Commit c9d9c9
2025-01-29 12:06:32 Samuli Seppänen: Add development status pages and links to them Signed-off-by: Samuli Seppänen <samuli.seppanen@gmail.com>| /dev/null .. Development/StatusOfOpenvpn24.md | |
| @@ 0,0 1,74 @@ | |
| + | # Introduction |
| + | |
| + | This page shows the high-level status of the OpenVPN 2.4 release. For all the details, see the [Active Tickets by Milestone](report:3) report. |
| + | |
| + | # Schedule |
| + | |
| + | - **November 16** - 2.4_beta1 |
| + | After this date, no new features are allowed; stabilizing starts for real. Some minor "nice to have" patches might be accepted after evaluation/discussion on IRC. |
| + | |
| + | - **(optional) November 24th/25th** - 2.4_beta2 |
| + | Only patches related to stabilizing and important bug-fixes are allowed after this point. No more "nice to have" patches after this point. This release can be skipped if there are no bug fixes or otherwise stabilizing code. |
| + | |
| + | - **December 1st** - 2.4_rc1 |
| + | Only really needed and critical bug fixes allowed. This is also the time where we change to a unified coding style across the whole source code. |
| + | |
| + | - **December 15th** - 2.4_rc2 |
| + | Branching out release/2.4 happens here. |
| + | |
| + | - **December 28th** - 2.4.0 |
| + | Final release. |
| + | |
| + | ## Deadline: Debian 9 freeze |
| + | |
| + | Mattock asked the Debian package maintainer about getting 2.4_something into Debian 9 before the freeze. Here's the response: *"I'll consider uploading 2.4_something in early December, so we have a month to fix possible issues. After December 29, it won't be doable."* |
| + | |
| + | # Features/Fixes to Include |
| + | |
| + | ## Must Have |
| + | |
| + | All done. |
| + | |
| + | ## Minor, but "We Should Try to Make It Happen" |
| + | |
| + | | **Task Description** | **Assigned to** | **Status** | |
| + | | --- | --- | --- | |
| + | | [struct argv overhaul](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12818.html) | d12fk | Patch review completed (dazo), patches 1-4 applied, patches 5-7 need v2 | |
| + | | [auth-gen-token: Inform client why auth-token was rejected](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12848.html) | dazo | Patch review in progress (syzzer) | |
| + | | [tftp/wpad patch](http://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg10511.html) | jjk | Patch on list, needs review and merge | |
| + | | Support TLS record splitting (like ovpn3) | syzzer | #554 (started, but no patches available yet) | |
| + | | [Allow OpenVPN to communicate to peers via a Linux VRF](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12767.html) | - | [Updated patches](https://github.com/OpenVPN/openvpn/pull/65/commits/1baa7e6782b39ed664eedb9b006728d31e22c07e) need review + ML submission | |
| + | | Test server that does --auth-user-pass and/or challenge stuff | cron2 (snair) | Not started | |
| + | | Update auth-user-pass docs | mattock | Not started, discussion [here](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12835.html) | |
| + | | Update OpenVPN PRF (move away from SHA1/MD5) | syzzer | Not started | |
| + | |
| + | ## Work Needed |
| + | |
| + | - Trac tickets (2.3.x, 2.4.x, unclassified) |
| + | |
| + | ## (Major) Items Already Done |
| + | |
| + | - Poor man's NCP (v6) |
| + | - Make openvpnserv2 use exit-events |
| + | - Combined 32/64-bit Windows installers |
| + | - Semi-automated testing of OpenVPN/OpenVPN-GUI/openvpnserv2 on Windows using [openvpn-windows-test](https://github.com/OpenVPN/openvpn-windows-test) |
| + | - dhcp-option DNS6 (stub, windows netsh+service, android) |
| + | - Bundle OpenSSL 1.0.2 on Windows |
| + | - [Refactor CRL handling](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12809.html) |
| + | - [--tls-crypt control channel encryption](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12974.html) #633 |
| + | - ifconfig-before-open reversal patch for Windows fixed (argv_printf) and merged |
| + | - openvpnserv2 integration |
| + | - Pushable ciphers, and cipher negotiation |
| + | - True dual-stack operation (2.3 has "dual single-stack") |
| + | - Interactive service + openvpn-gui integration |
| + | - IPv6 route-gateway redirection |
| + | - AEAD cipher |
| + | - Cipher negotiation (for all but a few corner cases) |
| + | - Peer-id (server and client, 2.3 has only client) |
| + | - Compression v2 = more efficient alignment |
| + | - Unified TCP timeout handling (Arne v3) |
| + | - New buildbots for FreeBSD 10.3, NetBSD 7.0.1, OpenBSD 6.0, MacOS X, various recent Linux versions |
| + | - --multihome fixed on BSD/amd64 architectures, tested by buildbots |
| + | - Recursive routing fixup (Lev v4) |
| + | - Block-outside-dns on multiple tunnels (v2, Selva) |
