Commit fe3618
2025-11-19 12:58:16 novaflash: -/-| /dev/null .. Meetings/2025/2025-11-19.md | |
| @@ 0,0 1,63 @@ | |
| + | # Basic info |
| + | |
| + | * Time: Wednesday 19 November 2025 at 14:00 CEST (12:00 UTC) |
| + | * Place: #openvpn-meeting channel on !LiberaChat IRC network |
| + | |
| + | # Topics |
| + | |
| + | - **Updated: Release 2.7** |
| + | OpenVPN 2.7rc2 went out containing among other things 2 CVE fixes. |
| + | CVE-2025-12106: IPv6 address parsing: fix buffer overread on invalid input |
| + | CVE-2025-13086: HMAC verification check: fix incorrect memcmp() call |
| + | The latter of these two also applies to the 2.6 branch, therefore a 2.6.16 release was done. |
| + | |
| + | - **Updated: Release 2.6.16** |
| + | Some of the issues for 2.7 also affected 2.6 code, therefore 2.6.16 with a fix for a CVE issue was released. |
| + | CVE-2025-13086: HMAC verification check: fix incorrect memcmp() call |
| + | |
| + | - **2.7 security audit** |
| + | ordex arranged mostly through STF funding to get a security audit of OpenVPN 2.7 (currently in release candidate phase). |
| + | Recently this has kicked off and 2.7 is being put through the meat grinder now by SRLabs. |
| + | |
| + | - **community meetup 2026** |
| + | Tentatively in Paderborn, Germany. |
| + | |
| + | - **forums situation** |
| + | minx from OpenVPN Inc. originally set up flarum and started migration process, but he left the company before completion. |
| + | Now we have eduardo at OpenVPN Inc. who is taking a look and he managed to get migration working. |
| + | He suggests some further migration testing, and to then plan a hard cutover date. |
| + | |
| + | ## Backlog |
| + | |
| + | - **t_server and t_client testing framework** |
| + | mattock reports that he's started publishing his work for t_server in this location: |
| + | https://github.com/mattock/openvpn-tests/tree/t_server_template/t_server |
| + | |
| + | - **format code using clang formatting** |
| + | It seems prudent to do this before the real 2.7 release. |
| + | It was discussed and there's some additional work to be paid either on reviewer or submitter side. |
| + | Strategy will be; get all code into beta1, collect bugfixes, reformat everything, then beta2. |
| + | Collect more bugfixes and then do release 2.7.0 and branch it off into its own release branch. |
| + | |
| + | - **push_update / live route updates** |
| + | Client-side support for push_update is now merged. |
| + | For server-side support, company did QA on it with openvpn2 but found some missing features that are being added now. |
| + | Client-side support made it into alpha3. |
| + | |
| + | - **Tunnelcrack progress (see TunnelCrack community wiki article)** |
| + | Status update on TunnelCrack mitigations: |
| + | The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this. |
| + | Windows, openvpn2: block-local merged to master, not to 2.6.x. openvpn3: in code review. |
| + | Linux, openvpn2: in progress. openvpn3: in progress. |
| + | macOS: to be determined. |
| + | iOS: to be determined. |
| + | Android: not vulnerable. |
| + | |
| + | - **donation collection** |
| + | From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations. |
| + | What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on. |
| + | There are some options to consider. There may be existing solutions that we want to consider. |
| + | PayPal seems overly expensive with all their fees. |
| + | Stripe could be worth considering for credit card processing. |
| + | GitHub Sponsors was mentioned as a possible solution, this is worth investigating. |
| + | Open Collective was also mentioned, that needs some investigating how that exactly would work for us. |
