Blame
| 39f6a8 | Samuli Seppänen | 2025-02-11 09:59:33 | 1 | # OpenVPN 2.3.18 |
| 2 | ||||
| 3 | ``` |
|||
| 4 | Antonio Quartulli (1): |
|||
| 5 | crypto: correct typ0 in error message |
|||
| 6 | ||||
| 7 | David Sommerseth (1): |
|||
| 8 | Preparing OpenVPN 2.3.18 release |
|||
| 9 | ||||
| 10 | Steffan Karger (2): |
|||
| 11 | Deprecate --ns-cert-type |
|||
| 12 | Fix bounds check in read_key() |
|||
| 13 | ||||
| 14 | Szilárd Pfeiffer (1): |
|||
| 15 | OpenSSL: Always set SSL_OP_CIPHER_SERVER_PREFERENCE flag |
|||
| 16 | ``` |
|||
| 17 | ||||
| 18 | # OpenVPN 2.3.17 |
|||
| 19 | ||||
| 20 | ``` |
|||
| 21 | David Sommerseth (2): |
|||
| 22 | backport: Ignore auth-nocache for auth-user-pass if auth-token is pushed |
|||
| 23 | auth-token with auth-nocache fix broke --disable-crypto builds |
|||
| 24 | ||||
| 25 | Gert Doering (3): |
|||
| 26 | Fix potential 1-byte overread in TCP option parsing. |
|||
| 27 | Fix remotely-triggerable ASSERT() on malformed IPv6 packet. |
|||
| 28 | Preparing for release v2.3.17 (ChangeLog, version.m4, Changes.rst) |
|||
| 29 | ||||
| 30 | Guido Vranken (6): |
|||
| 31 | refactor my_strupr |
|||
| 32 | Fix 2 memory leaks in proxy authentication routine |
|||
| 33 | Fix memory leak in add_option() for option 'connection' |
|||
| 34 | Ensure option array p[] is always NULL-terminated |
|||
| 35 | Fix a null-pointer dereference in establish_http_proxy_passthru() |
|||
| 36 | Prevent two kinds of stack buffer OOB reads and a crash for invalid input data |
|||
| 37 | ||||
| 38 | Jérémie Courrèges-Anglas (2): |
|||
| 39 | Fix an unaligned access on OpenBSD/sparc64 |
|||
| 40 | Missing include for socket-flags TCP_NODELAY on OpenBSD |
|||
| 41 | ||||
| 42 | Steffan Karger (4): |
|||
| 43 | openssl: fix overflow check for long --tls-cipher option |
|||
| 44 | Fix remote-triggerable memory leaks (CVE-2017-7521) |
|||
| 45 | Restrict --x509-alt-username extension types |
|||
| 46 | Fix potential double-free in --x509-alt-username (CVE-2017-7521) |
|||
| 47 | ``` |
|||
| 48 | ||||
| 49 | # OpenVPN 2.3.16 |
|||
| 50 | ||||
| 51 | ``` |
|||
| 52 | Antonio Quartulli (1): |
|||
| 53 | fix redirect-gateway behaviour when an IPv4 default route does not exist |
|||
| 54 | ||||
| 55 | Gert Doering (1): |
|||
| 56 | Preparing for release v2.3.16 (ChangeLog, version.m4) |
|||
| 57 | ||||
| 58 | Guido Vranken (1): |
|||
| 59 | Avoid a 1 byte overcopy in x509_get_subject (ssl_verify_openssl.c) |
|||
| 60 | ||||
| 61 | Selva Nair (1): |
|||
| 62 | Check for errors in the return value of GetModuleFileNameW() |
|||
| 63 | ||||
| 64 | Steven McDonald (1): |
|||
| 65 | Fix gateway detection with OpenBSD routing domains |
|||
| 66 | ``` |
|||
| 67 | ||||
| 68 | # OpenVPN 2.3.15 |
|||
| 69 | ||||
| 70 | ``` |
|||
| 71 | David Sommerseth (6): |
|||
| 72 | dev-tools: Added script for updating copyright years in files |
|||
| 73 | Update copyrights |
|||
| 74 | docs: Further improve --reneg-bytes and SWEET32 information |
|||
| 75 | git: Merge .gitignore files into a single file |
|||
| 76 | Make --cipher/--auth none more explicit on the risks |
|||
| 77 | Prepare v2.3.15 release |
|||
| 78 | ||||
| 79 | Gert Doering (1): |
|||
| 80 | Document --proto udp6, tcp6, etc. |
|||
| 81 | ||||
| 82 | Julien Muchembled (1): |
|||
| 83 | Fix implicit declarations when HAVE_OPENSSL_ENGINE is unset |
|||
| 84 | ||||
| 85 | Steffan Karger (6): |
|||
| 86 | Add missing includes in error.h |
|||
| 87 | cleanup: merge packet_id_alloc_outgoing() into packet_id_write() |
|||
| 88 | Document that OpenVPN 2.3 does not check the CRL signature |
|||
| 89 | Introduce and use secure_memzero() to erase secrets |
|||
| 90 | Drop packets instead of assert out if packet id rolls over (CVE-2017-7479) |
|||
| 91 | Don't assert out on receiving too-large control packets (CVE-2017-7478) |
|||
| 92 | ``` |
|||
| 93 | ||||
| 94 | # OpenVPN 2.3.14 |
|||
| 95 | ||||
| 96 | ``` |
