Blame
| 28afe8 | Samuli Seppänen | 2025-02-11 10:05:57 | 1 | ``` |
| 2 | OpenVPN |
|||
| 3 | Copyright (C) 2002-2008 OpenVPN, Inc. |
|||
| 4 | ||||
| 5 | $Id: ChangeLog 1330 2006-10-01 11:45:06Z james $ |
|||
| 6 | ||||
| 7 | 2006.10.01 -- Version 2.0.9 |
|||
| 8 | ||||
| 9 | * Windows installer updated with OpenSSL 0.9.7l DLLs to fix |
|||
| 10 | published vulnerabilities. |
|||
| 11 | ||||
| 12 | * Fixed TAP-Win32 bug that caused BSOD on Windows Vista |
|||
| 13 | (Henry Nestler). The TAP-Win32 driver has now been |
|||
| 14 | upgraded to version 8.4. |
|||
| 15 | ||||
| 16 | 2006.09.12 -- Version 2.0.8 |
|||
| 17 | ||||
| 18 | * Windows installer updated with OpenSSL 0.9.7k DLLs to fix |
|||
| 19 | RSA Signature Forgery (CVE-2006-4339). |
|||
| 20 | * No changes to OpenVPN source code between 2.0.7 and 2.0.8. |
|||
| 21 | ||||
| 22 | 2006.04.12 -- Version 2.0.7 |
|||
| 23 | ||||
| 24 | * Code added in 2.0.6-rc1 to extend byte counters |
|||
| 25 | to 64 bits caused a bug in the Windows version which has now |
|||
| 26 | been fixed. The bug could cause intermittent crashes. |
|||
| 27 | ||||
| 28 | 2006.04.05 -- Version 2.0.6 |
|||
| 29 | ||||
| 30 | * Security Vulnerability affecting OpenVPN 2.0 through 2.0.5. |
|||
| 31 | An OpenVPN client connecting to a |
|||
| 32 | malicious or compromised server could potentially receive |
|||
| 33 | "setenv" configuration directives from the server which could |
|||
| 34 | cause arbitrary code execution on the client via a LD_PRELOAD |
|||
| 35 | attack. A successful attack appears to require that (a) the |
|||
| 36 | client has agreed to allow the server to push configuration |
|||
| 37 | directives to it by including "pull" or the macro "client" in |
|||
| 38 | its configuration file, (b) the client configuration file uses |
|||
| 39 | a scripting directive such as "up" or "down", (c) the client |
|||
| 40 | succesfully authenticates the server, (d) the server is |
|||
| 41 | malicious or has been compromised and is under the control of |
|||
| 42 | the attacker, and (e) the attacker has at least some level of |
|||
| 43 | pre-existing control over files on the client (this might be |
|||
| 44 | accomplished by having the server respond to a client web |
|||
| 45 | request with a specially crafted file). Credit: Hendrik Weimer. |
|||
| 46 | CVE-2006-1629. |
|||
| 47 | ||||
| 48 | The fix is to disallow "setenv" to be pushed to clients from |
|||
| 49 | the server. For those who need this capability, OpenVPN |
|||
| 50 | 2.1 supports a new "setenv-safe" directive which is free |
|||
| 51 | of this vulnerability. |
|||
| 52 | ||||
| 53 | * When deleting routes under Linux, use the route metric |
|||
| 54 | as a differentiator to ensure that the route teardown |
|||
| 55 | process only deletes the identical route which was originally |
|||
| 56 | added via the "route" directive (Roy Marples). |
|||
| 57 | ||||
| 58 | * Fix the t_cltsrv.sh file in FreeBSD 4 jails |
|||
| 59 | (Matthias Andree, Dirk Meyer, Vasil Dimov). |
|||
| 60 | ||||
| 61 | * Extended tun device configure code to support ethernet |
|||
| 62 | bridging on NetBSD (Emmanuel Kasper). |
|||
| 63 | ||||
| 64 | 2006.01.03 -- Version 2.0.6-rc1 |
|||
| 65 | ||||
| 66 | * Fixed bug where "make check" inside a FreeBSD "jail" |
|||
| 67 | would never complete (Matthias Andree). |
|||
| 68 | * Fixed bug where --server directive in --dev tap mode |
|||
| 69 | claimed that it would support subnets of /30 or less |
|||
| 70 | but actually would only accept /29 or less. |
|||
| 71 | * Extend byte counters to 64 bits (M. van Cuijk). |
|||
| 72 | * Fixed bug in acinclude.m4 where capability of compiler |
|||
| 73 | to handle zero-length arrays in structs is tested |
|||
| 74 | (David Stipp). |
|||
| 75 | * Fixed typo in manage.c where inline function declaration |
|||
| 76 | was declared without the "static" keyword (David Stipp). |
|||
| 77 | * Removed redundant base64 code. |
|||
| 78 | * Better sanity checking of --server and --server-bridge |
|||
| 79 | IP pool ranges, so as not to hit the assertion at |
|||
| 80 | pool.c:119 (2.0.5). |
|||
| 81 | * Fixed bug where --daemon and --management-query-passwords |
|||
| 82 | used together would cause OpenVPN to block prior to |
|||
| 83 | daemonization. |
|||
| 84 | * Fixed client/server race condition which could occur |
|||
| 85 | when --auth-retry interact is set and the initially |
|||
| 86 | provided auth-user-pass credentials are incorrect, |
|||
| 87 | forcing a username/password re-query. |
|||
| 88 | * Fixed bug where if --daemon and --management-hold are |
|||
| 89 | used together, --user or --group options would be ignored. |
|||
| 90 | ||||
| 91 | 2005.11.02 -- Version 2.0.5 |
|||
| 92 | ||||
| 93 | * Fixed bug in Linux get_default_gateway function |
|||
| 94 | introduced in 2.0.4, which would cause redirect-gateway |
|||
| 95 | on Linux clients to fail. |
|||
| 96 | * Restored easy-rsa/2.0 tree (backported from 2.1 beta |
|||
| 97 | series) which accidentally disappeared in |
|||
| 98 | 2.0.2 -> 2.0.4 transition. |
|||
| 99 | ||||
| 100 | 2005.11.01 -- Version 2.0.4 |
|||
| 101 | ||||
| 102 | * Security fix -- Affects non-Windows OpenVPN clients of |
|||
| 103 | version 2.0 or higher which connect to a malicious or |
|||
| 104 | compromised server. A format string vulnerability |
|||
| 105 | in the foreign_option function in options.c could |
|||
| 106 | potentially allow a malicious or compromised server |
|||
| 107 | to execute arbitrary code on the client. Only |
|||
| 108 | non-Windows clients are affected. The vulnerability |
|||
| 109 | only exists if (a) the client's TLS negotiation with |
|||
| 110 | the server succeeds, (b) the server is malicious or |
|||
| 111 | has been compromised such that it is configured to |
|||
| 112 | push a maliciously crafted options string to the client, |
|||
| 113 | and (c) the client indicates its willingness to accept |
|||
| 114 | pushed options from the server by having "pull" or |
|||
| 115 | "client" in its configuration file (Credit: Vade79). |
|||
| 116 | CVE-2005-3393 |
|||
| 117 | * Security fix -- Potential DoS vulnerability on the |
|||
| 118 | server in TCP mode. If the TCP server accept() call |
|||
| 119 | returns an error status, the resulting exception handler |
|||
| 120 | may attempt to indirect through a NULL pointer, causing |
|||
| 121 | a segfault. Affects all OpenVPN 2.0 versions. |
|||
| 122 | CVE-2005-3409 |
|||
| 123 | * Fix attempt of assertion at multi.c:1586 (note that |
|||
| 124 | this precise line number will vary across different |
|||
| 125 | versions of OpenVPN). |
|||
| 126 | * Added ".PHONY: plugin" to Makefile.am to work around |
|||
| 127 | "make dist" issue. |
|||
| 128 | * Fixed double fork issue that occurs when --management-hold |
|||
| 129 | is used. |
|||
| 130 | * Moved TUN/TAP read/write log messages from --verb 8 to 6. |
|||
| 131 | * Warn when multiple clients having the same common name or |
|||
| 132 | username usurp each other when --duplicate-cn is not used. |
|||
| 133 | * Modified Windows and Linux versions of get_default_gateway |
|||
| 134 | to return the route with the smallest metric |
|||
| 135 | if multiple 0.0.0.0/0.0.0.0 entries are present. |
|||
| 136 | ||||
| 137 | 2005.09.23 -- Version 2.0.2-TO4 |
|||
| 138 | ||||
| 139 | * Added feature to TAP-Win32 adapter to allow it to be |
|||
| 140 | opened from non-administrator mode. This feature |
|||
| 141 | is enabled by default, and can be enabled/disabled |
|||
| 142 | in the adapter advanced properties dialog. |
|||
| 143 | * Added --allow-nonadmin standalone option for Windows to |
|||
| 144 | set TAP adapter to allow non-admin access. This |
|||
| 145 | is a user-mode version of the code, and duplicates |
|||
| 146 | the same feature as the above entry. |
|||
| 147 | * Added fix that attempts to solve corner case of tunnel not |
|||
| 148 | forwarding packets when system clock is reset to an earlier time. |
|||
| 149 | * Added --redirect-gateway bypass-dns option. (Developers: |
|||
| 150 | To add bypass-dhcp or bypass-dns support to other OSes, |
|||
| 151 | add a get_bypass_addresses function to route.c for |
|||
| 152 | your OS.) |
|||
| 153 | * Added OPENVPN_PLUGIN_CLIENT_CONNECT_V2 plugin callback, which |
|||
| 154 | allows a client-connect plugin to return configuration text |
|||
| 155 | in memory, rather than via a file. |
|||
| 156 | * Fixed a bug where --mode server --proto tcp-server --cipher none |
|||
| 157 | operation could cause tunnel packet truncation. |
|||
| 158 | * openvpn --version will show [LZO1] or [LZO2], depending on |
|||
| 159 | version that was linked. |
|||
| 160 | ||||
| 161 | 2005.09.07 -- Version 2.0.2-TO1 |
|||
| 162 | ||||
| 163 | * Added --topology directive. See man page. |
|||
| 164 | * Added --redirect-gateway bypass-dhcp option to add a route |
|||
| 165 | allowing DHCP packets to bypass the tunnel, when the |
|||
| 166 | DHCP server is non-local. Currently only implemented |
|||
| 167 | on Windows clients. |
|||
| 168 | * Modified OpenVPN Service on Windows to declare the DHCP |
|||
| 169 | client service as a dependency. |
|||
| 170 | * Extended the plugin interface to allow plugins to declare |
|||
| 171 | per-client constructor and destructor functions, to make |
|||
| 172 | it simpler for plugins to maintain per-client state. |
|||
| 173 | ||||
| 174 | 2005.09.25 -- Version 2.0.3-rc1 |
|||
| 175 | ||||
| 176 | * openvpn_plugin_abort_v1 function wasn't being properly |
|||
| 177 | registered on Windows. |
|||
| 178 | * Fixed a bug where --mode server --proto tcp-server --cipher none |
|||
| 179 | operation could cause tunnel packet truncation. |
|||
| 180 | ||||
| 181 | 2005.08.25 -- Version 2.0.2 |
|||
| 182 | ||||