| + | - Re-indent formatting (dazo, syzzer). More details on CodeStyle |
| \ | No newline at end of file |
| /dev/null .. Development/StatusOfOpenvpn25.md | |
| @@ 0,0 1,92 @@ | |
| + | # Introduction |
| + | |
| + | This page shows the high-level status of OpenVPN 2.5 release. For all the details, see the [Active Tickets by Milestone](report:3) report. |
| + | |
| + | # Schedule |
| + | |
| + | As we missed our original deadline (Debian Buster freeze), we don't have a schedule yet, except "in year 2020". Nevertheless, the release will proceed as follows: |
| + | |
| + | - **2.5_beta1 (August 14)** |
| + | After this date, no new features allowed, stabilizing starts for real. Some minor "nice to have patches" might be accepted after evaluation/discussion on IRC; but should be avoided. |
| + | Git will be branched to release/2.5 at that point. |
| + | |
| + | - **??? - 2.5_beta2 (optional)** |
| + | Only patches related to stabilizing and important bug-fixes are allowed after this point. No more "nice to have patches" after this point. |
| + | If we have no bug fixes or otherwise stabilizing code, this release can be skipped. |
| + | |
| + | - **??? - 2.5_rc1** |
| + | Only really needed and critical bug fixes allowed. |
| + | |
| + | - **??? - 2.5_rc2** |
| + | "If needed" |
| + | |
| + | - **2.5.0 (September 17)** |
| + | Final release. |
| + | |
| + | # Features/Fixes to Include |
| + | |
| + | ## Must Have |
| + | |
| + | | Task Description | Assigned to | Status | Ticket | |
| + | |------------------|-------------|--------|--------| |
| + | | [MSI installers](wiki:OpenvpnMSIInstaller) | mattock | Final integration tests not done | #1122 | |
| + | | update auth-user-pass docs | mattock | not started, discussion [here](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12835.html) | |
| + | | polish auth-token / auth-gen-token corner cases | cron2, plaisthos | pending | - | |
| + | |
| + | ## Postponed Items (former "nice to have" items for 2.5) |
| + | |
| + | | Task Description | Assigned to | Status | Ticket | |
| + | |------------------|-------------|--------|--------| |
| + | | support for multiple-protocol sockets (UDP/TCP) | ordex | wip | |
| + | | Support for multiple sockets (multi-port/multi-IP) | ordex | pending review | #556 | |
| + | | Dynamic routes ('route in ccd-file'), depends on netlink support | ??? | ??? | |
| + | | transport plugin (primary use case: obfuscation) | ordex | wip | |
| + | | [tftp/wpad patch](http://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg10511.html) | jjk | patch on list, needs review and merge | |
| + | | support TLS record splitting (like ovpn3) | syzzer | (started, but no patches available yet) | #554 | |
| + | | test server that does --auth-user-pass and/or challenge stuff | cron2 (snair) | not started | |
| + | | Update OpenVPN PRF (move away from SHA1/MD5) | syzzer | not started | |
| + | | maybe: add PRF plugin interface | ??? | ??? | |
| + | | maybe: add key exchange plugin interface | ??? | ??? | |
| + | | maybe: add data channel separation | ??? | ??? | |
| + | | maybe: fix radius-plugin | ??? | ??? | |
| + | | improve control channel performance | syzzer | ??? | |
| + | |
| + | ## Work Needed |
| + | - trac tickets (2.4.x, 2.5.x, unclassified) |
| + | - MSI testing and user documentation |
| + | |
| + | ## Items Already Done |
| + | - remove ENABLE_CRYPTO |
| + | - [ChaCha20-Poly1305 support for the data channel](https://patchwork.openvpn.net/patch/496/) |
| + | - tls-crypt-v2 (#1121) |
| + | - MSI packaging |
| + | - [struct argv overhaul](https://patchwork.openvpn.net/project/openvpn2/list/?series=638) |
| + | - [Wintun support](https://patchwork.openvpn.net/patch/824/) |
| + | - [Auth failure messages back to client](https://patchwork.openvpn.net/project/openvpn2/list/?series=543&submitter=&state=3&q=&archive=&delegate=) |
| + | - #6 - VLAN patch set |
| + | - #1123 - Netlink support (includes route.c / tun.c refactoring) |
| + | - [IPv6-only server](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg16998.html) | ordex & cron2 | most of the work is done! some details remain to be cleaned up | #208 | |
| + | - Implement asymmetric compression | plaisthos | v5 merged (lev/cron2) | |
| + | - [Allow OpenVPN to communicate to peers via a Linux VRF](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12767.html) | cron2 | patch v2 on the list & merged | |
| + | - man page formatting change | dazo | [merged](https://gitlab.com/openvpn/openvpn/-/commit/f500c49c8e0a77ce665b11f6adbea4029cf3b85f) | |
| + | - async client-connect support | plaisthos + ordex | [Merged](https://patchwork.openvpn.net/project/openvpn2/list/?series=827&state=*) | |
| + | |
| + | # Missing Pieces from MSI |
| + | |
