Blame

39f6a8 Samuli Seppänen 2025-02-11 09:59:33 1
# OpenVPN 2.3.18
2
3
```
4
Antonio Quartulli (1):
5
crypto: correct typ0 in error message
6
7
David Sommerseth (1):
8
Preparing OpenVPN 2.3.18 release
9
10
Steffan Karger (2):
11
Deprecate --ns-cert-type
12
Fix bounds check in read_key()
13
14
Szilárd Pfeiffer (1):
15
OpenSSL: Always set SSL_OP_CIPHER_SERVER_PREFERENCE flag
16
```
17
18
# OpenVPN 2.3.17
19
20
```
21
David Sommerseth (2):
22
backport: Ignore auth-nocache for auth-user-pass if auth-token is pushed
23
auth-token with auth-nocache fix broke --disable-crypto builds
24
25
Gert Doering (3):
26
Fix potential 1-byte overread in TCP option parsing.
27
Fix remotely-triggerable ASSERT() on malformed IPv6 packet.
28
Preparing for release v2.3.17 (ChangeLog, version.m4, Changes.rst)
29
30
Guido Vranken (6):
31
refactor my_strupr
32
Fix 2 memory leaks in proxy authentication routine
33
Fix memory leak in add_option() for option 'connection'
34
Ensure option array p[] is always NULL-terminated
35
Fix a null-pointer dereference in establish_http_proxy_passthru()
36
Prevent two kinds of stack buffer OOB reads and a crash for invalid input data
37
38
Jérémie Courrèges-Anglas (2):
39
Fix an unaligned access on OpenBSD/sparc64
40
Missing include for socket-flags TCP_NODELAY on OpenBSD
41
42
Steffan Karger (4):
43
openssl: fix overflow check for long --tls-cipher option
44
Fix remote-triggerable memory leaks (CVE-2017-7521)
45
Restrict --x509-alt-username extension types
46
Fix potential double-free in --x509-alt-username (CVE-2017-7521)
47
```
48
49
# OpenVPN 2.3.16
50
51
```
52
Antonio Quartulli (1):
53
fix redirect-gateway behaviour when an IPv4 default route does not exist
54
55
Gert Doering (1):
56
Preparing for release v2.3.16 (ChangeLog, version.m4)
57
58
Guido Vranken (1):
59
Avoid a 1 byte overcopy in x509_get_subject (ssl_verify_openssl.c)
60
61
Selva Nair (1):
62
Check for errors in the return value of GetModuleFileNameW()
63
64
Steven McDonald (1):
65
Fix gateway detection with OpenBSD routing domains
66
```
67
68
# OpenVPN 2.3.15
69
70
```
71
David Sommerseth (6):
72
dev-tools: Added script for updating copyright years in files
73
Update copyrights
74
docs: Further improve --reneg-bytes and SWEET32 information
75
git: Merge .gitignore files into a single file
76
Make --cipher/--auth none more explicit on the risks
77
Prepare v2.3.15 release
78
79
Gert Doering (1):
80
Document --proto udp6, tcp6, etc.
81
82
Julien Muchembled (1):
83
Fix implicit declarations when HAVE_OPENSSL_ENGINE is unset
84
85
Steffan Karger (6):
86
Add missing includes in error.h
87
cleanup: merge packet_id_alloc_outgoing() into packet_id_write()
88
Document that OpenVPN 2.3 does not check the CRL signature
89
Introduce and use secure_memzero() to erase secrets
90
Drop packets instead of assert out if packet id rolls over (CVE-2017-7479)
91
Don't assert out on receiving too-large control packets (CVE-2017-7478)
92
```
93
94
# OpenVPN 2.3.14
95
96
```
97
Christian Hesse (1):
98
update year in copyright message
99
100
David Sommerseth (2):
101
man: Improve the --keepalive section
102
Document the --auth-token option
103
104
Gert Doering (3):
105
Repair topology subnet on FreeBSD 11
106
Repair topology subnet on OpenBSD
107
Preparing release of v2.3.14
108
109
Lev Stipakov (1):
110
Drop recursively routed packets
111
112
Selva Nair (4):
113
Support --block-outside-dns on multiple tunnels
114
When parsing '--setenv opt xx ..' make sure a third parameter is present
115
Map restart signals from event loop to SIGTERM during exit-notification wait
116
Correctly state the default dhcp server address in man page
117
118
Steffan Karger (1):
119
Clean up format_hex_ex()
120
```
121
122
# OpenVPN 2.3.13
123
124
```
125
Arne Schwabe (2):
126
Use AES ciphers in our sample configuration files and add a few modern 2.4 examples
127
Incorporate the Debian typo fixes where appropriate and make show_opt default message clearer
128
129
David Sommerseth (5):
130
t_client.sh: Make OpenVPN write PID file to avoid various sudo issues
131
t_client.sh: Add support for Kerberos/ksu
132
t_client.sh: Improve detection if the OpenVPN process did start during tests
133
t_client.sh: Add prepare/cleanup possibilties for each test case
134
Preparing release of v2.3.13
135
136
Gert Doering (5):
137
Do not abort t_client run if OpenVPN instance does not start.
138
Fix t_client runs on OpenSolaris
139
make t_client robust against sudoers misconfiguration
140
add POSTINIT_CMD_suf to t_client.sh and sample config
141
Fix --multihome for IPv6 on 64bit BSD systems.
142
143
Ilya Shipitsin (1):
144
skip t_lpback.sh and t_cltsrv.sh if openvpn configured --disable-crypto
145
146
Lev Stipakov (2):
147
Exclude peer-id from pulled options digest
148
Fix compilation in pedantic mode
149
150
Samuli Seppänen (1):
151
Automatically cache expected IPs for t_client.sh on the first run
152
153
Steffan Karger (6):
154
Fix unittests for out-of-source builds
155
Make gnu89 support explicit
156
cleanup: remove code duplication in msg_test()
157
Update cipher-related man page text
158
Limit --reneg-bytes to 64MB when using small block ciphers
159
Add a revoked cert to the sample keys
160
```
161
162
# OpenVPN 2.3.12
163
164
```
165
Arne Schwabe (2):
166
Complete push-peer-info documentation and allow IV_PLAT_VER for other platforms than Windows if the client UI supplies it.
167
Move ASSERT so external-key with OpenSSL works again
168
169
David Sommerseth (5):
170
Only build and run cmocka unit tests if its submodule is initialized
171
Another fix related to unit test framework
172
Remove NOP function and callers
173
Revert "Drop recursively routed packets"
174
Preparing release of v2.3.12
175
176
Dorian Harmans (1):
177
Add CHACHA20-POLY1305 ciphersuite IANA name translations.
178
179
Ivo Manca (1):
180
Plug memory leak in mbedTLS backend
181
182
Jeffrey Cutter (1):
183
Update contrib/pull-resolv-conf/client.up for no DOMAIN
184
185
Jens Neuhalfen (2):
186
Add unit testing support via cmocka
187
Add a test for auth-pam searchandreplace
188
189
Josh Cepek (1):
190
Push an IPv6 CIDR mask used by the server, not the pool's size
191
192
Leon Klingele (1):
193
Add link to bug tracker
194
195
Lev Stipakov (1):
196
Drop recursively routed packets
197
198
Samuli Seppänen (2):
199
Update CONTRIBUTING.rst to allow GitHub PRs for code review purposes
200
Clarify the fact that build instructions in README are for release tarballs
201
202
Selva Nair (4):
203
Make error non-fatal while deleting address using netsh
204
Make block-outside-dns work with persist-tun
205
Ignore SIGUSR1/SIGHUP during exit notification
206
Promptly close the netcmd_semaphore handle after use
207
208
Steffan Karger (4):
209
Fix polarssl / mbedtls builds
210
Don't limit max incoming message size based on c2->frame
211
Fix '--cipher none --cipher' crash
212
Discourage using 64-bit block ciphers
213
```
214
215
# OpenVPN 2.3.11
216
217
```
218
Gert Doering (1):
219
Preparing for release v2.3.11 (ChangeLog, version.m4)
220
221
James Yonan (1):
222
Fixed port-share bug with DoS potential
223
224
Jens Neuhalfen (2):
225
Make intent of utun device name validation clear
226
Fix buffer overflow by user supplied data
227
228
Leonardo Basilio (1):
229
Correctly report TCP connection timeout on windows.
