Commit a75bb0
2025-01-29 07:33:21 Samuli Seppänen: Import last missing meetup pages Signed-off-by: Samuli Seppänen <samuli.seppanen@gmail.com>| /dev/null .. meetups/2017-karlsruhe.md | |
| @@ 0,0 1,138 @@ | |
| + | # OpenVPN Hackathon 2017 |
| + | |
| + | ## who |
| + | This year's hackathon is organized by Heiko Hund (d12fk). |
| + | |
| + | We will stick to the format of the previous years, which means attendance is in principle limited to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". We should have enough space in the meeting room for 16 devs. |
| + | |
| + | ## who is coming? |
| + | |
| + | | Name | Topics | Arrival | Departure | Hotel | |
| + | |-----------------|------------------------------------------|-----------------------|-------------------|-------------------| |
| + | | Heiko Hund | - | Fri. 10am | Sun. 20pm | @home | |
| + | | Antonio Quartulli | traffic manipulation API | Thu noon | Sun afternoon | Der Blaue Reiter | |
| + | | Samuli Seppänen | OpenVPN 3 development | Thu late evening | Sun mid-afternoon | Der Blaue Reiter | |
| + | | Steffan Karger | Post-quantum key exchange, performance | Fri 13:16 (Bhf Durlach)| Sun mid-afternoon | Blaue Reiter | |
| + | | Gert Döring | branch maintenance - what goes where, and why? | Fri noon-ish | Sun late afternoon| Blauer Reiter | |
| + | | Arne Schwabe | - | Fri 12 am at HBF | Sun late afternoon| Blauer Reiter | |
| + | | David Sommerseth| clean-ups, plug-ins, OpenVPN 3 client | Thursday evening | Sun afternoon | Blaue Reiter | |
| + | | Lev Stipakov | ovpn3 | Thu late evening | Sun mid-afternoon | Der Blaue Reiter | |
| + | | Jan Just Keijser| performance, EduVPN | Friday early afternoon| Sun late-afternoon| Der Blaue Reiter | |
| + | | Gert van Dijk | Post-quantum key exchange, documentation | Fri 13:16 (Bhf Durlach)| Sun mid-afternoon| Blaue Reiter | |
| + | | Johan Draaisma | Moral support | Thu noon-ish | Sun at noon | Der Blaue Reiter | |
| + | | James Yonan | | Thursday | - | - | |
| + | | Simon Rozman | eduVPN, MSI packaging | Thu late evening | Sun mid-afternoon | Der Blaue Reiter | |
| + | | François Kooman | eduVPN, OAuth | Thu afternoon | Mon | Der Blaue Reiter | |
| + | |
| + | ## where? |
| + | |
| + | The meeting is held at the Sophos office in Karlsruhe (Germany): [Sophos Office](https://osm.org/go/0DlEda7Ld?m=&node=2127345937). |
| + | |
| + | Karlsruhe is an one hour ICE train ride away from Frankfurt Airport. |
| + | |
| + | If you have any questions or got lost - please contact Heiko at +49 172 74 911 92. |
| + | |
| + | ## when? |
| + | |
| + | The hackathon will take place from Friday November 10th 2017 to Sunday November 12th. |
| + | |
| + | ## what? |
| + | |
| + | So what is the goal of the Hackathon? |
| + | |
| + | - Should we get rid of LZ4 as bundled library and always rely on what the system has installed? |
| + | - Plan clean up route.c and tun.c - which approach should we use? Improve OS/distro modularization? Settle on an improved API? |
| + | - Add more topics here! |
| + | |
| + | We're all open for additions here - I think the meetings in Brussels (2011+2012), Munich (2013+2014), Delft (2015) and Helsinki (2016) have shown that "just being able to sit together and hack" is a useful exercise. |
| + | |
| + | ## input |
| + | |
| + | There will be drinks and snacks to get us through the day. We have a kitchen, so you can also [make sandwiches](https://xkcd.com/149/) or a bowl of cereals. Chance of BBQ if there's demand in November. |
| + | |
| + | ## internet |
| + | |
| + | Free Wifi and wired network is available |
| + | |
| + | ## accommodation |
| + | |
| + | The closest Hotel is the "Der Blaue Reiter" just across the street.\ |
| + | Cheapest accommodation is [IBIS budget](http://www.ibis.com/gb/hotel-3179-ibis-budget-karlsruhe/index.shtml) a good 10 minute walk away. |
| + | |
| + | ## results |
| + | |
