Commit a75bb0

2025-01-29 07:33:21 Samuli Seppänen: Import last missing meetup pages Signed-off-by: Samuli Seppänen <samuli.seppanen@gmail.com>
/dev/null .. meetups/2017-karlsruhe.md
@@ 0,0 1,138 @@
+ # OpenVPN Hackathon 2017
+
+ ## who
+ This year's hackathon is organized by Heiko Hund (d12fk).
+
+ We will stick to the format of the previous years, which means attendance is in principle limited to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". We should have enough space in the meeting room for 16 devs.
+
+ ## who is coming?
+
+ | Name | Topics | Arrival | Departure | Hotel |
+ |-----------------|------------------------------------------|-----------------------|-------------------|-------------------|
+ | Heiko Hund | - | Fri. 10am | Sun. 20pm | @home |
+ | Antonio Quartulli | traffic manipulation API | Thu noon | Sun afternoon | Der Blaue Reiter |
+ | Samuli Seppänen | OpenVPN 3 development | Thu late evening | Sun mid-afternoon | Der Blaue Reiter |
+ | Steffan Karger | Post-quantum key exchange, performance | Fri 13:16 (Bhf Durlach)| Sun mid-afternoon | Blaue Reiter |
+ | Gert Döring | branch maintenance - what goes where, and why? | Fri noon-ish | Sun late afternoon| Blauer Reiter |
+ | Arne Schwabe | - | Fri 12 am at HBF | Sun late afternoon| Blauer Reiter |
+ | David Sommerseth| clean-ups, plug-ins, OpenVPN 3 client | Thursday evening | Sun afternoon | Blaue Reiter |
+ | Lev Stipakov | ovpn3 | Thu late evening | Sun mid-afternoon | Der Blaue Reiter |
+ | Jan Just Keijser| performance, EduVPN | Friday early afternoon| Sun late-afternoon| Der Blaue Reiter |
+ | Gert van Dijk | Post-quantum key exchange, documentation | Fri 13:16 (Bhf Durlach)| Sun mid-afternoon| Blaue Reiter |
+ | Johan Draaisma | Moral support | Thu noon-ish | Sun at noon | Der Blaue Reiter |
+ | James Yonan | | Thursday | - | - |
+ | Simon Rozman | eduVPN, MSI packaging | Thu late evening | Sun mid-afternoon | Der Blaue Reiter |
+ | François Kooman | eduVPN, OAuth | Thu afternoon | Mon | Der Blaue Reiter |
+
+ ## where?
+
+ The meeting is held at the Sophos office in Karlsruhe (Germany): [Sophos Office](https://osm.org/go/0DlEda7Ld?m=&node=2127345937).
+
+ Karlsruhe is an one hour ICE train ride away from Frankfurt Airport.
+
+ If you have any questions or got lost - please contact Heiko at +49 172 74 911 92.
+
+ ## when?
+
+ The hackathon will take place from Friday November 10th 2017 to Sunday November 12th.
+
+ ## what?
+
+ So what is the goal of the Hackathon?
+
+ - Should we get rid of LZ4 as bundled library and always rely on what the system has installed?
+ - Plan clean up route.c and tun.c - which approach should we use? Improve OS/distro modularization? Settle on an improved API?
+ - Add more topics here!
+
+ We're all open for additions here - I think the meetings in Brussels (2011+2012), Munich (2013+2014), Delft (2015) and Helsinki (2016) have shown that "just being able to sit together and hack" is a useful exercise.
+
+ ## input
+
+ There will be drinks and snacks to get us through the day. We have a kitchen, so you can also [make sandwiches](https://xkcd.com/149/) or a bowl of cereals. Chance of BBQ if there's demand in November.
+
+ ## internet
+
+ Free Wifi and wired network is available
+
+ ## accommodation
+
+ The closest Hotel is the "Der Blaue Reiter" just across the street.\
+ Cheapest accommodation is [IBIS budget](http://www.ibis.com/gb/hotel-3179-ibis-budget-karlsruhe/index.shtml) a good 10 minute walk away.
+
+ ## results
+
+ (informal notes on some of the discussions that benefit from writing down)
+
+ ### MSI
+ - TAP-Windows driver:
+ - MSI (and MSM) packages are to be built on Windows using WiX Toolset.
+ - Test certificates are injected prior driver installation on all supported Windows versions.
+ - Possible later improvements:
+ - tapinstall.exe is to be eventually replaced with vanilla GPL-licenced utility.
+ - Add metadata to the driver .inf file to allow it to be installed from the file's context menu in explorer.
+ - OpenVPN:
+ - MSI package creation is integrated into openvpn-build using either msitools (preferred) or by running WiX toolset with Mono.
+ - The initial installer will be a silent one and aimed for enterprises and advanced users.
+ - It will not include any GUI, so normal users may/will get confused.
+ - Simon prepares the initial sample, we discuss options when we have something to work on.
+ - UI while installing is not required or kept to the minimum.
+ - MSI packages are also to be packed into an EXE installer for end-users.