230
231
Lev Stipakov (1):
232
Report Windows bitness
233
234
Michael McConville (1):
235
Fix undefined signed shift overflow
236
237
Niels Ole Salscheider (1):
238
Fix build with libressl
239
240
Samuli Seppänen (1):
241
Improve LZO, PAM and OpenSSL documentation
242
243
Selva Nair (2):
244
Ensure input read using systemd-ask-password is null terminated
245
Support reading the challenge-response from console
246
247
Steffan Karger (10):
248
openssl: improve logging
249
polarssl: improve logging
250
Update manpage: OpenSSL might also need /dev/urandom inside chroot
251
socks.c: fix check on get_user_pass() return value(s)
252
Fix OCSP_check.sh
253
hardening: add safe FD_SET() wrapper openvpn_fd_set()
254
Fix memory leak in argv_extract_cmd_name()
255
Replace MSG_TEST() macro for static inline msg_test()
256
Restrict default TLS cipher list
257
Various Changes.rst fixes
258
259
ValdikSS (3):
260
Clarify mssfix documentation
261
Clarify --block-outside-dns documentation
262
Update --block-outside-dns to work on Windows Vista
263
```
264
265
# OpenVPN 2.3.10
266
267
```
268
Gert Doering (2):
269
Prepare for v2.3.10 release, list PolarSSL 1.2 to 1.3 upgrade
270
Preparing for release v2.3.10 (ChangeLog, version.m4)
271
272
Jan Just Keijser (1):
273
Make certificate expiry warning patch (091edd8e299686) work on OpenSSL 1.0.1 and earlier.
274
275
Lev Stipakov (1):
276
Repair IPv6 netsh calls if Win XP is detected
277
278
Phillip Smith (1):
279
Use bob.example.com and alice.example.com to improve clarity of documentation
280
281
Steffan Karger (6):
282
Remove unused variables from ssl_verify_polarssl.c's x509_get_serial()
283
Upgrade OpenVPN 2.3 to PolarSSL 1.3
284
Warn user if their certificate has expired
285
Make assert_failed() print the failed condition
286
cleanup: get rid of httpdigest.c type warnings
287
Fix regression in setups without a client certificate
288
289
Yegor Yefremov (1):
290
polarssl: fix unreachable code
291
```
292
293
# OpenVPN 2.3.9
294
295
OpenVPN 2.3.9 contains the following changes:
296
297
```
298
Arne Schwabe (7):
299
Show extra-certs in current parameters.
300
Fix commit a3160fc1bd7368395745b9cee6e40fb819f5564c
301
Do not set the buffer size by default but rely on the operation system default.
302
Remove --enable-password-save option
303
Reflect enable-password-save change in documentation
304
Also remove second instance of enable-password-save in the man page
305
Detect config lines that are too long and give a warning/error
306
307
Boris Lytochkin (1):
308
Log serial number of revoked certificate
309
310
Christos Trochalakis (1):
311
Adjust server-ipv6 documentation
312
313
David Sommerseth (1):
314
Avoid partial authentication state when using --disabled in CCD configs
315
316
Fish (1):
317
Make "block-outside-dns" option platform agnostic
318
319
Gert Doering (8):
320
Un-break --auth-user-pass on windows
321
Replace unaligned 16bit access to TCP MSS value with bytewise access
322
Repair test_local_addr() on WIN32
323
Fix possible heap overflow on read accessing getaddrinfo() result.
324
Fix FreeBSD-specific mishandling of gc arena pointer in create_arbitrary_remote()
325
remove unused gc_arena in FreeBSD close_tun()
326
Fix isatty() check for good.
327
Preparing for release v2.3.9 (ChangeLog, version.m4)
328
329
Heiko Hund (1):
330
put virtual IPv6 addresses into env
331
332
Lev Stipakov (5):
333
Use adapter index instead of name for windows IPv6 interface config
334
Client-side part for server restart notification
335
Use adapter index for add/delete_route_ipv6
336
Pass adapter index to up/down scripts
337
Fix VS2013 compilation
338
339
Lukasz Kutyla (1):
340
Fix privilege drop if first connection attempt fails
341
342
Michal Ludvig (1):
343
Support for username-only auth file.
344
345
Samuli Seppänen (2):
346
Add CONTRIBUTING.rst
347
Updates to Changes.rst
348
349
Selva Nair (4):
350
Fix termination when windows suspends/sleeps
351
Do not hard-code windows systemroot in env_block
352
Handle ctrl-C and ctrl-break events on Windows
353
Unbreak read username password from management
354
355
Steffan Karger (11):
356
Replace strdup() calls for string_alloc() calls
357
Check return value of ms_error_text()
358
Increase control channel packet size for faster handshakes
359
hardening: add insurance to exit on a failed ASSERT()
360
Fix memory leak in auth-pam plugin
361
Fix (potential) memory leak in init_route_list()
362
Fix unintialized variable in plugin_vlog()
363
Add macro to ensure we exit on fatal errors
364
Fix memory leak in add_option() by simplifying get_ipv6_addr
365
openssl: properly check return value of RAND_bytes()
366
Fix rand_bytes return value checking
367
368
ValdikSS (1):
369
Add Windows DNS Leak fix using WFP ('block-outside-dns')
370
371
janjust (1):
372
Fix "White space before end tags can break the config parser"
373
```
374
375
376
# OpenVPN 2.3.8
377
378
OpenVPN 2.3.8 contains the following changes:
379
380
```
381
Arne Schwabe (2):
382
Report missing endtags of inline files as warnings
383
Fix commit e473b7c if an inline file happens to have a line break exactly at buffer limit
384
385
Gert Doering (3):
386
Produce a meaningful error message if --daemon gets in the way of asking for passwords.
387
Document --daemon changes and consequences (--askpass, --auth-nocache).
388
Preparing for release v2.3.8 (ChangeLog, version.m4)
389
390
Holger Kummert (1):
391
Del ipv6 addr on close of linux tun interface
392
393
James Geboski (1):
394
Fix --askpass not allowing for password input via stdin
395
396
Steffan Karger (5):
397
write pid file immediately after daemonizing
398
Make __func__ work with Visual Studio too
399
fix regression: query password before becoming daemon
400
Fix using management interface to get passwords.
401
Fix overflow check in openvpn_decrypt()
402
```
403
404
The OpenVPN 2.3.8 source packages and Windows installers contain one ''additional'' fix:
405
406
```
407
Gert Doering (1):
408
Un-break --auth-user-pass on windows
409
```
410
411
This means that custom Windows builds should be based on 2.3.8 source packages or on the "release/2.3" branch instead of the "v2.3.8" tag in Git.
412
413
# OpenVPN 2.3.7
414
415
```
416
Alexander Pyhalov (1):
417
Default gateway can't be determined on illumos/Solaris platforms
418
419
Arne Schwabe (1):
420
Warn that tls-auth with free form files is going to be removed from OpenVPN 2.4
421
422
David Sommerseth (6):
423
autotools: Fix wrong ./configure help screen default values
424
down-root plugin: Replaced system() calls with execve()
425
down-root: Improve error messages
426
plugin, down-root: Fix compiler warnings
427
sockets: Remove the limitation of --tcp-nodelay to be server-only
428
plugins, down-root: Code style clean-up
429
430
David Woodhouse (2):
431
pkcs11: Load p11-kit-proxy.so module by default
432
Make 'provider' option to --show-pkcs11-ids optional where p11-kit is present
433
434
Felix Janda (1):
435
Use OPENVPN_ETH_P_* so that <netinet/if_ether.h> is unecessary
436
437
Gert Doering (18):
438
New approach to handle peer-id related changes to link-mtu (2.3 version)
439
Fix incorrect use of get_ipv6_addr() for iroute options.
440
Print helpful error message on --mktun/--rmtun if not available.
441
explain effect of --topology subnet on --ifconfig
442
Add note about file permissions and --crl-verify to manpage.
443
repair --dev null breakage caused by db950be85d37
444
assume res_init() is always there.
445
Correct note about DNS randomization in openvpn.8
446
Disallow usage of --server-poll-timeout in --secret key mode.
447
slightly enhance documentation about --cipher
448
Enforce "serial-tests" behaviour for tests/Makefile
449
Revert "Enforce "serial-tests" behaviour for tests/Makefile"
450
On signal reception, return EAI_SYSTEM from openvpn_getaddrinfo().
451
Use configure.ac hack to apply serial_test AM option only if supported.
452
Use EAI_AGAIN instead of EAI_SYSTEM for openvpn_getaddrinfo().
453
Move res_init() call to inner openvpn_getaddrinfo() loop
454
Fix FreeBSD ifconfig for topology subnet tunnels.
455
Preparing for release v2.3.7 (ChangeLog, version.m4)
456
457
Guy Yur (1):
458
Fix --redirect-private in --dev tap mode.
459
460
Jan Just Keijser (1):
461
include ifconfig_ environment variables in --up-restart env set
462
463
Jonathan K. Bullard (1):
464
Fix null pointer dereference in options.c
465
466
Lev Stipakov (1):
467
Fix mssfix default value in connection_list context
468
469
Matthias Andree (1):
470
Manual page update for Re-enabled TLS version negotiation.
471
472
Mike Gilbert (1):
473
Include systemd units in the source tarball (make dist)
474
475
Robert Fischer (1):
476
Updated manpage for --rport and --lport
477
478
Samuli Seppänen (2):
479
Properly escape dashes on the man-page
480
Improve documentation in --script-security section of the man-page
481
482
Steffan Karger (14):
483
Really fix '--cipher none' regression
484
Update doxygen (a bit)
485
Set tls-version-max to 1.1 if cryptoapicert is used
486
Account for peer-id in frame size calculation
487
Disable SSL compression
488
Fix frame size calculation for non-CBC modes.
