Commit bfd809

2025-06-27 21:13:01 novaflash: -/-
Meetings/2025/2025-05-28.md ..
@@ 5,100 5,14 @@
# Topics
- ## Current topics
-
- * **Updated: Release 2.7**\
- We are going for an alpha release - this was released 28 May 2025. Main website to be updated 29 May 2025 somewhere.\
- Currently collecting all the changes that are new to 2.7 and making a changes.rst and reviewing anything still left to handle.\
- Together with 2.7 a new Linux DCO module based on upstreamed (linux kernel) codebase will be released, the code for this is 'done' although there are still bugs being fixed.\
- Together with 2.7 a new Windows DCO module with server support will be released. The code for this is done but needs more testing.\
- DNS changes are in but there are still some minor bug fixes and such on the way.\
-
- * **Updated: Changes to community pages on main website**\
- Company reached out to novaflash about proposed changes. novaflash involved ordex and lev__ for feedback/ideas.\
- An initial design suggestion was put forward, hoping to get feedback from community on it to finetune it.\
- https://crashed.computer/new.png \
+ - **Updated: Release 2.7**
+ We are going for an alpha release - this was released 28 May 2025. Main website to be updated 29 May 2025 somewhere.
+ Currently collecting all the changes that are new to 2.7 and making a changes.rst and reviewing anything still left to handle.
+ Together with 2.7 a new Linux DCO module based on upstreamed (linux kernel) codebase will be released, the code for this is 'done' although there are still bugs being fixed.
+ Together with 2.7 a new Windows DCO module with server support will be released. The code for this is done but needs more testing.
+ DNS changes are in but there are still some minor bug fixes and such on the way.
+
+ - **Updated: Changes to community pages on main website**
+ Company reached out to novaflash about proposed changes. novaflash involved ordex and lev__ for feedback/ideas.
+ An initial design suggestion was put forward, hoping to get feedback from community on it to finetune it.
There was no immediate feedback in the community meeting, so novaflash, ordex, and lev__, will work together to come up with something sensible.
-
- ---
-
- ## Backlog
-
- * **DCO tasks**\
- Implementation of epoch data keys in user space in OpenVPN2 and OpenVPN3 are both done now. For Windows, Linux, and FreeBSD DCO this implementation still needs to happen.\
- lev__ has started work on epoch data keys in Windows DCO. Windows DCO has also support for server mode now so has some significant changes coming with 2.7.
- Red Hat 9.6 introduced a change that breaks the current production DCO kernel module code. A fix for this is available now.\
- Programs that rely on this like Access Server and OpenVPN3 Linux will push out an updated DCO kernel module with this fix soonish.\
- There are still some bugfixes for the backport copy of linux kernel upstreamed version of DCO for 2.7 to be resolved.
-
- * **OpenVPN community meetup 2025**\
- https://community.openvpn.net/openvpn/wiki/CommunityMeetup2025 \
- When: based on an availabilty poll and by agreement the weekend of 25 and 26 october as meeting days, with days before and after as travel days, seems best.\
- Where: Napoli, Italy.\
- Meeting room: giaan will take a look into this.\
- Hotel: giaan will take a look into this.\
- Beer: yes.\
- T-shirts: yes.
-
- * **security mailing list**\
- Contact page was updated (probably by accident) before it was approved.\
- There are several items that community would like to see addressed before it gets updated.
-
- * **forums situation**\
- Situation in a nutshell; old forums got flooded with spam. attempt was made to make new forums to fix it. this was aborted. now we're in limbo.\
- We now have someone from OpenVPN Inc to help us fix it up, so we'll let him try.
-
- * **push_update / live route updates**\
- Client-side support looks to be relatively straight-forward.\
- Server-side support patch is up and requires review and is a bit more involved.
-
- * **snapshot releases via Chocolatey software**\
- mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.\
- Seems like the maintainer is amenable to helping us achieve that goal.
-
- * **2.7 security audit**\
- ''ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.
-
- * **Tunnelcrack progress (see TunnelCrack community wiki article)\
- ''Status update on TunnelCrack mitigations:''\
- ''The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.''\
- ''Windows, openvpn2: block-local merged to master, not to 2.6.x. openvpn3: in code review.''\
- ''Linux, openvpn2: in progress. openvpn3: in progress.''\
- ''macOS: to be determined.''\
- ''iOS: to be determined.''\
- ''Android: not vulnerable.''
-
- * **donation collection**\
- ''From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.''\
- ''What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.''\
- ''There are some options to consider. There may be existing solutions that we want to consider.''\
- ''PayPal seems overly expensive with all their fees.''\
- ''Stripe could be worth considering for credit card processing.''\
- ''GitHub Sponsors was mentioned as a possible solution, this is worth investigating.''\
- ''Open Collective was also mentioned, that needs some investigating how that exactly would work for us.''
-
- * **Community AWS account governance**\
- ''Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization''\
- ''With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.''\
- ''Requires further discussion whether that is something we want.''
-
- * **Status of SBOM**\
- ''There was a discussion between MaxF and djpig and others.''\
- ''For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.''\
- ''The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.''
-
- * **Static-key mini how-to is outdated.**\
- ''This page is outdated badly: https://openvpn.net/community-resources/static-key-mini-howto/ ''\
- ''company will send this to tech writer to redo based on https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst info\
- and also retain a link to that github doc.\
- having a simple guide online will help adoption''
-
- * **What's going on with new taskbar icons?**\
- ''matt provided icons in https://github.com/OpenVPN/openvpn-gui/issues/595 ''\
- ''last update: will be picked up by selva when he has time''
-
- * **software code signing topic**\
- ''company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.''\
- ''in future we could possibly switch community to that same key. saves having to maintain 2 different keys.''\
- ''depends on how hard/easy it is to access company key signing thingee from community infrastructure.''\
- ''also no high priority at the moment, we have a working solution now.''
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9