+
+ ### route.c / tun.c rehaul
+ - Linux support for ifconfig/route is dropped.
+ - We keep iproute2 support.
+ - We add direct netlink support.
+ - Netlink support needs to come along with strong unit tests.
+ - We split route.c to route.c and route-platform.c.
+ - We look into splitting tun.c into tun-unix.c and tun-win32.c.
+ - Tun.c needs to see all those nearly-identical tun_read()/tun_write() functions merged into one place.
+
+ ### Vagrant
+ - We have a few use-cases for Vagrant.
+ - Mattock has a rudimentary Vagrant setup [here](https://github.com/mattock/openvpn-vagrant).
+ - Next steps include adding basic provisioning scripts and setting up a t_client style server setup.
+
+ ### block-ipv6 patch
+ - Considered a good idea, Arne will cleanup patch and resend patch.
+
+ ### `--tls-cert-profile`
+ - The OpenSSL 'custom security callbacks' are undocumented.
+ - We'll accept slightly different behavior between openssl and mbed TLS, at least for now.
+ - Steffan will send David his patches that attempt to reimplement tls-cert-profile for openssl, so he can give it a try too if he wants to.
+ - Steffan will send a v2 of the mbed patch that will print a warning for openssl build, instead of refusing to start, if `--tls-cert-profile` is used.
+ - Steffan will later send a patch to implement the seclevel approach for openssl.
+
+ ### argv processing clean-up (David, Heiko)
+ - Heiko has some patches on the ML which have been awaiting some updates since last Hackathon; approximately half of the patch-set have been applied but the rest have been lingering since that time.
+ - David and Heiko reviewed these last outstanding patches and agreed to clean them up and rebase on master to complete these patches.
+ - One bug is discovered and will be fixed before being sent to the ML.
+ - Considered if callers of the `argv_*()` functions should be enforced to provide a `gc_arena`. Decided such a change would be quite intrusive and not providing any clear gains.
+ - The `argv_*()` functions already have an internal `gc_arena` which is used for the argv arrays of string pointers and is handled properly there.
+ - Where memory is allocated by `argv_*()` functions to be returned to the calling function, a `gc_arena` pointer is already provided in that call; that allocation happens in the `gc_arena` owned by the caller.
+ - Will also try to add a bit more code comments to ensure the code is easier to understand in the future.
+
+ ### Version life cycle
+ - Agreed that our current approach is quite good, but poorly documented and communicated.
+ - David and Steffan wrote a draft that should help change that, comments and contributions very welcome: [Supported Versions](https://community.openvpn.net/openvpn/wiki/SupportedVersions)
+ - We will aim for having all 2.5 features in for the 2018 hackathon, and go into 'produce a release mode' afterwards.
+ - tls-crypt-v2
+ - transport plugin (primary use case: obfuscation)
+ - netlink support (includes route.c / tun.c refactoring)
+ - 'make VPN fast again!'
+ - remove ENABLE_CRYPTO
+ - purge NSIS installers (migrate to MSI installers)
+ - VLAN patch set
+ - support for multiple sockets (UDP/TCP/multi-port/multi-IP)
+ - dynamic routes ('route in ccd-file'), depends on netlink support
+ - improve control channel performance
+ - update the PRF to ditch MD5/SHA1 (not because broken crypto (it is not!), but for simplicity and marketing)
+ - maybe: add PRF plugin interface
+ - maybe: add key exchange plugin interface (allows easily doing .e.g post quantum kex)
+ - maybe: add data channel separation (or, move to ovpn3, which already has this?)
+ - maybe: fix radius-plugin - plugin is useful but not maintained very well
+
+ ### Control channel optimization
+ - Gert van Dijk and Steffan will be looking into optimizing the control channel in the coming weeks.
+ - Discussed with Arne that we probably would need some dynamic window size to increase performance.
+ - We want to keep the OpenVPN implementation simple, and have a very strong preference to not change the wire format (i.e., must be backward compatible).
+ - Arne will look into good candidate window size algorithms, and make a suggestion about which to use.
/dev/null .. meetups/2023-orihuela.md
@@ 0,0 1,100 @@
+ # OpenVPN Hackathon 2023
+
+ This year's hackathon is organized by Lev Stipakov. For the most part.
+
+ ## Dates
+
+ October 6-8, 2023
+
+ ## Venue
+
+ The venue for the hackathon is at [Scandinavian School Costa Blanca](https://skandinaviskaskolan.com/), which is in Orihuela Costa, Alicante province, Valencian Community, Spain.
+
+ [Address](https://goo.gl/maps/UGVHcnQyWAN2cUfNA?coh=178572&entry=tt):
+
+ ```
+ C. Pablo Picasso, 5
+ Bloque 6, 3ª Planta
+ 03189 Orihuela, Alicante
+ ```
+
+ The closest airport is [Alicante Elche](https://www.aena.es/en/alicante-elche-miguel-hernandez.html). From there it takes 50min by taxi to arrive at Orihuela Costa. Note that the venue located about 8km from Torrevieja center, so you probably don't want to book a hotel there.