| + | Bundling OpenVPN as an MSI will require changes to several projects: openvpn, openvpnserv2, openvpn-build, and tap-windows6. Here's a list of the missing pieces (hopefully) in the order in which they should be merged: |
| + | |
| + | 1. ~~[openvpn: the openvpnmsica and tapctl patch series](https://patchwork.openvpn.net/project/openvpn2/list/?series=662)~~ |
| + | 2. [tap-windows6: MSM packaging](https://github.com/OpenVPN/tap-windows6/pull/106) |
| + | 3. [openvpn-build: Windows MSI packaging](https://github.com/OpenVPN/openvpn-build/pull/141) |
| + | 4. [openvpn-vagrant: Add MSI build support](https://github.com/OpenVPN/openvpn-vagrant/pull/7) |
| + | - Needs to be adapted to final upstream URLs before merging |
| + | |
| + | ## Dropping tap-windows6 NSI Changes? |
| + | |
| + | I (mattock) propose we **drop** the following tap-windows6 PRs that change the **NSIS** installer: |
| + | |
| + | - [installer: Refine the WoW64 decision logic](https://github.com/OpenVPN/tap-windows6/pull/98) |
| + | - [installer: Select Win7/8/8.1 vs. Win10 driver at runtime](https://github.com/OpenVPN/tap-windows6/pull/99) |
| + | - [installer: Add code signing certificate before installing the driver](https://github.com/OpenVPN/tap-windows6/pull/100) |
| + | |
| + | Current OpenVPN / tap-windows6 NSIS installers are working well across all the platforms, so I'd prefer not to "rock the boat" by introducing changes unnecessarily. Also, I believe the above PRs were originally meant for OpenVPN 2.5, not for 2.4. And OpenVPN 2.5 does not need these PRs anymore now that we have [MSM packaging](https://github.com/OpenVPN/tap-windows6/pull/106) for tap-windows6. Even if we did decide that the above PRs make sense for 2.4, our support policy says that 2.4 would move to "Old stable" in ~6 months after 2.5.0, after which we would not provide any Windows installers. So the gain for 2.4 would be rather small, maybe for one or two 2.4.x releases at most. |
| \ | No newline at end of file |
| /dev/null .. Development/StatusOfOpenvpn26.md | |
| @@ 0,0 1,69 @@ | |
| + | # Introduction |
| + | |
| + | This page shows the high-level status of the OpenVPN 2.6 release. For all the details, see the [Active Tickets by Milestone](report:3) report. |
| + | |
| + | # Schedule |
| + | |
| + | Currently planned: |
| + | - All "must have" code in and all major (crash) bugs fixed: January 11, 2023 |
| + | - RC candidates: December 28, 2022, and January 12, 2023 |
| + | - 2.6.0 release: January 26, 2023 |
| + | |
| + | # Features/Fixes to Include |
| + | |
| + | ## Must Have |
| + | |
| + | | Task Description | Assigned to | Status | Ticket | Patchwork | |
| + | |------------------|-------------|--------|--------|-----------| |
| + | | DCO (on Linux) | ordex, plaisthos, cron2 | merged, now ironing out bugs (p2p reconnection) | - | [Series 1516](https://patchwork.openvpn.net/project/openvpn2/list/?series=1516) | |
| + | | DCO (on Windows) | lev, d12fk, plaisthos, ordex | merged, ironing out bugs (--windows-driver, --disable-dco quirks) | - | [Series 1516](https://patchwork.openvpn.net/project/openvpn2/list/?series=1516) | |
| + | | DCO (on FreeBSD) | kp, cron2 | merged, fine-tuning (/24-on-/24 iroute, peer stats, exit notification with stats) | - | - | |
| + | | Update auth-user-pass docs | mattock | wip: man-page updates ([discussion](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12835.html)) | - | - | |
| + | | TLS handshake replay protection (up for discussion) | plaisthos | pending review | - | [patch 2747](https://patchwork.openvpn.net/patch2747) | |
| + | | Sort out multiple-plugin auth mess | dazo, cron2 | on-going | - | [RFC patch 2327](https://patchwork.openvpn.net/patch/2327/) | |
| + | |
| + | ### Must Have - Completed/Done |
| + | |
| + | | Task Description | Assigned to | Status | Ticket | Patchwork | |
| + | |------------------|-------------|--------|--------|-----------| |
| + | | Frame/buffer size handling | plaisthos | **done** | - | - | |
| + | | OpenSSL 3.0.0 support | plaisthos | mostly **done** 2021-11-12 | - | - | |
| + | | OpenSSL 3.0.0 xkey | selva | **done** 2022-01-20 | - | - | |
| + | | Switch to 3.0.1 for Windows builds | lev, mattock | **done** | - | - | |
| + | | OpenSSL Config file handling | lev, selva(?) | **done** 2021-11-24 | - | - | |
| + | | `--nobind` for `--pull` by default | plaisthos | **done** 2021-12-06 | #936, #877 | - | |
| + | | DNS option rework (split DNS) - new option parsing | d12fk | **done** ([commit b3e0d95dcf](https://gitlab.com/openvpn/openvpn/-/commit/b3e0d95dcfd0de2a5fe6545fed8f46e0dd35784d)) | - | [patch 2494](https://patchwork.openvpn.net/patch/2494/) | |
| + | | Review INSTALL, README, PORTS, etc. files | cron2 | done | - | - | |