489
Allow for CN/username of 64 characters (fixes off-by-one)
490
Remove unneeded parameter 'first_time' from possibly_become_daemon()
491
Re-enable TLS version negotiation by default
492
Remove size limit for files inlined in config
493
Improve --tls-cipher and --show-tls man page description
494
Re-read auth-user-pass file on (re)connect if required
495
Clarify --capath option in manpage
496
Call daemon() before initializing crypto library
497
```
498
499
# OpenVPN 2.3.6
500
501
```
502
David Sommerseth (1):
503
systemd: Reworked the systemd unit file to handle server and client configs better
504
505
Gert Doering (2):
506
Add client-only support for peer-id.
507
Preparing for release v2.3.6 (ChangeLog, version.m4)
508
509
Samuli Seppänen (1):
510
Fix to --shaper documentation on the man-page
511
512
Steffan Karger (4):
513
Fix assertion error when using --cipher none
514
Add --tls-version-max
515
Modernize sample keys and sample configs
516
Drop too-short control channel packets instead of asserting out.
517
```
518
519
# OpenVPN 2.3.5
520
521
```
522
Andris Kalnozols (2):
523
Fix some typos in the man page.
524
Do not upcase x509-username-field for mixed-case arguments.
525
526
Arne Schwabe (1):
527
Fix server routes not working in topology subnet with --server [v3]
528
529
David Sommerseth (4):
530
Improve error reporting on file access to --client-config-dir and --ccd-exclusive
531
Don't let openvpn_popen() keep zombies around
532
Add systemd unit file for OpenVPN
533
systemd: Use systemd functions to consider systemd availability
534
535
Gert Doering (4):
536
Drop incoming fe80:: packets silently now.
537
Fix t_lpback.sh platform-dependent failures
538
Call init script helpers with explicit path (./)
539
Preparing for release v2.3.5 (ChangeLog, version.m4)
540
541
Heiko Hund (1):
542
refine assertion to allow other modes than CBC
543
544
Hubert Kario (2):
545
ocsp_check - signature verification and cert staus results are separate
546
ocsp_check - double check if ocsp didn't report any errors in execution
547
548
James Bekkema (1):
549
Fix socket-flag/TCP_NODELAY on Mac OS X
550
551
James Yonan (6):
552
Fixed several instances of declarations after statements.
553
In socket.c, fixed issue where uninitialized value (err) is being passed to to gai_strerror.
554
Explicitly cast the third parameter of setsockopt to const void * to avoid warning.
555
MSVC 2008 doesn't support dimensioning an array with a const var nor using %z as a printf format specifier.
556
Define PATH_SEPARATOR for MSVC builds.
557
Fixed some compile issues with show_library_versions()
558
559
Jann Horn (1):
560
Remove quadratic complexity from openvpn_base64_decode()
561
562
Mike Gilbert (1):
563
Add configure check for the path to systemd-ask-password
564
565
Philipp Hagemeister (2):
566
Add topology in sample server configuration file
567
Implement on-link route adding for iproute2
568
569
Samuel Thibault (1):
570
Ensure that client-connect files are always deleted
571
572
Steffan Karger (13):
573
Remove function without effect (cipher_ok() always returned true).
574
Remove unneeded wrapper functions in crypto_openssl.c
575
Fix bug that incorrectly refuses oid representation eku's in polar builds
576
Update README.polarssl
577
Rename ALLOW_NON_CBC_CIPHERS to ENABLE_OFB_CFB_MODE, and add to configure.
578
Add proper check for crypto modes (CBC or OFB/CFB)
579
Improve --show-ciphers to show if a cipher can be used in static key mode
580
Extend t_lpback tests to test all ciphers reported by --show-ciphers
581
Don't exit daemon if opening or parsing the CRL fails.
582
Fix typo in cipher_kt_mode_{cbc, ofb_cfb}() doxygen.
583
Fix regression with password protected private keys (polarssl)
584
ssl_polarssl.c: fix includes and make casts explicit
585
Remove unused variables from ssl_verify_openssl.c extract_x509_extension()
586
587
TDivine (1):
588
Fix "code=995" bug with windows NDIS6 tap driver.
589
```
590
591
# OpenVPN 2.3.4
592
593
```
594
Arne Schwabe (1):
595
Fix man page and OSCP script: tls_serial_{n} is decimal
596
597
Dmitrij Tejblum (1):
598
Fix is_ipv6 in case of tap interface.
599
600
Gert Doering (8):
601
IPv6 address/route delete fix for Win8
602
Add SSL library version reporting.
603
Minor t_client.sh cleanups
604
Repair --multihome on FreeBSD for IPv4 sockets.
605
Rewrite manpage section about --multihome
606
More IPv6-related updates to the openvpn man page.
607
Conditionalize calls to print_default_gateway on !ENABLE_SMALL
608
Preparing for release v2.3.4 (ChangeLog, version.m4)
609
610
James Yonan (2):
611
Use native strtoull() with MSVC 2013.
612
When tls-version-min is unspecified, revert to original versioning approach.
613
614
Steffan Karger (4):
615
Change signedness of hash in x509_get_sha1_hash(), fixes compiler warning.
616
Fix OCSP_check.sh to also use decimal for stdout verification.
617
Fix build system to accept non-system crypto library locations for plugins.
618
Make serial env exporting consistent amongst OpenSSL and PolarSSL builds.
619
620
Yawning Angel (1):
621
Fix SOCKSv5 method selection
622
623
kangsterizer (1):
624
Fix typo in sample build script to use LDFLAGS
625
```
626
627
# OpenVPN 2.3.3
628
629
```
630
Alon Bar-Lev (1):
631
pkcs11: use generic evp key instead of rsa
632
633
Arne Schwabe (8):
634
Add support of utun devices under Mac OS X
635
Add support to ignore specific options.
636
Add a note what setenv opt does for OpenVPN < 2.3.3
637
Add reporting of UI version to basic push-peer-info set.
638
Fix compile error in ssl_openssl introduced by polar external-management patch
639
Fix assertion when SIGUSR1 is received while getaddrinfo is successful
640
Add warning for using connection block variables after connection blocks
641
Introduce safety check for http proxy options
642
643
David Sommerseth (5):
644
man page: Update man page about the tls_digest_{n} environment variable
645
Remove the --disable-eurephia configure option
646
plugin: Extend the plug-in v3 API to identify the SSL implementation used
647
autoconf: Fix typo
648
Fix file checks when --chroot is being used
649
650
Davide Brini (1):
651
Document authfile for socks server
652
653
Gert Doering (9):
654
Fix IPv6 examples in t_client.rc-sample
655
Fix slow memory drain on each client renegotiation.
656
t_client.sh: ignore fields from "ip -6 route show" output that distort results.
657
Make code and documentation for --remote-random-hostname consistent.
658
Reduce IV_OPENVPN_GUI_VERSION= to IV_GUI_VER=
659
Document issue with --chroot, /dev/urandom and PolarSSL.
660
Rename 'struct route' to 'struct route_ipv4'
661
Replace copied structure elements with including <net/route.h>
662
Workaround missing SSL_OP_NO_TICKET in earlier OpenSSL versions
663
664
Heikki Hannikainen (1):
665
Always load intermediate certificates from a PKCS#12 file
666
667
Heiko Hund (2):
668
Support non-ASCII TAP adapter names on Windows
669
Support non-ASCII characters in Windows tmp path
670
671
James Yonan (3):
672
673
TLS version negotiation
674
Added "setenv opt" directive prefix.
675
Set SSL_OP_NO_TICKET flag in SSL context for OpenSSL builds, to disable TLS stateless session resumption.
676
677
Jens Wagner (1):
678
Fix spurious ignoring of pushed config options (trac#349).
679
680
Joachim Schipper (3):
681
Refactor tls_ctx_use_external_private_key()
682
--management-external-key for PolarSSL
683
external_pkcs1_sign: Support non-RSA_SIG_RAW hash_ids
684
685
Josh Cepek (2):
686
Correct error text when no Windows TAP device is present
687
Require a 1.2.x PolarSSL version
688
689
Klee Dienes (1):
690
tls_ctx_load_ca: Improve certificate error messages
691
692
Max Muster (1):
693
Remove duplicate cipher entries from TLS translation table.
694
695
Peter Sagerson (1):
696
Fix configure interaction with static OpenSSL libraries
697
698
Steffan Karger (7):
699
Do not pass struct tls_session* as void* in key_state_ssl_init().
700
Require polarssl >= 1.2.10 for polarssl-builds, which fixes CVE-2013-5915.
701
Use RSA_generate_key_ex() instead of deprecated, RSA_generate_key()
702
Also update TLSv1_method() calls in support code to SSLv23_method() calls.