+
+ Hotels close-by:
+ - [Hotel Servigroup La Zenia - Orihuela](https://www.servigroup.com/en/la-zenia-hotel-orihuela-costa/)
+
+ ## Who is coming?
+
+ | **Name** | **Topics** | **Arrival** | **Departure** | **Hotel** | **T-shirt size** |
+ |-------------------|----------------------------------------|------------------------------|-----------------------------|----------------|------------------|
+ | Lev Stipakov | DCO, new TAP driver | already there | 08.10 late evening | TBD | M |
+ | Gert Döring | triage open issues, Tunnelcrack | Thu. Oct. 5 16:20 at ALC | Sun Oct. 8 flight at 12:30 | Servigroup | XL |
+ | Arne Schwabe | things | Tur late (19:00 at ALC) | Sun afternoon (flight at 18:50) | TBD | XXL |
+ | Johan Draaisma | gerrit | Thu. Oct. 5. 16:30 | Sa. Oct. 14. 17:20 | una casa cerca de la escuela | XL |
+ | Frank Lichtenheld | gerrit | Thu. Oct. 5. 16:45 | So. Oct. 8. 18:10 | Servigroup | XL |
+ | Heiko Hund | future of --dhcp-options | Thu. Oct. 5. 16:25 | Sa. Oct. 14. 15:00 | una casa cerca de la escuela | XXL |
+ | Max Fillinger | TBD | Thu. 16:30 at ALC | Mon. 13:00 | Orihuela Costa Resort | XL |
+ | Antonio Quartulli | i just want a shirt kthxbye | not attending | not attending | not attending | M |
+ | James Yonan | unable to attend | not attending | not attending | not attending | XL |
+ | Samuli Seppänen | | not attending | not attending | not attending | |
+
+ ## Meeting summary
+
+ - **TunnelCrack vulnerabilities**
+ - Published a statement on the community wiki regarding TunnelCrack. A security advisory on the main site is to follow a bit later.
+ - Planned future mitigation steps to counter these vulnerabilities. Out of necessity the mitigations will be different per platform.
+ - **Windows:** Rework `--redirect-gateway block-local` to use Windows Filtering Platform - precedent for using WFP in `--block-outside-dns`.
+ - **macOS:** Look at the VPN API and maybe PF for a solution to block the unwanted traffic paths.
+ - **Linux:** Implement a separate routing table and set up a routing policy. Add options to control this.
+ - **BSD OSes:** Provide an `--up script` example and documentation to block unwanted traffic paths.
+ - **Android:** Has traffic isolation out of the box and is not affected by these vulnerabilities.
+ - **iOS:** Currently only implemented in OpenVPN Connect, so OpenVPN Inc. will look into a fix.
+
+ - **Change default for topology directive**
+ - Change the default from net30 topology to subnet topology planned for OpenVPN 2.7.
+
+ - **DNS implementation on Windows**
+ - Implement new split-DNS functionality using the new `--dns` directive.
+ - Deduplicate DNS and route handling code in the privileged interactive service.
+
+ - **DNS implementation on Linux**
+ - Provide a script with OpenVPN 2.7 on Linux that supports resolved and resolvconf out-of-the-box.
+
+ - **Windows GUI update mechanism**
+ - Consider adding a software update mechanism, possibly using Sparkle or another existing solution.
+
+ - **Future of dhcp-option directive**
+ - Evaluate all the dhcp-option directive options and see if any can be separated into its own directive.
+
+ - **Planned deprecation of NTLM proxy authentication methods**
+ - NTLMv1 is already deprecated and will be removed from OpenVPN 2.7. NTLMv2 will become marked as deprecated but still work in OpenVPN 2.7.
+
+ - **Planned deprecation of `--secret` static key directive**
+ - Begin deprecation in OpenVPN 2.7, and removal in OpenVPN 2.8.
+
+ - **Multiple authentication plugins support**
+ - Planned for OpenVPN 2.7.
+
+ - **Improve OpenVPN2 and network-manager integration**
+ - Implement changes in master intended for 2.7 and if non-disruptive backport to 2.6.
+
+ - **Multi-socket support**
+ - Implement the ability for OpenVPN2 to listen on multiple sockets at the same time in OpenVPN 2.7.
+
+ - **Live route updates**
+ - Support updating routes live on the client side without having to force a reconnect in OpenVPN 2.7.
+
+ - **Custom control channel packets**
+ - Implement a new control channel message for arbitrary messages in OpenVPN 2.7.
+
+ - **mbedTLS updates**
+ - Final stages of updating the licensing of OpenVPN2 to resolve this, allowing updates to newer mbedTLS versions.
+
+ - **Remove OpenSSL 1.0.2 support**
+ - Planned for OpenVPN 2.7.
+
+ - **2.6 client with DCO connecting to 2.4 server silent failure**
+ - Add a notification for this issue and advise upgrading to newer versions to solve it.
+
+ - **Incoming patchset for DCO-win**
+ - Lev will help with splitting the huge patchset into manageable related pieces and work on merging it.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9