| + | | Do not push route-ipv6 entries that are also in the iroute-ipv6 list | ordex, cron2 | done, commit 437812d4eac9 | #354 | [patch 332](https://patchwork.openvpn.net/patch/332) | |
| + | | Polish auth-token / auth-gen-token corner cases | cron2, plaisthos, selva | "seems to be all in good shape now" | - | [patch 2303](https://patchwork.openvpn.net/patch/2303/), [patch 2488](https://patchwork.openvpn.net/patch/2488) | |
| + | | DDoS reflection hardening (rate-limiting) | plaisthos, cron2 | merged | - | - | |
| + | |
| + | ## Nice to Have / Wild Ideas |
| + | |
| + | | Task Description | Assigned to | Status | Ticket | Patchwork | |
| + | |------------------|-------------|--------|--------|-----------| |
| + | | Implement kqueue on MacOS | plaisthos | wip (but slower than poll()) | - | - | |
| + | | DNS option rework (split DNS) - Windows backend | lev, d12fk | not started | - | - | |
| + | | Support TLS alerts | plaisthos | ??? | - | - | |
| + | | AUTH_TEMP_FAIL ("I cannot handle you *now*, but please come back later") | plaisthos | review pending | - | [series 1580](https://patchwork.openvpn.net/project/openvpn2/list/?series=1580) | |
| + | | Test server that does --auth-user-pass and/or challenge stuff | cron2 (snair) | --auth-user-pass done, challenge missing | - | - | |
| + | | Update OpenVPN PRF (move away from SHA1/MD5) | syzzer/plaisthos | done(?) | - | - | |
| + | | Maybe: fix radius-plugin | ??? | ??? | - | - | |
| + | | Test framework improvements (local "make check" crypto tests) | syzzer | - | - | - | |
| + | |
| + | ## Unlikely to Happen, Keeping the List |
| + | |
| + | | Task Description | Assigned to | Status | Ticket | Patchwork | |
| + | |------------------|-------------|--------|--------|-----------| |
| + | | Inner VRF support? | ?? | ?? | ?? | ?? | |
| + | | Route monitoring (enable clients to react to network changes) | cron2 | not started | - | - | |
| + | | Maybe: add PRF plugin interface | ??? | ??? | - | - | |
| + | | Maybe: add key exchange plugin interface (allows easily doing e.g., post-quantum kex) | ??? | ??? | - | - | |
| + | | Maybe: add data channel separation (or, move to ovpn3, which already has this?) | ??? | ??? | - | - | |
| + | | Dynamic routes ('route in ccd-file'), depends on netlink support | ??? | ??? | - | - | |
| + | | Transport plugin (primary use case: obfuscation) | ordex | wip | - | - | |
| + | | [tftp/wpad patch](http://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg10511.html) | jjk | patch on list, needs review and merge | - | - | |
| + | | Support TLS record splitting (like ovpn3) | syzzer | (started, but no patches available yet) | #554 | - | |
| + | | Support for multiple-protocol sockets (UDP/TCP) | ordex | wip | - | - | |
| + | | Support for multiple sockets (multi-port/multi-IP) | ordex | pending review | #556 | - | |
| + | | Improve control channel performance (further) - redo reliability layer, introduce windowing/scaling | syzzer | ??? | - | - | |
| \ | No newline at end of file |
| /dev/null .. Development/StatusOfOpenvpn27.md | |
| @@ 0,0 1,77 @@ | |
| + | # Introduction |
| + | |
| + | This page shows the high-level status of OpenVPN 2.7 release. If you want all the details, see the [Active Tickets by Milestone](report:3) report. |
| + | |
| + | # Schedule |
| + | |
| + | Release is roughly planned for two years after OpenVPN 2.6. So end of 2024 or beginning of 2025. |
| + | It was discussed that we should provide official preview builds earlier this time to gather more feedback for merged changes. |
| + | Also, the experience from the 2.6 release was to branch off release/2.7 later, since branching it off too early causes a lot of work for little benefit. |
| + | |
| + | # Features/fixes to include |
| + | |
| + | ## completed/done |
| + | |
| + | | **Task description** | **Assigned to** | **Status** | **Ticket** | **Patchwork / Gerrit** | |
| + | |----------------------|-----------------|------------|------------|------------------------| |
| + | | Switch from MSVC buildsystem to CMake for Windows builds | djpig | Done | - | [Change 266](https://gerrit.openvpn.net/c/openvpn/+/266) | |
| + | | Remove deprecated `--no-replay` | djpig | Done | [Deprecated Options](wiki:DeprecatedOptions#Option:--no-replayStatus:RemovedinOpenVPNv2.7) | [Change 281](https://gerrit.openvpn.net/c/openvpn/+/281) | |
| + | | Make it harder to use `--secret` | plaisthos | Done | [Deprecated Options](wiki:DeprecatedOptions#Option:--secretStatus:Deprecatedpendingremoval) | [Change 325](https://gerrit.openvpn.net/c/openvpn/+/325) | |
| + | | Remove deprecated NTLM v1 support | djpig | Done | [Deprecated Options](wiki:DeprecatedOptions#NTLMv1authenticationsupportin--http-proxyStatus:Deprecatedpendingremoval) | [Change 379](https://gerrit.openvpn.net/c/openvpn/+/379) [Change 500](https://gerrit.openvpn.net/c/openvpn/+/500) | |