703
Update TLSv1 error messages to SSLv23 to reflect changes from commit 4b67f98
704
If --tls-cipher is supplied, make --show-tls parse the list.
705
Add openssl-specific common cipher list names to ssl.c.
706
707
Tamas TEVESZ (1):
708
Add support for client-cert-not-required for PolarSSL.
709
710
Thomas Veerman (1):
711
Fix "." in description of utun.
712
```
713
714
# OpenVPN 2.3.2
715
716
```
717
Arne Schwabe (3):
718
Only print script warnings when a script is used. Remove stray mention of script-security system.
719
Move settings of user script into set_user_script function
720
Move checking of script file access into set_user_script
721
722
Davide Brini (1):
723
Provide more accurate warning message
724
725
Gert Doering (3):
726
Fix NULL-pointer crash in route_list_add_vpn_gateway().
727
Fix problem with UDP tunneling due to mishandled pktinfo structures.
728
Preparing for v2.3.2 (ChangeLog, version.m4)
729
730
James Yonan (1):
731
Always push basic set of peer info values to server.
732
733
Jan Just Keijser (1):
734
make 'explicit-exit-notify' pullable again
735
736
Josh Cepek (2):
737
Fix proto tcp6 for server & non-P2MP modes
738
Fix Windows script execution when called from script hooks
739
740
Steffan Karger (2):
741
Fixed tls-cipher translation bug in openssl-build
742
Fixed usage of stale define USE_SSL to ENABLE_SSL
743
744
svimik (1):
745
Fix segfault when enabling pf plug-ins
746
```
747
748
# OpenVPN 2.3.1
749
750
```
751
Arne Schwabe (4):
752
Remove dead code path and putenv functionality
753
Remove unused function xor
754
Move static prototype definition from header into c file
755
Remove unused function no_tap_ifconfig
756
757
Christian Hesse (1):
758
fix build with automake 1.13(.1)
759
760
Christian Niessner (1):
761
Fix corner case in NTLM authentication (trac #172)
762
763
Gert Doering (6):
764
Update README.IPv6 to match what is in 2.3.0
765
Repair "tcp server queue overflow" brokenness, more <stdbool.h> fallout.
766
Permit pool size of /64.../112 for ifconfig-ipv6-pool
767
Add MIN() compatibility macro
768
Fix directly connected routes for "topology subnet" on Solaris.
769
Preparing for v2.3.1 (ChangeLog, version.m4)
770
771
Heiko Hund (5):
772
close more file descriptors on exec
773
Ignore UTF-8 byte order mark
774
reintroduce --no-name-remapping option
775
make --tls-remote compatible with pre 2.3 configs
776
add new option for X.509 name verification
777
778
Jan Just Keijser (1):
779
man page patch for missing options
780
781
Josh Cepek (2):
782
Fix parameter listing in non-debug builds at verb 4
783
(updated) [PATCH] Warn when using verb levels >=7 without debug
784
785
Matthias Andree (1):
786
Enable TCP_NODELAY configuration on FreeBSD.
787
788
Samuli Seppänen (4):
789
Removed ChangeLog.IPv6
790
Added cross-compilation information INSTALL-win32.txt
791
Updated README
792
Cleaned up and updated INSTALL
793
794
Steffan Karger (7):
795
PolarSSL-1.2 support
796
Improve PolarSSL key_state_read_{cipher, plain}text messages
797
Improve verify_callback messages
798
Config compatibility patch. Added translate_cipher_name.
799
Switch to IANA names for TLS ciphers.
800
Fixed autoconf script to properly detect missing pkcs11 with polarssl.
801
Use constant time memcmp when comparing HMACs in openvpn_decrypt.
802
```
803
804
# OpenVPN 2.3.0
805
806
This release fixes two bugs present in 2.3-rc2 and earlier:
807
808
```
809
David Sommerseth (1):
810
Preparing for v2.3.0
811
812
Gert Doering (2):
813
Fix parameter type for IP_TOS setsockopt on non-Linux systems.
814
Fix client crash on double PUSH_REPLY.
815
```
816
817
It includes major changes compared to latest 2.2.x ("oldstable") release:
818
819
* Full IPv6 support
820
* SSL layer modularised, enabling easier implementation for other SSL libraries
821
* PolarSSL support as a drop-in replacement for OpenSSL
822
* New plug-in API providing direct certificate access, improved logging API and easier to extend in the future
823
* Added 'dev_type' environment variable to scripts and plug-ins - which is set to 'TUN' or 'TAP'
824
* New feature: --management-external-key - to provide access to the encryption keys via the management interface
825
* New feature: --x509-track option, more fine grained access to X.509 fields in scripts and plug-ins
826
* New feature: --client-nat support
827
* New feature: --mark which can mark encrypted packets from the tunnel, suitable for more advanced routing and firewalling
828
* New feature: --management-query-proxy - manage proxy settings via the management interface (supercedes --http-proxy-fallback)
829
* New feature: --stale-routes-check, which cleans up the internal routing table
830
* New feature: --x509-username-field, where other X.509v3 fields can be used for the authentication instead of Common Name
831
* Improved client-kill management interface command
832
* Improved UTF-8 support - and added --compat-names to provide backwards compatibility with older scripts/plug-ins
833
* Improved auth-pam with COMMONNAME support, passing the certificate's common name in the PAM conversation
834
* More options can now be used inside <connection> blocks
835
* Completely new build system, enabling easier cross-compilation and Windows builds
836
* Much of the code has been better documented
837
* Many documentation updates
838
* Plenty of bug fixes and other code clean-ups
839
840
# OpenVPN 2.3_rc2
841
842
```
843
Adriaan de Jong (1):
844
Fix --show-pkcs11-ids (Bug #239)
845
846
Arne Schwabe (4):
847
Error message if max-routes used incorrectly
848
Properly require --key even if defined(MANAGMENT_EXTERNAL_KEY)
849
Remove dnsflags_to_socktype, it is not used anywhere
850
Fix the proto is used inconsistently warning
851
852
David Sommerseth (4):
853
Fix double-free issue in pf_destroy_context()
854
The get_default_gateway() function uses warn() instead of msg()
855
Avoid recursion in virtual_output_callback_func()
856
Preparing for v2.3_rc2
857
858
Gert Doering (2):
859
Implement --mssfix handling for IPv6 packets.
860
Fix option inconsistency warnings about "proto" and "tun-ipv6"
861
862
Joachim Schipper (2):
863
doc/management-notes.txt: fix typo
864
Fix typo in ./configure message
865
```
866
867
# OpenVPN 2.3_rc1
868
869
```
870
Adriaan de Jong (1):
871
Fixed a bug where PolarSSL gave an error when using an inline file tag.
872
873
Arne Schwabe (2):
874
Document man agent-external-key
875
Options parsing demands unnecessary configuration if PKCS11 is used
876
877
David Sommerseth (3):
878
Make git ignore some more files
879
Remove the support for using system() when executing external programs or scripts
880
Preparing for v2.3_rc1
881
882
Heiko Hund (2):
883
Fix display of plugin hook types
884
Support UTF-8 --client-config-dir
885
886
Kenneth Rose (1):
887
Fix v3 plugins to support returning values back to OpenVPN.
888
```
889
890
891
# OpenVPN 2.3_beta1
892
893
```
894
Arne Schwabe (7):
895
Fixes error: --key fails with EXTERNAL_PRIVATE_KEY: No such file or directory if --management-external-key is used
896
Merge almost identical create_socket_tcp and create_socket_tcp6
897
Document the inlining of files in openvpn and document key-direction
898
Merge getaddr_multi and getaddr6 into one function
899
Document --management-client and --management-signal a bit better
900
Document that keep alive will double the second value in server mode and give a short explanation why the value is chosen.
901
Add checks for external-key-managements
902
903
David Sommerseth (1):
904
Fix reconnect issues when --push and UDP is used on the server
905
906
Gert Doering (4):
907
Reduce --version string detail about IPv6 to just "[IPv6]".
908
Put actual OpenVPN command line on top of corresponding log file.
909
Keep pre-existing tun/tap devices around on *BSD
910
make "ipv6 ifconfig" on linux compatible with busybox ifconfig
911
912
Heiko Hund (6):
913
fix regression with --http-proxy[-*] options
914
add x_msg_va() log function
915
add API for plug-ins to write to openvpn log
916
remove stale _openssl_get_subject() prototype
917
remove unused flag SSLF_NO_NAME_REMAPPING
918
Add --compat-names option
919
```
920
921
# OpenVPN 2.3-alpha3
922
923
This release fixes a major problem in "tap server" mode (Trac #216), adds support for querying proxy information via the management interface and fixes some smaller issues. In addition, the Windows installer comes with tap-windows-9.9.2 (fixes the "DHCP NAK bomb on Windows 7" bug, Trac #97) and openvpn-gui-1.0.5.
