Commit c14e58

2025-02-11 07:05:53 Samuli Seppänen: Add Download page
/dev/null .. Downloads.md
@@ 0,0 1,741 @@
+ # Downloads
+
+ ## OpenVPN 2.6.13 -- Released 15 January 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.6.13. This is a bugfix release.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.13/Changes.rst)
+
+ ### Feature changes:
+
+ - On non-windows clients (MacOS, Linux, Unix) send "release" string from `uname()` call as `IV_PLAT_VER` to server - while highly OS specific, this is still helpful to keep track of OS versions used on the client side ([#637](https://github.com/OpenVPN/openvpn/issues/637))
+ - Windows: protect cached username, password, and token in client memory using the `CryptProtectMemory()` Windows API.
+ - Windows: use new API to get dco-win driver version from driver (newly introduced non-exclusive control device) ([ovpn-dco-win#76](https://github.com/OpenVPN/ovpn-dco-win/issues/76))
+ - Linux: pass `--timeout=0` argument to `systemd-ask-password`, to avoid default timeout of 90 seconds ("console prompting also has no timeout") ([#649](https://github.com/OpenVPN/openvpn/issues/649))
+
+ ### Security fixes:
+
+ - Improve server-side handling of clients sending usernames or passwords longer than `USER_PASS_LEN` - this would not result in a crash, buffer overflow, or other security issues, but the server would then misparse incoming IV variables and produce misleading error messages.
+
+ ### Notable bug fixes:
+
+ - FreeBSD DCO: fix memory leaks in nvlist handling ([#636](https://github.com/OpenVPN/openvpn/issues/636))
+ - Purge proxy authentication credentials from memory after use (if `--auth-nocache` is in use)
+
+ ### Windows MSI changes since 2.6.12:
+ - Built against OpenSSL 3.4.0
+ - Included openvpn-gui updated to 11.51.0.0
+ - Higher resolution eye icons ([openvpn-gui#697](https://github.com/OpenVPN/openvpn-gui/issues/697))
+ - Support for concatenating OTP with password
+ - Optionally always prompt for OTP
+ - Fix tooltip positioning when the taskbar is at the top ([openvpn-gui#710](https://github.com/OpenVPN/openvpn-gui/issues/710))
+
+ ### Debian/Ubuntu packages
+ Debian/Ubuntu packages in OpenvpnSoftwareRepos are now available for Ubuntu 24.10 (oracular).
+
+ ### Downloads
+ - **Windows 64-bit MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-amd64.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-amd64.msi)
+ - **Windows ARM64 MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-arm64.msi)
+ - **Windows 32-bit MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-x86.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-x86.msi)
+ - **Source archive file:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.13.tar.gz.asc), [Download](https://swupdate.openvpn.org/community/releases/openvpn-2.6.13.tar.gz)
+
+ For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
+
+ ## OpenVPN 2.5.11 -- Released 18 July 2024The OpenVPN community project team is proud to release OpenVPN 2.5.11. This is a security fix release.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.5.11/Changes.rst).
+
+ **Security fixes:**
+ - [CVE-2024-5594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5594): control channel: refuse control channel messages with nonprintable characters in them. Security scope: a malicious openvpn peer can send garbage to openvpn log, or cause high CPU load. (Reynir Björnsson)
+ - (Backport of the security fix in 2.6.11 and the fix for the bugfix in 2.6.12)
+
+ In accordance with our [support policy](SupportedVersions), packages and installers are not provided for 2.5 anymore.
+
+ **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.11.tar.gz.asc)
+ - [openvpn-2.5.11.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.5.11.tar.gz)
+
+ ## OpenVPN 2.6.12 -- Released 18 July 2024
+ The OpenVPN community project team is proud to release OpenVPN 2.6.12. This is a bugfix release.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.12/Changes.rst).
+
+ **Bug fixes:**
+ - the fix for CVE-2024-5594 (refuse control channel messages with nonprintable characters) was too strict, breaking user configurations with AUTH_FAIL messages having trailing CR/NL characters. This often happens if the AUTH_FAIL reason is set by a script. Strip those before testing the command buffer ([#568](https://github.com/OpenVPN/openvpn/issues/568)). Also, add unit test.
+ - Http-proxy: fix bug preventing proxy credentials caching (trac #1187)
+
+ **Windows MSI changes since 2.6.11:**
+ - Built against OpenSSL 3.3.1
+ - Included openvpn-gui updated to 11.50.0.0
+ - Update Italian language ([#696](https://github.com/OpenVPN/openvpn-gui/pull/696))
+
+ **Windows 64-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-amd64.msi.asc)
+ - [OpenVPN-2.6.12-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-amd64.msi)
+
+ **Windows ARM64 MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi.asc)
+ - [OpenVPN-2.6.12-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi)
+
+ **Windows 32-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-x86.msi.asc)
+ - [OpenVPN-2.6.12-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-x86.msi)
+
+ **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.12.tar.gz.asc)
+ - [openvpn-2.6.12.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.12.tar.gz)
+
+ For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
+
+ ## OpenVPN 2.6.11 -- Released 20 June 2024
+ The OpenVPN community project team is proud to release OpenVPN 2.6.11. This is a bugfix release containing several security fixes.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.11/Changes.rst).
+
+ **Security fixes:**- [CVE-2024-4877](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4877): Windows: harden interactive service pipe.