| 183 | * No change from 2.0.2-rc1. |
|||
| 184 | ||||
| 185 | 2005.08.24 -- Version 2.0.2-rc1 |
|||
| 186 | ||||
| 187 | * Fixed regression bug in Win32 installer, introduced in 2.0.1, |
|||
| 188 | which incorrectly set OpenVPN service to autostart. |
|||
| 189 | * Don't package source code zip file in Windows installer |
|||
| 190 | in order to reduce the size of the installer. The source |
|||
| 191 | zip file can always be downloaded separately if needed. |
|||
| 192 | * Fixed bug in route.c in FreeBSD, Darwin, OpenBSD and NetBSD |
|||
| 193 | version of get_default_gateway. Allocated socket for route |
|||
| 194 | manipulation is never freed so number of mbufs continuously |
|||
| 195 | grow and exhaust system resources after a while (Jaroslav Klaus). |
|||
| 196 | * Fixed bug where "--proto tcp-server --mode p2p --management |
|||
| 197 | host port" would cause the management port to not respond until |
|||
| 198 | the OpenVPN peer connects. |
|||
| 199 | * Modified pkitool script to be /bin/sh compatible (Johnny Lam). |
|||
| 200 | ||||
| 201 | 2005.08.16 -- Version 2.0.1 |
|||
| 202 | ||||
| 203 | * Security Fix -- DoS attack against server when run with "verb 0" and |
|||
| 204 | without "tls-auth". If a client connection to the server fails |
|||
| 205 | certificate verification, the OpenSSL error queue is not properly |
|||
| 206 | flushed, which can result in another unrelated client instance on the |
|||
| 207 | server seeing the error and responding to it, resulting in disconnection |
|||
| 208 | of the unrelated client (CAN-2005-2531). |
|||
| 209 | * Security Fix -- DoS attack against server by authenticated client. |
|||
| 210 | This bug presents a potential DoS attack vector against the server |
|||
| 211 | which can only be initiated by a connected and authenticated client. |
|||
| 212 | If the client sends a packet which fails to decrypt on the server, |
|||
| 213 | the OpenSSL error queue is not properly flushed, which can result in |
|||
| 214 | another unrelated client instance on the server seeing the error and |
|||
| 215 | responding to it, resulting in disconnection of the unrelated client |
|||
| 216 | (CAN-2005-2532). Credit: Mike Ireton. |
|||
| 217 | * Security Fix -- DoS attack against server by authenticated client. |
|||
| 218 | A malicious client in "dev tap" ethernet bridging mode could |
|||
| 219 | theoretically flood the server with packets appearing to come from |
|||
| 220 | hundreds of thousands of different MAC addresses, causing the OpenVPN |
|||
| 221 | process to deplete system virtual memory as it expands its internal |
|||
| 222 | routing table. A --max-routes-per-client directive has been added |
|||
| 223 | (default=256) to limit the maximum number of routes in OpenVPN's |
|||
| 224 | internal routing table which can be associated with a given client |
|||
| 225 | (CAN-2005-2533). |
|||
| 226 | * Security Fix -- DoS attack against server by authenticated client. |
|||
| 227 | If two or more client machines try to connect to the server at the |
|||
| 228 | same time via TCP, using the same client certificate, and when |
|||
| 229 | --duplicate-cn is not enabled on the server, a race condition can |
|||
| 230 | crash the server with "Assertion failed at mtcp.c:411" |
|||
| 231 | (CAN-2005-2534). |
|||
| 232 | * Fixed server bug where under certain circumstances, the client instance |
|||
| 233 | object deletion function would try to delete iroutes which had never been |
|||
| 234 | added in the first place, triggering "Assertion failed at mroute.c:349". |
|||
| 235 | * Added --auth-retry option to prevent auth errors from being fatal |
|||
| 236 | on the client side, and to permit username/password requeries in case |
|||
| 237 | of error. Also controllable via new "auth-retry" management interface |
|||
| 238 | command. See man page for more info. |
|||
| 239 | * Added easy-rsa 2.0 scripts to the tarball in easy-rsa/2.0 |
|||
| 240 | * Fixed bug in openvpn.spec where rpmbuild --define 'without_pam 1' |
|||
| 241 | would fail to build. |
|||
| 242 | * Implement "make check" to perform loopback tests (Matthias Andree). |
|||
| 243 | ||||
| 244 | 2005.07.21 -- Version 2.0.1-rc7 |
|||
| 245 | ||||
| 246 | * Support LZO 2.01 which renamed its library to lzo2 (Matthias Andree). |
|||
| 247 | * Include linux/types.h before checking for linux/errqueue.h (Matthias |
|||
| 248 | Andree). |
|||
| 249 | ||||
| 250 | 2005.07.15 -- Version 2.0.1-rc6 |
|||
| 251 | ||||
| 252 | * Commented out "user nobody" and "group nobody" in sample |
|||
| 253 | client/server config files. |
|||
| 254 | * Allow '@' character to be used in --client-config-dir |
|||
| 255 | file names. |
|||
| 256 | ||||
| 257 | 2005.07.04 -- Version 2.0.1-rc5 |
|||
| 258 | ||||
| 259 | * Windows version will log a for-further-info URL when |
|||
| 260 | initialization sequence is completed with errors. |
|||
| 261 | * Added DLOPEN_PAM parameter to plugin/auth-pam/Makefile |
|||
| 262 | to control whether auth-pam plugin links to PAM via |
|||
| 263 | dlopen or -lpam. By default, DLOPEN_PAM=1 so pre-existing |
|||
| 264 | behavior should be preserved. DLOPEN_PAM=0 is the preferred |
|||
| 265 | setting to link via -lpam, but DLOPEN_PAM=1 works around |
|||
| 266 | a bug in SuSE 9.1 (and possibly other distros as well) |
|||
| 267 | where the PAM modules are not linked with -lpam. See |
|||
| 268 | thread on openvpn-devel for more discussion about this |
|||
| 269 | patch (Simon Perreault). |
|||
| 270 | ||||
| 271 | 2005.06.15 -- Version 2.0.1-rc4 |
|||
| 272 | ||||
| 273 | * Support LZO 2.00, including changes to configure script to |
|||
| 274 | autodetect LZO version. |
|||
| 275 | ||||
| 276 | 2005.06.12 -- Version 2.0.1-rc3 |
|||
| 277 | ||||
| 278 | * Fixed a bug which caused standard file handles to not be closed |
|||
| 279 | after daemonization when --plugin and --daemon are used together, |
|||
| 280 | and if the plugin initialization function forks (as does auth-pam |
|||
| 281 | and down-root) (Simon Perreault). |
|||
| 282 | * Added client-side up/down scripts in contrib/pull-resolv-conf |
|||
| 283 | for accepting server-pushed "dhcp-option DOMAIN" and "dhcp-option DNS" |
|||
| 284 | on Linux/Unix systems (Jesse Adelman). |
|||
| 285 | * Fixed bug where if client-connect scripts/plugins were cascaded, |
|||
| 286 | and one (but not all) of them returned an error status, there might |
|||
| 287 | be cases where for an individual script/plugin, client-connect was |
|||
| 288 | called but not client-disconnect. The goal of this fix is to |
|||
| 289 | ensure that if client-connect is called on a given client instance, |
|||
| 290 | then client-disconnect will definitely be called. A potential |
|||
| 291 | complication of this fix is that when client-connect functions are |
|||
| 292 | cascaded, it's possible that the client-disconnect function would |
|||
| 293 | be called in cases where the related client-connect function returned |
|||
| 294 | an error status. This fix should not alter OpenVPN behavior when |
|||
| 295 | scripts/plugins are not cascaded. |
|||
| 296 | * Changed the hard-to-reproduce "Assertion failed at fragment.c:312" |
|||
| 297 | fatal error to a warning: "FRAG: outgoing buffer is not empty". |
|||
| 298 | Need more info on how to reproduce this one. |
|||
| 299 | * When --duplicate-cn is used, the --ifconfig-pool allocation |
|||
| 300 | algorithm will now allocate the first available IP address. |
|||
| 301 | * When --daemon and --management-hold are used together, |
|||
| 302 | OpenVPN will daemonize before it enters the management hold state. |
|||
| 303 | ||||
| 304 | 2005.05.16 -- Version 2.0.1-rc2 |
|||
| 305 | ||||
| 306 | * Modified vendor test in openvpn.spec file to match against |
|||
| 307 | "Mandrakesoft" in addition to "MandrakeSoft". |
|||
| 308 | * Using --iroute in a --client-config-dir file while in --dev tap |
|||
| 309 | mode is not currently supported and will produce a warning |
|||
| 310 | message. Fixed bug where in certain cases, in addition to |
|||
| 311 | generating a warning message, this combination of options |
|||
| 312 | would also produce a fatal assertion in mroute.c. |
|||
| 313 | * Pass --auth-user-pass username to server-side plugin without |
|||
| 314 | performing any string remapping (plugins, unlike scripts, |
|||
| 315 | don't get any security benefit from string remapping). |
|||
| 316 | This is intended to fix an issue with openvpn-auth-pam/pam_winbind |
|||
| 317 | where backslash characters in a username ('\') were being remapped |
|||
| 318 | to underscore ('_'). |
|||
| 319 | * Updated OpenSSL DLLs in Windows build to 0.9.7g. |
|||
| 320 | * Documented --explicit-exit-notify in man page. |
|||
| 321 | * --explicit-exit-notify seconds parameter defaults to 1 if |
|||
| 322 | unspecified. |
|||
| 323 | ||||
| 324 | 2005.04.30 -- Version 2.0.1-rc1 |
|||
| 325 | ||||
| 326 | * Fixed bug where certain kinds of fatal errors after |
|||
| 327 | initialization (such as port in use) would leave plugin |
|||
| 328 | processes (such as openvpn-auth-pam) still running. |
|||
| 329 | * Added optional openvpn_plugin_abort_v1 plugin function for |
|||
| 330 | closing initialized plugin objects in the event of a fatal |
|||
| 331 | error by main OpenVPN process. |
|||
| 332 | * When the --remote list is > 1, and --resolv-retry is not |
|||
| 333 | specified (meaning that it defaults to "infinite"), apply the |
|||
| 334 | infinite timeout to the --remote list as a whole, but try each |
|||
| 335 | list item only once before moving on to the next item. |
|||
| 336 | * Added new --syslog directive which redirects output |
|||
| 337 | to syslog without requiring the use of the --daemon or --inetd |