924
925
'''Full list of changes'''
926
927
```
928
2012.07.20 -- Version 2.3_alpha3
929
Arne Schwabe (1):
930
Fix compiling with --disable-management
931
932
Gert Doering (1):
933
Repair "tap server" mode brokenness caused by <stdbool.h> fallout
934
935
Heiko Hund (4):
936
make non-blocking connect work on Windows
937
don't treat socket related errors special anymore
938
remove unused show_connection_list debug function
939
add option --management-query-proxy
940
```
941
942
943
# OpenVPN 2.3-alpha2
944
945
The largest change in OpenVPN 2.3-alpha2 is the split into several subprojects:
946
947
* [https://github.com/OpenVPN/openvpn openvpn] (the core project)
948
* [https://github.com/OpenVPN/tap-windows tap-windows] (Windows TAP-driver)
949
* [https://github.com/OpenVPN/easy-rsa easy-rsa] (PKI management package)
950
* [https://github.com/OpenVPN/openvpn-build openvpn-build] (external buildsystem)
951
* "generic": cross-compile on *NIX platforms (e.g. Linux -> Windows)
952
* "msvc": build using MSVC on Windows
953
* "windows-nsis": generate Windows installers on *NIX
954
955
These changes have resulted in a number of user-visible changes:
956
957
* Separate 32- and 64-bit installers for Windows (see ''INSTALL-win32.txt'')
958
* Old "domake-win" and Python-based buildsystems have been removed
959
* "easy-rsa" and "tap-windows" removed from the OpenVPN Git tree
960
* All Windows executables and libraries cross-compiled with mingw_w64 and signed
961
* Rewrite of the openvpn autotools buildsystem
962
963
In addition, there a number of changes not related to the above:
964
965
* Many bugfixes
966
* Stabilized the PolarSSL support
967
* Enabled IPv6 support on OSX
968
* General code cleanup
969
* Improved UTF-8 support in Windows
970
971
'''Full list of changes'''
972
973
```
974
tag v2.3_alpha2
975
Tagger: David Sommerseth <davids@redhat.com>
976
Date: Fri Jun 29 10:36:38 2012 +0200
977
978
2012.06.29 -- Version 2.3_alpha2
979
Adriaan de Jong (11):
980
Fixed off-by-one in serial length calculation
981
Migrated x509_get_subject to use of the garbage collector
982
Migrated x509_get_serial to use the garbage collector
983
Migrated x509_get_sha1_hash to use the garbage collector
984
Ensure sys/un.h autoconf detection includes sys/socket.h
985
Added support for new PolarSSL 1.1 RNG
986
Added a configuration option to enable prediction resistance in the PolarSSL random number generator.
987
Use POLARSSL_CFLAGS instead of POLARSSL_CRYPTO_CFLAGS in configure.ac
988
Removed support for PolarSSL < 1.1
989
Updated README.polarssl with build system changes.
990
Removed stray "Fox-IT hardening" string.
991
992
Alon Bar-Lev (94):
993
build: version should not contain '-'
994
package: rpm: strip should be handled by package management
995
cleanup: options.c: remove redundant include
996
cleanup: remove C++ warnings
997
cleanup: win32.c: wrong printf format
998
cleanup: remove redundant ';'
999
cleanup: crypto_openssl.c: remove support for pre-openssl-0.9.6
1000
cleanup: tun.c: fix incorrect option in message (ip-win32)
1001
cleanup: memcmp.c: remove unused source
1002
fixup: init.c: add missing conditional for ENABLE_CLIENT_CR
1003
build: correct place to alter WINVER is at build system
1004
Update .gitignore
1005
build: handle printf style format in mingw
1006
build: rename plugin directory to plugins
1007
build: plugins: properly use CC, CFLAGS and LDFLAGS
1008
build: we need the sample.ovpn in future
1009
Remove install-win32
1010
Remove easy-rsa
1011
Remove tap-win32
1012
cleanup: rename tap-windows function from win32 to win
1013
build: remove windows specific build system
1014
build: split acinclude.m4 into m4/*
1015
build: m4/ax_varargs.m4: cleanup
1016
build: m4/ax_emptyarray.m4: cleanup
1017
build: m4/ax_socklen_t.m4: cleanup
1018
build: autotools: first pass of trivial autotools changes
1019
build: autoconf: remove OPENVPN_ADD_LIBS useless macro
1020
build: remove awk and non-standard autoconf output processing
1021
build: standard directory layout
1022
build: add libtool + windows resources for executables
1023
build: autoconf: commands as environment
1024
build: libdl usage
1025
build: properly detect and use socket libs
1026
build: autoconf: minor cleanups
1027
build: proper selinux detection and usage
1028
build: distribute pkg.m4
1029
build: proper pkcs11-helper detection and usage
1030
build: properly process lzo-stub
1031
build: proper lzo detection and usage
1032
build: proper crypto detection and usage
1033
build: autoconf: update defaults for options
1034
build: win-msvc: msbuild format
1035
build: move out config.h include from syshead
1036
build: split out compat
1037
build: move gettimeofday() emulation to compat
1038
build: move daemon() emulation into compat
1039
build: move inet_ntop(), inet_pton() emulation into compat
1040
cleanup: move console related function into its own module
1041
build: move wrappers into platform module
1042
build: windows: install version.sh to allow installer read version
1043
build: distribute samples in windows
1044
build: use tap-windows.h as external dependency
1045
build: ax_varargs.m4: fixups
1046
build: autoconf: misc sockets fixups
1047
build: enable lzo by default
1048
build: windows: set vendor to openvpn project + cleanups
1049
build: assume dlfcn is available on all supported platforms
1050
build: openbsd: detect netinet/ip.h correctly
1051
build: tap: search for tap header
1052
build: msvc: upgrade to Visual Studio 2010 + fixups
1053
Enable pedantic in windows compilation
1054
cleanup: flags should not be bool
1055
cleanup: avoid using ~0 - generic
1056
cleanup: avoid using ~0 - ipv6
1057
cleanup: avoid using ~0 - netmask
1058
cleanup: avoid using ~0 - windows
1059
cleanup: gc usage
1060
build: fix some statement left from conversion
1061
build: properly detect netinet/ip.h structs
1062
build: properly detect TUNSETPERSIST
1063
cleanup: plugin: support C++ plugin
1064
cleanup: remove C++ comments
1065
cleanup: add .gitattributes to control eol style explicitly
1066
crash: packet_id_debug_print: sl may be null
1067
build: use stdbool.h if available
1068
build: fix typo in --enable-save-password
1069
build: windows: convert resources to UTF-8
1070
build: check minimum polarssl version
1071
cleanup: update .gitignore
1072
cleanup: spec: make space/tab consistent
1073
build: spec: we support openssl >= 0.9.7
1074
build: insall README* document using build system
1075
build: detect sys/wait.h required for *bsd
1076
build: add git revision to --version output if build from git repository
1077
build: cleanup: yet another forgotten brackets
1078
build: update INSTALL to recent changes
1079
build: support platforms that does not need explicit tun headers
1080
build: do not support <polarssl-1.1.0
1081
build: add --with-special-build to provide special build string
1082
cleanup: pkcs11.c: resolve wanings
1083
build: integrate plugins build into core build
1084
build: plugins: set defaults based on platform
1085
cleanup: windows: convert argv (UCS-2 to UTF-8) at earliest
1086
build: msvc: chdir with change drive to script location
1087
1088
Arne Schwabe (7):
1089
Add the query to the error message.
1090
Explain that route-nopull also causes the client to ignore dhcp options.
1091
Add the name of the context where option is not allowed to the error message.
1092
Only use tmpdir if tmp_dir is really used.
1093
Completely remove ancient IANA port warning.
1094
Remove ENABLE_INLINE_FILES conditionals
1095
Remove ENABLE_CONNECTIONS ifdefs
1096
1097
David Sommerseth (5):
1098
Clean-up: Presume that Linux is always IPv6 capable at build time
1099
Simplify check_cmd_access() function
1100
Change version to indicate the master branch is not a version
1101
Some filesystems don't like ':', which is a path 'make dist' would use
1102
Remove two unused functions
1103
1104
Frank de Brabander (1):
1105
Fix reported compile issues on OSX 10.6.8
1106
1107
Gert Doering (10):
1108
repair t_client.sh test after build system revolution
1109
t_client.sh iproute2 script fixes
1110
t_client.sh - fix for iproute2, print summary line
1111
Implement search for "first free" tun/tap device on Solaris
1112
cleanup and redefine metric handling for IPv6 routes
1113
remove "*option" element in "struct route_ipv6"
1114
Remove warning about explicit support for IPv6 support not provided MacOS X
1115
Add missing pieces to IPv6 route gateway handling.