+ Security scope: a malicious process with "some" elevated privileges (!SeImpersonatePrivilege) could open the pipe a second time, tricking openvpn GUI into providing user credentials (tokens), getting full access to the account openvpn-gui.exe runs as.
+ (Zeze with TeamT5)
+ - [CVE-2024-5594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5594): control channel: refuse control channel messages with nonprintable characters in them. Security scope: a malicious openvpn peer can send garbage to openvpn log, or cause high CPU load. (Reynir Björnsson)
+ - [CVE-2024-28882](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28882): only call schedule_exit() once (on a given peer). Security scope: an authenticated client can make the server "keep the session" even when the server has been told to disconnect this client (Reynir Björnsson)
+
+ ### New features:
+
+ - Windows Crypto-API: Implement Windows CA template match for searching certificates in windows crypto store.
+ - Support pre-created DCO interface on FreeBSD (OpenVPN would fail to set ifmode p2p/subnet otherwise)
+
+ ### Bug fixes:
+
+ - Fix connect timeout when using SOCKS proxies (trac #328, github [#267](https://github.com/OpenVPN/openvpn/issues/267))
+ - Work around LibreSSL crashing on OpenBSD 7.5 when enumerating ciphers (LibreSSL bug, already fixed upstream, but not backported to OpenBSD 7.5, see also [LibreSSL/OpenBSD#150](https://github.com/libressl/openbsd/issues/150))
+ - Add bracket in fingerprint message and do not warn about missing verification (github [#516](https://github.com/OpenVPN/openvpn/issues/516))
+
+ ### Documentation:
+
+ - Remove "experimental" denotation for --fast-io
+ - Correctly document ifconfig_* variables passed to scripts
+ - Documentation: make section levels consistent
+ - Samples: Update sample configurations (remove compression & old cipher settings, add more informative comments)
+
+ ### Windows MSI changes since 2.6.10:
+ - For the Windows-specific security fixes see above
+ - Built against OpenSSL 3.3.1
+ - Included openvpn-gui updated to 11.49.0.0
+ - Contains part of the fix for [CVE-2024-4877](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4877)
+
+ **Note:** Windows MSI was updated to I002 on June 26th. Changes in I002:
+ - Group names are localized in some localizations, so we have to use SIDs. (Github: [#671](https://github.com/OpenVPN/openvpn-build/issues/671))
+
+ **Windows 64-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-amd64.msi.asc)
+ - [OpenVPN-2.6.11-I002-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-amd64.msi)## OpenVPN Releases and Downloads
+
+ ### Windows MSI Installers
+ - **Windows ARM64 MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-arm64.msi.asc)
+ - [Download OpenVPN-2.6.11-I002-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-arm64.msi)
+ - **Windows 32-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-x86.msi.asc)
+ - [Download OpenVPN-2.6.11-I002-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-x86.msi)
+ - **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.11.tar.gz.asc)
+ - [Download openvpn-2.6.11.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.11.tar.gz)
+
+ For Community-maintained packages for Linux distributions, see OpenvpnSoftwareRepos.
+
+ ### OpenVPN 2.5.10 -- Released 21 March 2024
+ The OpenVPN community project team is proud to release OpenVPN 2.5.10. This is a bugfix release containing several security fixes specific to the Windows platform.
+
+ For details, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.5.10/Changes.rst).
+
+ **Security fixes:**
+ - [CVE-2024-27459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27459): Windows: fix a possible stack overflow in the interactive service component.
+ - [CVE-2024-24974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24974): Windows: disallow access to the interactive service pipe from remote computers.
+ - [CVE-2024-27903](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27903): Windows: disallow loading of plugins from untrusted installation paths.
+ - [CVE-2024-1305](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow.
+
+ **Windows MSI Installers:**
+ - **Windows 64-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-amd64.msi.asc)
+ - [Download OpenVPN-2.5.10-I601-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-amd64.msi)
+ - **Windows ARM64 MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-arm64.msi.asc)
+ - [Download OpenVPN-2.5.10-I601-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-arm64.msi)
+ - **Windows 32-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-x86.msi.asc)
+ - [Download OpenVPN-2.5.10-I601-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-x86.msi)
+ - **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.10.tar.gz.asc)
+ - [Download openvpn-2.5.10.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.5.10.tar.gz)
+
+ ### OpenVPN 2.6.10 -- Released 20 March 2024
+ The OpenVPN community project team is proud to release OpenVPN 2.6.10. This is a bugfix release containing several security fixes specific to the Windows platform.
+
+ For details, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.10/Changes.rst).- [CVE-2024-27459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27459): Windows: fix a possible stack overflow in the interactive service component which might lead to a local privilege escalation.
+ Reported by: Vladimir Tokarev <vtokarev@microsoft.com>
+ - [CVE-2024-24974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24974): Windows: disallow access to the interactive service pipe from remote computers.
+ Reported by: Vladimir Tokarev <vtokarev@microsoft.com>
+ - [CVE-2024-27903](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27903): Windows: disallow loading of plugins from untrusted installation paths, which could be used to attack `openvpn.exe` via a malicious plugin. Plugins can now only be loaded from the OpenVPN install directory, the Windows system directory, and possibly from a directory specified by `HKLM\SOFTWARE\OpenVPN\plugin_dir`.
+ Reported by: Vladimir Tokarev <vtokarev@microsoft.com>
+ - [CVE-2024-1305](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket.
