Blame
| 39e2d4 | Samuli Seppänen | 2025-03-19 08:31:17 | 1 | **NOTE: this article refers to an outdated version of tap-windows that was used on Windows systems before Windows 7. The information here is interesting only for digital archaeologists and historians** |
| 2 | ||||
| 3 | # Introduction |
|||
| 4 | ||||
| 5 | TAP-Windows is an [OpenVPN subproject](https://github.com/OpenVPN/tap-windows) in [GitHub](https://github.com/). TAP-Windows is built on a Windows box, and the [OpenVPN cross-compile buildsystem](/BuildingUsingGenericBuildsystem) takes care of embedding the produced TAP-Windows installer into the OpenVPN Windows installer. |
|||
| 6 | ||||
| 7 | If you're building [tap-windows6](https://github.com/OpenVPN/tap-windows6) instead, please look [here](/BuildingTapWindows6). |
|||
| 8 | ||||
| 9 | # Setting up the Windows build computer |
|||
| 10 | ||||
| 11 | First install a recent version of Windows DDK and [http://nsis.sourceforge.net NSIS]. |
|||
| 12 | ||||
| 13 | Next clone the *tap-windows* repository, e.g. using *Git Bash*: |
|||
| 14 | ||||
| 15 | ``` |
|||
| 16 | $ cd /c/users/myuser |
|||
| 17 | $ git clone https://github.com/OpenVPN/tap-windows |
|||
| 18 | ``` |
|||
| 19 | ||||
| 20 | Now set some environment variables: |
|||
| 21 | ||||
| 22 | ``` |
|||
| 23 | set DDK=c:\WINDDK\7600.16385.1 |
|||
| 24 | set DEVCON32=c:\WINDDK\7600.16385.1\tools\devcon\i386\devcon.exe |
|||
| 25 | set DEVCON64=c:\WINDDK\7600.16385.1\tools\devcon\amd64\devcon.exe |
|||
| 26 | set DEVCON_BASENAME=devcon.exe |
|||
| 27 | set SIGNTOOL=c:\WINDDK\7600.16385.1\bin\x86\signtool.exe |
|||
| 28 | set MAKENSIS=C:\Program Files (x86)\NSIS |
|||
| 29 | set OUTDIR=c:\users\myuser\tap-windows |
|||
| 30 | ``` |
|||
| 31 | ||||
| 32 | Some of these variables have sane default values, and you many not need to define all of them. If you use self-signed test certificates you also need these variables: |
|||
| 33 | ||||
| 34 | ``` |
|||
| 35 | set CODESIGN_PKCS12=c:\Users\John\tap-windows\my-self-signed-certificate.p12 |
|||
| 36 | set CODESIGN_PASS=mypassphrase |
|||
| 37 | set CODESIGN_ISTEST=yes |
|||
| 38 | ``` |
|||
| 39 | ||||
| 40 | For paid-for software publisher certificates (SPC) you'd use something like this: |
|||
| 41 | ||||
| 42 | ``` |
|||
| 43 | set CODESIGN_PKCS12="c:\Users\John\tap-windows\my-software-publisher-certificate.p12" |
|||
| 44 | set CODESIGN_PASS=mypassphrase |
|||
| 45 | set CODESIGN_ISTEST=no |
|||
| 46 | set CODESIGN_CROSS="C:\Users\John\tap-windows\ca-cross-certificate.crt" |
|||
| 47 | set CODESIGN_TIMESTAMP="http://timestamp.domain.com" |
|||
| 48 | ``` |
|||
| 49 | ||||
| 50 | If you imported the kernel-mode code-signing certicate using Internet Explorer, you can use *certmgr.exe* to export it in PFX (=PKCS12) format. Just make sure to include the private key in the file and to give it a sufficiently strong password, which you then define using *CODESIGN_PASS* variable. The CA cross certificate can be obtained from your CA and most likely needs no modifications. The URL for the timestamping service is CA-specific, but trivial to locate. |
|||
| 51 | ||||
| 52 | To simplify variable setting in the future, you can create a batch file with all the above commands and run it before running *configure.bat*. For details on available environment variables see |
|||
| 53 | ||||
| 54 | ``` |
|||
| 55 | > configure --help |
|||
| 56 | ``` |
|||
| 57 | ||||
| 58 | ||||
| 59 | # Building TAP-windows |
|||
| 60 | ||||
| 61 | First you need to configure the tap-windows build to use the variables you defined. Do this from a Visual Studio command prompt: |
|||
| 62 | ||||
| 63 | ``` |
|||
| 64 | > configure |
|||
| 65 | ``` |
|||
| 66 | ||||
| 67 | This copies the variables to *tap-windows\config-env.bat* and various other places. All that's left is to build the tap-windows drivers: |
|||
| 68 | ||||
| 69 | ``` |
|||
| 70 | > build |
|||
| 71 | ``` |
|||
| 72 | ||||
| 73 | If you want to customize the build further, e.g. to build a custom TAP-Windows driver that can coexist with stock OpenVPN TAP-Windows driver, you can edit the *version.m4* or create a separate *config-local.m4*. Any variables in *config-local.m4* should override those in *version.m4*. |
|||
| 74 | ||||
| 75 | Finally, if you're generating an OpenVPN installer with the your modified TAP-Windows driver, put the TAP-Windows installer on a webserver and point the [OpenVPN cross-compile buildsystem](/BuildingUsingGenericBuildsystem) to it. |
