Blame
| dc0a55 | Samuli Seppänen | 2025-02-28 16:25:21 | 1 | **NOTE:** this article is mostly of historic interest. |
| 2 | ||||
| 252810 | Samuli Seppänen | 2025-02-28 16:24:54 | 3 | # Introduction |
| 4 | ||||
| 5 | In the [Lviv hackathon](/Meetups/2018-Lviv) the we agreed on the following things: |
|||
| 6 | ||||
| 7 | * OpenVPN 2.5 Windows installer should be MSI-based |
|||
| 8 | * We won't provide NSIS installers for 2.5 unless there are major issues in the MSI |
|||
| 9 | * The installer should include OpenVPN, OpenVPNService, tap-windows6 etc. each as separate MSI feature |
|||
| 10 | * People who want to install just tap-windows6 can disable the OpenVPN features |
|||
| 11 | * We should not try to embed MSI installers into MSI installers due to lack of good documentation |
|||
| 12 | * Each installation architecture/target will get its own MSI installer |
|||
| 13 | * We should bundle all the MSI installer into a thin wrapper executable, such as a self-extracting p7zip archive with a script hook that detect which MSI to launch |
|||
| 14 | * The individual MSI files should also be made available for more technical users as well as system administrators |
|||
| 15 | * The custom action DLL used in the tap-windows6 MSI installation logic could be included in openvpn.git, so that openvpn-build could easily build and sign it, just as is done with openvpn.exe and openvpnserv.exe. Having it in tap-windows6 repository would make signing that DLL slightly more problematic, as we don't really sign anything with the tap-windows6 buildsystem anymore. |
|||
| 16 | * The MSI (WiX) code can be placed into a subdirectory in openvpn-build Git repository alongside "generic", "msvc" and "windows-nsis". The MSI should consume the artefacts that the openvpn-build cross-compile process produces. |
|||
| 17 | * The documentation and instructions on how to deploy, transform, or parameterize MSI packages should be published on Wiki and/or in the openvpn-build readme. |
|||
| 18 | * The documentation and instructions for developers on components, their functions and relationship should be published on Wiki and/or in the openvpn-build readme. |
|||
| 19 | ||||
| 20 | # Installer targets |
|||
| 21 | ||||
| 22 | There are several "targets" for the installer. We not only have the architecture split (i386, x64, amd64), but also different types of kernel-mode signatures for tap-windows6: |
|||
| 23 | ||||
| 24 | |**Operating system**|**KM signature** |**i386**|**x64**|**arm64**| |
|||
| 25 | |-|-|-|-|-| |
|||
| 26 | |Windows 7/8 |Cross-signed | X | X | | |
|||
| 27 | |Windows 10 |Attestation-signed![1]| X | X | X | |
|||
| 28 | |Windows Server 2012r2 |Cross-signed | | X | | |
|||
| 29 | |Windows Server 2016 |WHQL-certified | | X | | |
|||
| 30 | |Windows Server 2019 |WHQL-certified | | X | | |
|||
| 31 | ||||
| 32 | So we have the following architecture-signature combinations for tap-windows6: |
|||
| 33 | ||||
| 34 | 1. i386/x64 cross-signed |
|||
| 35 | 1. i386/x64/arm64 attestation signed |
|||
| 36 | 1. x64 WHQL certified |
|||
| 37 | ||||
| 38 | The user-mode signatures for openvpn.exe, openvpnserv.exe etc. can be created with standard, non-EV authenticode keys on all platforms. |
|||
| 39 | ||||
| 40 | # Notes |
|||
| 41 | ||||
| 42 | [1] The requirement for attestation signatures in kernel-mode code came into Windows 10 quite early. It is not know if really old Windows 10 version can load attestation-signed drivers, but that seems likely. Even if they don't we may not want to support those |