|||
| 97 | Christian Hesse (1): |
|||
| 98 | update year in copyright message |
|||
| 99 | ||||
| 100 | David Sommerseth (2): |
|||
| 101 | man: Improve the --keepalive section |
|||
| 102 | Document the --auth-token option |
|||
| 103 | ||||
| 104 | Gert Doering (3): |
|||
| 105 | Repair topology subnet on FreeBSD 11 |
|||
| 106 | Repair topology subnet on OpenBSD |
|||
| 107 | Preparing release of v2.3.14 |
|||
| 108 | ||||
| 109 | Lev Stipakov (1): |
|||
| 110 | Drop recursively routed packets |
|||
| 111 | ||||
| 112 | Selva Nair (4): |
|||
| 113 | Support --block-outside-dns on multiple tunnels |
|||
| 114 | When parsing '--setenv opt xx ..' make sure a third parameter is present |
|||
| 115 | Map restart signals from event loop to SIGTERM during exit-notification wait |
|||
| 116 | Correctly state the default dhcp server address in man page |
|||
| 117 | ||||
| 118 | Steffan Karger (1): |
|||
| 119 | Clean up format_hex_ex() |
|||
| 120 | ``` |
|||
| 121 | ||||
| 122 | # OpenVPN 2.3.13 |
|||
| 123 | ||||
| 124 | ``` |
|||
| 125 | Arne Schwabe (2): |
|||
| 126 | Use AES ciphers in our sample configuration files and add a few modern 2.4 examples |
|||
| 127 | Incorporate the Debian typo fixes where appropriate and make show_opt default message clearer |
|||
| 128 | ||||
| 129 | David Sommerseth (5): |
|||
| 130 | t_client.sh: Make OpenVPN write PID file to avoid various sudo issues |
|||
| 131 | t_client.sh: Add support for Kerberos/ksu |
|||
| 132 | t_client.sh: Improve detection if the OpenVPN process did start during tests |
|||
| 133 | t_client.sh: Add prepare/cleanup possibilties for each test case |
|||
| 134 | Preparing release of v2.3.13 |
|||
| 135 | ||||
| 136 | Gert Doering (5): |
|||
| 137 | Do not abort t_client run if OpenVPN instance does not start. |
|||
| 138 | Fix t_client runs on OpenSolaris |
|||
| 139 | make t_client robust against sudoers misconfiguration |
|||
| 140 | add POSTINIT_CMD_suf to t_client.sh and sample config |
|||
| 141 | Fix --multihome for IPv6 on 64bit BSD systems. |
|||
| 142 | ||||
| 143 | Ilya Shipitsin (1): |
|||
| 144 | skip t_lpback.sh and t_cltsrv.sh if openvpn configured --disable-crypto |
|||
| 145 | ||||
| 146 | Lev Stipakov (2): |
|||
| 147 | Exclude peer-id from pulled options digest |
|||
| 148 | Fix compilation in pedantic mode |
|||
| 149 | ||||
| 150 | Samuli Seppänen (1): |
|||
| 151 | Automatically cache expected IPs for t_client.sh on the first run |
|||
| 152 | ||||
| 153 | Steffan Karger (6): |
|||
| 154 | Fix unittests for out-of-source builds |
|||
| 155 | Make gnu89 support explicit |
|||
| 156 | cleanup: remove code duplication in msg_test() |
|||
| 157 | Update cipher-related man page text |
|||
| 158 | Limit --reneg-bytes to 64MB when using small block ciphers |
|||
| 159 | Add a revoked cert to the sample keys |
|||
| 160 | ``` |
|||
| 161 | ||||
| 162 | # OpenVPN 2.3.12 |
|||
| 163 | ||||
| 164 | ``` |
|||
| 165 | Arne Schwabe (2): |
|||
| 166 | Complete push-peer-info documentation and allow IV_PLAT_VER for other platforms than Windows if the client UI supplies it. |
|||
| 167 | Move ASSERT so external-key with OpenSSL works again |
|||
| 168 | ||||
| 169 | David Sommerseth (5): |
|||
| 170 | Only build and run cmocka unit tests if its submodule is initialized |
|||
| 171 | Another fix related to unit test framework |
|||
| 172 | Remove NOP function and callers |
|||
| 173 | Revert "Drop recursively routed packets" |
|||
| 174 | Preparing release of v2.3.12 |
|||
| 175 | ||||
| 176 | Dorian Harmans (1): |
|||
| 177 | Add CHACHA20-POLY1305 ciphersuite IANA name translations. |
|||
| 178 | ||||
| 179 | Ivo Manca (1): |
|||
| 180 | Plug memory leak in mbedTLS backend |
|||
| 181 | ||||
| 182 | Jeffrey Cutter (1): |
|||
| 183 | Update contrib/pull-resolv-conf/client.up for no DOMAIN |
|||
| 184 | ||||
| 185 | Jens Neuhalfen (2): |
|||
| 186 | Add unit testing support via cmocka |