| + | | Support TLS alerts | plaisthos | Done | - | [Change 449](https://gerrit.openvpn.net/c/openvpn/+/449) | |
| + | | Change default for `--topology` to `subnet` | djpig | Done | [Deprecated Options](wiki:DeprecatedOptions#Changedefault--topologynet30tosubnetStatus:Pending) | [Change 421](https://gerrit.openvpn.net/c/openvpn/+/421) | |
| + | | afunix/lwipovpn | plaisthos, cron2 | Done | - | [lwipovpn topic](https://gerrit.openvpn.net/q/topic:%22lwipovpn%22) | |
| + | | Tunnelcrack improvements for Windows | d12fk | Done | - | [Change 489](https://gerrit.openvpn.net/c/openvpn/+/489) | |
| + | |
| + | ## must have (might block the release) |
| + | |
| + | | **Task description** | **Assigned to** | **Status** | **Ticket** | **Gerrit / Patchwork** | |
| + | |----------------------|-----------------|------------|------------|------------------------| |
| + | | DNS option rework (split DNS) - windows backend | lev, d12fk | WIP | - | - | |
| + | | Support for multiple-protocol sockets (UDP/TCP) | Giaan | Gerrit | #556 | [multisocket topic](https://gerrit.openvpn.net/q/topic:%22multisocket%22) | |
| + | | New API for DCO kernel module on Linux | ordex | Trying to get in mainline first | - | - | |
| + | | Remove wintun driver support | lev | TBD | - | - | |
| + | | Remove support for compression on send | djpig | Gerrit | - | [Change 755](https://gerrit.openvpn.net/c/openvpn/+/755) | |
| + | |
| + | ## should have |
| + | |
| + | | **Task description** | **Assigned to** | **Status** | **Ticket** | **Gerrit / Patchwork** | |
| + | |----------------------|-----------------|------------|------------|------------------------| |
| + | | Data v3 format with AES rekeying | plaisthos, syzzer | WIP | - | - | |
| + | | Tunnelcrack improvements for Linux | d12fk | TBD | - | - | |
| + | | `--cipher`/`--data-ciphers` add DEFAULT syntax | plaisthos | TBD | - | - | |
| + | |
| + | ## nice to have / wild ideas |
| + | |
| + | | **Task description** | **Assigned to** | **Status** | **Ticket** | **Patchwork / Gerrit** | |
| + | |----------------------|-----------------|------------|------------|------------------------| |
| + | | Bloom-filter DDoS protection | plaisthos | Gerrit | - | [bloom topic](https://gerrit.openvpn.net/q/topic:%22bloom%22) | |
| + | | Live route updates / push-update | mrbff | Gerrit | - | [push-update-client topic](https://gerrit.openvpn.net/q/topic:%22PushUpdateClient%22) | |
| + | | dco-win multipeer (--server) | lev | WIP | - | - | |
| + | | HAProxy support | ralf_lici | Gerrit | - | [proxy-protocol topic](https://gerrit.openvpn.net/q/topic:%22proxy-protocol%22) | |
| + | | Transport plugin (primary use case: obfuscation) | giaan | WIP | - | - | |
| + | | Remove deprecated --ns-cert-type | - | - | [Deprecated Options](wiki:DeprecatedOptions#Option:--ns-cert-typeStatus:Pendingremoval) | - | |
| + | | Remove deprecated --tun-ipv6 | - | - | [Deprecated Options](wiki:DeprecatedOptions#Option:--tun-ipv6Status:Ignoredpendingremoval) | - | |
| + | | Remove deprecated --max-routes | - | - | [Deprecated Options](wiki:DeprecatedOptions#Option:--max-routesStatus:Ignoredpendingremoval) | - | |
| + | | Remove deprecated --dhcp-release | - | - | [Deprecated Options](wiki:DeprecatedOptions#Option:--dhcp-releaseStatus:Ignoredpendingremoval) | - | |
| + | | Properly deprecate _v1 and _v2 plugin functions | - | - | [Deprecated Options](wiki:DeprecatedOptions#plugin:_v1and_v2functionsforopenandfunccallStatus:Pendingremoval) | - | |
| + | | Deprecate NTLM v2 support | djpig | - | [Deprecated Options](wiki:DeprecatedOptions#NTLMv2authenticationsupportin--http-proxyStatus:Tobedeprecatedin2.7) | - | |
| + | | Implement kqueue on MacOS | plaisthos | wip (but slower than poll()) | - | - | |
| + | | Sort out multiple-plugin auth mess | dazo, cron2 | on-going | - | [RFC patch 2327](https://patchwork.openvpn.net/patch/2327/) | |
| + | | Improve NM-OVPN integration | cron2 | trying to establish contact | - | - | |
| + | | Make TAP6-Windows Really Fast | lev | not started | - | - | |
| + | | SRV patch (set) | ? | patch needs work | - | - | |
| + | | Test server that does --auth-user-pass and/or challenge stuff | cron2 (snair) | --auth-user-pass done, challenge missing | - | - | |
| + | | Update OpenVPN PRF (move away from SHA1/MD5) | syzzer/plaisthos | done(?) | - | - | |
| + | | Maybe: fix radius-plugin - plugin is useful but not maintained very well | ??? | ??? | - | - | |
| + | | Test framework improvements (local "make check" crypto tests) | syzzer | - | - | - | |
| + | | Inner VRF support? | ?? | ?? | ?? | - | |
| + | | Route monitoring (enable clients to react to network changes) | cron2 | not started | - | - | |
