in TLS-mode without opening ourselves to UDP->HMAC CPU DoS) |
| + | - "don't send it more than 1/second, don't send it unless you have heard from the server for more than <n> seconds"... |
| + | - watch out for MTU jumps -> "set aside that amount of space even if not used" |
| + | - TODO: |
| + | - define opcodes for "wire-protocol 2" for "short/swapped mode" and "swapped mode with session id" |
| + | - add "wire-protocol 2" to option.c etc |
| + | - add push-peer-info IV_PROTO=2 |
| + | - add logic to server to read IV_PROTO and push "wire-protocol <x>" to the maximum supported by client and server |
| \ | No newline at end of file |
| /dev/null .. meetups/2014-munich.md | |
| @@ 0,0 1,206 @@ | |
| + | # OpenVPN Hackathon 2014 |
| + | |
| + | ## who |
| + | |
| + | This is organized by Gert Döring (cron2) and sponsored by Spacenet AG ([http://www.space.net/](http://www.space.net/)). |
| + | |
| + | We have space for about 10 people in the conference room I have booked so far, so I'd limit this to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". If there is overwhelming interest, I can get a larger room, but then the address listed below would change (still in Munich, but not as centrally located). |
| + | |
| + | ## who is coming? |
| + | |
| + | | Name | Topics | Arrival | Departure | |
| + | |-----------------|---------------------------------|-------------------------|--------------------| |
| + | | Gert Döring | no particular topics | Fri morning-ish | Sun, late night | |
| + | | David Sommerseth| auth/kerberos, plug-ins | Fri 14-ish (SK4759) | Sun, afternoon (LH2456) | |
| + | | Samuli Seppänen | openvpn 2.4/3.x, community site | Thu, morning (BT221) | Sun, afternoon (BT224) | |
| + | | Steffan Karger | AES-GCM, Windows service review?| Fri, around noon | Sun, afternoon | |
| + | | Adriaan de Jong | tbd | Fri, around noon | Sun, afternoon | |
| + | | Arne Schwabe | timeouts in OpenVPN | Fri, train, 11:30 | Monday, morning, train| |
| + | | Jan Just Keijser| Win7+ integration, performance | Sat morning | Sun, afternoon | |
| + | | Heiko Hund | interactive service, NTLM patches, GOST | Fri. morning | Sun. evening | |
| + | | Lev Stipakov | peer-id patch, tbd | Thu. evening | Sun. evening | |
| + | | James Yonan | OpenVPN protocol changes | Thu. morning | - | |
| + | |
| + | ## where? |
| + | |
| + | We'll meet in one of the office locations of Spacenet. The address is: |
| + | |
| + | ``` |
| + | SpaceNet AG |
| + | Landsberger Strasse 155 |
| + | 80687 München (Munich) |
| + | Germany |
| + | ``` |
| + | |
| + | See [Google Maps](https://maps.google.de/maps?q=Landsberger+Stra%C3%9Fe+155,+M%C3%BCnchen&hl=de&ie=UTF8&ll=48.139892,11.526031&spn=0.002957,0.003358&sll=48.917413,11.407993&sspn=4.216739,6.877441&oq=landsb&hnear=Landsberger+Stra%C3%9Fe+155,+Laim+80687+M%C3%BCnchen&t=h&z=18). The entrance is in the upper left corner on the inside of the "#" formed building. |
| + | |
| + | Inside the "#", there are 4 entries in each of the corners, marked as "Haus 1" to "Haus 4". Take the entry "Haus 4". There is a reception for Cable&Wireless and SpaceNet there. Tell the security guy that you want to visit SpaceNet, and he'll call me or one of my colleagues and we'll pick you up (SpaceNet is on the 1st floor of Haus 4). The guard will require some sort of deposit - ID card, driver license, etc - to ensure people properly check out at leaving. |
| + | |
| + | This location is easy to reach by car or by public transport (Tram from central station). |
| + | |
| + | Specifically: |
| + | * if you arrive by plane, take S-Bahn S1 or S8 (it's a circle, S1 goes left, S8 goes right) and exit after about 45 minutes at "Hirschgarten" or "Donnersbergerbrücke". About 10 minutes walk from there, or take the Tram 18/19 for the remainder. |
| + | * if you end up near the central station (either arriving by train, or with the S-Bahn), exit the central station on the south side, take Tram 18 or 19 towards Willibaldplatz / Gondrellplatz (westwards), and exit at "Lokschuppen". Landsberger Strasse is the street the Tram travels, 155 is across the street next to the "Bauhaus" market |
| + | * if you come by car, parking in the vicinity is a bit problematic. You can park in the "Bauhaus" garage but that's "for their customers only", so you'd need to relocate to the SpaceNet parking garage when the SpaceNet crew has left (no guest parking there, unfortunately). We'll find something. |
| + | |
| + | If you get lost, call me: +49 177 2160221 |
| + | |
| + | ## when? |
| + | |
| + | The hackathon will take place from Nov 14 (Friday), 2014 to Nov 16 (Sunday). The room is ours for the full 3 days, and I (cron2) will be there at Friday 09:30-ish. I have no confirmed arrival dates from anyone else yet... |
| + | |
| + | ## food |
| + | |
| + | I'll sponsor soft drinks, snacks and the conference room, and I'll sponsor a "Weisswurstfrühstück" for Saturday (see [Weisswurst](https://en.wikipedia.org/wiki/Weisswurst)). |
| + | |
| + | Friday evening, we meet at [Cafe Westend](http://www.cafe-westend.com/) (19:00 local time, table reserved for "Döring"), sponsored by OpenVPN Tech. Good TexMex and local food. |
| + | |
| + | Saturday, it's [Wirtshaus am Bavariapark](http://wirtshaus-am-bavariapark.com/) (19:00 local time, table reserved for "Karger", I assume), sponsored by FoxIT. Bavarian food, beer :-) |
| + | |
| + | ## what? |
| + | |
| + | So what is the goal of the Hackathon? |
| + | |
| + | * meet in person, talk about things |
| + | * contributors agreement (CLA) for OpenVPN 3 |
| + | * future development of 2.x and 3.x |
| + | * GPL violation on multiple apps on the play store |
| + | * hack on the 2.4 codebase - there's a number of "large" things we could try to tackle |
| + | * peer-id patch set (full support in 2.4, client-side support in 2.3) |
| + | * new data packet format proposed for AEAD and "null-compression" |
| + | * fix compilation of "master" on windows |
| + | * openvpn interactive service - get code in git tree |
| + | * async plugin patch, inotify async auth patch (Lev) |
| + | * IPv6 gateway detection? |
| + | * work on open trac issues |
| + | * lots of things to review and bugs to fix |
| + | |
| + | I'm all open for additions here - I think the meetings in Brussels and Munich 2013 have shown that "just being able to sit together and hack" is a useful exercise. |
| + | |
| + | ## Internet |
| + | |
| + | Of course, there will be free WiFi available, and for bandwidth junkies, wired Internet as well :-) - Spacenet is an Internet service provider, and that's one of their core locations, connected with multiple 10Gbit links to the world... |
| + | |
| + | ## accommodation |
| + | |
| + | * "Motel One Munich City West" has been recommended as "being close, reasonably priced, and generally OK" |
| + | |
| + | ## results |
| + | |
| + | This is just a sort of unordered list of things we agree on, to avoid thoughts getting lost |
| + | |
| + | * drop Windows XP support in OpenVPN 2.4 |
| + | * this also affects Windows Server 2003 (extended support) and Windows XP Embedded |
| + | * specifically: XP will not get "interactive service" support, because the APIs used for IPv6 routing are not available on XP |
| + | * 2.3.x will continue to be supported |
| + | * 2.4.x might drop XP support if supporting it gets too hard, like "keep all the netsh calls in there" - it will be announced in the 2.4.0 release notes "use on your own risk, but not officially supported anymore" |
| + | * functionality that will fail on XP and older will be wrapped in an #ifdef |