+ Reported by: Vladimir Tokarev <vtokarev@microsoft.com>
+
+ **New features:**
+
+ - `t_client.sh` can now run pre-tests and skip a test block if needed (e.g. skip NTLM proxy tests if SSL library does not support MD4)
+
+ **User visible changes:**
+
+ - Update copyright notices to 2024
+
+ **Bug fixes:**
+
+ - Windows: if the win-dco driver is used (default) and the GUI requests use of a proxy server, the connection would fail. Disable DCO in this case. ([#522](https://github.com/OpenVPN/openvpn/issues/522))
+ - Compression: minor bugfix in checking option consistency vs. compiled-in algorithm support
+ - systemd unit files: remove obsolete syslog.target
+
+ **Documentation:**
+
+ - Remove license warnings about mbedTLS linking (README.mbedtls)
+ - Update documentation references in systemd unit files
+ - Sample config files: remove obsolete tls-*.conf files
+ - Document that auth-user-pass may be inlined
+
+ **Windows MSI changes since 2.6.9:**
+ - For the Windows-specific security fixes see above
+ - Built against OpenSSL 3.2.1
+ - Included tap6-windows driver updated to 9.27.0
+ - Security fix, see above
+ - Included ovpn-dco-win driver updated to 1.0.1
+ - Ensure we don't pass too large key size to CryptoNG. We do not consider this a security issue since the CryptoNG API handles this gracefully either way.
+ - Included openvpn-gui updated to 11.48.0.0
+ - Position tray tooltip above the taskbar### Tray Icon Tips
+ - Combine the title and message in the tray icon tooltip text.
+ - Use a custom tooltip window for the tray icon.
+
+ ### Windows MSI Updates
+ #### Update I002 (April 15th)
+ - **Updated**: ovpn-dco-win to v1.1.1
+ - Improves reconnect behavior after hibernate/standby. ([Issue #64](https://github.com/OpenVPN/ovpn-dco-win/issues/64))
+
+ #### Update I003 (May 23rd)
+ - **Updated**: ovpn-dco-win to v1.2.1
+ - Fix bug check in timer management routines. ([Issue #70](https://github.com/OpenVPN/ovpn-dco-win/issues/70))
+
+ ### MSI Installers
+ - **Windows 64-bit**: [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-amd64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-amd64.msi.asc)
+ - **Windows ARM64**: [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-arm64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-arm64.msi.asc)
+ - **Windows 32-bit**: [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-x86.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-x86.msi.asc)
+ - **Source Archive**: [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6.10.tar.gz) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.10.tar.gz.asc)
+
+ ### Community-maintained Linux Packages
+ For details on Linux distribution packages, see OpenvpnSoftwareRepos.
+
+ ### OpenVPN 2.6.9 Release (12 February 2024)
+ The OpenVPN community project team is pleased to announce the release of OpenVPN 2.6.9, a bugfix release that includes a crucial security fix for the Windows installer.
+
+ **Security Fixes:**
+ - **Windows Installer**: Fixed a vulnerability ([CVE-2023-7235](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7235)) where installing to a non-default directory could lead to local privilege escalation.
+
+ **New Features:**
+ - Support for building with mbedTLS 3.x.x.
+ - New `--force-tls-key-material-export` option.
+ - Windows: Updated pkcs11-helper to 1.30.
+ - Improved logging for SSL alerts.
+
+ **User Visible Changes:**
+ - License change completed; all code now under a new license (GPLv2 with a linking exception for Apache2 licensed code). See [COPYING](https://github.com/OpenVPN/openvpn/blob/release/2.6/COPYING) for details.
+
+ For more details on this release, see the [Change Log](https://github.com/OpenVPN/openvpn/blob/v2.6.9/Changes.rst).Original code has been assessed for feature compatibility by various developers through a review of both the old and new code alongside documentation. There *should* not be any user-visible changes.
+
+ - IPv6 route addition and deletion are now logged at the same level (3) as IPv4. Previously, IPv6 was always logged at `--verb 1`.
+ - Enhanced handling of TLS 1.0 PRF failures in the underlying SSL library, such as on some FIPS builds. These issues are now reported at startup, and clients prior to version 2.6.0 that cannot use TLS EKM to generate key material are rejected by the server. Additionally, error messages have been improved to clarify the specific failure.
+
+ ### Notable Bug Fixes:
+
+ - **FreeBSD:** For servers handling multiple clients, reporting of peer traffic statistics would fail due to insufficient buffer space. ([#487](https://github.com/OpenVPN/openvpn/issues/487))
+
+ ### Windows MSI Changes Since 2.6.8:
+ - Security fix (detailed above).
+ - Built against OpenSSL 3.2.0.
+ - Included openvpn-gui updated to version 11.47.0.0:
+ - **Windows GUI:** The tray icon is always updated on state changes. ([#669](https://github.com/OpenVPN/openvpn-gui/issues/669)) This is particularly important for persistent connection profiles where the "connecting" state might not display.
+
+ **Download Links:**
+ - **Windows 64-bit MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-amd64.msi.asc) | [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-amd64.msi)
+ - **Windows ARM64 MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-arm64.msi.asc) | [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-arm64.msi)
+ - **Windows 32-bit MSI installer:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-x86.msi.asc) | [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-x86.msi)
+ - **Source archive file:** [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.9.tar.gz.asc) | [Download](https://swupdate.openvpn.org/community/releases/openvpn-2.6.9.tar.gz)
+
+ For Community-maintained packages for Linux distributions, see OpenvpnSoftwareRepos.