| + | (informal notes on some of the discussions that benefit from writing down) |
| + | |
| + | ### MSI |
| + | - TAP-Windows driver: |
| + | - MSI (and MSM) packages are to be built on Windows using WiX Toolset. |
| + | - Test certificates are injected prior driver installation on all supported Windows versions. |
| + | - Possible later improvements: |
| + | - tapinstall.exe is to be eventually replaced with vanilla GPL-licenced utility. |
| + | - Add metadata to the driver .inf file to allow it to be installed from the file's context menu in explorer. |
| + | - OpenVPN: |
| + | - MSI package creation is integrated into openvpn-build using either msitools (preferred) or by running WiX toolset with Mono. |
| + | - The initial installer will be a silent one and aimed for enterprises and advanced users. |
| + | - It will not include any GUI, so normal users may/will get confused. |
| + | - Simon prepares the initial sample, we discuss options when we have something to work on. |
| + | - UI while installing is not required or kept to the minimum. |
| + | - MSI packages are also to be packed into an EXE installer for end-users. |
| + | |
| + | ### route.c / tun.c rehaul |
| + | - Linux support for ifconfig/route is dropped. |
| + | - We keep iproute2 support. |
| + | - We add direct netlink support. |
| + | - Netlink support needs to come along with strong unit tests. |
| + | - We split route.c to route.c and route-platform.c. |
| + | - We look into splitting tun.c into tun-unix.c and tun-win32.c. |
| + | - Tun.c needs to see all those nearly-identical tun_read()/tun_write() functions merged into one place. |
| + | |
| + | ### Vagrant |
| + | - We have a few use-cases for Vagrant. |
| + | - Mattock has a rudimentary Vagrant setup [here](https://github.com/mattock/openvpn-vagrant). |
| + | - Next steps include adding basic provisioning scripts and setting up a t_client style server setup. |
| + | |
| + | ### block-ipv6 patch |
| + | - Considered a good idea, Arne will cleanup patch and resend patch. |
| + | |
| + | ### `--tls-cert-profile` |
| + | - The OpenSSL 'custom security callbacks' are undocumented. |
| + | - We'll accept slightly different behavior between openssl and mbed TLS, at least for now. |
| + | - Steffan will send David his patches that attempt to reimplement tls-cert-profile for openssl, so he can give it a try too if he wants to. |
| + | - Steffan will send a v2 of the mbed patch that will print a warning for openssl build, instead of refusing to start, if `--tls-cert-profile` is used. |
| + | - Steffan will later send a patch to implement the seclevel approach for openssl. |
| + | |
| + | ### argv processing clean-up (David, Heiko) |
| + | - Heiko has some patches on the ML which have been awaiting some updates since last Hackathon; approximately half of the patch-set have been applied but the rest have been lingering since that time. |
| + | - David and Heiko reviewed these last outstanding patches and agreed to clean them up and rebase on master to complete these patches. |
| + | - One bug is discovered and will be fixed before being sent to the ML. |
| + | - Considered if callers of the `argv_*()` functions should be enforced to provide a `gc_arena`. Decided such a change would be quite intrusive and not providing any clear gains. |
| + | - The `argv_*()` functions already have an internal `gc_arena` which is used for the argv arrays of string pointers and is handled properly there. |
| + | - Where memory is allocated by `argv_*()` functions to be returned to the calling function, a `gc_arena` pointer is already provided in that call; that allocation happens in the `gc_arena` owned by the caller. |
| + | - Will also try to add a bit more code comments to ensure the code is easier to understand in the future. |
| + | |
| + | ### Version life cycle |
| + | - Agreed that our current approach is quite good, but poorly documented and communicated. |