| + | |
| + | * strip out the PRNG support from OpenVPN, as both SSL libraries have good PRNG inside, and at least PolarSSL's is faster (syzzer) |
| + | |
| + | * about removing snappy support - we keep it for the time being (#ifdef), because OpenVPN 3 and OpenVPN AS support and use it. Since compression can be negotiated, we can just leave it off for platforms where it is complicated to build (like Windows due to the libstdc++.dll being so big) |
| + | |
| + | * coding style in OpenVPN source - see [Bikeshed](http://blue.bikeshed.org/) and [Indent style](http://en.wikipedia.org/wiki/Indent_style) - candidates: Allman, GNU, K&R (higher git impact when changing over due to the opening bracket moving), and then tabs/no-tabs. |
| + | * everybody is "okayish" with changing, as long as it is done consistently, everywhere |
| + | * slightly stronger feeling for Allman style - **Allman style** it is |
| + | * syzzer volunteers to make the non-consistent files consistent |
| + | * "the big whitespace change" for existing code happens at 2.4-RC, and then we will no longer do "patches to master and 2.3" (which would have different indentation) but to "master and 2.4" (same style), except for critical issues, which usually are small and manageable |
| + | * line length? |
| + | * "stick to what we have for now", do not reformat arbitrarily |
| + | * breaking a line in the middle: align to opening (round) brackets in line above |
| + | * tabs vs. spaces: "not mixed" |
| + | * majority for "only spaces, no tabs" |
| + | * this is what we change to: all spaces |
| + | |
| + | * new packet format? (Mail from James, Message-ID: <54648EAC.70204@openvpn.net>) |
| + | * AEAD: 12-byte nonce is needed - use session ID plus HMAC random for that? James and Syzzer agree on that. |
| + | * compression V2 format - yes, go for it |
| + | * to support COMPRESS_V2 the server needs to actually send the peer-id packet format as well (right now only the client sends peer-id packets) |
| + | * discussion: |
| + | * James: let's actually negotiate COMPRESS_V2 so we do not couple peer-id and compression which is actually independent parts/layers of the code |
| + | * Arne: this could be "PACKET_FORMAT_3" (peer-id+compress-v2) |
| + | * James: lean to "negotiate compression and packet format independently, as they are different layers" |
| + | * Jan Just: nice thing about scalar packet format is that you **know** which features have to be in there - but "don't do too many of these versions" |
| + | * discussion ended up with crypto negotiations, but I think we'll just see a patch from James with "whatever will be the outcome" for COMPRESS_V2 |
| + | |
| + | * regarding --enable-ssl/disable-ssl - decided to a) ask the openvpn-users whether there is anyone using OpenVPN without SSL, and if not, remove the option (so --enable-crypto would bring SSL, --disable-crypto would take away SSL and all crypto) - one different #ifdef variant less |
| + | |
| + | * timeouts on client connect (Arne) |
| + | * we have various timeouts in the client - socket timeout, proxy connect timeout, tls handshake timeout |
| + | * master timeout - if connect does not succeed in that time, go to next <remote> |
| + | * goal: only have "master timeout", get rid of individual timeout bits |
| + | * "server poll timeout" -> must receive at least "some answer" in (short) time, to decide whether server is alive at all. Total handshake needs to be much longer (slow CPUs, etc.) --> short timeout to skip over dead servers / dead networks, longer "master timeout" to handle whole setup |
| + | * James: please keep server poll timeout, and keep that short (4s-ish) - the rest could be integrated unless there is a reason to keep them separate |
| + | * feature-ACK: remove all the individual timeouts and replace by "server poll timeout" that is "up to the first packet coming back from the server". If nothing is configured, current default is "0" = "no server poll timeout" - new default: 60 seconds to mimic existing TCP connect timeouts, plus log notice ("if we have multiple remotes and no server-poll-timeout, user experience might be better setting this to a lower value, like 5s"). |
| + | |
| + | * inotify patch from Lev (on list) - feature discussion |
| + | * this is about async authentication plugin (deferred authentication) |
| + | * "response from plugin" is delivered by the creation of a file |
| + | * currently, we stat() in regular intervals -> replace by inotify so system load is lower |
| + | * it's done via a single file descriptor that is added to the master poll() in the event loop which will tell you about an arbitrary number of files that are watched |
| + | * portability? |
| + | * feature-ACK so far ("generally OK"), patch needs review |
| + | |
| + | * async-plugin patch |
| + | * used in production at Lev's servers since some months and Fabian Knittel's server |
| + | * enables async handling of client-connect script and plugin |
| + | * -> openvpn is not stuck while client-connect script does "slow things" (like, radius start records taking 300ms) |
| + | * impairs performance on busy servers |
| + | * David looking into patch, on the mailing list - whitespace changes, not easy to read |
| + | * "someone needs to talk to Fabian to rebase to master" |
| + | * there is general interest in the feature, but we need to find time! |
| + | |
| + | * performance (general performance, and Windows in particular) |
| + | * throughput is worse than "Cisco Connect" client (2-3x - David can reproduce it at will to server side) |
| + | * might be related to socket buffers - please test setting to 256k or more |
| + | * jjk: throughput is not crypto-bound, is "networking" (latency/buffers?) - can be reproduced with "cipher none" |
| + | * windows performance is way lower even (factor 5!) |
| + | * jjk: we need to measure this in a more controlled experiment ("I am a physicist" - cron2 agrees) |
| + | * to sum up: jjk "has the equipment" (will run baseline on Linux) |
| + | * log file seems to suggest packets receiving out of order --> **check that** |
| + | * experiment with socket buffer options |
| + | * James will check with Thomas Divine whether he has an idea on Windows performance |
| + | * upload speeds via VPN to David's servers in RedHat VPN seem to be limited by RedHat internal lines... |
| + | |
| + | * future plans? mid term, long term? |
| + | * 2.4 (mid-term goals for 2.x) |
| + | * interactive service! MUST HAVE |
| + | * timeout stuff fixes (Arne) |
| + | * peer-id MUST HAVE |
| + | * inotify "good chance", async plugin "depends on time" |
| + | * IPv6 gateway handling - really should go in, but cron2 has no time :( - depends on how the remaining schedule surrounding 2.4 goes |
| + | * AEAD/GCM - code is there, not performing nicely yet - MUST HAVE |
| + | * EC with external keys is not working yet - "nice to have", nobody working on it, not actually hard, just "many small pieces to touch" |
| + | * new data packet format (COMPRESS_V2) |
| + | * NTLMv2 proxy fixes (in 2.4.0 and 2.3.x, please - bugfix!) |
| + | * new windows installer for gui and everything (mattock), fixes lots of bugs, should be in 2.4.0 - MUST HAVE |
| + | * rough timeline: march 2015 for 2.4.0-RC? |
| + | * coding style change right before 2.4.0-RC |
| + | * improve systemd support (patches on the list) |
| + | * --enable/disable-ssl -> remove #ifdefs |
| + | * get rid of "useless #define" - find your pet peeve, ask on the list, send patch if feature-ACK |
| + | * look at trac |