| + | | Maybe: add PRF plugin interface | ??? | ??? | - | - | |
| + | | Maybe: add key exchange plugin interface (allows easily doing .e.g post quantum kex) | ??? | ??? | - | - | |
| + | | Maybe: add data channel separation (or, move to ovpn3, which already has this?) | ??? | ??? | - | - | |
| + | | Investigate TUNSLMODE on FreeBSD and NetBSD to get rid of iroute table (iroutes become normal system routes) | cron2 | not started | - | - | |
| + | | Dynamic routes ('route in ccd-file'), depends on netlink support | ordex | not started | - | - | |
| + | | [tftp/wpad patch](http://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg10511.html) | jjk | patch on list, needs review and merge | - | - | |
| + | | Support TLS record splitting (like ovpn3) | syzzer | (started, but no patches available yet) | #554 | - | |
| + | | Improve control channel performance (further) - redo reliability layer, introduce windowing / scaling | syzzer | ??? | - | - | |
| \ | No newline at end of file |
| Meetings/2016/2016-06-13.md .. | |
| @@ 6,7 6,7 @@ | |
| # Topics | |
| ## OpenVPN 2.4 patches (these are the priority) | |
| - | - For overview, see [StatusOfOpenvpn24](wiki:StatusOfOpenvpn24) |
| + | - For overview, see [StatusOfOpenvpn24](../../Development/StatusOfOpenvpn24) |
| - [PATCHv2 3/5: Add client-side support for cipher negotiation](http://article.gmane.org/gmane.network.openvpn.devel/11869) | |
| - [PATCHv2 4/5: Add options to restrict cipher negotiation](http://article.gmane.org/gmane.network.openvpn.devel/11872) | |
| - [PATCHv2 5/5: Add server-side support for cipher negotiation](http://article.gmane.org/gmane.network.openvpn.devel/11873) | |
| Meetings/2016/2016-10-10.md .. | |
| @@ 10,7 10,7 @@ | |
| - [http://build.openvpn.net/downloads/temp/openvpn-install-2.3_git-do-ifconfig-after-tun-v2-I601-i686.exe](http://build.openvpn.net/downloads/temp/openvpn-install-2.3_git-do-ifconfig-after-tun-v2-I601-i686.exe) | |
| - [http://build.openvpn.net/downloads/temp/openvpn-install-2.3_git-do-ifconfig-after-tun-v2-I601-x86_64.exe](http://build.openvpn.net/downloads/temp/openvpn-install-2.3_git-do-ifconfig-after-tun-v2-I601-x86_64.exe) | |
| 2. OpenVPN 2.4-alpha1 release | |
| - | - [Release status page](wiki:StatusOfOpenvpn24) |
| + | - [Release status page](../../Development/StatusOfOpenvpn24) |
| 3. OpenVPN 2.3.13 release | |
| - | [Back to meeting list](..) |
| \ | No newline at end of file |
| + | [Back to meeting list](..) |
| Meetings/2016/2016-11-07.md .. | |
| @@ 13,7 13,7 @@ | |
| - CI systems can poll patchwork and auto-test apply + compile incoming patches (using throwaway VMs that get reset after each test run) | |
| - Quagga is doing this [Quagga Patchwork](https://patchwork.quagga.net/project/quagga/list/) | |
| 2. **OpenVPN 2.4 - next steps?** | |
| - | - [Release status page](wiki:StatusOfOpenvpn24) |
| + | - [Release status page](../../Development/StatusOfOpenvpn24) |
| - RFC: deprecate or remove `--key-method 1`? | |
| - Getting 2.4 into Debian 9 | |
| - Mail from the Debian package maintainer: "I'll consider uploading 2.4_something in early December, so we have a month to fix possible issues. After December 29 it won't be doable." | |
| Meetings/2016/2016-11-14.md .. | |
| @@ 6,7 6,7 @@ | |
| # Topics | |
| 1. OpenVPN 2.4 - next steps? | |
| - | - [Release status page](wiki:StatusOfOpenvpn24) |
| + | - [Release status page](../../Development/StatusOfOpenvpn24) |
| - RFC: deprecate or remove `--key-method 1`? | |
| 2. OpenVPN 2.3.14 release | |
| - what is missing? | |
| Meetings/2016/2016-11-23.md .. | |
| @@ 6,7 6,7 @@ | |
| # Topics | |
| 1. OpenVPN 2.4 - next steps? | |
| - | - [Release status page](wiki:StatusOfOpenvpn24) |
| + | - [Release status page](../../Development/StatusOfOpenvpn24) |
| 2. OpenVPN 2.3.14 release | |
| - what is missing? | |
| Meetings/2016/2016-11-30.md .. | |
| @@ 6,7 6,7 @@ | |
| # Topics | |
| 1. OpenVPN 2.4 - next steps? | |
| - | - [Release status page](wiki:StatusOfOpenvpn24) |
| + | - [Release status page](../../Development/StatusOfOpenvpn24) |
| - trac#775 - decide what to do (just remove the "net stop dnscache" calls?) | |
| 2. OpenVPN 2.3.14 release | |
| - Release date? | |
| Meetings/2016/2016-12-07.md .. | |
| @@ 6,7 6,7 @@ | |
| # Topics | |
| 1. **OpenVPN 2.4 - next steps?** | |
| - | - [Release status page](wiki:StatusOfOpenvpn24) |
| + | - [Release status page](../../Development/StatusOfOpenvpn24) |
| - mechanics of the code reformatting - who, where, how to review, ...? | |
| 2. **patchwork status** | |
| 3. **Stripping out user choices from the Windows installer** | |
| Meetings/2016/2016-12-14.md .. | |
| @@ 6,6 6,6 @@ | |
| # Topics | |
| 1. OpenVPN 2.4 - next steps? | |