|||
| 338 | directives. |
|||
| 339 | * Added openvpn.spec option to allow RPM to be built with support |
|||
| 340 | for passwords read from a file: |
|||
| 341 | rpmbuild -tb [openvpn.x.tar.gz] --define 'with_password_save 1' |
|||
| 342 | ||||
| 343 | 2005.04.17 -- Version 2.0 |
|||
| 344 | ||||
| 345 | * Fixed minor options string typo in options.c. |
|||
| 346 | ||||
| 347 | 2005.04.10 -- Version 2.0-rc21 |
|||
| 348 | ||||
| 349 | * Change license description from "GPL Version 2 or (at your |
|||
| 350 | option) any later version" to just "GPL Version 2". |
|||
| 351 | ||||
| 352 | 2005.04.04 -- Version 2.0-rc20 |
|||
| 353 | ||||
| 354 | * Dag Wieers has put together an OpenVPN/LZO binary RPM set with |
|||
| 355 | excellent distro/version coverage for RH/EL/Fedora, though |
|||
| 356 | using his own SPEC. I modified openvpn.spec to follow some of |
|||
| 357 | the same conventions such as putting sample scripts and doc |
|||
| 358 | files in %doc rather than /usr/share/openvpn. |
|||
| 359 | * Minor change to init scripts to run the user-defined script |
|||
| 360 | /etc/openvpn/openvpn-startup (if it exists) before any OpenVPN |
|||
| 361 | configs are started, and to run /etc/openvpn/openvpn-shutdown |
|||
| 362 | after all OpenVPN configs have been stopped. The |
|||
| 363 | openvpn-startup script can be used for stuff like |
|||
| 364 | insmod tun.o, setting up firewall rules, or starting |
|||
| 365 | ethernet bridges. |
|||
| 366 | ||||
| 367 | 2005.03.29 -- Version 2.0-rc19 |
|||
| 368 | ||||
| 369 | * Omit additions of routes where the network and |
|||
| 370 | gateway are equal and the netmask is 255.255.255.255. |
|||
| 371 | This can come up if you are using both |
|||
| 372 | server/ifconfig-pool and client-config-dir with |
|||
| 373 | ifconfig-push static addresses for some subset of clients |
|||
| 374 | which directly reference the server IP address as the |
|||
| 375 | remote endpoint. |
|||
| 376 | ||||
| 377 | 2005.03.28 -- Version 2.0-rc18 |
|||
| 378 | ||||
| 379 | * Packaged Windows installer with OpenSSL 0.9.7f. |
|||
| 380 | * Built Windows installer with NSIS 2.06. |
|||
| 381 | ||||
| 382 | 2005.03.12 -- Version 2.0-rc17 |
|||
| 383 | ||||
| 384 | * "MANAGEMENT: CMD" log file output will now only occur |
|||
| 385 | at --verb 7 or greater. |
|||
| 386 | * Added an optional name/value configuration list to |
|||
| 387 | the openvpn-auth-pam plugin module argument list. See |
|||
| 388 | plugin/auth-pam/README for documentation. This is necessary |
|||
| 389 | in order for openvpn-auth-pam to work with queries generated |
|||
| 390 | by arbitrary PAM modules. |
|||
| 391 | * In both auth-pam and down-root plugins, in the forked process, |
|||
| 392 | a read error on the parent process socket is no longer fatal. |
|||
| 393 | * MandrakeSoft liblzo1 RPM only Provides for a 'liblzo1'. |
|||
| 394 | A conditional test of the vendor has been added to |
|||
| 395 | Require the appropriately named 'lzo' (liblzo1 / lzo). |
|||
| 396 | (Tom Walsh - http://openhardware.net) |
|||
| 397 | ||||
| 398 | ||||
| 399 | 2005.02.20 -- Version 2.0-rc16 |
|||
| 400 | ||||
| 401 | * Fixed bug introduced in rc13 where Windows service wrapper |
|||
| 402 | would be installed with a startup type of Automatic. |
|||
| 403 | This fix restores the previous behavior of installing |
|||
| 404 | with a startup type of Manual. |
|||
| 405 | ||||
| 406 | 2005.02.19 -- Version 2.0-rc15 |
|||
| 407 | ||||
| 408 | * Added warning when --keepalive is not used in a server |
|||
| 409 | configuration. |
|||
| 410 | * Don't include OpenSSL md4.h file if we are not building |
|||
| 411 | NTLM proxy support (Waldemar Brodkorb). |
|||
| 412 | * Added easy-rsa/build-key-pkcs12 and |
|||
| 413 | easy-rsa/Windows/build-key-pkcs12.bat scripts |
|||
| 414 | (Mathias Sundman). |
|||
| 415 | ||||
| 416 | 2005.02.16 -- Version 2.0-rc14 |
|||
| 417 | ||||
| 418 | * Fixed small memory leak that occurs when --crl-verify |
|||
| 419 | is used. |
|||
| 420 | * Upgraded Windows installer and .nsi script to NSIS 2.05 |
|||
| 421 | (Mathias Sundman). |
|||
| 422 | * Changed #include backslash usage in cryptoapi.c to use |
|||
| 423 | forward slashes instead (Gisle Vanem). |
|||
| 424 | * Created easy-rsa/revoke-full to handle revocations in |
|||
| 425 | a single step: (a) revoke crt, (b) regenerate CRL, and |
|||
| 426 | (c) verify that revocation succeeded. |
|||
| 427 | * Renamed easy-rsa/Windows/revoke-key to revoke-full so |
|||
| 428 | that both *nix and Windows scripts are equivalent. |
|||
| 429 | ||||
| 430 | 2005.02.11 -- Version 2.0-rc13 |
|||
| 431 | ||||
| 432 | * Improve human-readability of local/remote options |
|||
| 433 | diff, when inconsistencies are present. |
|||
| 434 | * For Windows easy-rsa, distribute vars.bat.sample and |
|||
| 435 | openssl.cnf.sample, then copy them to their normal |
|||
| 436 | filenames (without the .sample) when init-config.bat |
|||
| 437 | is run. This is to prevent OpenVPN upgrades from |
|||
| 438 | wiping out vars.bat and openssl.cnf edits. |
|||
| 439 | * Modified service wrapper (Windows) to use a |
|||
| 440 | case-insensitive search when scanning for .ovpn files |
|||
| 441 | in \Program Files\OpenVPN\config. Prior versions |
|||
| 442 | required an all-lower-case .ovpn file extension. |
|||
| 443 | * Miscellaneous service wrapper code cleanup. |
|||
| 444 | * If --user/--group is used on Windows, treat it |
|||
| 445 | as a no-op with a warning (this makes it easier to |
|||
| 446 | distribute the same client config file to Windows |
|||
| 447 | and *nix users). |
|||
| 448 | * Warn if --ifconfig-pool-persist is used with |
|||
| 449 | --duplicate-cn. |
|||
| 450 | ||||
| 451 | 2005.02.05 -- Version 2.0-rc12 |
|||
| 452 | ||||
| 453 | * Removed some debugging code inadvertently included |
|||
| 454 | in rc11 which would print the --auth-user-pass |
|||
| 455 | username/password provided by clients in the server |
|||
| 456 | logfile. |
|||
| 457 | * Client code for cycling through --remote list will |
|||
| 458 | retry the last address which successfully authenticated |
|||
| 459 | before moving on through the list. |
|||
| 460 | * Windows installer will now install sample configuration |
|||
| 461 | files in \Program Files\OpenVPN\sample-configs as well |
|||
| 462 | as generate a start menu shortcut to this directory. |
|||
| 463 | * Minor type change in buffer.[ch] to work around char-type |
|||
| 464 | ambiguity bug. Caused management interface lock-ups on |
|||
| 465 | ARM when building with armv4b-hardhat-linux-gcc 2.95.3. |
|||
| 466 | ||||
| 467 | 2005.02.03 -- Version 2.0-rc11 |
|||
| 468 | ||||
| 469 | * Windows installer will now install easy-rsa directory |
|||
| 470 | in \Program Files\OpenVPN |
|||
| 471 | * Allow syslog facility to be controlled at compile time, |
|||
| 472 | e.g. -DLOG_OPENVPN=LOG_LOCAL6 (P Kern). |
|||
| 473 | * Changed certain shell scripts in distribution to use |
|||
| 474 | #!/bin/sh rather than #!/bin/bash for better portability. |
|||
| 475 | * If --ifconfig-pool-persist seconds parameter is 0, treat |
|||
| 476 | persist file as an allocation of fixed IP addresses |
|||
| 477 | (previous versions took IP-to-common-name associations |
|||
| 478 | from this list as hints, not mandatory static allocations). |
|||
| 479 | * Fixed bug on *nix where if --auth-user-pass and --log |
|||
| 480 | were used together, the username prompt would be sent to |
|||
| 481 | the log file rather than /dev/tty. |
|||
| 482 | * Spurious text in openvpn.8 detected by doclifter |
|||
| 483 | (Eric S. Raymond). |
|||
| 484 | * Call closelog later on daemon kill so that process |
|||
| 485 | exit message is written to syslog. |
|||
| 486 | ||||
| 487 | 2005.01.27 -- Version 2.0-rc10 |
|||
| 488 | ||||
| 489 | * When ./configure is run with plugins enabled (the default), |
|||
| 490 | check whether or not dlopen exists in libc before testing |
|||
| 491 | for libdl. This is to fix an issue on FreeBSD and possibly |
|||
| 492 | other OSes which bundle libdl functions in libc. |
|||
| 493 | * On Windows, filter initial WSAEINVAL warning which occurs |
|||
| 494 | on the initial read attempt of an unbound socket. |
|||
| 495 | * The easy-rsa scripts build-key, build-key-pass, and |
|||
| 496 | build-key-server will now chmod the .key file |
|||
| 497 | to 0600. This is in addition to the fact the generated |
|||
| 498 | keys directory has always been similarly protected |
|||
| 499 | (Pete Harlan). |
|||
| 500 | ||||
| 501 | 2005.01.23 -- Version 2.0-rc9 |
|||
| 502 | ||||
| 503 | * Fixed error "ROUTE: route addition failed using |
|||
| 504 | CreateIpForwardEntry ..." on Windows when --redirect-gateway |
|||
| 505 | is used over a RRAS internet link. |
|||
| 506 | * When using --route-method exe on Windows, include the |
|||
| 507 | gateway parameter on route delete commands (Mathias Sundman). |
|||
| 508 | * Try not to do a hard reset (i.e. SIGHUP) when two |
|||
| 509 | SIGUSR1 signals are received in close succession. |
|||
| 510 | * If the push list tries to grow beyond its buffer capacity, |
|||
| 511 | the resulting error will be non-fatal. |
|||
| 512 | * To increase the push list capacity (must be done on both |
|||
| 513 | client and server), increase TLS_CHANNEL_BUF_SIZE in |
|||
| 514 | common.h (default=1024). |
|||
| 515 | ||||
| 516 | 2005.01.15 -- Version 2.0-rc8 |
|||
| 517 | ||||
| 518 | * Fixed bug introduced in rc7 where options error |
|||
| 519 | "--auth-user-pass requires --pull" might occur even |
|||
| 520 | if --pull was correctly specified. |
|||
| 521 | * Changed management interface code to bind once |
|||
| 522 | to TCP socket, rather than rebinding after every |
|||
| 523 | client disconnect. |