| + | * auth-user-pass inline (patch from pekster?) - status? followup on it? |
| + | * GOST (nice to have, but no pressing need now - Heiko to rebase to master, overlap with AEAD for "newer openssl APIs"? - look at it) |
| + | * 2.5 (long term goal for 2.x) |
| + | * multiple server sockets (TCP+UDP) |
| + | * multiple threads ("however it might look like in the end"), depending on the performance bottlenecks discovered |
| + | * improved testing framework (andj) - MUST HAVE, some stuff might go to 2.4 |
| + | * isolate functionality better (no central context everywhere, gets into the way of testing) (syzzer) |
| + | * better document internal API and wire protocol - go for a (personal) RFC? (syzzer/james) |
| + | * cipher negotiation |
| + | * 3.0 (mid term and long term)? |
| + | * today: solid client (iOS, Android) |
| + | * work being done on adding server functionality |
| + | * James feels more comfortable about "putting it out to the public" when it has (basic) server functionality |
| + | * CLA issues still open - current state: discussed inside OpenVPN Tech, "nearly done"; similar to Google CLA for Android |
| + | * 3 being used as a testbed for new ideas |
| + | * James: "I've watched python 2 to 3 disaster, learned from it" - on the wire protocol will be 100% compatible, most client config stuff is compatible |
| + | * Andj: splitting community resources is tricky, James agrees |
| + | * Heiko: it would be nice to have a "cli wrapper" that presents the same cli + mgmt interface to "GUI users" (like Tunnelblick, etc.) |
| + | * James: agree, mgmt interface would be good |
| + | * Arne: I can push an Android version with my gui, if James is comfortable with it - James: "when I'm comfortable with the code, still very much refactoring going on, so wait for the server functionality to be done" |
| + | * Andj: multithreading? James: it's sort of thread-agnostic, but there is no active multithreading functionality yet |
| + | * multi-socket server is actually very easy, as you just create a few ASIO socket objects and listen to them (and it's **fast** too!) |
| + | |
| + | * weekly community meetings: **new time** Monday, 20:00-22:00 European local time, make it more frequently again - first meeting: Monday 21st |
| \ | No newline at end of file |
| /dev/null .. meetups/2015-delft.md | |
| @@ 0,0 1,67 @@ | |
| + | # OpenVPN Hackathon 2015 |
| + | |
| + | ## who |
| + | This year's hackathon is organized by Steffan Karger (syzzer) and sponsored by Fox-IT. |
| + | |
| + | We will stick to the format of the previous years, which means attendance is in principle limited to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". We should have enough space in the meeting room for ~16 devs. |
| + | |
| + | ## who is coming? |
| + | |
| + | | Name | Topics | Arrival | Departure | |
| + | |-----------------|--------------------------------------|-------------------|--------------------------| |
| + | | Steffan Karger | Crypto stuff | ∞ | ∞ | |
| + | | Gert Döring | IPv6 RGI | Fri around 14:30 | Sun, around 13:00-13:30 | |
| + | | Jan Just Keijser| PKCS!#11, speed | Fri morning | Sun, late afternoon | |
| + | | Arne Schwabe | IPv6/IPv4 Handover | Thr | Sun 14:35 train | |
| + | | Samuli Seppänen | OpenVPN 2.4/3.x | Fri afternoon | Sun, ~15:30 | |
| + | | Lev Stipakov | inotify, occ_server_exit, etc | Thr evening | Sun, ~15:30 | |
| + | | David Sommerseth| systemd, user/pass auth | Thu afternoon (KL1144) | Mon, early morning (KL1145) | |
| + | | Adriaan de Jong | Crypto stuff, planning | ∞ | ∞ | |
| + | | James Yonan | - | Thu | - | |
| + | |
| + | ## where? |
| + | |
| + | The meeting is held at the office of Fox-IT: Olof Palmestraat 6, Delft, the Netherlands. Our house rules require that you allow your visit to be registered at the front desk. A valid identity document is required. More details at [Fox-IT contact page](https://www.fox-it.com/en/contact/delft/). |
| + | |
| + | Directions [from the train station to the West Cord hotel](https://www.google.nl/maps/dir/Delft,+Van+Leeuwenhoeksingel+42A,+2611+AC+Delft/WestCord+Hotel+Delft,+Olof+Palmestraat,+Delft/@52.010419,4.3585806,15z/data=!3m2!4b1!5s0x47c5b5c0c25b354b:0x93ba42de4fd604fc!4m14!4m13!1m5!1m1!1s0x47c5b5c0c28ca02f:0xc098eaf8cccc90d7!2m2!1d4.3565297!2d52.007545!1m5!1m1!1s0x47c5b5f13b7c9c69:0x1d6d450585fd0a7c!2m2!1d4.3809835!2d52.010918!3e1). |
| + | |
| + | Directions [from the hotel to Fox-IT](https://www.google.nl/maps/dir/WestCord+Hotel+Delft,+Olof+Palmestraat,+Delft/Fox-IT,+Olof+Palmestraat,+Delft/@52.0122377,4.3780805,18z/data=!3m2!4b1!5s0x47c5b5c0c25b354b:0x93ba42de4fd604fc!4m14!4m13!1m5!1m1!1s0x47c5b5f13b7c9c69:0x1d6d450585fd0a7c!2m2!1d4.3809835!2d52.010918!1m5!1m1!1s0x47c5b5f014b95e5b:0x7c7f292b6cd82270!2m2!1d4.3774843!2d52.0135541!3e2). |
| + | |
| + | ## when? |
| + | |
| + | The hackathon will take place from Oct 9 (Friday), 2015 to Oct 11 (Sunday). |
| + | |
| + | ## food |
| + | |
| + | Fox-IT will provide for breakfast, lunch, coffee, soft drinks, etc. during daytime. |
| + | |
| + | ## what? |
| + | |
| + | So what is the goal of the Hackathon? |
| + | |
| + | * Meet in person, talk about things |
| + | * contributors agreement (CLA) for OpenVPN 3 |
| + | * future development of 2.x and 3.x |
| + | * Hack on the 2.4 codebase - there's a number of "large" things we could try to tackle |
| + | * new data packet format proposed for AEAD and "null-compression" |
| + | * openvpn interactive service - get code in git tree |
| + | * async plugin patch, inotify async auth patch (Lev) |
| + | * IPv6 gateway detection (rgi6)? |
| + | * how to handle servers with v4+v6 addresses and roaming clients (3G/wifi) that roam from between various brokenness variants, like "from v6+NAT64 3G to native v6 Wifi" or "to v4-only Wifi", etc. |
| + | * Go through the list of pending patches and ACK/NACK them or assign person to review them |
| + | * Work on open trac issues |
| + | * lots of things to review and bugs to fix |
| + | |
| + | We're all open for additions here - I think the meetings in Brussels and Munich 2013 + 2014 have shown that "just being able to sit together and hack" is a useful exercise. |
| + | |
| + | ## Internet |
| + | |
| + | A wireless guest network with internet access is available at the meeting location for sure. We will probably be able to throw a switch on the table for wired connections too (no promises yet). |
| + | |
| + | ## accommodation |
| + | |
| + | Most people stay at the [WestCord hotel](http://www.westcordhoteldelft.com/locations/delft): very close to the Fox-IT office |
| + | |
| + | Alternatively, you can opt for the slightly more expensive [Hampshire Hotel](http://www.hoteldelftcentre.nl/?lang=en): farther away from the office, but closer to downtown Delft. |
| + | |
| + | ## results |
| \ | No newline at end of file |
| /dev/null .. meetups/2016-helsinki.md | |
| @@ 0,0 1,78 @@ | |
| + | # OpenVPN Hackathon 2016 |
| + | |
| + | ## who |
| + | This year's hackathon is organized by Lev Stipakov (lev__). |
| + | |
| + | We will stick to the format of the previous years, which means attendance is in principle limited to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". We should have enough space in the meeting room for ~10 devs. |
| + | |
| + | ## who is coming? |
| + | |
| + | | Name | Topics | Arrival | Departure | Hotel | |
| + | |------------------|-------------------------------------------------------------------|----------------------------------|----------------------------------|---------------------------------------| |
| + | | Lev Stipakov | - | Wed | Sun | Holiday Inn | |