| - | - [Release status page](wiki:StatusOfOpenvpn24) |
| + | - [Release status page](../../Development/StatusOfOpenvpn24) |
| [Back to meeting list](..) | |
| \ | No newline at end of file |
| Meetings/2016/2016-12-21.md .. | |
| @@ 6,7 6,7 @@ | |
| # Topics | |
| ## 1. OpenVPN 2.4 - next steps? | |
| - | - [Release status page](wiki:StatusOfOpenvpn24) |
| + | - [Release status page](../../Development/StatusOfOpenvpn24) |
| ## 2. Decommissioning openvpn-testing.git (proposal from dazo) | |
| - The testing git repo has not served the purpose it was designed for in a long time, due to the development model having changed dramatically. | |
| Meetings/2019/2019-03-12.md .. | |
| @@ 6,7 6,7 @@ | |
| # Topics | |
| 1. OpenVPN 2.5 updates / planning | |
| - | - Update [status page](wiki:StatusOfOpenvpn25) which is badly outdated |
| + | - Update [status page](../../Development/StatusOfOpenvpn25) which is badly outdated |
| 2. tap-windows6 HLK testing updates | |
| 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/) | |
| Meetings/2020/2020-03-26.md .. | |
| @@ 7,7 7,7 @@ | |
| 1. Review [PATCHv3: travis-ci: add arm64, s390x builds](https://patchwork.openvpn.net/patch/1045/) | |
| 2. OpenVPN 2.5 updates / planning | |
| - | - Merging MSI/MSM-related changes (see [status page](wiki:StatusOfOpenvpn25)) |
| + | - Merging MSI/MSM-related changes (see [status page](../../Development/StatusOfOpenvpn25)) |
| 3. Review patches on [Patchwork](https://patchwork.openvpn.net/project/openvpn2/list/) | |
| # Topics on hold | |
| Meetings/2024/2024-09-25.md .. | |
| @@ 11,7 11,7 @@ | |
| - **Done: OpenVPN Community Meetup 2024** | |
| - Meetup was concluded. 13 persons in attendance. | |
| - | - Much time was spent planning the 2.7 release. Planned for January 2025. (Not yet reflected on wiki:StatusOfOpenvpn27) |
| + | - Much time was spent planning the 2.7 release. Planned for January 2025. (Not yet reflected on ../../Development/StatusOfOpenvpn27) |
| - Meeting notes: [https://cryptpad.fr/pad/#/2/pad/edit/KPJKt7RSPrvC9grrvQ0KhbwE/](https://cryptpad.fr/pad/#/2/pad/edit/KPJKt7RSPrvC9grrvQ0KhbwE/) | |
| - **New: --dns Patch Review Upcoming** | |
| Meetings/2024/2024-10-02.md .. | |
| @@ 10,7 10,7 @@ | |
| ### Current topics | |
| - **Release 2.7** | |
| - | [StatusOfOpenvpn27](wiki:StatusOfOpenvpn27) was updated with the results from Karlsruhe meetup. |
| + | [StatusOfOpenvpn27](../../Development/StatusOfOpenvpn27) was updated with the results from Karlsruhe meetup. |
| Compare [CommunityMeetup2024](wiki:CommunityMeetup2024). | |
| Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right. | |
| Meetings/2024/2024-10-09.md .. | |
| @@ 24,7 24,7 @@ | |
| _The tests against latest git master server against older openvpn client versions are almost done._ | |
| - **Release 2.7** | |
| - | _[StatusOfOpenvpn27](wiki:StatusOfOpenvpn27) was updated with the results from Karlsruhe meetup._ |
| + | _[StatusOfOpenvpn27](../../Development/StatusOfOpenvpn27) was updated with the results from Karlsruhe meetup._ |
| _compare [CommunityMeetup2024](wiki:CommunityMeetup2024)._ | |
| _Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right._ | |
| Meetings/2024/2024-10-16.md .. | |
| @@ 37,7 37,7 @@ | |
| *The tests against latest git master server against older openvpn client versions are almost done.* | |
| - **Release 2.7** | |
| - | *wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.* |
| + | *../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.* |
| *compare wiki:CommunityMeetup2024.* | |
| *Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right.* | |
| Meetings/2024/2024-10-23.md .. | |
| @@ 44,7 44,7 @@ | |
| - The tests against latest git master server against older openvpn client versions are almost done. | |
| - **Release 2.7** | |
| - | - wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| + | - ../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| - compare wiki:CommunityMeetup2024. | |
| - Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right. | |
| Meetings/2024/2024-10-30.md .. | |
| @@ 42,7 42,7 @@ | |
| _The tests against latest git master server against older openvpn client versions are almost done._ | |
| - **Release 2.7** | |
| - | _wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup._ |
| + | _../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup._ |
| _compare wiki:CommunityMeetup2024._ | |
| _Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right._ | |
| Meetings/2024/2024-11-06.md .. | |
| @@ 46,7 46,7 @@ | |
| _The tests against latest git master server against older openvpn client versions are almost done._ | |
| - **Release 2.7** | |
| - | _wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup._ |
| + | _../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup._ |