|||
| 187 | Add a test for auth-pam searchandreplace |
|||
| 188 | ||||
| 189 | Josh Cepek (1): |
|||
| 190 | Push an IPv6 CIDR mask used by the server, not the pool's size |
|||
| 191 | ||||
| 192 | Leon Klingele (1): |
|||
| 193 | Add link to bug tracker |
|||
| 194 | ||||
| 195 | Lev Stipakov (1): |
|||
| 196 | Drop recursively routed packets |
|||
| 197 | ||||
| 198 | Samuli Seppänen (2): |
|||
| 199 | Update CONTRIBUTING.rst to allow GitHub PRs for code review purposes |
|||
| 200 | Clarify the fact that build instructions in README are for release tarballs |
|||
| 201 | ||||
| 202 | Selva Nair (4): |
|||
| 203 | Make error non-fatal while deleting address using netsh |
|||
| 204 | Make block-outside-dns work with persist-tun |
|||
| 205 | Ignore SIGUSR1/SIGHUP during exit notification |
|||
| 206 | Promptly close the netcmd_semaphore handle after use |
|||
| 207 | ||||
| 208 | Steffan Karger (4): |
|||
| 209 | Fix polarssl / mbedtls builds |
|||
| 210 | Don't limit max incoming message size based on c2->frame |
|||
| 211 | Fix '--cipher none --cipher' crash |
|||
| 212 | Discourage using 64-bit block ciphers |
|||
| 213 | ``` |
|||
| 214 | ||||
| 215 | # OpenVPN 2.3.11 |
|||
| 216 | ||||
| 217 | ``` |
|||
| 218 | Gert Doering (1): |
|||
| 219 | Preparing for release v2.3.11 (ChangeLog, version.m4) |
|||
| 220 | ||||
| 221 | James Yonan (1): |
|||
| 222 | Fixed port-share bug with DoS potential |
|||
| 223 | ||||
| 224 | Jens Neuhalfen (2): |
|||
| 225 | Make intent of utun device name validation clear |
|||
| 226 | Fix buffer overflow by user supplied data |
|||
| 227 | ||||
| 228 | Leonardo Basilio (1): |
|||
| 229 | Correctly report TCP connection timeout on windows. |
|||
| 230 | ||||
| 231 | Lev Stipakov (1): |
|||
| 232 | Report Windows bitness |
|||
| 233 | ||||
| 234 | Michael McConville (1): |
|||
| 235 | Fix undefined signed shift overflow |
|||
| 236 | ||||
| 237 | Niels Ole Salscheider (1): |
|||
| 238 | Fix build with libressl |
|||
| 239 | ||||
| 240 | Samuli Seppänen (1): |
|||
| 241 | Improve LZO, PAM and OpenSSL documentation |
|||
| 242 | ||||
| 243 | Selva Nair (2): |
|||
| 244 | Ensure input read using systemd-ask-password is null terminated |
|||
| 245 | Support reading the challenge-response from console |
|||
| 246 | ||||
| 247 | Steffan Karger (10): |
|||
| 248 | openssl: improve logging |
|||
| 249 | polarssl: improve logging |
|||
| 250 | Update manpage: OpenSSL might also need /dev/urandom inside chroot |
|||
| 251 | socks.c: fix check on get_user_pass() return value(s) |
|||
| 252 | Fix OCSP_check.sh |
|||
| 253 | hardening: add safe FD_SET() wrapper openvpn_fd_set() |
|||
| 254 | Fix memory leak in argv_extract_cmd_name() |
|||
| 255 | Replace MSG_TEST() macro for static inline msg_test() |
|||
| 256 | Restrict default TLS cipher list |
|||
| 257 | Various Changes.rst fixes |
|||
| 258 | ||||
| 259 | ValdikSS (3): |
|||
| 260 | Clarify mssfix documentation |
|||
| 261 | Clarify --block-outside-dns documentation |
|||
| 262 | Update --block-outside-dns to work on Windows Vista |
|||
| 263 | ``` |
|||
| 264 | ||||
| 265 | # OpenVPN 2.3.10 |
|||
| 266 | ||||
| 267 | ``` |
|||
| 268 | Gert Doering (2): |
|||
| 269 | Prepare for v2.3.10 release, list PolarSSL 1.2 to 1.3 upgrade |
|||
| 270 | Preparing for release v2.3.10 (ChangeLog, version.m4) |
|||
| 271 | ||||
| 272 | Jan Just Keijser (1): |
|||
| 273 | Make certificate expiry warning patch (091edd8e299686) work on OpenSSL 1.0.1 and earlier. |
|||
| 274 | ||||
| 275 | Lev Stipakov (1): |
|||
| 276 | Repair IPv6 netsh calls if Win XP is detected |
|||
| 277 | ||||
| 278 | Phillip Smith (1): |
|||
| 279 | Use bob.example.com and alice.example.com to improve clarity of documentation |
|||
| 280 | ||||
| 281 | Steffan Karger (6): |
|||
| 282 | Remove unused variables from ssl_verify_polarssl.c's x509_get_serial() |
|||
| 283 | Upgrade OpenVPN 2.3 to PolarSSL 1.3 |