|||
| 524 | * Added "disable" directive for client-config-dir |
|||
| 525 | files. |
|||
| 526 | * Windows binary install is now distributed with |
|||
| 527 | OpenSSL 0.9.7e. |
|||
| 528 | * Query the management interface for --http-proxy |
|||
| 529 | username/password if authfile is set to "stdin". |
|||
| 530 | * Added current OpenVPN version number to "Unrecognized |
|||
| 531 | option or missing parameter" error message. |
|||
| 532 | * Added "-extensions server" to "openssl req" command |
|||
| 533 | in easy-rsa/build-key-server (Nir Yeffet). |
|||
| 534 | ||||
| 535 | 2005.01.10 -- Version 2.0-rc7 |
|||
| 536 | ||||
| 537 | * Fixed bug in management interface which could cause |
|||
| 538 | 100% CPU utilization in --proto tcp-server mode |
|||
| 539 | on all *nix OSes except for Linux 2.6. |
|||
| 540 | * --ifconfig-push now accepts DNS names as well as |
|||
| 541 | IP addresses. |
|||
| 542 | * Added sanity check errors when --pull or |
|||
| 543 | --auth-user-pass is used in an incorrect mode. |
|||
| 544 | * Updated man page entries for --client-connect and |
|||
| 545 | --ifconfig-push. |
|||
| 546 | * Added "String Types and Remapping" section to man |
|||
| 547 | page to consisely document the way which OpenVPN |
|||
| 548 | may convert certain types of characters in strings |
|||
| 549 | to ('_'). |
|||
| 550 | * Modified bridging description in HOWTO to emphasize |
|||
| 551 | the fact that bridging allows Windows file and print |
|||
| 552 | sharing without a WINS server (Charles Duffy). |
|||
| 553 | ||||
| 554 | 2004.12.20 -- Version 2.0-rc6 |
|||
| 555 | ||||
| 556 | * Improved checking for epoll support in ./configure |
|||
| 557 | to fix false positive on RH9 (Jan Just Keijser). |
|||
| 558 | * Made the "MULTI TCP: I/O wait required blocking in |
|||
| 559 | multi_tcp_action, action=7" error nonfatal and replaced |
|||
| 560 | with "MULTI: Outgoing TUN queue full, dropped packet". |
|||
| 561 | So far the issue only seems to occur on Linux 2.2 |
|||
| 562 | in --mode server --proto tcp mode. It occurs when |
|||
| 563 | the TUN/TAP driver locks up and refuses to accept |
|||
| 564 | new packet writes for a second or more. |
|||
| 565 | * Fixed bug where if a --client-config-dir file tried |
|||
| 566 | to include another file using "config", and if that |
|||
| 567 | include failed, OpenVPN would abort with a fatal |
|||
| 568 | error. Now such inclusion failures will be logged |
|||
| 569 | but are no longer fatal. |
|||
| 570 | * Global changes to the way that packet buffer alignment |
|||
| 571 | is handled. Previously we didn't care about alignment |
|||
| 572 | and took care, when handling 16 and 32 bit words |
|||
| 573 | in buffers, to always use alignment-safe transfers. |
|||
| 574 | This approach appears to be inadequate on some |
|||
| 575 | architectures such as alpha. The new approach is |
|||
| 576 | to initialize packet buffers in a way that anticipates |
|||
| 577 | how component structures will be allocated within |
|||
| 578 | them, to maintain correct alignment. |
|||
| 579 | * Added --dhcp-option DISABLE-NBT to disable NetBIOS |
|||
| 580 | over TCP (Jan Just Keijser). |
|||
| 581 | * Added --http-proxy-option directive for controlling |
|||
| 582 | miscellaneous HTTP proxy options. |
|||
| 583 | * Management state will no longer transition to "WAIT" |
|||
| 584 | during TLS renegotiations. |
|||
| 585 | ||||
| 586 | 2004.12.16 -- Version 2.0-rc5 |
|||
| 587 | ||||
| 588 | * The --client-config-dir option will now try to open |
|||
| 589 | a default file called "DEFAULT" if no file matching |
|||
| 590 | the common name of the incoming client was found. |
|||
| 591 | * The --client-connect script/plugin can now veto client |
|||
| 592 | authentication by returning a failure code. |
|||
| 593 | * The --learn-address script/plugin can now prevent a |
|||
| 594 | client-instance/address association from being learned |
|||
| 595 | by returning a failure code. |
|||
| 596 | * Changed RPM group in .spec file to Applications/Internet. |
|||
| 597 | ||||
| 598 | 2004.12.14 -- Version 2.0-rc4 |
|||
| 599 | ||||
| 600 | * SuSE only -- Fixed interaction between openvpn.spec and |
|||
| 601 | suse/openvpn.init where the .spec file was writing the |
|||
| 602 | OpenVPN binary to a different location than where the |
|||
| 603 | .init script was referencing it (Stefan Engel). |
|||
| 604 | * Solaris only -- Split Solaris ifconfig command into two |
|||
| 605 | parts (Jan Just Keijser). |
|||
| 606 | * Some cleanup in add_option(). |
|||
| 607 | * Better error checking on input dotted quad IP addresses. |
|||
| 608 | * Verify that --push argument is quoted, if there is |
|||
| 609 | more than one. |
|||
| 610 | * More miscellaneous option sanity checks. |
|||
| 611 | ||||
| 612 | 2004.12.13 -- Version 2.0-rc3 |
|||
| 613 | ||||
| 614 | * On Windows, when --log or --log-append is used, |
|||
| 615 | save the original stderr for username and password |
|||
| 616 | prompts. |
|||
| 617 | * Fixed a bug introduced in the late 2.0 betas where |
|||
| 618 | if a "verb" parameter >= 16 was used, it would be |
|||
| 619 | ignored and the actual verb level would remain at 1. |
|||
| 620 | * Fixed a bug mostly seen on OS X where --management-hold |
|||
| 621 | or --management-query-passwords would cause the management |
|||
| 622 | interface to be unresponsive to incoming client connections. |
|||
| 623 | * Trigger an options error if one of the management-modifying |
|||
| 624 | options is used without "management" itself. |
|||
| 625 | ||||
| 626 | 2004.12.12 -- Version 2.0-rc2 |
|||
| 627 | ||||
| 628 | * Amplified warnings in documentation about possible |
|||
| 629 | man-in-the-middle attack when clients do not properly |
|||
| 630 | verify server certificate. Changes to easy-rsa README, |
|||
| 631 | FAQ, HOWTO, man page, and sample client config file. |
|||
| 632 | * Added a warning message if --tls-client or --client |
|||
| 633 | is used without also specifying one of either |
|||
| 634 | --ns-cert-type, --tls-remote, or --tls-verify. |
|||
| 635 | * status_open() fixes for MSVC builds (Blaine Fleming). |
|||
| 636 | * Fix attempt of "ntlm.c:55: error: `des_cblock' undeclared" |
|||
| 637 | compiler error which has been reported on some platforms. |
|||
| 638 | * The openvpn.spec file for rpmbuild has several |
|||
| 639 | new build-time options. See comments in the file. |
|||
| 640 | * Plugins are now built and packaged in the RPM and |
|||
| 641 | will be saved in /usr/share/openvpn/plugin/lib. |
|||
| 642 | * Added --management-hold directive to start OpenVPN |
|||
| 643 | in a hibernating state until released by the |
|||
| 644 | management interface. Also added "hold" command |
|||
| 645 | to the management interface. |
|||
| 646 | ||||
| 647 | 2004.12.07 -- Version 2.0-rc1 |
|||
| 648 | ||||
| 649 | * openvpn.spec workaround for SuSE confusion regarding |
|||
| 650 | /etc/init.d vs. /etc/rc.d/init.d (Stefan Engel). |
|||
| 651 | ||||
| 652 | 2004.12.05 -- Version 2.0-beta20 |
|||
| 653 | ||||
| 654 | * The ability to read --askpass and --auth-user-pass |
|||
| 655 | passwords from a file has been disabled by default. |
|||
| 656 | To re-enable, use ./configure --enable-password-save. |
|||
| 657 | * Added additional pre-connected states to management |
|||
| 658 | interface. See management/management-notes.txt |
|||
| 659 | for more info. |
|||
| 660 | * State history is now recorded by the management |
|||
| 661 | interface, and the "state" command now works like |
|||
| 662 | the log or echo commands. |
|||
| 663 | * State history and real-time state change notifications |
|||
| 664 | are now prepended with an integer unix timestamp. |
|||
| 665 | * Added --http-proxy-timeout option, previously |
|||
| 666 | the timeout was hardcoded to 5 seconds. |
|||
| 667 | ||||
| 668 | 2004.12.02 -- Version 2.0-beta19 |
|||
| 669 | ||||
| 670 | * Fixed bug in management interface line termination |
|||
| 671 | where output lines incorrectly contained a \00 char |
|||
| 672 | after the customary \0d \0a. |
|||
| 673 | * Fixed bug introduced in beta18 where Windows version |
|||
| 674 | would segfault on options errors. |
|||
| 675 | * Fixed bug in management interface where an empty |
|||
| 676 | quoted string ("") entered as a parameter would cause |
|||
| 677 | a segfault. |
|||
| 678 | * Fixed bug where --resolv-retry was not working |
|||
| 679 | properly with multiple --remote hosts. |
|||
| 680 | * Added additional ./configure options to reduce |
|||
| 681 | executable size for embedded applications. |
|||
| 682 | See ./configure --help. |
|||
| 683 | ||||
| 684 | 2004.11.28 -- Version 2.0-beta18 |
|||
| 685 | ||||
| 686 | * Added management interface. See new --management-* |
|||
| 687 | options or the full management interface documentation |
|||
| 688 | in management/management-notes.txt in the tarball. |
|||
| 689 | Management interface inclusion can be disabled by |
|||
| 690 | ./configure --disable-management. |
|||
| 691 | * Added two new plugin modules: auth-pam and down-root. |
|||
| 692 | Auth-pam supports pam-based authentication using a |
|||
| 693 | split privilege execution model, while down-root enables |
|||
| 694 | a down script to be executed with root privileges, even |
|||
| 695 | when --user/--group is used to drop root privileges. |
|||
| 696 | See the plugin directory in the tarball for READMEs, |
|||
| 697 | source code, and Makefiles. |
|||
| 698 | * Plugin developers should note that some changes were |
|||
| 699 | made to the plugin interface since beta17. See |
|||
| 700 | openvpn-plugin.h for details. |
|||
| 701 | Plugin interface inclusion can be disabled with |
|||
| 702 | ./configure --disable-plugins |