| _compare wiki:CommunityMeetup2024._ | |
| _Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right._ | |
| Meetings/2024/2024-11-13.md .. | |
| @@ 54,7 54,7 @@ | |
| The tests against latest git master server against older openvpn client versions are almost done. | |
| - **Release 2.7** | |
| - | wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| + | ../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| compare wiki:CommunityMeetup2024. | |
| Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right. | |
| Meetings/2024/2024-11-20.md .. | |
| @@ 64,7 64,7 @@ | |
| T-shirts: yes. | |
| - **Release 2.7** | |
| - | wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| + | ../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| compare wiki:CommunityMeetup2024. | |
| Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right. | |
| Meetings/2024/2024-11-27.md .. | |
| @@ 71,7 71,7 @@ | |
| - *Instead, we could create an openvpn3-builds@ ML. djpig will look into that.* | |
| - **Release 2.7** | |
| - | - *wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.* |
| + | - *../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.* |
| - *compare wiki:CommunityMeetup2024.* | |
| - *Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right.* | |
| Meetings/2024/2024-12-04.md .. | |
| @@ 71,7 71,7 @@ | |
| *maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work.* | |
| - **Release 2.7** | |
| - | *wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.* |
| + | *../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.* |
| *compare wiki:CommunityMeetup2024.* | |
| *Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right.* | |
| Meetings/2024/2024-12-11.md .. | |
| @@ 72,7 72,7 @@ | |
| _maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work._ | |
| - **Release 2.7** | |
| - | _wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup._ |
| + | _../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup._ |
| _compare wiki:CommunityMeetup2024._ | |
| _Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right._ | |
| Meetings/2025/2025-01-08.md .. | |
| @@ 47,7 47,7 @@ | |
| [Gerrit DCO Windows Multi-peer](https://gerrit.openvpn.net/c/openvpn/+/815) | |
| - **Updated: Release 2.7** | |
| - | wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| + | ../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| compare wiki:CommunityMeetup2024. | |
| Want to do a first preview release as soon as possible, but need to get at least one of the big patch series in, preferably multi-socket. | |
| Meetings/2025/2025-01-15.md .. | |
| @@ 41,7 41,7 @@ | |
| [DNS option gerrit link](https://gerrit.openvpn.net/q/topic:%22dns+option%22) | |
| - **Release 2.7** | |
| - | wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| + | ../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| compare wiki:CommunityMeetup2024. | |
| Want to do a first preview release as soon as possible, but need to get at least one of the big patch series in, preferably multi-socket. | |
| Meetings/2025/2025-01-22.md .. | |
| @@ 41,7 41,7 @@ | |
| - [DNS Option Review](https://gerrit.openvpn.net/q/topic:%22dns+option%22) | |
| - **Release 2.7** | |
| - | - wiki:StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| + | - ../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup. |
| - Compare with wiki:CommunityMeetup2024. | |
| - Want to do a first preview release as soon as possible, but need to get at least one of the big patch series in, preferably multi-socket. | |
| Pages/Managing TAP-Windows drivers.md .. | |
| @@ 10,7 10,7 @@ | |
| **NOTES:** | |
| - OpenVPN 2.3_alpha1 and earlier `devcon.exe` was called `tapinstall.exe`. | |
| - | - OpenVPN 2.3_rc2 installer does not install TAP utilities by default. [This bug](ticket:255) is fixed in later releases. |
| + | - OpenVPN 2.3_rc2 installer does not install TAP utilities by default. This bug is fixed in later releases. |
| # Manual configuration of the TAP-Windows adapter | |
| On XP Go to `Start -> Control Panel -> Network Connections`. | |
| @@ 93,7 93,7 @@ | |
| Windows also has command line utilities to accomplish these same kinds of tasks such as "devcon", "netsh", and "ipconfig". | |
| # Renaming the TAP-driver | |
| - | Look at [this page](wiki:TapRenameScript) for a script that can be used to rename TAP-drivers. |
| + | Look at [this page](Tap%20rename%20script) for a script that can be used to rename TAP-drivers. |
| # Debugging installation problems | |
| People occasionally report tap-windows installation issues, assuming they are all caused by a single bug, because `devcon.exe` gives the same error message/code. This is unfortunately not the case, and the reason for an install failure could be: | |