1116
Update TODO.IPv6 list
1117
Remove #include "config.h" from ssl_polarssl.h
1118
1119
Heiko Hund (3):
1120
remove wrapper code for Windows CryptoAPI function
1121
fix warnings in event.c when building for win32-64
1122
remove the --auto-proxy option from openvpn
1123
1124
Igor Novgorodov (1):
1125
Remove calls to OpenSSL when building with --disable-ssl
1126
1127
Jonathan K. Bullard (2):
1128
Fix file access checks on commands
1129
Clarified the docs and help screen about what a 'cmd' is
1130
1131
Samuli Seppänen (1):
1132
Added notes about upgrading from 2.3-alpha1 and earlier to INSTALL-win32.txt
1133
-----BEGIN PGP SIGNATURE-----
1134
Version: GnuPG v1.4.11 (GNU/Linux)
1135
1136
iEYEABECAAYFAk/taVIACgkQDC186MBRfrpdxQCfQ+jfqA5kujaoZ+1Vj6SUOoms
1137
ljkAn1obwJrSAP7MYiVp944u6t2EQ3r7
1138
=uh6E
1139
-----END PGP SIGNATURE-----
1140
```
1141
1142
# OpenVPN 2.3-alpha1
1143
1144
This release includes a large number of new features:
1145
1146
* Complete IPv6 support, both transport and payload
1147
* Optional PolarSSL support (build time configuration)
1148
* Improved plug-in API (v3) which can more easily be expanded in the future. Includes support for direct access to X.509 certificate data in plug-ins
1149
* New build-time configuration option: --enable-lzo-stub - Clients tell the server if they support LZO or not, and server can automatically disable LZO for that client.
1150
* [https://sourceforge.net/projects/openvpn-gui/ New OpenVPN-GUI]
1151
1152
* New options / updated options
1153
* ''--stale-routes-check'': remove routes that haven't had activity recently
1154
* ''--client-nat'': one-to-one NAT to avoid IP address conflicts between local and remote networks
1155
* ''--extra-certs'': certificates which completes the CA chain, without trusting these certificates
1156
* ''--verify-hash'': Fingerprint matching on level-1 certificates
1157
* ''--memstats'': Write live usage stats to memory mapped binary files
1158
* ''--crl-verify'' directory mode: file names in this dir which matching the serial numbers are treated as a revoked certificate. These files itself may be empty, as it is only done a match against the file name.
1159
1160
1161
* Management interface improvements
1162
* New option ''--management-external-key'': Load RSA keys via management interface
1163
* New option ''--management-up-down'': notify management interface on tunnel up/down events
1164
* New management command for servers: ''client-kill''
1165
* New management command for clients: ''auth-token'' provides a feature to avoid storing passwords in memory and use a temporary token as an alternative to passing the password.
1166
* New management command for clients: ''remote'' which can override the configured --remote options
1167
1168
Many enhancements are also included:
1169
1170
* Management command for server, status, can report username for each connected user (requires status log version >= 2)
1171
* UTF-8 support for certificate fields
1172
* Windows UTF-8 support: Filenames may now contain wide characters and environment variables handled as UCS-2 characters
1173
* Fixed client issues with DHCP Router option extraction/deletion with layer 2 DHCP proxies.
1174
* Added "on-link" routes on Linux. This solves --redirect-gateway issues where routes are set up with devices instead of IP addresses
1175
* Several configuration options are now supported inside <connection> blocks
1176
* Add extv3 X509 field support to --x509-username-field
1177
* Several man page updates
1178
1179
A few changes have been made which may affect existing installations:
1180
1181
* 'echo' options will no longer be written to log files and will only be available via the management interface.
1182
* The certificate strings have changed syntax to the new standard provided newer OpenSSL APIs. Earlier the format was:
1183
1184
```/CN=Common Name/O=Organisation/L=Location```
1185
1186
The new format will look like:
1187
1188
```CN=Common Name, O=Organisation, L=Location```
1189
1190
This change impacts plug-ins, scripts and --tls-remote which parses these certificate strings.
1191
1192
'''Full list of changes'''
1193
1194
```
1195
Adriaan de Jong (127):
1196
Added Doxygen doxyfile
1197
Changed configure to accept --with-ssl-type=openssl
1198
Refactored to rand_bytes for OpenSSL-independency
1199
Refactored OpenSSL-specific constants
1200
Refactored maximum cipher and hmac length constants
1201
Refactored show_available_* functions
1202
Refactored SSL_clear_error()
1203
Refactored crypto initialisation functions
1204
Refactored DES key manipulation functions
1205
Refactored NTLM DES key generation
1206
Refactored message digest type functions
1207
Refactored message digest functions
1208
Refactored HMAC functions
1209
Refactored cipher key types
1210
Refactored cipher functions
1211
Added PRNG doxygen
1212
Refactored: Moved crypto.h inline functions to end of file
1213
Removed stale OpenSSL defines from crypto.h
1214
Added a check for Openssl or PolarSSL defines
1215
Refactored: Added stubs for new files
1216
Refactored SSL initialisation functions
1217
Refactored TLS_PRF to new hmac and md primitives
1218
Refactored tls_show_available_ciphers
1219
Refactored get_highest_preference_tls_cipher
1220
Refactored root SSL context initialisation
1221
Refactored new external key code
1222
Refactored DH paramater loading
1223
Refactored root TLS option settings
1224
Refactored PKCS#12 key loading
1225
Refactored PKCS#11 loading
1226
Refactored windows cert loading
1227
Refactored load certificate functions
1228
Refactored private key loading code
1229
Refactored external key loading from management
1230
Refactored CA and extra certs code
1231
Refactored cipher restriction code
1232
Refactored tls_options, key_state, and key_source data structures
1233
Refactored initalisation of key_states
1234
Refactored key_state free code
1235
Refactored print_details
1236
Refactored key_state read code (including bio_read())
1237
Refactored key_state write functions
1238
Refactored: Moved BIO debug functions to OpenSSL backend
1239
Refactored: removed ks and ks_lame macro for clarity
1240
Refactored: moved write_empty_string function back
1241
Refactored Doxygen for tls_multi functions
1242
Migrated data structures needed by verification functions to ssl_common.h
1243
Refactored client_config_dir_exclusive function
1244
Refactored certificate hash lock checks
1245
Refactored common name locking functions
1246
Refactored username and password authentication code
1247
Add some extra comments
1248
Refactored: split verify_callback into two parts
1249
Added function to extract and verify the subject from a certificate
1250
Added function to verify and extract the username
1251
Refactored: removed global x509_username_field
1252
Refactored: separated environment setup during verification
1253
Refactored: Netscape certificate type verification
1254
Refactored key usage verification code
1255
Refactored EKU verification
1256
Refactored tls-remote checking
1257
Refactored tls-verify-plugin code
1258
Refactored tls-verify script code
1259
Refactored CRL checks
1260
Minor cleanup in verify_cert:
1261
Refactored: Moved verify_cert to ssl_verify
1262
Cleaned up ssl.h
1263
Refactored: made M_SSL dependent on USE_OPENSSL
1264
Refactored: renamed X509 functions from verify_*
1265
Separated OpenSSL-specific parts of the PKCS#11 driver
1266
Modified base64 code in preparation for PolarSSL merge
1267
Final cleanup before PolarSSL addition:
1268
Refactored X509 track feature to be contained within the openssl backend
1269
Added PolarSSL support:
1270
Fixed a missing include in ssl_backend.h
1271
Fixed a bug in the hash generation in ssl_verify_openssl.c
1272
Added SHA_DIGEST_SIZE definition
1273
Changed PolarSSL crypto backend to support v0.99-pre5
1274
Updated ssl_polarssl.c to work with 0.99-pre5
1275
Fixed a compilation warning for size_t key sizes
1276
Added a warning that the PolarSSL library does not support pkcs12 files.
1277
Added warning that --capath is not available with PolarSSL
1278
Disable CryptoAPI when not using OpenSSL, and document that fact.
1279
Removed support for management external keys in PolarSSL
1280
Removed stray X509_free from ssl.c
1281
Refactored (and disabled for PolarSSL) support for writing external cert files in scripts
1282
Added an extra define to allow building without PKCS#11
1283
Added SSL library to title string
1284
Disabled X.509 track and username selection for PolarSSL
1285
Hardening: periodically reset the PRNG's nonce value
1286
Fixes for the plugin system:
1287
Further improvements to plugin support:
1288
Fixed an unintentional change in the options calculated key size.
1289
Moved print messages back to generic crypto.c from cipher backends
1290
Moved HMAC prints back to main crypto module
1291
Added back checks for ks->authenticated in verify_user_pass
1292
Moved gc_new and gc_free to begin end of function
1293
Fixed a bug in the return value of ssl_verify when pre_verify failed
1294
Unified verification function return values:
1295
Removed a stray Fox-IT tag
1296
Fixed a typo: print the subject instead of the serial for verification errors
1297
Made SSL_CIPHER const in print_details, to fix warning
1298
Moved to PolarSSL 1.0.0:
1299
Added missing #ifdef to allow --disable-managent to work again
1300
Fixed disabling crypto and SSL
1301
Got rid of a few magic numbers in ntlm.c
1302
Removed obsolete des_cblock and des_keyschedule
1303
Further removal of des_old.h based calls
1304
Fixed missing comma in plugin.h
1305
Moved prng_uninit out of crypto_uninit_lib
1306
Moved CryptoAPI header include to the ssl_openssl.c
1307
Reordered functions to ensure warning-free Windows build
1308
Added options to switch between OpenSSL and PolarSSL and PKCS11...