|||
| 703 | * Added easy-rsa/build-key-server script which will |
|||
| 704 | build a certificate with with nsCertType=server. |
|||
| 705 | * Added --ns-cert-type option for verification |
|||
| 706 | of nsCertType field in peer certificate. |
|||
| 707 | * If --fragment n is specified and --mssfix is specified |
|||
| 708 | without a parameter, default --mssfix to n. This restores |
|||
| 709 | the 1.6 behavior when using --mssfix without a parameter. |
|||
| 710 | * Fixed SSL context initialization bug introduced in beta14 |
|||
| 711 | where this error might occur on restarts: "Cannot load |
|||
| 712 | certificate chain ... PEM_read_bio:no start line". |
|||
| 713 | ||||
| 714 | 2004.11.11 -- Version 2.0-beta17 |
|||
| 715 | ||||
| 716 | * Changed default port number to 1194 per IANA official |
|||
| 717 | port number assignment. |
|||
| 718 | * Added --plugin directive which allows compiled |
|||
| 719 | modules to intercept script callbacks. See |
|||
| 720 | plugin folder in tarball for more info. |
|||
| 721 | * Fixed bug introduced in beta12 where --key-method 1 |
|||
| 722 | authentications which should have succeeded would fail. |
|||
| 723 | * Ignore SIGUSR1 during DNS resolution. |
|||
| 724 | * Added SuSE support to openvpn.spec (Umberto Nicoletti). |
|||
| 725 | * Fixed --cryptoapicert SUBJ: parsing bug (Peter 'Luna' |
|||
| 726 | Runestig). |
|||
| 727 | ||||
| 728 | 2004.11.07 -- Version 2.0-beta16 |
|||
| 729 | ||||
| 730 | * Modified sample-scripts/auth-pam.pl to get username |
|||
| 731 | and password from OpenVPN via a file rather than |
|||
| 732 | via environmental variables. |
|||
| 733 | * Added bytes_sent and bytes_received environmental |
|||
| 734 | variables to be set prior to client-disconnect script. |
|||
| 735 | * Changed client virtual IP derivation precedence: |
|||
| 736 | (1) use --ifconfig-push directive from --client-connect |
|||
| 737 | script, (2) use --ifconfig-push directive from |
|||
| 738 | --client-config-dir, and (3) use --ifconfig-pool |
|||
| 739 | address. |
|||
| 740 | * If a --client-config-dir file specifies --ifconfig-push, |
|||
| 741 | it will be visible to the --client-connect-script in |
|||
| 742 | the ifconfig_pool_remote_ip environmental variable. |
|||
| 743 | * For tun-style tunnels, the ifconfig_pool_local_ip |
|||
| 744 | environmental variable will be set, while for |
|||
| 745 | tap-style tunnels, the ifconfig_pool_netmask variable |
|||
| 746 | will be set. |
|||
| 747 | * Added intelligence to autoconf script to test |
|||
| 748 | compiler for the accepted form of zero-length arrays. |
|||
| 749 | * Fixed a bug introduced in beta12 where --ip-win32 |
|||
| 750 | netsh would fail if --dev-node was not explicitly |
|||
| 751 | specified. |
|||
| 752 | * --ip-win32 netsh will now work on hidden adapters. |
|||
| 753 | * Fix attempt of "Assertion failed at crypto.c:149". |
|||
| 754 | This assertion has also been reported on 1.x with a |
|||
| 755 | slightly different line number. The fix is twofold: |
|||
| 756 | (1) In previous releases, --mtu-test may trigger this |
|||
| 757 | assertion -- this bug has been fixed. (2) If something |
|||
| 758 | else causes the assertion to be thrown, don't panic, |
|||
| 759 | just output a nonfatal warning to the log and drop |
|||
| 760 | the packet which generated the error. |
|||
| 761 | * Support TAP interfaces on Mac OS X (Waldemar Brodkorb). |
|||
| 762 | * Added --echo directive. |
|||
| 763 | * Added --auth-nocache directive. |
|||
| 764 | ||||
| 765 | 2004.10.28 -- Version 2.0-beta15 |
|||
| 766 | ||||
| 767 | * Changed environmental variable character classes |
|||
| 768 | so that names must consist of alphanumeric or |
|||
| 769 | underbar chars and values must consist of printable |
|||
| 770 | characters. Illegal chars will be deleted. |
|||
| 771 | Versions prior to 2.0-beta12 were more restrictive |
|||
| 772 | and would map spaces to '.'. |
|||
| 773 | * On Windows, when the TAP adapter fails to |
|||
| 774 | initialize with the correct IP address, output |
|||
| 775 | "Initialization Sequence Completed with Errors" |
|||
| 776 | to the console or log file. |
|||
| 777 | * Added a warning when user/group/chroot is used |
|||
| 778 | without persist-tun and persist-key. |
|||
| 779 | * Added cryptoapi.[ch] to tarball and source zip. |
|||
| 780 | * --tls-remote option now works with common name |
|||
| 781 | prefixes as well as with the full X509 subject |
|||
| 782 | string. This is a useful alternative to using |
|||
| 783 | a CRL on the client. |
|||
| 784 | * common names associated with a static |
|||
| 785 | --ifconfig-push setting will no longer leave |
|||
| 786 | any state in the --ifconfig-pool-persist file. |
|||
| 787 | * Hard TLS errors (TLS handshake failed) will now |
|||
| 788 | trigger either a SIGUSR1 signal by default |
|||
| 789 | or SIGTERM (if --tls-exit is specified). In TCP |
|||
| 790 | mode, all TLS errors are considered to be hard. |
|||
| 791 | In server mode, the signal will be local to the |
|||
| 792 | client instance. |
|||
| 793 | * Added method parameter to --auth-user-pass-verify |
|||
| 794 | directive to select whether username/password |
|||
| 795 | is passed to script via environment or a temporary |
|||
| 796 | file. |
|||
| 797 | * Added --status-version option to control format |
|||
| 798 | of --status file. The --mode server |
|||
| 799 | --status-version 2 format now includes a line |
|||
| 800 | type token, the virtual IP address is shown |
|||
| 801 | in the client list (even in --dev tap mode), |
|||
| 802 | and the integer time_t value is shown anywhere |
|||
| 803 | an ascii-formatted time/date is also shown. |
|||
| 804 | * Added --remap-usr1 directive which can be used |
|||
| 805 | to control whether internally or externally |
|||
| 806 | generated SIGUSR1 signals are remapped to |
|||
| 807 | SIGHUP (restart without persisting state) or |
|||
| 808 | SIGTERM (exit). |
|||
| 809 | * When running as a Windows service (using |
|||
| 810 | --service option), check the exit event before |
|||
| 811 | and after reading one line of input from |
|||
| 812 | stdin, when reading username/password info. |
|||
| 813 | * For developers: Extended the --gremlin function |
|||
| 814 | to better stress-test the new 2.0 features, |
|||
| 815 | added Valgrind support on Linux and Dmalloc |
|||
| 816 | support on Windows. |
|||
| 817 | ||||
| 818 | 2004.10.19 -- Version 2.0-beta14 |
|||
| 819 | ||||
| 820 | * Fixed a bug introduced in Beta12 that would occur |
|||
| 821 | if you use a --client-connect script without also |
|||
| 822 | defining --tmp-dir. |
|||
| 823 | * Fixed a bug introduced in Beta12 where a learn-address |
|||
| 824 | script might segfault on the delete method. |
|||
| 825 | * Added Crypto API support in Windows version via |
|||
| 826 | the --cryptoapicert option (Peter 'Luna' Runestig). |
|||
| 827 | ||||
| 828 | 2004.10.18 -- Version 2.0-beta13 |
|||
| 829 | ||||
| 830 | * Fixed an issue introduced in Beta12 where the private |
|||
| 831 | key password would not be prompted for unless --askpass |
|||
| 832 | was explicitly specified in the config. |
|||
| 833 | ||||
| 834 | 2004.10.17 -- Version 2.0-beta12 |
|||
| 835 | ||||
| 836 | * Added support for username/password-based authentication. |
|||
| 837 | Clients can now authentication themselves with the server |
|||
| 838 | using either a certificate, a username/password, or both. |
|||
| 839 | New directives: --auth-user-pass, --auth-user-pass-verify, |
|||
| 840 | --client-cert-not-required, and --username-as-common-name. |
|||
| 841 | * Added NTLM proxy patch (William Preston). |
|||
| 842 | * Added --ifconfig-pool-linear server flag to allocate |
|||
| 843 | individual tun addresses for clients rather than /30 |
|||
| 844 | subnets (won't work with Windows clients). |
|||
| 845 | * Modified --http-proxy code to cache username/password |
|||
| 846 | across restarts. |
|||
| 847 | * Modified --http-proxy code to read username/password |
|||
| 848 | from the console when the auth file is given as "stdin". |
|||
| 849 | * Modified --askpass to take an optional filename argument. |
|||
| 850 | * --persist-tun and --persist-key now work in client mode |
|||
| 851 | and can be pushed to clients as well. |
|||
| 852 | * Added --ifconfig-pool-persist directive, to maintain |
|||
| 853 | ifconfig-pool info in a file which is persistent across |
|||
| 854 | daemon instantiations. |
|||
| 855 | * --user and --group privilege downgrades as well as |
|||
| 856 | --chroot now also work in client mode (the |
|||
| 857 | dowgrade/chroot will be delayed until the initialization |
|||
| 858 | sequence is completed). |
|||
| 859 | * Added --show-engines standalone directive to show |
|||
| 860 | available OpenSSL crypto accelerator engine support. |
|||
| 861 | * --engine directive now accepts an optional engine-ID |
|||
| 862 | parameter to control which engine is used. |
|||
| 863 | * "Connection reset, restarting" log message now shows |
|||
| 864 | which client is being reset. |
|||
| 865 | * Added --dhcp-pre-release directive in Windows version. |
|||
| 866 | * Second parm to --ip-win32 can be "default", e.g. |
|||
| 867 | --ip-win32 dynamic default 60. |
|||
| 868 | * Fixed documentation bug regarding environmental |
|||
| 869 | variable settings for --ifconfig-pool IP addresses. |
|||
| 870 | The correct environmental variable names are: |
|||
| 871 | ifconfig_pool_local_ip and ifconfig_pool_remote_ip. |
|||
| 872 | * ifconfig_pool_local_ip and ifconfig_pool_remote_ip |
|||
| 873 | environmental variables are now passed to the |
|||
| 874 | client-disconnect script. |
|||
| 875 | * In server mode, environmental variables are now scoped |