| + | | David Sommerseth | query-user, systemd, d-bus, auth-token, fips | Thu Sept 15, 15:40 (Finnair 656) | Mon Sept 19, 12:15 (Finnair 655) | Radisson Blu Seaside Hotel (Ruoholahdenranta 3) | |
| + | | Arne Schwabe | MTU problems | Thu Sept 15, 15:10 AY0704 | Staying a bit longer to explore Helsinki | - | |
| + | | Steffan Karger | tls-crypt, user-specific tls-auth | Fri 13:20 (KLM1167) | Sun 18:15 (KLM1170) | Holiday Inn | |
| + | | Gert Döring | 2.4, testing | Fri 12:40 (LH2462) | Sun 19:25 (LH2465) | Holiday Inn | |
| + | | ~~Adriaan de Jong~~ | ... | ~~Fri 13:20 (KLM1167)~~ | ~~Sun 18:15 (KLM1170)~~ | ~~Holiday Inn~~ | |
| + | | Samuli Seppänen | OpenVPN 3.x | Thu 16:23 (train) | Mon | - | |
| + | | James Yonan | | Thu | Mon | Holiday Inn | |
| + | | Heiko Hund | | Thu. | Mon. | Scandic Grand Marina | |
| + | |
| + | ## where? |
| + | |
| + | The meeting is held at the office of F-Secure: [Tammasaarenkatu 7, Helsinki, Finland](https://www.google.fi/maps/place/Tammasaarenkatu+7,+00180+Helsinki/@60.1615776,24.904545,17z/data=!3m1!4b1!4m5!3m4!1s0x46920a4f3181845:0x49f2c671fe3f120b!8m2!3d60.1615749!4d24.9067337?hl=en). You will be given a temporary ID card at the front desk. |
| + | |
| + | Both Holiday Inn hotel and our office are easily reachable by public transport - there is a metro station Ruoholahti [a few hundred meters away](https://www.google.fi/maps/dir/Ruoholahden+metroasema,+Helsinki/Tammasaarenkatu+7,+00180+Helsinki/@60.1626167,24.9102654,17z/data=!4m14!4m13!1m5!1m1!1s0x46920a496884d6eb:0xa732d2873ace2091!2m2!1d24.9138961!2d60.1632683!1m5!1m1!1s0x46920a4f30181845:0x49f2c671fe3f120b!2m2!1d24.9067337!2d60.1615749!3e2?hl=en). From the Helsinki Vantaa Airport you could take a train to Helsinki Central Railway Station (Rautatientori) and from there 2 metro stops to Ruoholahti. |
| + | |
| + | If you have any questions - please contact Lev at +358 40 0453610. |
| + | |
| + | ## when? |
| + | |
| + | The hackathon will take place from Sep 16 (Friday), 2016 to Sep 18 (Sunday). |
| + | |
| + | ## what? |
| + | |
| + | So what is the goal of the Hackathon? |
| + | |
| + | - Introduce a IV_PROTO=3 and remove -master only but always there IV_xx? (every compression also as V2 version, IV_RGI6, IV_TCPNL (when implemented before 2.4)) |
| + | - Meet in person, talk about things |
| + | - Future development of 2.x and 3.x |
| + | - Hack on the 2.4 codebase - there's a number of "large" things we could try to tackle |
| + | - Support for negotiable ciphers and "null-compression" |
| + | - Support for control channel encryption ('tls-crypt') and user-specific tls-auth ('tls-cookie') |
| + | - How to handle servers with v4+v6 addresses and roaming clients (3G/wifi) that roam from between various brokenness variants, like "from v6+NAT64 3G to native v6 Wifi" or "to v4-only Wifi", etc. |
| + | - Go through the list of pending patches and ACK/NACK them or assign person to review them |
| + | - Work on open trac issues |
| + | - Lots of things to review and bugs to fix |
| + | - OpenVPN 3 |
| + | - Release the tap-windows6 header file additionally under the MIT license |
| + | - This originated from Thermi of the Freeswan project |
| + | - It was agreed that this is a reasonable request |
| + | |
| + | We're all open for additions here - I think the meetings in Brussels (2011+2012), Munich (2013+2014) and Delft (2015) have shown that "just being able to sit together and hack" is a useful exercise. |
| + | |
| + | ## Internet |
| + | |
| + | Free Wifi is available. |
| + | |
| + | ## accommodation |
| + | |
| + | Probably the closest hotel is [Holiday Inn Ruoholahti](http://www.booking.com/hotel/fi/hoildayinncitywest.html). |
| + | |
| + | ## results |
| + | |
| + | - OpenVPN 3 |
| + | - Released to [GitHub](https://github.com/OpenVPN/openvpn3) |
| + | - Contributor Agreement. Discussed a draft for a contributor agreement to the OpenVPN 3 code base. It is based on the [DCO](http://www.developercertificate.org/) which is used by the Linux kernel as well as several other projects, but it has an extension to allow OpenVPN Technologies to re-license contributions, but also includes a promise that OpenVPN Technologies, Inc will share any changes to said contributions. Dazo will reach out to some contacts with legal expertise so OpenVPN Technologies can get a proper legal review on this agreement. |
| + | - OpenVPN 3 walk through - James did a couple of sessions walking through parts of the OpenVPN 3 code base. |
| + | - OpenVPN 2.4 |
| + | - A semi-automated Windows test script was created. This will give us more confidence in the Windows code before making the alpha1 release. |
| + | - Discussed adding server-side support to OpenVPN 3. Even though OpenVPN 3 codebase would be much easier to work with than OpenVPN 2's codebase, adding server support would be a significant effort. |
| + | - Many Trac tickets were resolved or closed |
| + | - Buildbot setup was improved significantly, with the addition of a MacOS X buildslave and general fixes and cleanups. That said, many buildslaves require exceptions in various parts, so further refactoring and cleanup might be in order. |
| + | - D-Bus integration in OpenVPN 2.x and 3.x |
| + | - cron2: "Resistance is futile". |
| + | - This adds interesting possibilities and it makes sense for OpenVPN 3 code base. However, there are concerns about the complexity of adding it to the current OpenVPN 2 code base. There are also some concerns that this will primarily be used on Linux only, as many *BSD installs do not install D-Bus packages. |
| + | - Next year hackathon's |
| + | - We discussed the location. One option would be [Karlsruhe](https://en.wikipedia.org/wiki/Karlsruhe) in Germany, as Sophos has an office there and Heiko works there. Another option would be to meet in the United States; cost-wise areas near the major airports with direct flights from Europe (Chicago or New York) would be best. |
| \ | No newline at end of file |
| /dev/null .. meetups/2018-lviv.md | |
| @@ 0,0 1,163 @@ | |
| + | # OpenVPN Hackathon 2018 |
| + | |
| + | This year's hackathon is organized by Andriy Revin and David Sommerseth |
| + | |
| + | We will stick to the format of the previous years, which means attendance is in principle limited to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". We should have enough space in the meeting room for 10-14 devs. |
| + | |
| + | ## Who is coming? |
| + | |
| + | | Name | Topics | Arrival | Departure | Hotel | |
| + | |------|--------|---------|-----------|-------| |
| + | | Andriy Revin | - | - | - | @home | |
| + | | David Sommerseth | clean-ups, plug-ins, OpenVPN 3 client | Thu evening (LO482/LO763) | Tue (LO766/LO483) | Ibis | |
| + | | Antonio Quartulli | remaining IPv6-only work, VLAN patches, netlink, multi-socket/multi-protocol, transport API(?) | Fri | Tue | Ibis | |
| + | | Steffan Karger | Performance, clean ups, crypto stuff | Thu (OS381, ETA 15:20 @ airport) | Sun | Ibis | |
| + | | Gert Döring | VLAN Patches / Architecture, Challenge / Plugin stuff, Performance (Threading?) | Fri (LH2550, ETA 11:30 @airport) | Mon (LH2551) | Ibis | |
| + | | Samuli Seppänen | Packaging (MSI, DEB, RPM), !HackerOne tuning | Fri late evening | Mon early morning | Ibis | |
| + | | James Yonan | - | - | - | - | |
| + | | Arne Schwabe | random stuff | Thu (LO410/LO765) | Tue (LO766/LO407) | Ibis | |
| + | | Johan Draaisma | things | 3 oct | 8 oct | somewhere | |
| + | | Lev Stipakov | things | Fri evening (TK443) | Tue | Ibis | |
| + | |
| + | ## Where? |
| + | |