+
+ ## OpenVPN 2.6.8 -- Released 17 November 2023
+ The OpenVPN community project team proudly announces the release of OpenVPN 2.6.8. This update focuses on fixing a few regressions found in the 2.6.7 release.
+
+ For details, see the [Changes documentation](https://github.com/OpenVPN/openvpn/blob/v2.6.8/Changes.rst).
+
+ ### User Visible Changes:
+ - **Windows:** A warning is now printed if pushed options require DHCP (e.g., DOMAIN-SEARCH) and the current driver does not utilize DHCP (e.g., wintun, dco).
+
+ ### Bug Fixes:
+ - **SIGSEGV Crash:** Do not check key_state buffers that are in S_UNDEF state. ([#449](https://github.com/OpenVPN/openvpn/issues/449)) The new sanity check function introduced in 2.6.7 could sometimes attempt to use a NULL pointer after an unsuccessful TLS handshake.
+ - **Windows:** The `--dns` option did not function when the tap-windows6 driver was in use because the internal flag for "apply DNS option to DHCP server" wasn't set. ([#447](https://github.com/OpenVPN/openvpn/issues/447))
+ - **Windows:** Fixed status/log file permissions, a regression caused by the switch to the CMake build system. ([#454](https://github.com/OpenVPN/openvpn/issues/454), [Trac #1430](https://community.openvpn.net/openvpn/ticket/1430))**Windows:** fix `--chdir` failures, also caused by error in CMake build system ([#448](https://github.com/OpenVPN/openvpn/issues/448))
+
+ **Windows MSI changes since 2.6.7:**
+ - Included openvpn-gui updated to 11.46.0.0
+
+ **Download Links:**
+
+ - **Windows 64-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-amd64.msi.asc)
+ - [OpenVPN-2.6.8-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-amd64.msi)
+
+ - **Windows ARM64 MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-arm64.msi.asc)
+ - [OpenVPN-2.6.8-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-arm64.msi)
+
+ - **Windows 32-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-x86.msi.asc)
+ - [OpenVPN-2.6.8-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-x86.msi)
+
+ - **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.8.tar.gz.asc)
+ - [openvpn-2.6.8.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.8.tar.gz)
+
+ For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
+
+ ---
+
+ ## OpenVPN 2.6.7 -- Released 09 November 2023
+
+ The OpenVPN community project team is proud to release OpenVPN 2.6.7. This is a bugfix release containing security fixes.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.7/Changes.rst)
+
+ **Security Fixes:**
+
+ - [CVE-2023-46850](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46850): OpenVPN versions between 2.6.0 and 2.6.6 incorrectly use a send buffer after it has been free()d in some circumstances, causing some free()d memory to be sent to the peer. All configurations using TLS (e.g. not using --secret) are affected by this issue. (found while tracking down [CVE-2023-46849](https://github.com/OpenVPN/openvpn/issues/400), [#417](https://github.com/OpenVPN/openvpn/issues/417))
+ - [CVE-2023-46849](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46849): OpenVPN versions between 2.6.0 and 2.6.6 incorrectly restore `--fragment` configuration in some circumstances, leading to a division by zero when `--fragment` is used. On platforms where division by zero is fatal, this will cause an OpenVPN crash.
+
+ **User visible changes:**
+
+ - DCO: warn if DATA_V1 packets are sent by the other side - this a hard incompatibility between a 2.6.x client connecting to a 2.4.0-2.4.4 server, and the only fix is to use `--disable-dco`.
+ - Remove OpenSSL Engine method for loading a key. This had to be removed because the original author did not agree to relicensing the code with the new linking exception added. This was a somewhat obsolete feature anyway as it only worked with OpenSSL 1.x, which is end-of-support.
+ - Add warning if p2p NCP client connects to a p2mp server - this is a combination that used to work without cipher negotiation (pre 2.6 on both ends), but would fail in non-obvious ways with 2.6 to 2.6.
+ - Add warning to `--show-groups` that not all supported groups are listed (this is due to the internal enumeration in OpenSSL being a bit weird, omitting X448 and X25519 curves).
+ - `--dns`: remove support for `exclude-domains` argument (this was a new 2.6 option, with no backend support implemented yet on any platform, and it turns out that no platform supported it at all - so remove option again)
+ - Warn user if INFO control message too long, do not forward to management client (safeguard against protocol-violating server implementations)
+
+ **New features:**
+
+ - DCO-WIN: get and log driver version (for easier debugging).
+ - Print "peer temporary key details" in TLS handshake.## Changelog
+
+ ### General Changes
+ - Log OpenSSL errors on failure to set certificate, especially when the algorithms used are unacceptable to OpenSSL (Note: misleading messages may appear in cryptoapi/pkcs11 scenarios).
+ - Implement CMake build system for MinGW and MSVC builds.
+ - Remove old MSVC build system.
+ - Enhance cmocka unit test building for Windows.
+
+ ### Windows MSI Updates Since 2.6.6
+ - Included openvpn-gui updated to 11.45.0.0:
+ - Add clarity for error on missing management parameter. [See GH #657](https://github.com/OpenVPN/openvpn-gui/issues/657)
+ - Improve "OpenVPN GUI" tooltip handling. [See GH #649](https://github.com/OpenVPN/openvpn-gui/issues/649)
+ - MSIs now use OpenSSL 3.1.4
+
+ ### MSI Download Links
+ - **Windows 64-bit MSI installer**: [OpenVPN-2.6.7-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-amd64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-amd64.msi.asc)
+ - **Windows ARM64 MSI installer**: [OpenVPN-2.6.7-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-arm64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-arm64.msi.asc)
+ - **Windows 32-bit MSI installer**: [OpenVPN-2.6.7-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-x86.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-x86.msi.asc)
+ - **Source archive file**: [openvpn-2.6.7.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.7.tar.gz) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.7.tar.gz.asc)
+
+ For community-maintained packages for Linux distributions, see OpenvpnSoftwareRepos.