|||
| 284 | Warn user if their certificate has expired |
|||
| 285 | Make assert_failed() print the failed condition |
|||
| 286 | cleanup: get rid of httpdigest.c type warnings |
|||
| 287 | Fix regression in setups without a client certificate |
|||
| 288 | ||||
| 289 | Yegor Yefremov (1): |
|||
| 290 | polarssl: fix unreachable code |
|||
| 291 | ``` |
|||
| 292 | ||||
| 293 | # OpenVPN 2.3.9 |
|||
| 294 | ||||
| 295 | OpenVPN 2.3.9 contains the following changes: |
|||
| 296 | ||||
| 297 | ``` |
|||
| 298 | Arne Schwabe (7): |
|||
| 299 | Show extra-certs in current parameters. |
|||
| 300 | Fix commit a3160fc1bd7368395745b9cee6e40fb819f5564c |
|||
| 301 | Do not set the buffer size by default but rely on the operation system default. |
|||
| 302 | Remove --enable-password-save option |
|||
| 303 | Reflect enable-password-save change in documentation |
|||
| 304 | Also remove second instance of enable-password-save in the man page |
|||
| 305 | Detect config lines that are too long and give a warning/error |
|||
| 306 | ||||
| 307 | Boris Lytochkin (1): |
|||
| 308 | Log serial number of revoked certificate |
|||
| 309 | ||||
| 310 | Christos Trochalakis (1): |
|||
| 311 | Adjust server-ipv6 documentation |
|||
| 312 | ||||
| 313 | David Sommerseth (1): |
|||
| 314 | Avoid partial authentication state when using --disabled in CCD configs |
|||
| 315 | ||||
| 316 | Fish (1): |
|||
| 317 | Make "block-outside-dns" option platform agnostic |
|||
| 318 | ||||
| 319 | Gert Doering (8): |
|||
| 320 | Un-break --auth-user-pass on windows |
|||
| 321 | Replace unaligned 16bit access to TCP MSS value with bytewise access |
|||
| 322 | Repair test_local_addr() on WIN32 |
|||
| 323 | Fix possible heap overflow on read accessing getaddrinfo() result. |
|||
| 324 | Fix FreeBSD-specific mishandling of gc arena pointer in create_arbitrary_remote() |
|||
| 325 | remove unused gc_arena in FreeBSD close_tun() |
|||
| 326 | Fix isatty() check for good. |
|||
| 327 | Preparing for release v2.3.9 (ChangeLog, version.m4) |
|||
| 328 | ||||
| 329 | Heiko Hund (1): |
|||
| 330 | put virtual IPv6 addresses into env |
|||
| 331 | ||||
| 332 | Lev Stipakov (5): |
|||
| 333 | Use adapter index instead of name for windows IPv6 interface config |
|||
| 334 | Client-side part for server restart notification |
|||
| 335 | Use adapter index for add/delete_route_ipv6 |
|||
| 336 | Pass adapter index to up/down scripts |
|||
| 337 | Fix VS2013 compilation |
|||
| 338 | ||||
| 339 | Lukasz Kutyla (1): |
|||
| 340 | Fix privilege drop if first connection attempt fails |
|||
| 341 | ||||
| 342 | Michal Ludvig (1): |
|||
| 343 | Support for username-only auth file. |
|||
| 344 | ||||
| 345 | Samuli Seppänen (2): |
|||
| 346 | Add CONTRIBUTING.rst |
|||
| 347 | Updates to Changes.rst |
|||
| 348 | ||||
| 349 | Selva Nair (4): |
|||
| 350 | Fix termination when windows suspends/sleeps |
|||
| 351 | Do not hard-code windows systemroot in env_block |
|||
| 352 | Handle ctrl-C and ctrl-break events on Windows |
|||
| 353 | Unbreak read username password from management |
|||
| 354 | ||||
| 355 | Steffan Karger (11): |
|||
| 356 | Replace strdup() calls for string_alloc() calls |
|||
| 357 | Check return value of ms_error_text() |
|||
| 358 | Increase control channel packet size for faster handshakes |
|||
| 359 | hardening: add insurance to exit on a failed ASSERT() |
|||
| 360 | Fix memory leak in auth-pam plugin |
|||
| 361 | Fix (potential) memory leak in init_route_list() |
|||
| 362 | Fix unintialized variable in plugin_vlog() |
|||
| 363 | Add macro to ensure we exit on fatal errors |
|||
| 364 | Fix memory leak in add_option() by simplifying get_ipv6_addr |
|||
| 365 | openssl: properly check return value of RAND_bytes() |
|||
| 366 | Fix rand_bytes return value checking |
|||
| 367 | ||||
| 368 | ValdikSS (1): |
|||
| 369 | Add Windows DNS Leak fix using WFP ('block-outside-dns') |