| + | The meeting is held at the OpenVPN office in Lviv (Ukraine): [Shevchenka Ave 5](https://www.openstreetmap.org/search?query=49.83826%2C24.03129#map=19/49.83826/24.03129&layers=N). |
| + | |
| + | Lviv Danylo Halytskyi International Airport is quite close to the city. Best way of public transport is via Uber. |
| + | |
| + | If you have any questions - please contact Andriy Revin (andriy @ openvpn.net). |
| + | |
| + | ## When? |
| + | |
| + | The hackathon will take place from Friday October 5th 2018 to Sunday October 7th. |
| + | |
| + | ## What? |
| + | |
| + | 1. What features do we want in 2.5? Set the timeline accordingly. |
| + | - tls-crypt v2, sitnl, vlan patches, ipv6-only, transport plug-in? |
| + | - MSI packaging? |
| + | - EasyRSA 3 for Windows (NSIS/MSI) installers? |
| + | - **conclusion:** [check here](https://community.openvpn.net/openvpn/wiki/LvivHackathon2018#featuresin2.5thatwewant) |
| + | |
| + | 2. Should OpenVPN be a "swiss army knife" or "secure vpn client for dummies" |
| + | - Could the split between OpenVPN 2.x and 3.x reflect these two roles? |
| + | - **conclusion:** making OpenVPN 2.x a simple client for dummies is not a priority, but devs will try to reduce complexity by removing as many ifdefs as possible and by reviewing options whenever it is possible. |
| + | |
| + | 3. Feature changes |
| + | - Do we need `--opt-verify`? Is this a feature strictly needed these days? |
| + | - **conclusion:** check last item in the [2.5 discussion section](https://community.openvpn.net/openvpn/wiki/LvivHackathon2018#featuresin2.5thatwewant) |
| + | |
| + | 4. MSI packaging |
| + | - Available for testing for tap-windows6, but not yet for OpenVPN 2 |
| + | - **conclusion:** get MSI packaging working with 2.5 (NSIS will be dropped) |
| + | |
| + | ## Input |
| + | |
| + | TBD |
| + | |
| + | ## Internet |
| + | |
| + | Free wifi network is available at the office |
| + | |
| + | ## Accommodation |
| + | |
| + | There are many options with hotels and Airbnb alternatives in walking distance from the office (5-10 minutes). Most reasonably priced hotels are fairly small and availability is varying a lot, but double check against hotels.com, booking.com, trivago.com or similar sites to ensure you get a good price. |
| + | |
| + | Some hotels close by (4-8 minutes walk): |
| + | |
| + | | Hotel | URL | Comments | |
| + | |-------|-----|----------| |
| + | | Ibis Styles Lviv Center | [Link](https://www.accorhotels.com/gb/hotel-9709-ibis-styles-lviv-center/index.shtml) | Most likely one of the bigger ones, small rooms but decent | |
| + | | Swiss Hotel | [Link](http://swiss-hotel.lviv.ua/en/) | Reasonable hotel when getting good price offers | |
| + | | ANTARES Apart hotel | [Link](https://antares-apart.com.ua/en/) | - | |
| + | | Danylo Inn | [Link](http://www.danyloinn.com/) | - | |
| + | |
| + | ## Results |
| + | |
| + | (informal notes on some of the discussions that benefit from writing down) |
| + | |
| + | ### 2.4.7 |
| + | |
| + | - We need to do a 2.4.7 release "soonish", to fix the `--opt-verify` issue Lev and Johan have encountered with NCP (patch has been merged in master+release/2.4). |
| + | - We want the "asymmetric compression" change from Arne in there. |
| + | - The `--allow-compression` option will be added which forcefully allows the local side to send compressed data. The current patch will be updated to **not** allow this new option to be pushable. We will require this to be explicitly set in the configuration file on both sides to enable compression. |
| + | - 2.4.7 will be initially released with the old TAP6 driver, and then we can do a re-release with the new TAP6 driver after sufficient testing (when our new approach can get all testing/signing issues fixed, estimated ~4-6 weeks). |
| + | - TLS1.3 related patches are acceptable for 2.4.7 if they do not change existing behavior (unless you use `--tls-ciphersuite`). |
| + | |
| + | ### T-Shirts |
| + | |
| + | - are buggy |
| + | - 30 day refund policy |
| + | |
| + | ### features in 2.5 that we want |
| + | |
| + | The following is what was discussed in terms of "2.5 release" during the hackathon, but for a more schematic status report about 2.5, please check [this link](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn25) |
| + | |
| + | - we have a page in the wiki so people can read up on this |
| + | - MSI packaging (Simon, Samuli) //must have// |
| + | - tls-cryptv2 //must have// |
| + | - Antonio is reviewing, goal: this weekend |
| + | - IPv6-only //really nice to have// |
| + | - client side is already finished(!) |
| + | - server side needs brains to closely check disentanglement of ipv4/ipv6 server pools for unexpected side effects |
| + | - Gert needs to finish review and test bed |
| + | - netlink / sitnl refactoring of tun.c, route.c //must have/ |
| + | - Arne volunteers to review, but is entangled in ipv6-only changes (so might need rebasing) -> Antonio to check |
| + | - code is there, but needs better coordination |
| + | - blocker |
| + | - transport plugin (obfuscation or others) //nice to have// |
| + | - operator foundation, founded by google |
| + | - coordinating with Antonio |
| + | - patches based on 2.4 - asked to rebase on master |
| + | - "nice to have"? |
| + | - "make VPN fast again" (Antonio) - //nice to have// |
| + | - split control/data channel -> separate threads |
| + | - "client connect" activity will no longer interfere with "forwarding packets for other clients" |
| + | - going from there to multiple workers for data channel |
| + | - "all the complicated event handling" -> control thread |
| + | - send/receive multi-messages |
| + | - use tun driver more efficiently |
| + | - tap6 on server 2016 - maybe slow because driver reports attributes wrongly? |
| + | - initial connect speed of 2.x clients compared to 3.x clients |
| + | - there is one "1 second" coarse timer left in the 2.x code base |
| + | - Gert and Steffan did not dare to remove this one yet |
| + | - OpenVPN3 offload API? |
| + | - ongoing activity... |
| + | - VLAN patchset //must have// |
| + | - Antonio volunteers to rebase + adjust the code to master |
| + | - Arne volunteers to review |
| + | - Gert to build test infrastructure |
| + | - David: suggest to checkout the code tree "right before the uncrustify changes", apply Fabian's v2 patch set, and proceed from there |
| + | - asynchronous client-connect (?) patchset from Fabian Kittel - //must have// |
| + | - Gert/Arne/Antonio |
| + | - multi-listen / multi-port / multi-ip patch set |
| + | - multi-port is done, with multi-ip (if same protocol) (first chunk) "in beta" //must have// |
| + | - multi-protocol (TCP+UDP) "not even alpha" //postpone to 2.6, too early code// |
| + | - Arne feels like he needs to review this |
| + | - dynamic-route (routes in CCD/) |
| + | - today: OpenVPN only adds route at startup |
| + | - adding routes at client-connect time needs to be done "outside" |
| + | - //nice to have(!!)// - it can be done with `--client-connect` or in plugin code - but easier debugged if "built in" |
| + | - enable `--enable-async-push` by default |
| + | - it is tested fairly well now |
| + | - get rid of extra #ifdef |
| + | - cross-platform - today this depends on inotify, which is not available on most platforms we support (Linux, maybe FreeBSD, nothing else) |
| + | - David pushed out a new build enabling this by default for [Fedora Rawhide](https://koji.fedoraproject.org/koji/buildinfo?buildID=1150556) (future Fedora 30) and [Fedora 29](https://bodhi.fedoraproject.org/updates/openvpn-2.4.6-3.fc29) |
