Commit a0aa83

2026-01-15 18:06:38 uddr: 2.7-rc5-I013
ReleaseHistory.md ..
@@ 1,3 1,75 @@
+ ## OpenVPN 2.7_rc5 -- Released 15 January 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.7_rc5. This is the fifth release candidate for the feature release 2.7.0.
+
+ Security fixes:
+ * [CVE-2025-15497](https://www.cve.org/CVERecord?id=CVE-2025-15497): in epoch key handling (an authenticated remote system
+ can send a valid OpenVPN data packet that triggers an edge case
+ where a too-strict check would trigger an ASSERT(), exiting OpenVPN)
+
+ Important bug fixes since 2.7_rc4:
+ * remove "resolve --remote on incoming TCP connects on --tcp-server"
+ code base, because that did not work in a long time (since 2.4) and
+ is seen as too obscure and too complicated to rescue.
+ * repair interaction between DCO and persist-tun after reconnection
+ (in this case the client side would fail to set up the DCO event
+ handler, and not notice further --ping timeouts - GH: #947)
+ * remove ENABLE_X509ALTUSERNAME conditional, always enabling
+ "configure --enable-x509-alt-username". Effectively no change in
+ code size, and one less build variant to maintain and test (GH: [OpenVPN/openvpn#917](https://github.com/OpenVPN/openvpn/issues/917)).
+ * require "script-security 2" when using `--dev unix:<program>`
+ * socks client: fix and improve various code parts
+ * configure etc: drop support for systemd 216 and older, adapt
+ other checks to reflect modern systemd setups
+ * fix unit test building with libcmocka 2.0+
+ * fix Android build warnings about unused variables/methods
+ * allow --test-crypto to run without --secret
+ (prepare for removal of --secret after 2.7)
+ * improve WolfSSL build compatibility
+
+ For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc4...v2.7_rc5).
+
+ Highlights of 2.7 include:
+ * Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
+ * Improved Client support for DNS options
+ * Client implementations for Linux/BSD/macOS, included with the default install
+ * New client implementation for Windows, adding support for features like split DNS and DNSSEC
+ * Architectural improvements on Windows
+ * The `block-local` flag is now enforced with WFP filters
+ * Windows network adapters are now generated on demand
+ * Windows automatic service now runs as an unpriviledged user
+ * Support for server mode in win-dco driver
+ * Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
+ * Improved data channel
+ * Enforcement of AES-GCM usage limit
+ * Epoch data keys and packet format
+ * Support for new upstream DCO Linux kernel module
+ * This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
+ * Client-side support for new `PUSH_UPDATE` control-channel message
+ * This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
+ * PUSH_UPDATE server support (minimal)
+ * New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
+ * TLS 1.3 support with bleeding-edge mbedTLS versions
+ * Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
+ * Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
+ * "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
+ * COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc5/Changes.rst)
+
+ Windows MSI changes since 2.7_rc4:
+ * Built against OpenSSL 3.6.0
+ * Included openvpn-gui updated to 11.61.0.0
+ * Included win-dco driver updated to 2.8.0
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-amd64.msi.asc)|[OpenVPN-2.7_rc5-I013-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-arm64.msi.asc)|[OpenVPN-2.7_rc5-I013-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-x86.msi.asc)|[OpenVPN-2.7_rc5-I013-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc5.tar.gz.asc)|[openvpn-2.7_rc5.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc5.tar.gz)|
+
+ For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
+
## OpenVPN 2.7_rc4 -- Released 17 December 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_rc4. This is the fourth release candidate for the feature release 2.7.0.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9