Commit dc3121
2025-11-05 13:53:08 novaflash: -/-| /dev/null .. Meetings/2025/2025-11-05.md | |
| @@ 0,0 1,67 @@ | |
| + | # Basic info |
| + | |
| + | * Time: Wednesday 5 November 2025 at 14:00 CEST (12:00 UTC) |
| + | * Place: #openvpn-meeting channel on !LiberaChat IRC network |
| + | |
| + | # Topics |
| + | |
| + | - **Updated: Release 2.7** |
| + | OpenVPN 2.7 release candidate 1 was released 31st of October. |
| + | There were some reports of bugs and issues, which are being fixed and prepared for the rc2 release. |
| + | |
| + | - **New: Release 2.6.16** |
| + | Some of the issues also affected 2.6 code. |
| + | So a 2.6.16 release seems prudent, to coincide with similar/same fixes done in 2.7rc2. |
| + | |
| + | - **Updated, closed: wolfSSL license changed from gplv2 to gplv3** |
| + | The release notes of wolfSSL indicate the license changed to GPLv3. |
| + | This basically makes wolfSSL incompatible in regards to licensing with OpenVPN, because OpenVPN is GPLv2 licensed. |
| + | After a discussion between maxF, plaisthos, from OpenVPN community, and people from wolfSSL, a conclusion was reached. |
| + | wolfSSL believes that an exception to allow linking wolfSSL with OpenVPN is sufficient. They will implement such an exception in their license. |
| + | For us this means the topic is closed. |
| + | |
| + | - **New: community meetup 2026** |
| + | Tentatively in Paderborn, Germany. |
| + | |
| + | - **forums situation** |
| + | minx from OpenVPN Inc. originally set up flarum and started migration process, but he left the company before completion. |
| + | Now we have eduardo at OpenVPN Inc. who is taking a look and he managed to get migration working. |
| + | He suggests some further migration testing, and to then plan a hard cutover date. |
| + | |
| + | ## Backlog |
| + | |
| + | - **t_server and t_client testing framework** |
| + | mattock reports that he's started publishing his work for t_server in this location: |
| + | https://github.com/mattock/openvpn-tests/tree/t_server_template/t_server |
| + | |
| + | - **format code using clang formatting** |
| + | It seems prudent to do this before the real 2.7 release. |
| + | It was discussed and there's some additional work to be paid either on reviewer or submitter side. |
| + | Strategy will be; get all code into beta1, collect bugfixes, reformat everything, then beta2. |
| + | Collect more bugfixes and then do release 2.7.0 and branch it off into its own release branch. |
| + | |
| + | - **push_update / live route updates** |
| + | Client-side support for push_update is now merged. |
| + | For server-side support, company did QA on it with openvpn2 but found some missing features that are being added now. |
| + | Client-side support made it into alpha3. |
| + | |
| + | - **2.7 security audit** |
| + | ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code. |
| + | |
| + | - **Tunnelcrack progress (see TunnelCrack community wiki article)** |
| + | Status update on TunnelCrack mitigations: |
| + | The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this. |
| + | Windows, openvpn2: block-local merged to master, not to 2.6.x. openvpn3: in code review. |
| + | Linux, openvpn2: in progress. openvpn3: in progress. |
| + | macOS: to be determined. |
| + | iOS: to be determined. |
| + | Android: not vulnerable. |
| + | |
| + | - **donation collection** |
| + | From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations. |
| + | What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on. |
| + | There are some options to consider. There may be existing solutions that we want to consider. |
| + | PayPal seems overly expensive with all their fees. |
| + | Stripe could be worth considering for credit card processing. |
| + | GitHub Sponsors was mentioned as a possible solution, this is worth investigating. |
| + | Open Collective was also mentioned, that needs some investigating how that exactly would work for us. |