| + | - OpenSolaris: fix fragment handling for IPv4 - ***done*** |
| + | - IPv6 fragments over tun work, IPv4 fragments not |
| + | - not an OpenVPN problem, but combination of OpenSolaris, FreeBSD pf(4) and `scrub in all` without the `no-df` flag triggered this |
| + | - AIX: tunnel emulation //nice to have// |
| + | - AIX has no tun interface, only tap |
| + | - to talk to "have no tap interface, only tun" peers, one side needs to emulate |
| + | - AIX code nearly done, waiting for ICMPv6 generation code in OpenVPN 2.x code to show up (block-ipv6 v4) |
| + | - `--opt-verify` handling |
| + | - remove it from the AS config default ("it breaks clients") |
| + | - the way it is now is not really needed anymore - most option mismatches can be pushed from the server, except for the caveats... |
| + | - make all the `--*mtu*` things pushable (not easy: reallocation of buffers needed) |
| + | - include "more sane ciphers" in the default NCP cipherlist (Arne, Steffan) |
| + | - what else? |
| + | |
| + | ### features we want in 2.6 |
| + | - asynchronous netlink (= do not block waiting for kernel ACK) |
| + | - performance enhancements on multi-CPU machines |
| + | - multithreading? Do we want to just go for 3.0 here? |
| \ | No newline at end of file |
| /dev/null .. meetups/2019-trento.md | |
| @@ 0,0 1,129 @@ | |
| + | # OpenVPN Hackathon 2019 |
| + | |
| + | This year's hackathon is organized by Antonio Quartulli |
| + | |
| + | We will stick to the format of the previous years, which means attendance is in principle limited to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". We should have enough space in the meeting room for 10-14 devs. |
| + | |
| + | ## Who is coming? |
| + | |
| + | | Name | Topics | Arrival | Departure | Hotel | |
| + | |-------------------|-------------------|--------------------------|---------------------|----------------------| |
| + | | Antonio Quartulli | - | - | - | @home | |
| + | | Gert Döring | devel process, networking | Friday about 14:30 | Sunday afternoon-ish | Albergo Accademia | |
| + | | David Sommerseth | * | Friday morning | Sunday afternoon | Albergo Accademia | |
| + | | Arne Schwabe | * | Friday morning | Sunday afternoon | Albergo Accademia | |
| + | | Steffan Karger | - | Friday afternoon | Monday afternoon | Albergo Accademia | |
| + | | Simon Rozman | - | Friday noonish | Sunday afternoon | Albergo Accademia | |
| + | | Lev Stipakov | - | Friday morning | Sunday afternoon | Albergo Accademia | |
| + | | Uipko Berghuis | - | Friday afternoon | Monday afternoon | Albergo Accademia | |
| + | | Samuli Seppänen | - | Thursday late evening | Sunday | Albergo Accademia | |
| + | | ~~Jan Just Keijser~~ | - | ~~Friday noonish~~ | ~~Sunday noon~~ | ~~NH Trento~~ | |
| + | | Johan Draaisma | - | yes | yes | amazing place | |
| + | |
| + | ## When? |
| + | |
| + | The hackathon will take place from Friday November 8th 2019 to Sunday November 10th. |
| + | |
| + | ## Where? |
| + | |
| + | The Hackathon will be held in a meeting room fully reserved for us with 24h access (as long as I am around) within the "Impact Hub Trentino" co-working space. |
| + | Full address: [Via Roberto da Sanseverino, 95 - Trento - Italy](https://www.openstreetmap.org/way/71520579) |
| + | "Impact Hub Trentino" is a co-working space in Trento, North-Eastern Italy and it is part of an international network of co-working spaces. |
| + | Some of you may have already heard about the "Impact Hub" brand. |
| + | |
| + | The co-working space provides free wifi, a pantry, and some vending machines. |
| + | There is no "free food", but I'll see if I can arrange some basic catering for the event. |
| + | |
| + | The venue is conveniently located nearby the city center which translates to several accommodations and restaurants in range. |
| + | |
| + | ### Entrance to the venue |
| + | |
| + | Our meeting room is outside of the main building, therefore it can be reached by crossing the parking lot (green route). |
| + | This route can be taken on Friday, when the ImpactHub (and the parking lot) is open. |
| + | |
| + | On Saturday/Sunday the parking lot will be closed, therefore you have to enter from the main building (red route) cross it all and then exit on the other side. |
| + | The main building might stay locked during the weekend, therefore if you arrive at a $random time, please drop me a message so that I can come and open :-) |
| + | |
| + |  |
| + | |
| + | ### City |
| + | |
| + | By Italian standards Trento is a small but very nice and safe city. It hosts a university with around 17k students, who contribute to the good feeling and vibe. |
| + | The city is surrounded by amazing mountains which offer incredible landscapes and are absolutely easy to reach (even for day trips). |
| + | |
| + | The city center is fairly small and you can visit it all by foot. |
| + | Tickets for local trains and buses to go around the area can be purchased online with the OpenMove app (so no need to fiddle with vending machines or ticket offices). |
| + | |
| + | ### How to get there |
| + | |
| + | - **By air**: Trento does not have its own commercial airport. The closest airport is Verona (VRN) - 96km/1h by car - which is small, but connected to a couple of hubs in Europe (i.e. flying Lufthansa or Alitalia). Flying to Venice (VCE), Bergamo (BGY) or Bologna (BLQ) is also an option, but the commute to Trento is longer. Flying to Innsbruck (Austria) may also be feasible, but it's still quite far. If you land in Verona, you can take a direct bus to the train station "Verona Porta Nuova" (the bus is just outside the arrival area) and then catch a train to "Trento" from there. |
| + | |
| + | - **By train**: Trento train station is in the center of the city and quite close to the venue. Several trains stop there (also Deutsche Bahn trains). The major railway company in Italy can be found at [trenitalia.com](https://www.trenitalia.com/en.html) - station name is just "Trento". |
| + | |
| + | - **By Car**: Trento sits next to the A22 motorway, which connects the city center to the various airports, the rest of Italy, and Austria/Germany. |
| + | |
| + | |
| + | If you have any questions - please contact Antonio Quartulli (antonio @ openvpn.net). |
| + | |
| + | ## What? |
| + | |
| + | - **man page** |
| + | - Currently formatted in groff (nroff supported too?), which is a cumbersome format for humans to edit. |
| + | - OpenVPN 3 Linux decided to use [rst2man](http://docutils.sourceforge.net/docs/user/rst/quickstart.html), which converts [.rst files](https://github.com/OpenVPN/openvpn3-linux/tree/master/docs/man/) to man pages with quite good results. It can also produce other formats as well, such as HTML, XML, LaTeX, ODT. |
| + | - Downside: rst2man is a Python utility |
| + | - Upside: Much easier to write man pages where even the [source file is readable](https://raw.githubusercontent.com/OpenVPN/openvpn3-linux/master/docs/man/openvpn2.1.rst). |
| + | - There might be other tools similar to rst2man, which does not require Python. |
| + | - **Getting 2.5 out** |
| + | - test + merge the VLAN patchset (cron2/ordex) |
| + | - review and ACK the client-connect patchset (ordex/plaisthos) |
| + | - **networking topics** |
| + | - ipv6-only (client side) for 2.4 (cron2/ordex) |
| + | - get rid of "broadcast" ifconfig setting (cron2/ordex, /31 thread) |
| + | - **test framework** |
| + | - t_client "this address MUST NOT ping after the VPN is up" (client isolation testing with vlan patchset) |