1309
Moved from strsep to strtok, for Windows compatibility
1310
Minor cleanup to enable warning-free Windows build:
1311
Fixed a typo when initialising cryptoapi certs
1312
Minor code cleanup: cleaned up error handling in verify_cert.
1313
Moved out of memory prototype to error.h, as the definition is in error.c
1314
Removed support for calling gc_malloc with a NULL gc_arena struct
1315
1316
(The follwing patches from Adriaan was mistakenly merged with
1317
the wrong commit author in the git tree)
1318
Doxygen: Added data channel crypto docs
1319
Added control channel crypto docs
1320
Added compression docs
1321
Added reliability layer documentation
1322
Added memory management documentation
1323
Added data channel fragmentation docs
1324
Added main/control docs
1325
Moved doxygen-specific files to a separate directory
1326
1327
Byron Ellacott (1):
1328
autoconf fixes for building on OSX
1329
1330
David Sommerseth (50):
1331
Provide 'dev_type' environment variable to plug-ins and script hooks
1332
Define the new openvpn_plugin_{open,func}_v3() API
1333
Implement the core v3 plug-in function calls.
1334
Extend the v3 plug-in API to send over X509 certificates
1335
Added a simple plug-in demonstrating the v3 plug-in API.
1336
Separate the general plug-in version constant and v3 plug-in structs version
1337
Use a version-less version identifier on the master branch
1338
Fix the --client-cert-not-required feature
1339
Change the default --tmp-dir path to a more suitable path
1340
Improve the mysprintf() issue in openvpnserv.c
1341
Add a simple comment regarding openvpn_snprintf() is duplicated
1342
Merge branch 'feat_ipv6_transport'
1343
Merge branch 'feat_ipv6_payload'
1344
Merge branch 'svn-branch-2.1' into merge
1345
Solved hidden merge conflicts between master and svn-branch-2.1
1346
Fix const declarations in plug-in v3 structs
1347
Merge remote-tracking branch 'cron2/feat_ipv6_payload_2.3'
1348
Don't define ENABLE_PUSH_PEER_INFO if SSL is not available
1349
Fix compiling issues with pkcs11 when --disable-management is configured
1350
Remove support for Linux 2.2 configuration fallback
1351
Revert "Add new openssl.cnf to easy-rsa/Windows"
1352
Merge remote branch SVN 2.1 into the git tree
1353
Merge branch 'svn-merger'
1354
Fix Microsoft Visual Studio incompatibility in plugin.c
1355
Fixed compile issues on FreeBSD and Solaris
1356
Fix PolarSSL and --pkcs12 option issues
1357
Fix FreeBSD/OpenBSD/NetBSD compiler warnings in get_default_gateway()
1358
Make '--win-sys env' default
1359
Do some file/directory tests before really starting openvpn
1360
Fix bug after removing Linux 2.2 support
1361
Don't look for 'stdin' file when using --auth-user-pass
1362
Fix compiling with --disable-crypto and/or --disable-ssl
1363
Fix a couple of issues in openvpn_execve()
1364
Move away from openvpn_basename() over to platform provided basename()
1365
Enable access() when building in Visual Studio
1366
New Windows build fixes
1367
Fix compilation errors on Linux platforms without SO_MARK
1368
autotools ./configure don't like compat.h
1369
Fix pool logging when IPv6 is not enabled
1370
Don't check for file presence on inline files
1371
Add --route-pre-down/OPENVPN_PLUGIN_ROUTE_PREDOWN script/plug-in hook
1372
Enhance the error handling in _openssl_get_subject()
1373
Fix assert() situations where gc_malloc() is called without a gc_arena object
1374
Fix compile issues when plug-ins are disabled.
1375
Remove --show-gateway if debug info is not enabled (--disable-debug)
1376
Fix compile issues with status.c
1377
Connection entry {tun,link}_mtu_defined not set correctly
1378
Makefile.am referenced a now non-existing config-win32.h
1379
Makefile.am was missing ssl_common.h
1380
Revamp check_file_access() checks in stdin scenarios
1381
1382
Davide Guerri (1):
1383
New feauture: Add --stale-routes-check
1384
1385
Frank de Brabander (1):
1386
Fixed wrong return type of cipher_kt_mode
1387
1388
Frederic Crozat (1):
1389
Add support to forward console query to systemd
1390
1391
Gert Doering (45):
1392
Add more detailed explanation regarding the function of "--rdns-internal"
1393
Enable IPv6 Payload in OpenVPN p2mp tun server mode. 20100104-1 release.
1394
remove NOTES file from commit - private scribbling
1395
NetBSD fixes - on 4.0 and up, use multi-af mode.
1396
new feature: "ifconfig-ipv6-push" (from ccd/ config)
1397
add some TODOs to TODO.IPv6
1398
undo accidential duplication of existing "--iroute" line in the help text
1399
basic documentation of IPv6 related options and their syntax
1400
Enable IPv6 Payload in OpenVPN p2mp tun server mode.
1401
remove NOTES file from commit - private scribbling
1402
env_block(): if PATH is not set, add standard PATH setting to env
1403
add IPv6 route add / route delete code for windows (using "netsh")
1404
- Win32 IPv6 ifconfig support, using "netsh" calls
1405
drop "book ipv6" from open_tun() and tuncfg() prototypes
1406
document recent changes and open TODOs, adapt --version info, tag release
1407
Win32: set next-hop for IPv6 routes according to TUN/TAP mode
1408
when deleting a route on win32, also add gateway address
1409
WIN32: if IPv6 requested in TUN mode, check if TUN/TAP driver < 9.7
1410
revert unconditionally-enabling of setenv_es() logging
1411
implement IPv6 ifconfig + route setup/deletion on OpenBSD
1412
full "VPN client connect" test framework for OpenVPN t_client.rc-sample
1413
renamed t_client.sh to t_client.sh.in
1414
2.2-beta3 has a signed TAP driver with the IPv6 code - test for 9.8
1415
correct URL for "more information about IPv6 patch is *here*"
1416
bugfix for linux/iproute2: IPv6 ifconfig code block was not called for "dev tun"+"topology subnet"
1417
bump IPv6 version number (openvpn --version) to 20100922-1
1418
Implement "ipv6 ifconfig" for TAP interfaces on Solaris interfaces
1419
rebased to 2.2RC2 (beta 2.2 branch)
1420
Windows IPv6 cleanup - properly remove IPv6 routes and interface config
1421
For all accesses to "struct route_list * rl", check first that rl is non-NULL
1422
Replace 32-bit-based add_in6_addr() implementation by an 8-bit based one
1423
Platform cleanup for NetBSD
1424
Move block for "stale-routes-check" config inside #ifdef P2MP_SERVER block
1425
add missing break between "case IPv4" and "case IPv6"
1426
bump tap driver version from 9.8 to 9.9
1427
log error message and exit for "win32, tun mode, tap driver version 9.8"
1428
work around inet_ntop/inet_pton problems for MSVC builds on WinXP
1429
Fix build-up of duplicate IPv6 routes on reconnect.
1430
Fix list-overrun checks in copy_route_[ipv6_]option_list()
1431
add "print test titles" and "use sudo" functionality to t_client.rc
1432
Platform cleanup for FreeBSD
1433
Implement IPv6 interface config with non-/64 prefix lengths.
1434
Fix RUN_SUDO functionality for t_client.sh
1435
Document IPv6-related environment variables.
1436
Platform cleanup for OpenBSD
1437
1438
Gisle Vanem (1):
1439
Avoid re-defining uint32_t when using mingw compiler
1440
1441
Gustavo Zacarias (1):
1442
Fix compile issues when using --enable-small and --disable-ssl/--disable-crypto
1443
1444
Heiko Hund (16):
1445
add .gitignore to official repository
1446
remove function is_proto_tcp()
1447
remove legacy code to query IE proxy information
1448
lowercase include header name in syshead.h
1449
define IN6_ARE_ADDR_EQUAL macro for WIN32
1450
add --mark option to set SO_MARK sockopt
1451
Windows UTF-8 input/output
1452
UTF-8 X.509 distinguished names
1453
set Windows environment variables as UCS-2
1454
handle Windows unicode paths
1455
replace check for TARGET_WIN32 with WIN32
1456
do not use mode_t on Windows
1457
use the underscore version of stat on Windows
1458
make MSVC link against shell32 as well
1459
move variable declaration to top of function
1460
define access mode flag X_OK as 0 on Windows
1461
1462
Igor Novgorodov (1):
1463
The code blocks enabled by ENABLE_CLIENT_CR depends on management
1464
1465
James Yonan (57):
1466
Added "management-external-key" option.