| + | - David and Steffan wrote a draft that should help change that, comments and contributions very welcome: [Supported Versions](https://community.openvpn.net/openvpn/wiki/SupportedVersions) |
| + | - We will aim for having all 2.5 features in for the 2018 hackathon, and go into 'produce a release mode' afterwards. |
| + | - tls-crypt-v2 |
| + | - transport plugin (primary use case: obfuscation) |
| + | - netlink support (includes route.c / tun.c refactoring) |
| + | - 'make VPN fast again!' |
| + | - remove ENABLE_CRYPTO |
| + | - purge NSIS installers (migrate to MSI installers) |
| + | - VLAN patch set |
| + | - support for multiple sockets (UDP/TCP/multi-port/multi-IP) |
| + | - dynamic routes ('route in ccd-file'), depends on netlink support |
| + | - improve control channel performance |
| + | - update the PRF to ditch MD5/SHA1 (not because broken crypto (it is not!), but for simplicity and marketing) |
| + | - maybe: add PRF plugin interface |
| + | - maybe: add key exchange plugin interface (allows easily doing .e.g post quantum kex) |
| + | - maybe: add data channel separation (or, move to ovpn3, which already has this?) |
| + | - maybe: fix radius-plugin - plugin is useful but not maintained very well |
| + | |
| + | ### Control channel optimization |
| + | - Gert van Dijk and Steffan will be looking into optimizing the control channel in the coming weeks. |
| + | - Discussed with Arne that we probably would need some dynamic window size to increase performance. |
| + | - We want to keep the OpenVPN implementation simple, and have a very strong preference to not change the wire format (i.e., must be backward compatible). |
| + | - Arne will look into good candidate window size algorithms, and make a suggestion about which to use. |
| /dev/null .. meetups/2023-orihuela.md | |
| @@ 0,0 1,100 @@ | |
| + | # OpenVPN Hackathon 2023 |
| + | |
| + | This year's hackathon is organized by Lev Stipakov. For the most part. |
| + | |
| + | ## Dates |
| + | |
| + | October 6-8, 2023 |
| + | |
| + | ## Venue |
| + | |
| + | The venue for the hackathon is at [Scandinavian School Costa Blanca](https://skandinaviskaskolan.com/), which is in Orihuela Costa, Alicante province, Valencian Community, Spain. |
| + | |
| + | [Address](https://goo.gl/maps/UGVHcnQyWAN2cUfNA?coh=178572&entry=tt): |
| + | |
| + | ``` |
| + | C. Pablo Picasso, 5 |
| + | Bloque 6, 3ª Planta |
| + | 03189 Orihuela, Alicante |
| + | ``` |
| + | |
| + | The closest airport is [Alicante Elche](https://www.aena.es/en/alicante-elche-miguel-hernandez.html). From there it takes 50min by taxi to arrive at Orihuela Costa. Note that the venue located about 8km from Torrevieja center, so you probably don't want to book a hotel there. |
| + | |
| + | Hotels close-by: |
| + | - [Hotel Servigroup La Zenia - Orihuela](https://www.servigroup.com/en/la-zenia-hotel-orihuela-costa/) |
| + | |
| + | ## Who is coming? |
| + | |
| + | | **Name** | **Topics** | **Arrival** | **Departure** | **Hotel** | **T-shirt size** | |
| + | |-------------------|----------------------------------------|------------------------------|-----------------------------|----------------|------------------| |
| + | | Lev Stipakov | DCO, new TAP driver | already there | 08.10 late evening | TBD | M | |
| + | | Gert Döring | triage open issues, Tunnelcrack | Thu. Oct. 5 16:20 at ALC | Sun Oct. 8 flight at 12:30 | Servigroup | XL | |
| + | | Arne Schwabe | things | Tur late (19:00 at ALC) | Sun afternoon (flight at 18:50) | TBD | XXL | |
| + | | Johan Draaisma | gerrit | Thu. Oct. 5. 16:30 | Sa. Oct. 14. 17:20 | una casa cerca de la escuela | XL | |
| + | | Frank Lichtenheld | gerrit | Thu. Oct. 5. 16:45 | So. Oct. 8. 18:10 | Servigroup | XL | |
| + | | Heiko Hund | future of --dhcp-options | Thu. Oct. 5. 16:25 | Sa. Oct. 14. 15:00 | una casa cerca de la escuela | XXL | |
| + | | Max Fillinger | TBD | Thu. 16:30 at ALC | Mon. 13:00 | Orihuela Costa Resort | XL | |