| + | - **management API, external keys, TLS 1.3 / OpenSSL 1.1.1** |
| + | - patch from Arne |
| + | - **Two-Factor-Auth Patchset in trac** |
| + | - what, why, how? sample config? |
| + | - get merged (dazo/plaisthos) |
| + | - (...more.topics...) |
| + | |
| + | ## Internet |
| + | |
| + | Free wifi network is available at the venue |
| + | |
| + | ## Accommodation |
| + | |
| + | These are some accommodations Antonio has picked among those in the surroundings of the venue: |
| + | |
| + | | Name | Type | Price (1p, 3nights) | Distance from Impact Hub (Venue) | Distance from Piazza Duomo (Main square) | |
| + | |--------------------------------|------------|---------------------|----------------------------------|-----------------------------------------| |
| + | | **The Closest to the Impact Hub** | | | | | |
| + | | NH Trento | Hotel | 155,00€ | 350m | 1.3km | |
| + | | Komodo Apartments | Residence | 153,00€ | 400m | 1.3km | |
| + | | Bed & go Trento | B&B | 198,00€ | 450m | 1.2km | |
| + | | **The Cheapest** | | | | | |
| + | | International Youth Hostel 'Giovane Europa' | Hostel | 80,00€ | 1.6km | 400m | |
| + | | **City Center Accomodations** | | | | | |
| + | | Albergo Accademia | Hotel | 151,00€ | 1.7km | 200m | |
| + | | Al Cavour 34 | B&B | 136,00€ | 1.6km | 100m | |
| + | | B&B al Palazzo Malfatti | B&B | 163,00€ | 1.6km | 100m | |
| + | | Torrione Trento | Guesthouse | 171,00€ | 1.5km | 300m | |
| + | |
| + | Most of the above can be found on booking.com. |
| + | Many more options are available also on airbnb.com or the portal of your choice. |
| + | |
| + | ## Results |
| + | |
| + | ### The way forward for NCP |
| + | |
| + | Arne and Steffan discussed, concluded: |
| + | 1. It's time to implement actual negotiation. Would be nice to get into 2.5, but will not block a 2.5 release. |
| + | 2. Client will still send `IV_NCP=2`, but add `IV_NCP_CIPHERS=<colon-separated-cipher-list>` (e.g. `IV_NCP_CIPHERS=AES-256-GCM:AES-128-GCM`) |
| + | 3. Server will select a cipher based on the server cipher lists preferences. I.e. the server will push the first cipher in its local `--ncp-ciphers` list that's also listed in the client's `IV_NCP_CIPHERS`. |
| + | 4. For now, both client and server remain required to support `AES-128-GCM` and `AES-256-GCM` to do NCP. |
| + | 5. At some point, the client will no longer send `IV_NCP`, but just `IV_NCP_CIPHERS`. From then on, supporting the AES-GCM ciphers is no longer needed. |
| + | |
| + | ## Recap |
| + | |
| + | [https://openvpn.net/openvpn-hackathon-2019/](https://openvpn.net/openvpn-hackathon-2019/) |
| \ | No newline at end of file |
| /dev/null .. meetups/2021-munich.md | |
| @@ 0,0 1,101 @@ | |
| + | # OpenVPN Hackathon 2021 |
| + | |
| + | This year's hackathon is jointly organized by Gert Döring (community part) and Arne Schwabe (closed part). |
| + | |
| + | We will stick to the format of the previous years, which means attendance is in principle limited to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". We have enough space in the meeting room for 20 devs (covid19 restrictions, the room is much bigger). |
| + | |
| + | Full vaccination against covid19 is required. |
| + | |
| + | Please also read the border entry regulations from German government at: |
| + | - [FAQ Tests Einreisende Englisch](https://www.bundesgesundheitsministerium.de/coronavirus-infos-reisende/faq-tests-einreisende-englisch.html) |
| + | - [Risikogebiete Neu](https://www.rki.de/DE/Content/InfAZ/N/Neuartiges_Coronavirus/Risikogebiete_neu.html) |
| + | |
| + | tl;dr: you have to pre-register if traveling from a high risk area and basically always have to be vaccinated |
| + | |
| + | ## Who is coming? |
| + | |
| + | Proposed T-shirt designs were [here](https://build.openvpn.net/downloads/temp/hackathon-ideas.jpg). The top left design was chosen. |
| + | |
| + | | **Name** | **Topics** | **Arrival** | **Departure** | **Hotel** | **T-shirt size** | **Preferred T-shirt design** | |
| + | |------------------|---------------------------------|-----------------------------|----------------------------|----------------|------------------|------------------------------| |
| + | | Gert Döring | - | 5 November, Friday, early morning | 7 November, Sunday, late evening | @home | XL | it must be black! And then 'top left' | |
| + | | Heiko Hund | - | 2 November, Tuesday, 11:00 | 7 November, Sunday, 18:00 | Bold Giesing | XL | Top or bottom left | |
| + | | Samuli Seppänen | - | | | | L | Top right | |
| + | | Johan Draaisma | DNS | 2 November, Tuesday, 12:00 | 7 November, Sunday, 16:00 | tbd | XL | Top left, shirt just like in pic | |
| + | | David Sommerseth | - | 2 November, Tuesday, 11:00 | 7 November, Sunday, 14:00 | Bold Giesing | XL | Top or bottom left | |
| + | | Kyryl Tumanov | - | 1 November, Monday, 15:00 | 7 November, Sunday, 12:00 | Bold Giesing | M or L.. probably L | |
| + | | Frank Lichtenheld | - | 2 November, Tuesday, 11:00 | 7 November, Sunday, 18:00 | Bold Giesing | XL | Top Left | |
| + | | James Yonan | - | 1 November, Monday, --:-- | 7 November, Sunday, --:-- | Bold Giesing | XL | | |
| + | | Lev Stipakov | - | 1 November, Monday, 18:00 | 7 November, Sunday, 18:00 | Bold Giesing | M | | |
| + | | Jeff Lucovsky | - | 1 November, Monday, 11:00 | 8 November, Monday, 07:00 | Bold Giesing | XL | Top left | |
| + | | Steffan Karger | - | 4 November, Thursday, 22:30 | 7 November, Sunday, 12:00 | Bold Giesing | L (sent) | | |
| + | | Jan Just Keijser | - | 5 November, Friday, 12:40 | 7 November, Sunday, 21:00 | Bold Giesing | M (via syzzer) | Top left | |
| + | | Arne Schwabe | - | 1 November, Monday | 8 November, Monday, 11:00 | Bold Giesing | XXL | Top left, then bottom left| |
| + | | Mark Deric | - | 1 November, Monday, 13:30 | 8 November, Monday, 11:55 | Bold Giesing | XL, XXL if EU sourced | Top left | |
| + | | Max Fillinger | mbedTLS 3.0 support (?) | 4 November, Thursday, 18:10 | 8 November, Monday, 12:00 | Bold Giesing | XL (via syzzer) | | |
| + | | Antonio Quartulli| - | not coming | but I still want a shirt! | home | M | Top left | |
| + | | Selva Nair | | not coming | me too would like one | | M | --- | |
| + | | wiscii | | not coming | Please and thanks | | L | Top right | |
| + | | Pippin | | not coming | would also like one | Netherlands | M (via syzzer) | Top left | |
| + | | themiron | | not coming | would be great to have one | Russia | M | Top middle, then top right | |
| + | |
| + | The original Doodle participation poll was [here](https://doodle.com/poll/ac9dbsqwd8ftkqup). |
| + | |
| + | ## When? |
| + | |
| + | The hackathon will take place from Tuesday November 2nd 2021 to Sunday November 7th. Tue-Thu is restricted to "OpenVPN Inc" employees, Fri-Sun is open. |
| + | |
| + | ## Where? |
| + | |
| + | The Hackathon takes space in the "area 42" meeting area of QAWARE Munich ([QAWARE Website](http://www.qaware.de)). QAWARE is a software / cloud centric company that uses lots of Open Source and sponsors the room, coffee, tea and soft drinks to "give back to the community" (much appreciated!). |
| + | |
| + | The venue is located south of the Munich city centre, easily reached by public transport, and there are Hotels nearby. Food can be found in the QAWARE cantina, or in walking distance. |
| + | |
| + | ### Entrance to the venue |
| + | |
| + | Arne will be there Tuesday morning and has the contact data for qaware. So all Corp people, please coordinate with Arne. |
| + | |
| + | Gert will be there Friday morning. If you want to attend and have questions, contact me on gert@greenie.muc.de or +49 177 2160221 (mobile / whatsapp / signal) or +49 89 35655024 (wired). Or cron2 on IRC. |