|||
| 370 | ||||
| 371 | janjust (1): |
|||
| 372 | Fix "White space before end tags can break the config parser" |
|||
| 373 | ``` |
|||
| 374 | ||||
| 375 | ||||
| 376 | # OpenVPN 2.3.8 |
|||
| 377 | ||||
| 378 | OpenVPN 2.3.8 contains the following changes: |
|||
| 379 | ||||
| 380 | ``` |
|||
| 381 | Arne Schwabe (2): |
|||
| 382 | Report missing endtags of inline files as warnings |
|||
| 383 | Fix commit e473b7c if an inline file happens to have a line break exactly at buffer limit |
|||
| 384 | ||||
| 385 | Gert Doering (3): |
|||
| 386 | Produce a meaningful error message if --daemon gets in the way of asking for passwords. |
|||
| 387 | Document --daemon changes and consequences (--askpass, --auth-nocache). |
|||
| 388 | Preparing for release v2.3.8 (ChangeLog, version.m4) |
|||
| 389 | ||||
| 390 | Holger Kummert (1): |
|||
| 391 | Del ipv6 addr on close of linux tun interface |
|||
| 392 | ||||
| 393 | James Geboski (1): |
|||
| 394 | Fix --askpass not allowing for password input via stdin |
|||
| 395 | ||||
| 396 | Steffan Karger (5): |
|||
| 397 | write pid file immediately after daemonizing |
|||
| 398 | Make __func__ work with Visual Studio too |
|||
| 399 | fix regression: query password before becoming daemon |
|||
| 400 | Fix using management interface to get passwords. |
|||
| 401 | Fix overflow check in openvpn_decrypt() |
|||
| 402 | ``` |
|||
| 403 | ||||
| 404 | The OpenVPN 2.3.8 source packages and Windows installers contain one ''additional'' fix: |
|||
| 405 | ||||
| 406 | ``` |
|||
| 407 | Gert Doering (1): |
|||
| 408 | Un-break --auth-user-pass on windows |
|||
| 409 | ``` |
|||
| 410 | ||||
| 411 | This means that custom Windows builds should be based on 2.3.8 source packages or on the "release/2.3" branch instead of the "v2.3.8" tag in Git. |
|||
| 412 | ||||
| 413 | # OpenVPN 2.3.7 |
|||
| 414 | ||||
| 415 | ``` |
|||
| 416 | Alexander Pyhalov (1): |
|||
| 417 | Default gateway can't be determined on illumos/Solaris platforms |
|||
| 418 | ||||
| 419 | Arne Schwabe (1): |
|||
| 420 | Warn that tls-auth with free form files is going to be removed from OpenVPN 2.4 |
|||
| 421 | ||||
| 422 | David Sommerseth (6): |
|||
| 423 | autotools: Fix wrong ./configure help screen default values |
|||
| 424 | down-root plugin: Replaced system() calls with execve() |
|||
| 425 | down-root: Improve error messages |
|||
| 426 | plugin, down-root: Fix compiler warnings |
|||
| 427 | sockets: Remove the limitation of --tcp-nodelay to be server-only |
|||
| 428 | plugins, down-root: Code style clean-up |
|||
| 429 | ||||
| 430 | David Woodhouse (2): |
|||
| 431 | pkcs11: Load p11-kit-proxy.so module by default |
|||
| 432 | Make 'provider' option to --show-pkcs11-ids optional where p11-kit is present |
|||
| 433 | ||||
| 434 | Felix Janda (1): |
|||
| 435 | Use OPENVPN_ETH_P_* so that <netinet/if_ether.h> is unecessary |
|||
| 436 | ||||
| 437 | Gert Doering (18): |
|||
| 438 | New approach to handle peer-id related changes to link-mtu (2.3 version) |
|||
| 439 | Fix incorrect use of get_ipv6_addr() for iroute options. |
|||
| 440 | Print helpful error message on --mktun/--rmtun if not available. |
|||
| 441 | explain effect of --topology subnet on --ifconfig |
|||
| 442 | Add note about file permissions and --crl-verify to manpage. |
|||
| 443 | repair --dev null breakage caused by db950be85d37 |
|||
| 444 | assume res_init() is always there. |
|||
| 445 | Correct note about DNS randomization in openvpn.8 |
|||
| 446 | Disallow usage of --server-poll-timeout in --secret key mode. |
|||
| 447 | slightly enhance documentation about --cipher |
|||
| 448 | Enforce "serial-tests" behaviour for tests/Makefile |
|||
| 449 | Revert "Enforce "serial-tests" behaviour for tests/Makefile" |
|||
| 450 | On signal reception, return EAI_SYSTEM from openvpn_getaddrinfo(). |
|||
| 451 | Use configure.ac hack to apply serial_test AM option only if supported. |