|||
| 876 | according to the client they are associated with, |
|||
| 877 | to solve the problem of "crosstalk" between different |
|||
| 878 | client's environmental variable sets. |
|||
| 879 | * Added --down-pre flag to cause --down script to be |
|||
| 880 | called before TUN/TAP close (rather than after). |
|||
| 881 | * Added --tls-exit flag which will cause OpenVPN |
|||
| 882 | to exit on any TLS errors. |
|||
| 883 | * Don't push a route to a client if it exactly |
|||
| 884 | matches an iroute (this lets you push routes to |
|||
| 885 | all clients, and OpenVPN will automatically remove |
|||
| 886 | the route from the route push list only for that client |
|||
| 887 | which the route actually belongs to). |
|||
| 888 | * Made '--resolv-retry infinite' the default. |
|||
| 889 | --resolv-retry can be disabled by using a parameter of 0. |
|||
| 890 | * For clients which plan to pull config info from server, |
|||
| 891 | set an initial default ping-restart of 60 seconds. |
|||
| 892 | * Optimized mute code to lessen the load on the processor |
|||
| 893 | when messages are being muted at a higher frequency. |
|||
| 894 | * Made route log messages non-mutable. |
|||
| 895 | * Silence the Linux "No buffer space available" message. |
|||
| 896 | * Added miscellaneous additional option sanity checks. |
|||
| 897 | * Added Windows version of easy-rsa scripts in |
|||
| 898 | easy-rsa/Windows directory (Andrew J. Richardson). |
|||
| 899 | * Added NetBSD route patch (Ed Ravin). |
|||
| 900 | * Added OpenBSD patch for TAP + --redirect-gateway |
|||
| 901 | (Waldemar Brodkorb). |
|||
| 902 | * Directives which prompt for a username and/or password |
|||
| 903 | will now work with --daemon (OpenVPN will prompt |
|||
| 904 | before forking). |
|||
| 905 | * Warn if CRL is from a different issuer than the |
|||
| 906 | issuer of the peer certificate (Bernhard Weisshuhn). |
|||
| 907 | * Changed init script chkconfig parameters to start |
|||
| 908 | OpenVPN daemon(s) before NFS. |
|||
| 909 | * Bug fix attempt of "too many I/O wait events" which occurs |
|||
| 910 | on OSes which prefer select() over poll() such as Mac OS X. |
|||
| 911 | * Added --ccd-exclusive flag. This flag will require, as a |
|||
| 912 | condition of authentication, that a connecting client has |
|||
| 913 | a --client-config-dir file. |
|||
| 914 | * TAP-Win32 open code will attempt to open a free adapter |
|||
| 915 | if --dev-node is not specified (Mathias Sundman). |
|||
| 916 | * Resequenced --nice and --chroot ordering so that --nice |
|||
| 917 | occurs first. |
|||
| 918 | * Added --suppress-timestamps flag (Charles Duffy). |
|||
| 919 | * Source code changes to allow compilation by MSVC |
|||
| 920 | (Peter 'Luna' Runestig). |
|||
| 921 | * Added experimental --fast-io flag which optimizes |
|||
| 922 | TUN/TAP/UDP writes on non-Windows systems. |
|||
| 923 | ||||
| 924 | 2004.08.18 -- Version 2.0-beta11 |
|||
| 925 | ||||
| 926 | * Added --server, --server-bridge, --client, and |
|||
| 927 | --keepalive helper directives. See client.conf |
|||
| 928 | and server.conf in sample-config-files for sample |
|||
| 929 | configurations which use the new directives. |
|||
| 930 | * On Windows, added --route-method to control |
|||
| 931 | whether IP Helper API or route.exe is used |
|||
| 932 | to add/delete routes. |
|||
| 933 | * On Windows, added a second parameter to |
|||
| 934 | --route-delay to control the maximum time period |
|||
| 935 | to wait for the TAP-Win32 adapter to come up |
|||
| 936 | before adding routes. |
|||
| 937 | * Fixed bug in Windows version where configurations |
|||
| 938 | which omit --ifconfig might fail to recognize when |
|||
| 939 | the TAP adapter is up. |
|||
| 940 | * Proxy connection failures will now retry according |
|||
| 941 | to the --connect-retry parameter. |
|||
| 942 | * Fixed --dev null handling on Windows so that TLS |
|||
| 943 | loopback test described in INSTALL file works |
|||
| 944 | correctly on Windows. |
|||
| 945 | * Added "Initialization Sequence Completed" message |
|||
| 946 | after all initialization steps have been completed |
|||
| 947 | and the VPN can be considered "up". |
|||
| 948 | * Better sanity-checking on --ifconfig-pool parameters. |
|||
| 949 | * Added --tcp-queue-limit option to control |
|||
| 950 | TUN/TAP -> TCP socket overflow. |
|||
| 951 | * --ifconfig-nowarn flag will now silence general |
|||
| 952 | warnings about possible --ifconfig address |
|||
| 953 | conflicts, including the warning about --ifconfig |
|||
| 954 | and --remote addresses being in same /24 subnet. |
|||
| 955 | * Fixed case where server mode did not correctly |
|||
| 956 | identify certain types of ethernet multicast packets |
|||
| 957 | (Marcel de Kogel). |
|||
| 958 | * Added --explicit-exit-notify option (experimental). |
|||
| 959 | ||||
| 960 | 2004.08.02 -- Version 2.0-beta10 |
|||
| 961 | ||||
| 962 | * Fixed possible reference after free of option strings |
|||
| 963 | after a restart, bug was introduced in beta8. |
|||
| 964 | * Fixed segfault at route.c:919 in the beta9 |
|||
| 965 | Windows version that was being caused by indirection |
|||
| 966 | through a NULL pointer. |
|||
| 967 | * Mistakenly built debug version of TAP-Win32 driver |
|||
| 968 | for beta9. Beta10 has correct release build. |
|||
| 969 | ||||
| 970 | 2004.07.30 -- Version 2.0-beta9 |
|||
| 971 | ||||
| 972 | * Fixed --route issue on Windows that was introduced with |
|||
| 973 | the new beta8 route implementation based on the |
|||
| 974 | IP Helper API. |
|||
| 975 | ||||
| 976 | 2004.07.27 -- Version 2.0-beta8 |
|||
| 977 | ||||
| 978 | * Added TCP support in server mode. |
|||
| 979 | * Added PKCS #12 support (Mathias Sundman). |
|||
| 980 | * Added patch to make revoke-crt and make-crl work |
|||
| 981 | seamlessly within the easy-rsa environment (Jan Kiszka). |
|||
| 982 | * Modified --mode server ethernet bridge code to forward |
|||
| 983 | special IEEE 802.1d MAC Groups, i.e. 01:80:C2:XX:XX:XX. |
|||
| 984 | * Added --dhcp-renew and --dhcp-release flags to Windows |
|||
| 985 | version. Normally DHCP renewal and release on the TAP |
|||
| 986 | adapter occurs automatically under Windows, however |
|||
| 987 | if you set the TAP-Win32 adapter Media Status property |
|||
| 988 | to "Always Connected", you may need these flags. |
|||
| 989 | * Added --show-net standalone flag to Windows version to |
|||
| 990 | show OpenVPN's view of the system adapter and routing |
|||
| 991 | tables. |
|||
| 992 | * Added --show-net-up flag to Windows version to output |
|||
| 993 | the system routing table and network adapter list to |
|||
| 994 | the log file after the TAP-Win32 adapter has been brought |
|||
| 995 | up and any routes have been added. |
|||
| 996 | * Modified Windows version to add routes using the IP Helper |
|||
| 997 | API rather than by calling route.exe. |
|||
| 998 | * Fixed bug where --route-up script was not being called |
|||
| 999 | if no --route options were specified. |
|||
| 1000 | * Added --mute-replay-warnings to suppress packet replay |
|||
| 1001 | warnings. This is a common false alarm on WiFi nets. |
|||
| 1002 | * Added "def1" flag to --redirect-gateway option to override |
|||
| 1003 | the default gateway by using 0.0.0.0/1 and 128.0.0.0/1 |
|||
| 1004 | rather than 0.0.0.0/0. This has the benefit of overriding |
|||
| 1005 | but not wiping out the original default gateway. |
|||
| 1006 | (Thanks to Jim Carter for pointing out this idea). |
|||
| 1007 | * You can now run OpenVPN with a single config file argument. |
|||
| 1008 | For example, you can now say "openvpn config.conf" |
|||
| 1009 | rather than "openvpn --config config.conf". |
|||
| 1010 | * On Windows, made --route and --route-delay more adaptive |
|||
| 1011 | with respect to waiting for interfaces referenced by the |
|||
| 1012 | route destination to come up. Routes added by --route |
|||
| 1013 | should now be added as soon as the interface comes up, |
|||
| 1014 | rather than after an obligatory 10 second delay. The |
|||
| 1015 | way this works internally is that --route-delay now |
|||
| 1016 | defaults to 0 on Windows. Previous versions would |
|||
| 1017 | wait for --route-delay seconds then add the routes. |
|||
| 1018 | This version will wait --route-delay seconds and then |
|||
| 1019 | test the routing table at one second intervals for the |
|||
| 1020 | next 30 seconds and will not add the routes until they |
|||
| 1021 | can be added without errors. |
|||
| 1022 | * On Windows, don't setsockopt SO_SNDBUF or SO_RCVBUF by |
|||
| 1023 | default on TCP/UDP socket in light of reports that this |
|||
| 1024 | action can have undesirable global side effects on the |
|||
| 1025 | MTU settings of other adapters. These parameters can |
|||
| 1026 | still be set, but you need to explicitly specify |
|||
| 1027 | --sndbuf and/or --rcvbuf. |
|||
| 1028 | * Added --max-clients option to limit the maximum number |
|||
| 1029 | of simultaneously connected clients in server mode. |
|||
| 1030 | * Added error message to illuminate shell escape gotcha when |
|||
| 1031 | single backslashes are used in Windows path names. |
|||
| 1032 | * Added optional netmask parm to --ifconfig-pool. |
|||
| 1033 | * Fixed bug where http-proxy connect retry attempts were |
|||
| 1034 | incorrectly going to the remote OpenVPN server, |
|||
| 1035 | not to the HTTP proxy server. |
|||
| 1036 | ||||
| 1037 | 2004.06.29 -- Version 2.0-beta7 |
|||
| 1038 | ||||
| 1039 | * Fixed bug in link_socket_verify_incoming_addr() which |
|||
| 1040 | under certain circumstances could have caused --float |
|||
| 1041 | behavior even if --float was not specified. |
|||