| + | |
| + | ### City |
| + | |
| + | (Details to come) |
| + | |
| + | ### How to get there |
| + | |
| + | The Hackathon is taking place at QAware, Aschauer Str. 32, 81549 München |
| + | |
| + | The closest public transport stop is "Giesing", for both U-Bahn and S-Bahn. From there it is just a few hundred meters walking distance. |
| + | |
| + | To get there from the airport takes ~50 minutes, from the central train station ~10 minutes. |
| + | |
| + | You can plan your trip on the MVV website: [MVV Munich](https://efa.mvv-muenchen.de/) |
| + | |
| + | ## What? |
| + | |
| + | - Getting 2.6 out |
| + | - test + merge the DCO patchset (cron2/ordex) |
| + | - networking topics |
| + | - get rid of "broadcast" ifconfig setting (cron2/ordex, /31 thread) |
| + | - cleanup tun.c, route.c |
| + | - DNS configuration (--dhcp-options DOMAIN/DOMAIN-SEARCH/ADAPTER_DOMAIN_SUFFIX) |
| + | - test framework |
| + | - t_client "this address MUST NOT ping after the VPN is up" (client isolation testing with vlan patchset) |
| + | - testing management API |
| + | - (...more.topics...) |
| + | |
| + | ## Internet |
| + | |
| + | Free wifi network is available at the venue |
| + | |
| + | ## Accommodation |
| + | |
| + | (Details to come) |
| + | |
| + | | Name | Type | Price (1p, 1night) | Distance from QAWARE (Venue) | Distance from Marienplatz (city centre) | |
| + | |------|------|--------------------|------------------------------|-----------------------------------------| |
| + | | [Bold Giesing](https://bold-hotels.com/en/hotels/bold-munich-giesing/) | Hotel | ~80 € incl. Brkfst | 100 m | 5 km | |
| + | |
| + | ## Results |
| + | |
| + | ## Recap |
| \ | No newline at end of file |
| /dev/null .. meetups/2022-delft.md | |
| @@ 0,0 1,73 @@ | |
| + | # OpenVPN Hackathon 2022 |
| + | |
| + | This year's hackathon is organized by Max Fillinger. |
| + | |
| + | ## Who is coming? |
| + | |
| + | | **Name** | **Topics** | **Arrival** | **Departure** | **Hotel** | |
| + | |-------------------|----------------------------------------|------------------------------|-----------------------------|----------------| |
| + | | Heiko Hund | Modernize code contribution and review | 25 November, Friday, 12:00 | 27 November, Sunday, 18:00 | WestCord Hotel | |
| + | | Antonio Quartulli | Structure feature planning/collection | 25 November, Friday | 27 November, Sunday | WestCord Hotel | |
| + | | Max Fillinger | - | Already there | - | Home | |
| + | | Johan Draaisma | AS and DCO | 24 November, Thursday, 17:00 | 28 November, Monday, 13:00 | WestCord Hotel | |
| + | | Lev Stipakov | dco-win and Windows TA | 24 November, Thursday, 20:00 | 28 November, Monday, 9:00 | WestCord Hotel | |
| + | | Samuli Seppänen | - | 24 November, Thursday, 20:00 | 28 November, Monday, 9:00 | WestCord Hotel | |
| + | | Gert Döring | IPv6 to community, automated testing | 25 November, Friday | 27 November, Sunday | WestCord Hotel | |
| + | | Frank Lichtenheld | Windows automated testing | 24 November, Thursday, 18:00 | 27 November, Sunday, 17:00 | WestCord Hotel | |
| + | | Kristof Provost | FreeBSD DCO | 25 November, Friday | 27 November, Sunday | WestCord Hotel | |
| + | | Arne Schwabe | - | 24 November, 17:00 | 28 November, 9:00 | WestCord Hotel | |
| + | | Steffan Karger | Testing | Already there | - | Home | |
| + | |
| + | The original Doodle participation poll was [here](https://doodle.com/meeting/participate/id/dRgEwERe/vote). |
| + | |
| + | ## When? |
| + | |
| + | The hackathon will take place from Friday November 25th 2022 to Sunday November 27th. |
| + | |
| + | ## Where? |
| + | |
| + | The Hackathon takes place at Fox IT in Delft, Netherlands. |
| + | Most people stay at the WestCord Hotel, which is located closest to Fox IT. |
| + | |
| + | ### Entrance to the venue |
| + | |
| + | From the hotel, follow the road left in front of the IKEA. You should see the Fox-IT logo. The address is Olof Palmestraat 6. You're welcome from 9:30 to 18:00. **Please bring an ID card, you're not allowed to enter without.** |
| + | |
| + | On Friday, you can just ring the bell tell the reception that you're here for the OpenVPN hackathon and to get Maximilian Fillinger. I'll also be at the entrance in the morning. |
| + | |
| + | In the weekend, we're opening the office at 9:30. If you come later, call Max at +31 644932753. |
| + | |
| + | ### City |
| + | |
| + | (Details to come) |
| + | |
| + | ### How to get there |
| + | |
| + | If you arrive via Shithole Airport, there's a trainstation in the basement of the airport's main plaza that you can take to Delft trainstation. It usually leaves platform 6. In the plaza there are ticket machines in English that you can use to purchase a ticket easily to take you to Delft with a transfer at Leiden. Usually takes about half an hour to an hour depending on whether you get the fast train or the one that stops everywhere, and depends also on your transfer connection. You can check [NS Journey Planner](https://www.ns.nl/en/journeyplanner/#/) to plan your journey and get details. |
| + | |
| + | Public transport works with cards that you get printed at the ticket machine and you hold in front of a column intended for it to check-in and check-out (RFID). Or via subscriptions on a more long-term pass. Just buying one-way tickets should be just fine, just remember to check-in by holding it against one of the NS check-in columns on the plaza before you go down the escalators to the platforms. Check-out usually doesn't matter much with a one-way ticket unless you're at a station where they won't let you out without checking out at one of the gates. |
| + | |
| + | Johan Draaisma will be in Delft with his car and can be a taxi driver to get you from train station to hotel. Most guys from OpenVPN community already have his phone number and signal contact. |
| + | |
| + | ## What? |
| + | * Discuss change to GPL2+ or/add add something to be compatible with Apache2. |
| + | |
| + | ## Internet |
| + | |
| + | ... |
| + | |
| + | ## Accommodation |
| + | |
| + | | Name | Type | Price (1p, 1night) | Distance from Fox IT (Venue) | Distance from city | |
| + | |---------------------------------------|------------------|--------------------|------------------------------|--------------------| |
| + | | WestCord Hotel Delft (aka IKEA hotel) | Hotel | 120 Euro | 400m | 2km | |
| + | | Hampshire Hotel Delft | Hotel | 108 Euro | 1km | 650m | |
| + | | Bed&Breakfast Gasthuis288 | Bed and Breakfast| 95 Euro | 600m | 1.6km | |
| + | | Shanghai Hotel Holland | Hotel | 86 Euro | 2km | 2km | |
| + | | Campanile Delft | Hotel | 72 Euro | 2km | 2km | |
| + | |
| + | There are several more hotels in the 90-120 Euro range near the city center (1.6km to Fox-IT). The above are the closest and cheapest I could find at the moment. So far, most attendees have chosen to stay at the WestCord. |
| + | |
| + | ## Results |
| + | |
| + | ## Recap |
| \ | No newline at end of file |
| meetups/communitymeetup2024.md .. meetups/2024-karlsruhe.md | |
| /dev/null .. meetups/2025-naples.md | |
| @@ 0,0 1,13 @@ | |
| + | # OpenVPN Community Meetup 2025 |
| + | |
| + | [TOC] |
| + | |
| + | ## Dates |
| + | |
| + | To be determined by availability of people, using nuudle poll: |
| + | |
| + | [https://nuudel.digitalcourage.de/NROHeFlkfaYnoNGC](https://nuudel.digitalcourage.de/NROHeFlkfaYnoNGC) |
| + | |
| + | ## Location |
| + | |
| + | Somewhere in Napoli, Italy. |
| \ | No newline at end of file |