+
+ ## OpenVPN 2.6.6 -- Released 15 August 2023
+ The OpenVPN community project team is proud to release OpenVPN 2.6.6, a small bugfix release.
+
+ For details, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.6/Changes.rst)
+
+ ### User Visible Changes:
+ - OCC exit messages are now more visibly logged. [See GH #391](https://github.com/OpenVPN/openvpn/issues/391).
+ - OpenSSL error messages now log more details (e.g., which .so was tried and why it failed). [See GH #361](https://github.com/OpenVPN/openvpn/issues/361).
+ - Print a more user-friendly message when tls-crypt-v2 client auth fails.
+ - Packaging now includes all documentation in the source tarball.
+
+ ### New Features:
+ - Set WINS server via interactive service - supports "dhcp-option WINS 192.0.2.1" for DCO + wintun interfaces where no DHCP server is used. [See GH #373](https://github.com/OpenVPN/openvpn/issues/373).
+
+ ### Windows MSI Updates Since 2.6.5:
+ - Included openvpn-gui updated to 11.44.0.0.
+ - MSIs now use OpenSSL 3.1.2.
+
+ ### MSI Download Links for 2.6.6
+ - **Windows 64-bit MSI installer**: [OpenVPN-2.6.6-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-amd64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-amd64.msi.asc)
+ - **Windows ARM64 MSI installer**: [OpenVPN-2.6.6-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-arm64.msi) | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-arm64.msi.asc)### Downloads
+
+ **Windows 32-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-x86.msi.asc)
+ - [OpenVPN-2.6.6-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-x86.msi)
+
+ **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.6.tar.gz.asc)
+ - [openvpn-2.6.6.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.6.tar.gz)
+
+ For Community-maintained packages for Linux distributions see [OpenvpnSoftwareRepos](https://github.com/OpenVPN/openvpn-software-repos)
+
+ ### OpenVPN 2.6.5 -- Released 13 June 2023
+ The OpenVPN community project team is proud to release OpenVPN 2.6.5. This is a small bugfix release.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.5/Changes.rst)
+
+ **User visible changes:**
+
+ - **tapctl (windows):** generate driver-specific names. See [GH #337](https://github.com/OpenVPN/openvpn/issues/337).
+ - **interactive service (windows):** do not force target desktop for openvpn.exe. See [openvpn-gui#626](https://github.com/OpenVPN/openvpn-gui/issues/626)
+
+ **Windows MSI changes since 2.6.4:**
+ - MSIs now use OpenSSL 3.1.1
+
+ Debian/Ubuntu packages in [OpenvpnSoftwareRepos](https://github.com/OpenVPN/openvpn-software-repos) are now available for arm64.
+
+ **Windows 64-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-amd64.msi.asc)
+ - [OpenVPN-2.6.5-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-amd64.msi)
+
+ **Windows ARM64 MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-arm64.msi.asc)
+ - [OpenVPN-2.6.5-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-arm64.msi)
+
+ **Windows 32-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-x86.msi.asc)
+ - [OpenVPN-2.6.5-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-x86.msi)
+
+ **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.5.tar.gz.asc)
+ - [openvpn-2.6.5.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.5.tar.gz)
+
+ For Community-maintained packages for Linux distributions see [OpenvpnSoftwareRepos](https://github.com/OpenVPN/openvpn-software-repos)
+
+ ### OpenVPN 2.6.4 -- Released 11 May 2023
+ The OpenVPN community project team is proud to release OpenVPN 2.6.4. This is a small bugfix release.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.4/Changes.rst)
+
+ **Note:**
+ - **License amendment:** all **new** commits fall under a modified license that explicitly permits linking with Apache2 libraries (mbedTLS, OpenSSL). See COPYING for details. Existing code will fall under the new license as soon as all contributors have agreed to the change - work ongoing.
+
+ **Feature changes:**
+ - **DCO:** support kernel-triggered key rotation (avoid IV reuse after 2^32 packets). This is the userland side, accepting a message from kernel, and initiating a TLS renegotiation. As of 2.6.4 release, only implemented in FreeBSD kernel.## Windows MSI Changes Since 2.6.3
+
+ - Rebuilt included tap-windows driver with the correct version of the old Windows 7 driver, removing a warning about unsigned driver on Windows 7 installation. See [openvpn-build#365](https://github.com/OpenVPN/openvpn-build/issues/365).
+
+ ### Downloads
+
+ - **Windows 64-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-amd64.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-amd64.msi)
+
+ - **Windows ARM64 MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-arm64.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-arm64.msi)
+
+ - **Windows 32-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-x86.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-x86.msi)
+
+ - **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.4.tar.gz.asc)
+ - [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6.4.tar.gz)
+
+ For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
+
+ ## OpenVPN 2.6.3 -- Released 13 April 2023
+
+ The OpenVPN community project team is proud to release OpenVPN 2.6.3. This is a small bugfix release.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.3/Changes.rst)
+
+ ### Feature Changes
+
+ - Windows: support setting DNS domain in configurations without GUI and DHCP (typically wintun or windco drivers), see [openvpn#306](https://github.com/OpenVPN/openvpn/issues/306).