|||
| 452 | Use EAI_AGAIN instead of EAI_SYSTEM for openvpn_getaddrinfo(). |
|||
| 453 | Move res_init() call to inner openvpn_getaddrinfo() loop |
|||
| 454 | Fix FreeBSD ifconfig for topology subnet tunnels. |
|||
| 455 | Preparing for release v2.3.7 (ChangeLog, version.m4) |
|||
| 456 | ||||
| 457 | Guy Yur (1): |
|||
| 458 | Fix --redirect-private in --dev tap mode. |
|||
| 459 | ||||
| 460 | Jan Just Keijser (1): |
|||
| 461 | include ifconfig_ environment variables in --up-restart env set |
|||
| 462 | ||||
| 463 | Jonathan K. Bullard (1): |
|||
| 464 | Fix null pointer dereference in options.c |
|||
| 465 | ||||
| 466 | Lev Stipakov (1): |
|||
| 467 | Fix mssfix default value in connection_list context |
|||
| 468 | ||||
| 469 | Matthias Andree (1): |
|||
| 470 | Manual page update for Re-enabled TLS version negotiation. |
|||
| 471 | ||||
| 472 | Mike Gilbert (1): |
|||
| 473 | Include systemd units in the source tarball (make dist) |
|||
| 474 | ||||
| 475 | Robert Fischer (1): |
|||
| 476 | Updated manpage for --rport and --lport |
|||
| 477 | ||||
| 478 | Samuli Seppänen (2): |
|||
| 479 | Properly escape dashes on the man-page |
|||
| 480 | Improve documentation in --script-security section of the man-page |
|||
| 481 | ||||
| 482 | Steffan Karger (14): |
|||
| 483 | Really fix '--cipher none' regression |
|||
| 484 | Update doxygen (a bit) |
|||
| 485 | Set tls-version-max to 1.1 if cryptoapicert is used |
|||
| 486 | Account for peer-id in frame size calculation |
|||
| 487 | Disable SSL compression |
|||
| 488 | Fix frame size calculation for non-CBC modes. |
|||
| 489 | Allow for CN/username of 64 characters (fixes off-by-one) |
|||
| 490 | Remove unneeded parameter 'first_time' from possibly_become_daemon() |
|||
| 491 | Re-enable TLS version negotiation by default |
|||
| 492 | Remove size limit for files inlined in config |
|||
| 493 | Improve --tls-cipher and --show-tls man page description |
|||
| 494 | Re-read auth-user-pass file on (re)connect if required |
|||
| 495 | Clarify --capath option in manpage |
|||
| 496 | Call daemon() before initializing crypto library |
|||
| 497 | ``` |
|||
| 498 | ||||
| 499 | # OpenVPN 2.3.6 |
|||
| 500 | ||||
| 501 | ``` |
|||
| 502 | David Sommerseth (1): |
|||
| 503 | systemd: Reworked the systemd unit file to handle server and client configs better |
|||
| 504 | ||||
| 505 | Gert Doering (2): |
|||
| 506 | Add client-only support for peer-id. |
|||
| 507 | Preparing for release v2.3.6 (ChangeLog, version.m4) |
|||
| 508 | ||||
| 509 | Samuli Seppänen (1): |
|||
| 510 | Fix to --shaper documentation on the man-page |
|||
| 511 | ||||
| 512 | Steffan Karger (4): |
|||
| 513 | Fix assertion error when using --cipher none |
|||
| 514 | Add --tls-version-max |
|||
| 515 | Modernize sample keys and sample configs |
|||
| 516 | Drop too-short control channel packets instead of asserting out. |
|||
| 517 | ``` |
|||
| 518 | ||||
| 519 | # OpenVPN 2.3.5 |
|||
| 520 | ||||
| 521 | ``` |
|||
| 522 | Andris Kalnozols (2): |
|||
| 523 | Fix some typos in the man page. |
|||
| 524 | Do not upcase x509-username-field for mixed-case arguments. |
|||
| 525 | ||||
| 526 | Arne Schwabe (1): |
|||
| 527 | Fix server routes not working in topology subnet with --server [v3] |
|||
| 528 | ||||
| 529 | David Sommerseth (4): |
|||
| 530 | Improve error reporting on file access to --client-config-dir and --ccd-exclusive |
|||
| 531 | Don't let openvpn_popen() keep zombies around |
|||
| 532 | Add systemd unit file for OpenVPN |
|||
| 533 | systemd: Use systemd functions to consider systemd availability |
|||
| 534 | ||||
| 535 | Gert Doering (4): |
|||
| 536 | Drop incoming fe80:: packets silently now. |
|||
| 537 | Fix t_lpback.sh platform-dependent failures |
|||
| 538 | Call init script helpers with explicit path (./) |
|||
| 539 | Preparing for release v2.3.5 (ChangeLog, version.m4) |
|||