| 1042 | * --tls-auth option now works with --mode server. |
|||
| 1043 | All clients and the server should use the same |
|||
| 1044 | --tls-auth key when operating in client/server mode. |
|||
| 1045 | * Added --engine option to make use of OpenSSL-supported |
|||
| 1046 | crypto acceleration hardware. |
|||
| 1047 | * Fixed some high verbosity print format size issues |
|||
| 1048 | in event.c for 64 bit platforms (Janne Johansson). |
|||
| 1049 | * Made failure to open --log or --log-append file |
|||
| 1050 | a non-fatal error. |
|||
| 1051 | ||||
| 1052 | 2004.06.23 -- Version 2.0-beta6 |
|||
| 1053 | ||||
| 1054 | * Fixed Windows installer to intelligently put |
|||
| 1055 | up a reboot dialog only if tapinstall tells |
|||
| 1056 | us that it's really necessary. |
|||
| 1057 | * Fixed "Assertion failed at fragment.c:309" |
|||
| 1058 | bug when --mode server and --fragment are used |
|||
| 1059 | together. |
|||
| 1060 | * Ignore HUP, USR1, and USR2 signals during |
|||
| 1061 | initialization. Prior versions would abort. |
|||
| 1062 | * Fixed bug on OS X: "Assertion failed at event.c:406". |
|||
| 1063 | * Added --service option to Windows version, for use |
|||
| 1064 | when OpenVPN is being programmatically instantiated |
|||
| 1065 | by another process (see man page for info). |
|||
| 1066 | * --log and --log-append options now work on Windows. |
|||
| 1067 | * Update OpenBSD INSTALL notes (Janne Johansson). |
|||
| 1068 | * Enable multicast on tun interface when running on |
|||
| 1069 | OpenBSD (Pavlin Radoslavov). |
|||
| 1070 | * Fixed recent --test-crypto breakage, where options |
|||
| 1071 | such as --cipher were not being parsed correctly. |
|||
| 1072 | * Modified options compatibility string by removing |
|||
| 1073 | ifconfig substring if it is empty. Incremented |
|||
| 1074 | options compatibility string version number to 4. |
|||
| 1075 | * Fixed typo in --tls-timeout option parsing |
|||
| 1076 | (Mikael Lonnroth). |
|||
| 1077 | ||||
| 1078 | 2004.06.13 -- Version 2.0-beta5 |
|||
| 1079 | ||||
| 1080 | * Fixed rare --mode server crash that could occur |
|||
| 1081 | if data was being routed to a client at |
|||
| 1082 | high bandwidth at the precise moment that the |
|||
| 1083 | client instance object on the server was being |
|||
| 1084 | deleted. |
|||
| 1085 | * Fixed issue on machines which have epoll.h and |
|||
| 1086 | the epoll_create glibc call defined, but which |
|||
| 1087 | don't actually implement epoll in the kernel. |
|||
| 1088 | OpenVPN will now gracefully fall back to the |
|||
| 1089 | poll API in this case. |
|||
| 1090 | * Fixed Windows bug which would cause the following |
|||
| 1091 | error in a --mode server --dev tap configuration: |
|||
| 1092 | "resource limit WSA_MAXIMUM_WAIT_EVENTS has been |
|||
| 1093 | exceeded". |
|||
| 1094 | * Added CRL (certificate revocation list) management |
|||
| 1095 | scripts to easy-rsa directory (Jon Bendtsen). |
|||
| 1096 | * Do a better job of getting the ifconfig component |
|||
| 1097 | of the options consistency check to work correctly |
|||
| 1098 | when --up-delay is used. |
|||
| 1099 | * De-inlined some functions which were too complex |
|||
| 1100 | to be inlined anyway with gcc. |
|||
| 1101 | * If a --dhcp-option option is pushed to a non-windows |
|||
| 1102 | client, the option will be saved in the client's |
|||
| 1103 | environment before the --up script is called, under |
|||
| 1104 | the name "foreign_option_{n}". |
|||
| 1105 | * Added --learn-address script (see man page) which |
|||
| 1106 | allows for firewall access through the VPN to be |
|||
| 1107 | controlled based on the client common name. |
|||
| 1108 | * In mode --server mode, when a client connects to |
|||
| 1109 | the server, the server will disconnect any |
|||
| 1110 | still-active clients which use the same common |
|||
| 1111 | name. Use --duplicate-cn flag to revert to |
|||
| 1112 | previous behavior of allowing multiple clients |
|||
| 1113 | to concurrently connect with the same common name. |
|||
| 1114 | ||||
| 1115 | 2004.06.08 -- Version 2.0-beta4 |
|||
| 1116 | ||||
| 1117 | * Fixed issue with beta3 where Win32 service wrapper |
|||
| 1118 | was keying off of old TAP HWID as a dependency. To |
|||
| 1119 | ensure that the new service wrapper is correctly |
|||
| 1120 | installed, the Windows install script will uninstall |
|||
| 1121 | the old wrapper before installing the new one, |
|||
| 1122 | causing a reset of service properties. |
|||
| 1123 | * Fixed permissions issue on --status output file, |
|||
| 1124 | with default access permissions of owner read/write |
|||
| 1125 | only (default permissions can be changed of course with |
|||
| 1126 | chmod). |
|||
| 1127 | ||||
| 1128 | 2004.06.05 -- Version 2.0-beta3 |
|||
| 1129 | ||||
| 1130 | * More changes to TAP-Win32 driver's INF file which |
|||
| 1131 | affects the placement of the driver in the Windows |
|||
| 1132 | device namespace. This is done to work around an |
|||
| 1133 | apparent bug in Windows when short HWIDs are used, |
|||
| 1134 | and will also ease the upgrade from 1.x to 2.0 by |
|||
| 1135 | reducing the chances that a reboot will be needed |
|||
| 1136 | on upgrade. Like beta2, this upgrade will |
|||
| 1137 | delete existing TAP-Win32 interfaces, and reinstall |
|||
| 1138 | a single new interface with default properties. |
|||
| 1139 | * Major rewrite of I/O event wait layer in the style |
|||
| 1140 | of libevent. This is a precursor to TCP support |
|||
| 1141 | in --mode server. |
|||
| 1142 | * New feature: --status. Outputs a SIGUSR2-like |
|||
| 1143 | status summary to a given file, updated once |
|||
| 1144 | per n seconds. The status file is comma delimited |
|||
| 1145 | for easy machine parsing. |
|||
| 1146 | * --ifconfig-pool now remembers common names and |
|||
| 1147 | will try to assign a consistent IP to a given |
|||
| 1148 | common name. Still to do: persist --ifconfig-pool |
|||
| 1149 | memory across restarts by saving state in file. |
|||
| 1150 | * Fixed bug in event timer queue which could cause |
|||
| 1151 | recurring timer events such as --ping to not |
|||
| 1152 | correctly schedule again after firing. This in |
|||
| 1153 | turn would cause spurrious ping restarts and possible |
|||
| 1154 | connection outages. Thanks to Denis Vlasenko for |
|||
| 1155 | tracking this down. |
|||
| 1156 | * Possible fix to reported bug where --daemon argument |
|||
| 1157 | was not printing to syslog correctly after restart. |
|||
| 1158 | * Fixed bug where pulling --route or --dhcp-option |
|||
| 1159 | directives from a server would problematically |
|||
| 1160 | interact with --persist-tun on the client. |
|||
| 1161 | * Updated contrib/multilevel-init.patch (Farkas Levente). |
|||
| 1162 | * Added RPM build option to .spec and .spec.in files |
|||
| 1163 | to optionally disable LZO inclusion (Ian Pilcher). |
|||
| 1164 | * The latest MingW runtime and headers define |
|||
| 1165 | 'ssize_t', so a patch is needed (Gisle Vanem). |
|||
| 1166 | ||||
| 1167 | 2004.05.14 -- Version 2.0-beta2 |
|||
| 1168 | ||||
| 1169 | * Fixed signal handling bug in --mode server, where |
|||
| 1170 | SIGHUP and SIGUSR1 were treated as SIGTERM. |
|||
| 1171 | * Changed the TAP-Win32 HWID from "TAP" to "TAPDEV". |
|||
| 1172 | Apparently the larger string may work around |
|||
| 1173 | a problem where the TAP adapter is sometimes missing |
|||
| 1174 | from the network connections panel, especially under |
|||
| 1175 | XP SP2. Also note that installing this upgrade will |
|||
| 1176 | uninstall any pre-existing TAP-Win32 adapters, and then |
|||
| 1177 | install a single new adapter, meaning that old adapter |
|||
| 1178 | properties will be lost. Thanks to Md5Chap for solving |
|||
| 1179 | this one. |
|||
| 1180 | * For --mode server --dev tap, the options --ifconfig and |
|||
| 1181 | --ifconfig-pool are now optional. This allows address |
|||
| 1182 | assignment via DHCP or use of a TAP VPN without |
|||
| 1183 | IP support, as has always been possible with 1.x. |
|||
| 1184 | * Fixed bug where --ifconfig may not work correctly on |
|||
| 1185 | Linux 2.2. |
|||
| 1186 | * Added 'local' flag to --redirect-gateway for use on |
|||
| 1187 | networks where both OpenVPN daemons are connected |
|||
| 1188 | to a shared subnet, such as wireless. |
|||
| 1189 | ||||
| 1190 | 2004.05.09 -- Version 2.0-beta1 |
|||
| 1191 | ||||
| 1192 | * Unchanged from test29 except for version number |
|||
| 1193 | upgrade. |
|||
| 1194 | ||||
| 1195 | 2004.05.08 -- Version 2.0-test29 |
|||
| 1196 | ||||
| 1197 | * Modified --dev-node on Windows to accept a TAP-Win32 |
|||
| 1198 | GUID name. In addition, --show-adapters will now |
|||
| 1199 | display the high-level name and GUID of each adapter. |
|||
| 1200 | This is an attempt to work around an issue in Windows |
|||
| 1201 | where sometimes the TAP-Win32 adapter installs correctly |
|||
| 1202 | but has no icon in the network connections control |
|||
| 1203 | panel. In such cases, being able to specify |
|||
| 1204 | --dev-node {TAP-GUID} can work around the missing icon. |
|||
| 1205 | ||||
| 1206 | 2004.05.07 -- Version 2.0-test28 |
|||
| 1207 | ||||
| 1208 | * Fixed bug which could cause segfault on program |
|||
| 1209 | shutdown if --route and --persist-tun are used |
|||
| 1210 | together. |
|||
| 1211 | ||||
| 1212 | 2004.05.06 -- Version 2.0-test27 |
|||
| 1213 | ||||
| 1214 | * Fixed bug in close_instance() which might cause |
|||
| 1215 | memory to be accessed after it had already been freed. |
|||
| 1216 | * Fixed bug in verify_callback() that might have |
|||
| 1217 | caused uninitialized data to be referenced. |
|||
| 1218 | * --iroute now allows full CIDR subnet routing. |