+
+ ### Windows MSI Changes Since 2.6.2
+
+ - Several Windows-specific issues fixed:
+ - Ensure interactive service stays enabled after silent reinstall, see [openvpn-build#348](https://github.com/OpenVPN/openvpn-build/issues/348), [openvpn-build#349](https://github.com/OpenVPN/openvpn-build/issues/349), and [openvpn-build#351](https://github.com/OpenVPN/openvpn-build/issues/351).
+ - Repair querying install path info for easyrsa-start.bat on some Windows language versions, see [openvpn-build#352](https://github.com/OpenVPN/openvpn-build/issues/352).
+ - MSIs are now built against OpenSSL 3.1.0.
+ - Update included openvpn-gui to 11.41.0.0
+ - This update removes the ability to change the password of a private key from the GUI. This was a niche feature which caused a direct dependency of GUI on OpenSSL. Use openssl.exe directly if you need to edit a private key.
+
+ ### Note: Windows MSI was updated to I002 on April 26th
+
+ - The GPG subkey for creating the .asc files for the downloads has been updated. You might need to re-download or update the GPG key if verifying the signatures.
+ - Fix the encoding of some documentation/sample files included in the installer. See [openvpn-build#358](https://github.com/OpenVPN/openvpn-build/issues/358)
+ - Update include tap-windows6 driver to 9.25.0
+ - Fixes a problem with sending small non-IP packets (e.g., PPPoE) over the VPN connection. See [tap-windows6#158](https://github.com/OpenVPN/tap-windows6/issues/158)
+ - Fixes occasional TCP performance degradation on Windows Server 2022 See [tap-windows6#147](https://github.com/OpenVPN/tap-windows6/pull/147)
+ - Note: The new driver is only used on Windows 10 and newer. We can't rebuild drivers for Windows 7/8 since Microsoft doesn't support the signing mechanism anymore. We include the previous driver version to still allow installation on Windows 7/8.
+ - Update included openvpn-gui to 11.42.0.0
+ - Fixes a problem with passphrase prompt was sometimes not displayed. See [openvpn-gui#619](https://github.com/OpenVPN/openvpn-gui/issues/619)
+ - Adds "Password Reveal" feature which allows you to see passwords while entering them.
+
+ ### Note: Windows MSI was updated to I003 on April 27th
+
+ - Update include tap-windows6 driver to 9.26.0
+ - Revert fix for occasional TCP performance degradation on Windows Server 2022 (GH [tap-windows6#147](https://github.com/OpenVPN/tap-windows6/pull/147)) since users reported BSODs in some (undetermined) scenarios.
+
+ ### Downloads for OpenVPN 2.6.3
+
+ - **Windows 64-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-amd64.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-amd64.msi)
+
+ - **Windows ARM64 MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-arm64.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-arm64.msi)
+
+ - **Windows 32-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-x86.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-x86.msi)
+
+ - **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.3.tar.gz.asc)
+ - [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6.3.tar.gz)
+
+ ## OpenVPN 2.6.2 -- Released 24 March 2023
+
+ The OpenVPN community project team is proud to release OpenVPN 2.6.2. This is mostly a bugfix release with some improvements.For details, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.2/Changes.rst).
+
+ ### Feature Changes:
+ - Implement byte counter statistics for DCO Linux (p2mp server and client).
+ - Implement byte counter statistics for DCO Windows (client only).
+ - `--dns server <n> address ...` now permits up to 8 v4 or v6 addresses.
+
+ **Important note for Linux DCO users**:
+ - New control packets flow for data channel offloading on Linux:
+ Version 2.6.2+ changes the way OpenVPN control packets are handled on Linux when DCO is active, fixing the lockups observed with versions 2.6.0/2.6.1 under high client connect/disconnect activity.
+ This is an **INCOMPATIBLE** change, and therefore an ovpn-dco kernel module older than v0.2.20230323 (commit ID 726fdfe0fa21) will not work anymore and must be upgraded. The kernel module was renamed to "ovpn-dco-v2.ko" to highlight this change and ensure that users and userspace software could easily understand which version is loaded. Attempting to use the old ovpn-dco with 2.6.2+ will lead to disabling DCO at runtime.
+
+ ### Windows MSI Changes since 2.6.1:
+ - Update included OpenVPN-GUI to 11.39.0.0.
+
+ **Windows 64-bit MSI installer**:
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-amd64.msi.asc)
+ - [OpenVPN-2.6.2-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-amd64.msi)
+
+ **Windows ARM64 MSI installer**:
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-arm64.msi.asc)
+ - [OpenVPN-2.6.2-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-arm64.msi)
+
+ **Windows 32-bit MSI installer**:
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-x86.msi.asc)
+ - [OpenVPN-2.6.2-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-x86.msi)
+
+ **Source archive file**:
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.2.tar.gz.asc)
+ - [openvpn-2.6.2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.2.tar.gz)
+
+ ## OpenVPN 2.6.1 -- Released 8 March 2023
+ The OpenVPN community project team is proud to release OpenVPN 2.6.1. This release is mostly focused on bugfixes with some improvements.
+
+ For details, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.1/Changes.rst).
