The OpenVPN community project team is proud to release OpenVPN 2.7_beta3. This is the third Beta release for the feature release 2.7.0. As the Beta name implies this is an early release build, it is not intended for production use.
-
-
Feature changes since 2.7_beta2:
-
* improvements on PUSH_UPDATE handling on the server side
-
* improve "recursive routing checks", prepare the way for a policy-based setup where "packets to VPN server" could end up in the tunnel without interfering with OpenVPN operations
-
* add support for "epoch" data format to DCO on Windows
-
* clean up and remove outdated stuff from COPYING
-
-
Important bug fixes since 2.7_beta2:
-
* bugfixes reconnect and PUSH_UPDATE handling on the client side (notably handling of ifconfig/ifconfig-ipv6/redirect-gateway ipv6 if the server is not always pushing the same address families)
-
-
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_beta2...v2.7_beta3).
+
## OpenVPN 2.7_rc1 -- Released 31 October 2025
+
The OpenVPN community project team is proud to release OpenVPN 2.7_rc1. This is the first release candidate for the feature release 2.7.0.
+
+
Feature changes since 2.7_beta3:
+
* add warning for unsupported combination of --push and --tls-server
+
* add warning for unsupported combination of `--reneg-bytes` or `--reneg-pkts` with DCO
+
* remove perf_push()/perf_pop() infrastructure (because it did not work anymore, and compiler profiling will give better results today)
+
* ensure compatibility with OpenSSL 3.6.0 - specifically, do not crash in t_lpback.sh trying to use new encrypt-then-mac (ETM) ciphers
+
* improved PUSH_UPDATE server side support, which now handles changes of pushed ifconfig/ifconfig-ipv6 addresses correctly (send packets to new IP addresses to this client, stop sending packets to the old addresses).
+
* freshen URLs all over the tree, and change to HTTPS where possible
+
* on DCO Linux/FreeBSD, add support for clients receiving an IPv4/IPv6 address that is not part of the --server/--server-ipv6 subnet (= install extra on-interface host routes).
+
* Windows programs use a new API for path name canonicalization now (PathCchCanonicalizeEx()) which will break building with MinGW on Ubuntu 22.04 -> Upgrade to 24.04 to make builds work again.
+
* on Windows, when setting up WINS servers using netsh, use interface index instead of adapter name now ("as for all other netsh calls")
+
* remove undocumented and unused --memstats feature
+
+
Important bug fixes since 2.7_beta3:
+
* even more type conversion related warnings have been fixed
+
* more bugfixes related to BYTECOUNT display on the management interface and byte counters on DCO platforms in general
+
* numerous minibugs reported by ZeroPath AI have been fixed (small memleaks, possible file descriptor leaks, improved sanity checks, add ASSERT() on function contracts, etc.)
+
+
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_beta3...v2.7_rc1).
Highlights of 2.7 include:
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
@@ 36,21 44,29 @@
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
-
* COPYING: license details only relevant to our Windows installers havebeen updated and moved to the openvpn-build repo
+
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
-
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_beta3/Changes.rst)
+
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc1/Changes.rst)
-
Windows MSI changes since 2.7_beta2:
+
Windows MSI changes since 2.7_beta3:
* Built against OpenSSL 3.6.0
-
* Included openvpn-gui updated to 11.56.0.0
+
* Included openvpn-gui updated to 11.57.0.0
+
* Encrypt username saved in registry
+
* Avoid blocking calls during WM_OVPN_ECHOMSG processing
+
* Fixes segfault when echo msg-notify happens with no message to display (Github: [OpenVPN/openvpn-gui#771](https://github.com/OpenVPN/openvpn-gui/issues/771))
+
* Check the path of the process listening on management port
+
* Error out if imported profile file name is too long
+
* Disallow Windows special filenames for imported profile
+
* Replace % characters in param->id as it's used in format template
+
* Excplicitly check that urls start with http:// or https://
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.