1467
Minor addition of logging info before and after execution of Windows net commands.
1468
Misc fixes to r6708.
1469
Added --x509-track option.
1470
* added --management-up-down option to allow management interface to be notified of tunnel up/down events.
1471
Fixed minor compile issue triggered on builds where MANAGEMENT_DEF_AUTH is not enabled.
1472
Implemented get_default_gateway_mac_addr for Mac OS X
1473
Fixes to r6925.
1474
Properly handle certificate serial numbers > 32 bits.
1475
Added "client-nat" option for stateless, one-to-one NAT on the client side.
1476
Renamed branch to reflect that it is no longer beta.
1477
env_filter_match now includes the serial number of all certs
1478
Fixed issue where a client might receive multiple push replies from a server
1479
Fixed bug introduced in r7031 that might cause this error message:
1480
Extended "client-kill" management interface command (server-side)
1481
Client will now try to reconnect if no push reply received within handshake-window seconds.
1482
Version 2.1.3n
1483
Fixed compiling issues when using --disable-crypto
1484
Added "management-external-key" option.
1485
Misc fixes to r6708.
1486
win/sign.py now accepts an optional tap-dir argument.
1487
Added "auth-token" client directive
1488
Added ./configure --enable-osxipconfig option for Mac OS X
1489
Added more packet ID debug info at debug level 3 for debugging false positive packet replays.
1490
Fixed bug that incorrectly placed stricter TCP packet replay rules on UDP sessions
1491
Fixed bug in port-share that could cause port share process to crash
1492
For Mac OSX, when DARWIN_USE_IPCONFIG is defined, retry ipconfig command on failure
1493
Version 2.1.3t
1494
Revert r7092 and r7151, i.e. remove --enable-osxipconfig configure option.
1495
Added 'dir' flag to "crl-verify" (see man page for info).
1496
Added new "extra-certs" and "verify-hash" options
1497
Fixed compile issues on Windows.
1498
Added --enable-lzo-stub configure option to build an OpenVPN client without LZO
1499
Added optional journal directory argument to "port-share" directive
1500
Reduce log verbosity at level 3, with a focus on removing excessive log verbosity generated by port-share activity.
1501
env_filter_match now includes the serial number of all certs in chain
1502
Added support for static challenge/response protocol.
1503
r7316 fixes.
1504
Added redirect-gateway block-local flag, with support for Linux, Mac OS X
1505
Extended x509-track to allow SHA1 certificate hash to be extracted
1506
Added "management-query-remote" directive (client) to allow the management interface to override the "remote" directive.
1507
Version 2.1.5.
1508
Fixed MSVC compile error related to r7408.
1509
Redact "echo" directive strings from log, since these strings (going forward) could conceivably contain security-sensitive data.
1510
Modified sanitize_control_message to remove redacted data from control string rather than blotting it out with "_" chars.
1511
Changed CC_PRINT character class to allow UTF-8 chars.
1512
Increased the --verb threshold for "PID_ERR replay" messages to 4 from 3.
1513
Fixed issue where redirect-gateway block-local code was not correctly calculating...
1514
CC_PRINT character class now allows any 8-bit character value >= 32.
1515
"status" management interface command (version >= 2) will now include the username for each connected user.
1516
Minor fix to CC_PRINT char class
1517
Fixed management interface bug where >FATAL notifications were not being output properly
1518
Raised D_PID_DEBUG_LOW from level 3 to 4 to reduce replay error verbosity at level 3.
1519
Added "memstats" option to maintain real-time operating stats in a memory-mapped file.
1520
Fixed client issues with DHCP Router option extraction/deletion when using layer 2 with DHCP proxy:
1521
Allow "tap-win32 dynamic <offset>" to be used in topology subnet mode.
1522
Added support for "on-link" routes on Linux client
1523
1524
Jan Just Keijser (1):
1525
Made some options connection-entry specific
1526
1527
Joe Patterson (1):
1528
common_name passing in auth_pam plugin
1529
1530
JuanJo Ciarlante (40):
1531
* rebased openvpn-2.1_rc1b.jjo.20061206.d.patch
1532
* created getaddr6(), use it from resolve_remote()
1533
* migrated all getaddrinfo() to getaddr6
1534
* socket.c: use USE_PF_INET6 in switch constructs to actually toss them out,
1535
* support --disable-ipv6 build properly:
1536
* important fix for tcp6 reconnection was incorrectly creating a PF_INET socket
1537
* added README.ipv6.txt
1538
* fixed win32 non-ipv6 build
1539
* ipv6 on win32 "milestone": 1st snapshot that passes all unittests
1540
* document ipv6 milestone status
1541
* doc update w/unittests results
1542
* make possible to x-compile openvpn/win32 in Linux
1543
* correctly setup hints.ai_socktype for getaddrinfo(), althought sorta hacky, see TODO.ipv6.
1544
* renamed README.ipv6{.txt,}
1545
* updated {README,TODO}.ipv6 from feedback at openvpn-devel mlist
1546
* init.c: document the ENABLE_MANAGEMENT place to work on
1547
* init.c: small in-doc tweaks
1548
* fix multi-tcp crash (corrected assertion)
1549
* TODO.ipv6 update
1550
* socket.c: better buf logic in print_sockaddr_ex
1551
* fixed segfault for undef address family in print_sockaddr_ex (thanks Marcel!)
1552
* doc updates
1553
* openbsd: no IFF_MULTICAST, #ifdef around it
1554
* no new funcionality, just small cleanups
1555
* (prototype) fix for supporting "redirect-gateway" for tunneled ipv4 over ipv6 endpoints
1556
* polished redirect-gateway (ipv4 on ipv6 endpoints) support
1557
* updated doc
1558
* fix --disable-ipv6 build
1559
* doc updates
1560
* rebased to v2.1.1 release
1561
* undo mroute.c changes related to ipv6 payload
1562
* fix --multihome for ipv4
1563
* fix --multihome for ipv6
1564
* ipv6-0.4.14: fix xinetd usage
1565
* ipv6-0.4.15: add --multihome support to xBSD
1566
* ipv6-0.4.15b: rebase over openvpn-testing-master
1567
* ipv6-0.4.16: fix mingw32 build
1568
* make ipv6_payload compile under windowze
1569
USE_PF_INET6 by default for v2.3
1570
fix ipv6 compilation under macosx >= 1070 - v3
1571
1572
Markus Koetter (1):
1573
Add extv3 X509 field support to --x509-username-field
1574
1575
Matthew L. Creech (1):
1576
Fix 2.2.0 build failure when management interface disabled
1577
1578
Matthias Andree (1):
1579
Skip rather than fail test in addressless FreeBSD jails.
1580
1581
Robert Fischer (8):
1582
Update man page with info about --capath
1583
Update man page with info about --connect-timeout
1584
Added info about --show-proxy-settings
1585
Documented --x509-username-field option
1586
Documented --errors-to-stderr option
1587
Documented --push-peer-info option
1588
Update man page with info about --remote-random-hostname
1589
Added man page entry for --management-client
1590
1591
Samuli Seppänen (19):
1592
Add man page entry for --redirect-private
1593
Change all CRLF linefeeds to LF linefeeds
1594
Fix a bug in devcon source code handling
1595
Removed Win2k from supported platforms list in INSTALL and win/openvpn.nsi
1596
Fixed copying of tapinstall.exe to dist/bin when using prebuilt TAP-drivers
1597
Fixed a bug with GUI icon deletion on upgrade from 2.2-RC or earlier
1598
Fix a build-ca issue on Windows
1599
Add new openssl.cnf to easy-rsa/Windows
1600
Updated "easy-rsa" for OpenSSL 1.0.0
1601
Made domake-win builds to use easy-rsa/2.0/openssl-1.0.0.cnf
1602
Fixes to easy-rsa/2.0
1603
Merged TODO.IPv6 with TODO.ipv6 and README.IPv6 with README.ipv6
1604
Fixed a number of fatal build errors on Visual Studio 2008
1605
Fix a Visual Studio 2008 build issue in socket.c
1606
Additional Visual Studio 2008 build fixes to tun.c
1607
Fixed a typo in win32.h that prevented building with Visual Studio
1608
Fixed a regression causing VS2008/Python build failure
1609
Fix a Visual Studio 2008 build error in tun.c
1610
Fix a Visual Studio 2008 build error in options.c
1611
1612
Simon Matter (1):
1613
Fix issues with some older GCC compilers
1614
1615
Stefan Hellermann (2):
1616
plugin.h: update prototype of plugin_call dummy in !ENABLE_PLUGIN case
1617
Fixed typo in plugin.h
1618
1619
chantra (1):
1620
Clarify --tmp-dir option
1621
1622
smos (1):
1623
Change the netsh.exe command from "add" to "set".
1624
```