+
+ ### Feature Changes:
+ - **Dynamic TLS Crypt**:
+ When both peers are OpenVPN 2.6.1+, OpenVPN will dynamically create a tls-crypt key that is used for renegotiation. This ensures that only the previously authenticated peer can trigger renegotiation and complete renegotiations.
+ - **CryptoAPI (Windows)**: support issuer name as a selector. Certificate selection string can now specify a partial issuer name string as `--cryptoapicert ISSUER:<string>`, where `<string>` is matched as a substring of the issuer (CA) name in the certificate.
+
+ **Note**: The `configure` script now enables DCO build by default on FreeBSD and Linux. On Linux, this introduces a new default dependency for libnl-genl (for Linux distributions that are too old to have a suitable version of the library, use `configure --disable-dco`).## Windows MSI Changes Since 2.6.0:
+ - Update included ovpn-dco-win driver to 0.9.2
+
+ ### Download Links:
+ - **Windows 64-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-amd64.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-amd64.msi)
+ - **Windows ARM64 MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-arm64.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-arm64.msi)
+ - **Windows 32-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-x86.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-x86.msi)
+ - **Source archive file**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.1.tar.gz.asc), [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6.1.tar.gz)
+
+ ## OpenVPN 2.5.9 -- Released 15 February 2023
+ The OpenVPN community project team is proud to release OpenVPN 2.5.9. This is a small bugfix release.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.5.9/Changes.rst)
+
+ ### Windows MSI Changes Since 2.5.8:
+ - Build against OpenSSL 1.1.1t which contains several security fixes.
+
+ #### Download Links:
+ - **Windows 64-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-amd64.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-amd64.msi)
+ - **Windows ARM64 MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-arm64.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-arm64.msi)
+ - **Windows 32-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-x86.msi.asc), [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-x86.msi)
+ - **Source archive file**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.9.tar.gz.asc), [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.5.9.tar.gz)
+
+ ## OpenVPN 2.6.0 -- Released 25 January 2023
+ The OpenVPN community project team is proud to release OpenVPN 2.6.0. This is a release with some major new features.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.0/Changes.rst)
+
+ ### Changes Since RC2:
+ - Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.0/Changes.rst)
+
+ ### Windows MSI Changes Since RC2:
+ - Included openvpn-gui updated to 11.37.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.37.0.0/CHANGES.rst).
+ - DCO driver is now included as an installer module (msm) so that other products (like OpenVPN Connect) can share the DCO installation.
+
+ #### Note:
+ - MSI was updated to I003 on January 26th: Fixes installation on Windows 7 and a broken tray icon menu with single profile.
+ - MSI was updated to I004 on February 6th: Update included ovpn-dco-win driver to 0.9.0, fixing an issue that breaks Windows boot on some machines. See [Issue #24](https://github.com/OpenVPN/ovpn-dco-win/issues/24).
+ - MSI was updated to I005 on February 15th: Update included ovpn-dco-win driver to 0.9.1, fixing potential crash on machines using "legacy standby" and incompatibility with Citrix DNE Lightweight Filter. Built against OpenSSL 3.0.8.# OpenVPN 2.6.0 Features and Improvements
+
+ ## Key Updates
+ - **Data Channel Offload (DCO)** kernel acceleration support for Windows, Linux, and FreeBSD.
+ - **OpenSSL 3** support, now the default on Windows.
+ - Improved handling of **tunnel MTU**, including support for pushable MTU.
+ - **Outdated cryptographic algorithms** disabled by default, with options to override if necessary.
+ - Reworked **TLS handshake**, enhancing security against replay-packet state exhaustion attacks.
+ - Introduced `--peer-fingerprint` mode for simpler certificate setup and verification.
+ - **Pre-Logon Access Provider support** added to OpenVPN GUI for Windows.
+ - Enhanced **protocol negotiation** for faster connection setup.
+ - Updated **easy-rsa3** bundled with the Windows installer.
+
+ ### Windows Default Settings
+ On Windows, DCO is enabled by default for client connections unless the configuration specifies settings that are not DCO compatible, such as compression.
+
+ ### Linux Requirements
+ For Linux, DCO support necessitates an additional kernel module, available from our [OpenvpnSoftwareRepos software repositories for Linux](https://github.com/OpenVPN/openvpn), and for the OpenVPN3 Linux client.
+
+ ## Download Links
+
+ - **Windows 64-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-amd64.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-amd64.msi)
+
+ - **Windows ARM64 MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-arm64.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-arm64.msi)
+
+ - **Windows 32-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-x86.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-x86.msi)
+
+ - **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.0.tar.gz.asc)
+ - [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6.0.tar.gz)
+
+ ## OpenVPN 2.6_rc2 - Released 12 January 2023
+ The OpenVPN community project team is proud to present OpenVPN 2.6_rc2. This beta release features major new features and updates. For a stable version, download from the [stable release](https://openvpn.net/community-downloads).
+
+ For more details, see the [Changes Document](https://github.com/OpenVPN/openvpn/blob/v2.6_rc2/Changes.rst).
+
+ ### Changes Since RC1:
+ - Added a rate limiter for incoming "initial handshake packets", set to 100 packets per 10 seconds by default.
+ - `CONNECTED,ROUTE_ERROR` status reported to management GUI if connection succeeds but not all routes can be installed (specific to Windows and Linux/Netlink).
+ - Various bug fixes detailed in the [Changes Document](https://github.com/OpenVPN/openvpn/blob/v2.6_rc2/Changes.rst).