|||
| 1219 | * In "--mode server --dev tun" usage, source addresses |
|||
| 1220 | on VPN packets coming from a particular client must |
|||
| 1221 | be associated with that client in the OpenVPN internal |
|||
| 1222 | routing table. |
|||
| 1223 | ||||
| 1224 | 2004.04.28 -- Version 2.0-test26 |
|||
| 1225 | ||||
| 1226 | * Optimized broadcast path in multi-client mode. |
|||
| 1227 | * Added socket buffer size options --rcvbuf & --sndbuf. |
|||
| 1228 | * Configure Linux tun/tap driver to use a more sensible |
|||
| 1229 | txqueuelen default. Also allow explicit setting |
|||
| 1230 | via --txqueuelen option (Harald Roelle). |
|||
| 1231 | * The --remote option now allows the port number |
|||
| 1232 | to be specified as the second parameter. If |
|||
| 1233 | unspecified, the port number defaults to the |
|||
| 1234 | --rport value. |
|||
| 1235 | * Multiple --remote options on the client can now be |
|||
| 1236 | specified for load balancing and failover. The |
|||
| 1237 | --remote-random flag can be used to initially randomize |
|||
| 1238 | the --remote list for basic load balancing. |
|||
| 1239 | * If a remote DNS name resolves to multiple DNS addresses, |
|||
| 1240 | one will be chosen by random as a kind of basic |
|||
| 1241 | load-balancing feature if --remote-random is used. |
|||
| 1242 | * Added --connect-freq option to control maximum |
|||
| 1243 | new connection frequency in multi-client mode. |
|||
| 1244 | * In multi-client mode, all syslog messages associated |
|||
| 1245 | with a specific client now include a client-ID prefix. |
|||
| 1246 | * For Windows, use a gettimeofday() function based |
|||
| 1247 | on QueryPerformanceCounter (Derek Burdick). |
|||
| 1248 | * Fixed bug in interaction between --key-method 2 |
|||
| 1249 | and DES ciphers, where dynamic keys would be generated |
|||
| 1250 | with bad parity and then be rejected. |
|||
| 1251 | ||||
| 1252 | 2004.04.17 -- Version 2.0-test24 |
|||
| 1253 | ||||
| 1254 | * Reworked multi-client broadcast handling. |
|||
| 1255 | ||||
| 1256 | 2004.04.13 -- Version 2.0-test23 |
|||
| 1257 | ||||
| 1258 | * Fixed bug in --dev tun --client-to-client routing. |
|||
| 1259 | * Fixed a potential deadlock in --pull. |
|||
| 1260 | * Fixed a problem with select() usage which could |
|||
| 1261 | cause a repeating sequence of "select : Invalid |
|||
| 1262 | argument (code=22)" |
|||
| 1263 | ||||
| 1264 | 2004.04.11 -- Version 2.0-test22 |
|||
| 1265 | ||||
| 1266 | * Fixed bug where --mode server + --daemon was |
|||
| 1267 | prematurely closing syslog connection. |
|||
| 1268 | * Added support for --redirect-gateway on Mac OS X |
|||
| 1269 | (Jeremy Apple). |
|||
| 1270 | * Minor changes to TAP-Win32 driver based on feedback |
|||
| 1271 | from the NDISTest tool. |
|||
| 1272 | ||||
| 1273 | 2004.04.11 -- Version 2.0-test21 |
|||
| 1274 | ||||
| 1275 | * Optimizations in multi-client server event loop. |
|||
| 1276 | ||||
| 1277 | 2004.04.10 -- Version 2.0-test20 |
|||
| 1278 | ||||
| 1279 | * --mode server capability now works with either tun |
|||
| 1280 | or tap interfaces. When used with tap interfaces, |
|||
| 1281 | OpenVPN will internally bridge all client tap |
|||
| 1282 | interfaces with the server tap interface. |
|||
| 1283 | * Connecting clients can now have a client-specific |
|||
| 1284 | configuration on the server, based on the client |
|||
| 1285 | common name embedded in the client certificate. |
|||
| 1286 | See --client-config-dir and --client-connect. |
|||
| 1287 | These options can be used to configure client-specific |
|||
| 1288 | routes. |
|||
| 1289 | * Added an option --client-to-client that enables |
|||
| 1290 | internal client-to-client routing or bridging. |
|||
| 1291 | Otherwise, clients will only "see" the server, |
|||
| 1292 | not other connected clients. |
|||
| 1293 | * Fixed bug in route scheduling which would have caused |
|||
| 1294 | --mode server to not work on Windows in test18 |
|||
| 1295 | and test19 with the sample config file. |
|||
| 1296 | * Man page is up to date with all new options. |
|||
| 1297 | * OpenVPN 2.0 release notes on web site updated |
|||
| 1298 | with tap-style tunnel examples. |
|||
| 1299 | ||||
| 1300 | 2004.04.02 -- Version 2.0-test19 |
|||
| 1301 | ||||
| 1302 | * Fixed bug where routes pushed from server were |
|||
| 1303 | not working correctly on Windows clients. |
|||
| 1304 | * Added Mac OS X route patch (Jeremy Apple). |
|||
| 1305 | ||||
| 1306 | 2004.03.30 -- Version 2.0-test18 |
|||
| 1307 | ||||
| 1308 | * Minor fixes + Windows self-install modified |
|||
| 1309 | to use OpenSSL 0.9.7d. |
|||
| 1310 | ||||
| 1311 | 2004.03.29 -- Version 2.0-test17 |
|||
| 1312 | ||||
| 1313 | * Fixed some bugs related to instance timeout and deletion. |
|||
| 1314 | * Extended --push/--pull option to support additional |
|||
| 1315 | option classes. |
|||
| 1316 | ||||
| 1317 | 2004.03.28 -- Version 2.0-test16 |
|||
| 1318 | ||||
| 1319 | * Successful test of --mode udp-server, --push, |
|||
| 1320 | --pull, and --ifconfig-pool with server on |
|||
| 1321 | Linux 2.4 and clients on Linux and Windows. |
|||
| 1322 | ||||
| 1323 | 2004.03.25 -- Version 2.0-test15 |
|||
| 1324 | ||||
| 1325 | * Implemented hash-table lookup of client instances |
|||
| 1326 | based either on remote UDP address/port or remote |
|||
| 1327 | ifconfig endpoint. |
|||
| 1328 | * Implemented a randomized binary tree based |
|||
| 1329 | scheduler for scalably scheduling a large number |
|||
| 1330 | of client instance events. Uses the treap |
|||
| 1331 | data structure and node rotation algorithm |
|||
| 1332 | to keep the tree balanced. |
|||
| 1333 | * Initial implementation of ifconfig-pool. |
|||
| 1334 | * Made --key-method 2 the default. |
|||
| 1335 | ||||
| 1336 | 2004.03.20 -- Version 2.0-test14 |
|||
| 1337 | ||||
| 1338 | * Implemented --push and --pull. |
|||
| 1339 | ||||
| 1340 | 2004.03.20 -- Version 2.0-test13 |
|||
| 1341 | ||||
| 1342 | * Reduced struct tls_multi and --single-session |
|||
| 1343 | memory footprint. |
|||
| 1344 | * Modified --single-session flag to be used |
|||
| 1345 | in multi-client UDP server client instances. |
|||
| 1346 | ||||
| 1347 | 2004.03.19 -- Version 2.0-test12 |
|||
| 1348 | ||||
| 1349 | * Added the key multi-client UDP server options, |
|||
| 1350 | --mode, --push, --pull, and --ifconfig-pool. |
|||
| 1351 | * Revamped GC (garbage collection) code to not rely |
|||
| 1352 | on any global data. |
|||
| 1353 | * Modifications to thread.[ch] to allow a more |
|||
| 1354 | flexible thread model. |
|||
| 1355 | ||||
| 1356 | 2004.03.16 -- Version 2.0-test11 |
|||
| 1357 | ||||
| 1358 | * Moved all timer code to interval.h, added new file |
|||
| 1359 | interval.c. |
|||
| 1360 | * Fixed missing include. |
|||
| 1361 | ||||
| 1362 | 2004.03.16 -- Version 2.0-test10 |
|||
| 1363 | ||||
| 1364 | * More TAP-Win32 fixes. |
|||
| 1365 | * Initial debugging and testing of multi.[ch]. |
|||
| 1366 | ||||
| 1367 | 2004.03.14 -- Version 2.0-test9 |
|||
| 1368 | ||||
| 1369 | * Branch merge with 1.6-rc3 |
|||
| 1370 | * More point-to-multipoint work in multi.[ch]. |
|||
| 1371 | * Major TAP-Win32 driver restructuring to use |
|||
| 1372 | NdisMRegisterDevice instead of |
|||
| 1373 | IoCreateDevice/IoCreateSymbolicLink. |
|||
| 1374 | * Changed TAP-Win32 symbolic links to use \DosDevices\Global\ |
|||
| 1375 | pathname prefix. |
|||
| 1376 | * In the majority of cases, TAP-Win32 should now be |
|||
| 1377 | able to install and uninstall on Win2K without requiring |
|||
| 1378 | a reboot. |
|||
| 1379 | * TAP-Win32 MAC address can now be explicitly set in the |
|||
| 1380 | adapter advanced properties page. |
|||
| 1381 | ||||
| 1382 | 2004.03.04 -- Version 2.0-test8 |
|||
| 1383 | ||||
| 1384 | * Branch merge with 1.6-rc2. |
|||
| 1385 | ||||
| 1386 | 2004.03.03 -- Version 2.0-test7 |
|||
| 1387 | ||||
| 1388 | * Branch merge with 1.6-rc1.2. |
|||
| 1389 | ||||
| 1390 | 2004.03.02 -- Version 2.0-test6 |
|||
| 1391 | ||||
| 1392 | * Branch merge with 1.6-rc1. |
|||
| 1393 | ||||
| 1394 | 2004.03.02 -- Version 2.0-test5 |
|||
| 1395 | ||||
| 1396 | * Move Socks5 UDP header append/remove to socks.c, and is |
|||
| 1397 | called from forward.c. |
|||
| 1398 | * Moved verify statics from ssl.c into struct tls_session. |
|||
| 1399 | * Wrote multi.[ch] to handle top level of point-to-multipoint |
|||
| 1400 | mode. |
|||
| 1401 | * Wrote some code to allow a struct link_socket in a child context |
|||
| 1402 | to be slaved to the parent context. |
|||
| 1403 | * Broke up packet read and process functions in forward.c |
|||
| 1404 | (from socket or tuntap) into separate functions for read |
|||
| 1405 | and process, so that point-to-point and point-to-multipoint can |
|||
| 1406 | share the same code. |
|||
| 1407 | * Expand TLS control channel to allow the passing of configuration |
|||
| 1408 | commands. |
|||
| 1409 | * Wrote mroute.[ch] to handle internal packet routing for |
|||
| 1410 | point-to-multipoint mode. |
|||
| 1411 | ||||
| 1412 | 2004.02.22 -- Version 2.0-test3 |
|||
| 1413 | ||||
| 1414 | * Initial work on UDP multi-client server. |
|||
| 1415 | * Branch merge of 1.6-beta7 |
|||
| 1416 | ||||
| 1417 | 2004.02.14 -- Version 2.0-test2 |
|||
| 1418 | ||||
| 1419 | * Refactorization of openvpn.c into openvpn.[ch] |
|||
| 1420 | init.[ch] forward.[ch] forward-inline.h |
|||
| 1421 | occ.[ch] occ-inline.h ping.[ch] ping-inline.h |
|||
| 1422 | sig.[ch]. Created a master per-tunnel |
|||
| 1423 | struct context in openvpn.h. |
|||
| 1424 | * Branch merge of 1.6-beta6.2 |
|||
| 1425 | ||||
| 1426 | 2003.11.06 -- Version 2.0-test1 |
|||
| 1427 | ||||
| 1428 | * Initial testbed for 2.0. |
|||
| 1429 | ``` |