| 540 | ||||
| 541 | Heiko Hund (1): |
|||
| 542 | refine assertion to allow other modes than CBC |
|||
| 543 | ||||
| 544 | Hubert Kario (2): |
|||
| 545 | ocsp_check - signature verification and cert staus results are separate |
|||
| 546 | ocsp_check - double check if ocsp didn't report any errors in execution |
|||
| 547 | ||||
| 548 | James Bekkema (1): |
|||
| 549 | Fix socket-flag/TCP_NODELAY on Mac OS X |
|||
| 550 | ||||
| 551 | James Yonan (6): |
|||
| 552 | Fixed several instances of declarations after statements. |
|||
| 553 | In socket.c, fixed issue where uninitialized value (err) is being passed to to gai_strerror. |
|||
| 554 | Explicitly cast the third parameter of setsockopt to const void * to avoid warning. |
|||
| 555 | MSVC 2008 doesn't support dimensioning an array with a const var nor using %z as a printf format specifier. |
|||
| 556 | Define PATH_SEPARATOR for MSVC builds. |
|||
| 557 | Fixed some compile issues with show_library_versions() |
|||
| 558 | ||||
| 559 | Jann Horn (1): |
|||
| 560 | Remove quadratic complexity from openvpn_base64_decode() |
|||
| 561 | ||||
| 562 | Mike Gilbert (1): |
|||
| 563 | Add configure check for the path to systemd-ask-password |
|||
| 564 | ||||
| 565 | Philipp Hagemeister (2): |
|||
| 566 | Add topology in sample server configuration file |
|||
| 567 | Implement on-link route adding for iproute2 |
|||
| 568 | ||||
| 569 | Samuel Thibault (1): |
|||
| 570 | Ensure that client-connect files are always deleted |
|||
| 571 | ||||
| 572 | Steffan Karger (13): |
|||
| 573 | Remove function without effect (cipher_ok() always returned true). |
|||
| 574 | Remove unneeded wrapper functions in crypto_openssl.c |
|||
| 575 | Fix bug that incorrectly refuses oid representation eku's in polar builds |
|||
| 576 | Update README.polarssl |
|||
| 577 | Rename ALLOW_NON_CBC_CIPHERS to ENABLE_OFB_CFB_MODE, and add to configure. |
|||
| 578 | Add proper check for crypto modes (CBC or OFB/CFB) |
|||
| 579 | Improve --show-ciphers to show if a cipher can be used in static key mode |
|||
| 580 | Extend t_lpback tests to test all ciphers reported by --show-ciphers |
|||
| 581 | Don't exit daemon if opening or parsing the CRL fails. |
|||
| 582 | Fix typo in cipher_kt_mode_{cbc, ofb_cfb}() doxygen. |
|||
| 583 | Fix regression with password protected private keys (polarssl) |
|||
| 584 | ssl_polarssl.c: fix includes and make casts explicit |
|||
| 585 | Remove unused variables from ssl_verify_openssl.c extract_x509_extension() |
|||
| 586 | ||||
| 587 | TDivine (1): |
|||
| 588 | Fix "code=995" bug with windows NDIS6 tap driver. |
|||
| 589 | ``` |
|||
| 590 | ||||
| 591 | # OpenVPN 2.3.4 |
|||
| 592 | ||||
| 593 | ``` |
|||
| 594 | Arne Schwabe (1): |
|||
| 595 | Fix man page and OSCP script: tls_serial_{n} is decimal |
|||
| 596 | ||||
| 597 | Dmitrij Tejblum (1): |
|||
| 598 | Fix is_ipv6 in case of tap interface. |
|||
| 599 | ||||
| 600 | Gert Doering (8): |
|||
| 601 | IPv6 address/route delete fix for Win8 |
|||
| 602 | Add SSL library version reporting. |
|||
| 603 | Minor t_client.sh cleanups |
|||
| 604 | Repair --multihome on FreeBSD for IPv4 sockets. |
|||
| 605 | Rewrite manpage section about --multihome |
|||
| 606 | More IPv6-related updates to the openvpn man page. |
|||
| 607 | Conditionalize calls to print_default_gateway on !ENABLE_SMALL |
|||
| 608 | Preparing for release v2.3.4 (ChangeLog, version.m4) |
|||
| 609 | ||||
| 610 | James Yonan (2): |
|||
| 611 | Use native strtoull() with MSVC 2013. |
|||
| 612 | When tls-version-min is unspecified, revert to original versioning approach. |
|||
| 613 | ||||
| 614 | Steffan Karger (4): |
|||
| 615 | Change signedness of hash in x509_get_sha1_hash(), fixes compiler warning. |
|||
| 616 | Fix OCSP_check.sh to also use decimal for stdout verification. |
|||
| 617 | Fix build system to accept non-system crypto library locations for plugins. |