+
+ ### MSI and Debian Package Updates Since RC1:
+ - **Windows MSI:** Includes updated openvpn-gui to 11.35.0.0 with new features and fixes for upgrade issues.
+ - **Debian Packages:** Now available for Debian bookworm.
+
+ These enhancements and additions aim to further secure and streamline OpenVPN usage across various platforms.## Changelog for OpenVPN Releases
+
+ ### OpenVPN 2.6_rc2 - Recent Changes
+
+ - Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
+ - Improved protocol negotiation, leading to faster connection setup.
+ - Updated easy-rsa3 bundled with the installer on Windows.
+
+ **Note:** On Windows, DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, which is available from our [software repositories for Linux](OpenvpnSoftwareRepos), and is also available for OpenVPN3 Linux client.
+
+ #### Download Links for Windows
+
+ - **Windows 64-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-amd64.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-amd64.msi)
+ - **Windows ARM64 MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-arm64.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-arm64.msi)
+ - **Windows 32-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-x86.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-x86.msi)
+ - **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc2.tar.gz.asc)
+ - [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc2.tar.gz)
+
+ ### OpenVPN 2.6_rc1 - Released 28 December 2022
+
+ The OpenVPN community project team is proud to announce the release of OpenVPN 2.6_rc1. This version includes several new features and is currently in beta. For those needing a stable release, the [stable version](https://openvpn.net/community-downloads) is also available.
+
+ For detailed changes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_rc1/Changes.rst).
+
+ #### Highlights:
+
+ - Officially deprecated NTLMv1 proxy auth method in 2.6, to be removed in 2.7.
+ - Support for an unlimited number of connection entries and remote entries.
+ - New management commands to enumerate and list remote entries.
+ - Various bug fixes detailed in the [change log](https://github.com/OpenVPN/openvpn/blob/v2.6_rc1/Changes.rst).
+
+ #### Windows MSI Updates:
+
+ - OpenVPN GUI updated to 11.34.0.0, with connections active on exit/logout now automatically restarted in the next session.
+ - Windows installers are now built with Visual Studio 17 2022 (previously Visual Studio 16 2019).
+
+ #### Download Links for Windows
+
+ - **Windows 64-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-amd64.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-amd64.msi)
+ - **Windows ARM64 MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-arm64.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-arm64.msi)
+ - **Windows 32-bit MSI installer**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-x86.msi.asc)
+ - [Download MSI](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-x86.msi)
+ - **Source archive file**
+ - [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc1.tar.gz.asc)
+ - [Download Source](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc1.tar.gz)
+
+ ### OpenVPN 2.6_beta2 - Released 15 December 2022
+
+ The OpenVPN community project team is pleased to release OpenVPN 2.6_beta2, featuring major new features and still in the beta testing phase. For those requiring a stable version, the [stable release](https://openvpn.net/community-downloads) is recommended.For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_beta2/Changes.rst)
+
+ ### Changes since Beta 1:
+
+ - Transport statistics (bytes in/out) for DCO environments. Currently only for Windows clients and FreeBSD servers. Other platforms will be fixed in the next release.
+ - Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_beta2/Changes.rst)
+
+ ### Windows MSI changes since Beta 1:
+ - Included openvpn-gui updated to 11.33.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.33.0.0/CHANGES.rst).
+ - Update included pkcs11-helper so it can load pkcs11 providers from outside of its own install directory.
+ - Add legacy provider for included OpenSSL so that the workarounds documented for old ciphers work on Windows.
+
+ ### New features and improvements in 2.6.0 compared to 2.5.8:
+
+ - Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
+ - OpenSSL 3 support, which is now the default on Windows.
+ - Improved handling of tunnel MTU, including support for pushable MTU.
+ - Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
+ - Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
+ - Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
+ - Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
+ - Improved protocol negotiation, leading to faster connection setup.
+ - Updated easy-rsa3 bundled with the installer on Windows.
+
+ On Windows, DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, available from our [software repositories for Linux](OpenvpnSoftwareRepos), and is also available for OpenVPN3 Linux client.
+
+ ### Installers:
+ - **Windows 64-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-amd64.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-amd64.msi)
+ - **Windows ARM64 MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-arm64.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-arm64.msi)
+ - **Windows 32-bit MSI installer**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-x86.msi.asc), [Download](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-x86.msi)
+ - **Source archive file**: [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta2.tar.gz.asc), [Download](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta2.tar.gz)
+
+ ---
+
+ ### OpenVPN 2.6_beta1 -- Released 2 December 2022
+ The OpenVPN community project team is proud to release OpenVPN 2.6_beta1. This is a release with some major new features and currently in beta. You may find the [stable release](https://openvpn.net/community-downloads) should you require it.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_beta1/Changes.rst)
+
+ This release includes numerous new features and improvements similar to those listed for Beta 2.| Description | GnuPG Signature | Download Link |
+ |-------------|-----------------|---------------|
+ | **Windows 64-bit MSI installer** | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-amd64.msi.asc) | [OpenVPN-2.6_beta1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-amd64.msi) |
+ | **Windows ARM64 MSI installer** | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-arm64.msi.asc) | [OpenVPN-2.6_beta1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-arm64.msi) |
+ | **Windows 32-bit MSI installer** | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-x86.msi.asc) | [OpenVPN-2.6_beta1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-x86.msi) |
+ | **Source archive file** | [GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta1.tar.gz.asc) | [openvpn-2.6_beta1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta1.tar.gz) |
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9