| + | | Antonio Quartulli | i just want a shirt kthxbye | not attending | not attending | not attending | M | |
| + | | James Yonan | unable to attend | not attending | not attending | not attending | XL | |
| + | | Samuli Seppänen | | not attending | not attending | not attending | | |
| + | |
| + | ## Meeting summary |
| + | |
| + | - **TunnelCrack vulnerabilities** |
| + | - Published a statement on the community wiki regarding TunnelCrack. A security advisory on the main site is to follow a bit later. |
| + | - Planned future mitigation steps to counter these vulnerabilities. Out of necessity the mitigations will be different per platform. |
| + | - **Windows:** Rework `--redirect-gateway block-local` to use Windows Filtering Platform - precedent for using WFP in `--block-outside-dns`. |
| + | - **macOS:** Look at the VPN API and maybe PF for a solution to block the unwanted traffic paths. |
| + | - **Linux:** Implement a separate routing table and set up a routing policy. Add options to control this. |
| + | - **BSD OSes:** Provide an `--up script` example and documentation to block unwanted traffic paths. |
| + | - **Android:** Has traffic isolation out of the box and is not affected by these vulnerabilities. |
| + | - **iOS:** Currently only implemented in OpenVPN Connect, so OpenVPN Inc. will look into a fix. |
| + | |
| + | - **Change default for topology directive** |
| + | - Change the default from net30 topology to subnet topology planned for OpenVPN 2.7. |
| + | |
| + | - **DNS implementation on Windows** |
| + | - Implement new split-DNS functionality using the new `--dns` directive. |
| + | - Deduplicate DNS and route handling code in the privileged interactive service. |
| + | |
| + | - **DNS implementation on Linux** |
| + | - Provide a script with OpenVPN 2.7 on Linux that supports resolved and resolvconf out-of-the-box. |
| + | |
| + | - **Windows GUI update mechanism** |
| + | - Consider adding a software update mechanism, possibly using Sparkle or another existing solution. |
| + | |
| + | - **Future of dhcp-option directive** |
| + | - Evaluate all the dhcp-option directive options and see if any can be separated into its own directive. |
| + | |
| + | - **Planned deprecation of NTLM proxy authentication methods** |
| + | - NTLMv1 is already deprecated and will be removed from OpenVPN 2.7. NTLMv2 will become marked as deprecated but still work in OpenVPN 2.7. |
| + | |
| + | - **Planned deprecation of `--secret` static key directive** |
| + | - Begin deprecation in OpenVPN 2.7, and removal in OpenVPN 2.8. |
| + | |
| + | - **Multiple authentication plugins support** |
| + | - Planned for OpenVPN 2.7. |
| + | |
| + | - **Improve OpenVPN2 and network-manager integration** |
| + | - Implement changes in master intended for 2.7 and if non-disruptive backport to 2.6. |
| + | |
| + | - **Multi-socket support** |
| + | - Implement the ability for OpenVPN2 to listen on multiple sockets at the same time in OpenVPN 2.7. |
| + | |
| + | - **Live route updates** |
| + | - Support updating routes live on the client side without having to force a reconnect in OpenVPN 2.7. |
| + | |
| + | - **Custom control channel packets** |
| + | - Implement a new control channel message for arbitrary messages in OpenVPN 2.7. |
| + | |
| + | - **mbedTLS updates** |
| + | - Final stages of updating the licensing of OpenVPN2 to resolve this, allowing updates to newer mbedTLS versions. |
| + | |
| + | - **Remove OpenSSL 1.0.2 support** |
| + | - Planned for OpenVPN 2.7. |
| + | |
| + | - **2.6 client with DCO connecting to 2.4 server silent failure** |
| + | - Add a notification for this issue and advise upgrading to newer versions to solve it. |
| + | |
| + | - **Incoming patchset for DCO-win** |
| + | - Lev will help with splitting the huge patchset into manageable related pieces and work on merging it. |