|||
| 618 | Make serial env exporting consistent amongst OpenSSL and PolarSSL builds. |
|||
| 619 | ||||
| 620 | Yawning Angel (1): |
|||
| 621 | Fix SOCKSv5 method selection |
|||
| 622 | ||||
| 623 | kangsterizer (1): |
|||
| 624 | Fix typo in sample build script to use LDFLAGS |
|||
| 625 | ``` |
|||
| 626 | ||||
| 627 | # OpenVPN 2.3.3 |
|||
| 628 | ||||
| 629 | ``` |
|||
| 630 | Alon Bar-Lev (1): |
|||
| 631 | pkcs11: use generic evp key instead of rsa |
|||
| 632 | ||||
| 633 | Arne Schwabe (8): |
|||
| 634 | Add support of utun devices under Mac OS X |
|||
| 635 | Add support to ignore specific options. |
|||
| 636 | Add a note what setenv opt does for OpenVPN < 2.3.3 |
|||
| 637 | Add reporting of UI version to basic push-peer-info set. |
|||
| 638 | Fix compile error in ssl_openssl introduced by polar external-management patch |
|||
| 639 | Fix assertion when SIGUSR1 is received while getaddrinfo is successful |
|||
| 640 | Add warning for using connection block variables after connection blocks |
|||
| 641 | Introduce safety check for http proxy options |
|||
| 642 | ||||
| 643 | David Sommerseth (5): |
|||
| 644 | man page: Update man page about the tls_digest_{n} environment variable |
|||
| 645 | Remove the --disable-eurephia configure option |
|||
| 646 | plugin: Extend the plug-in v3 API to identify the SSL implementation used |
|||
| 647 | autoconf: Fix typo |
|||
| 648 | Fix file checks when --chroot is being used |
|||
| 649 | ||||
| 650 | Davide Brini (1): |
|||
| 651 | Document authfile for socks server |
|||
| 652 | ||||
| 653 | Gert Doering (9): |
|||
| 654 | Fix IPv6 examples in t_client.rc-sample |
|||
| 655 | Fix slow memory drain on each client renegotiation. |
|||
| 656 | t_client.sh: ignore fields from "ip -6 route show" output that distort results. |
|||
| 657 | Make code and documentation for --remote-random-hostname consistent. |
|||
| 658 | Reduce IV_OPENVPN_GUI_VERSION= to IV_GUI_VER= |
|||
| 659 | Document issue with --chroot, /dev/urandom and PolarSSL. |
|||
| 660 | Rename 'struct route' to 'struct route_ipv4' |
|||
| 661 | Replace copied structure elements with including <net/route.h> |
|||
| 662 | Workaround missing SSL_OP_NO_TICKET in earlier OpenSSL versions |
|||
| 663 | ||||
| 664 | Heikki Hannikainen (1): |
|||
| 665 | Always load intermediate certificates from a PKCS#12 file |
|||
| 666 | ||||
| 667 | Heiko Hund (2): |
|||
| 668 | Support non-ASCII TAP adapter names on Windows |
|||
| 669 | Support non-ASCII characters in Windows tmp path |
|||
| 670 | ||||
| 671 | James Yonan (3): |
|||
| 672 | ||||
| 673 | TLS version negotiation |
|||
| 674 | Added "setenv opt" directive prefix. |
|||
| 675 | Set SSL_OP_NO_TICKET flag in SSL context for OpenSSL builds, to disable TLS stateless session resumption. |
|||
| 676 | ||||
| 677 | Jens Wagner (1): |
|||
| 678 | Fix spurious ignoring of pushed config options (trac#349). |
|||
| 679 | ||||
| 680 | Joachim Schipper (3): |
|||
| 681 | Refactor tls_ctx_use_external_private_key() |
|||
| 682 | --management-external-key for PolarSSL |
|||
| 683 | external_pkcs1_sign: Support non-RSA_SIG_RAW hash_ids |
|||
| 684 | ||||
| 685 | Josh Cepek (2): |
|||
| 686 | Correct error text when no Windows TAP device is present |
|||
| 687 | Require a 1.2.x PolarSSL version |
|||
| 688 | ||||
| 689 | Klee Dienes (1): |
|||
| 690 | tls_ctx_load_ca: Improve certificate error messages |
|||
| 691 | ||||
| 692 | Max Muster (1): |
|||
| 693 | Remove duplicate cipher entries from TLS translation table. |
|||
| 694 | ||||
| 695 | Peter Sagerson (1): |
|||
| 696 | Fix configure interaction with static OpenSSL libraries |
|||
| 697 | ||||
| 698 | Steffan Karger (7): |
|||
| 699 | Do not pass struct tls_session* as void* in key_state_ssl_init(). |
|||
| 700 | Require polarssl >= 1.2.10 for polarssl-builds, which fixes CVE-2013-5915. |
|||
| 701 | Use RSA_generate_key_ex() instead of deprecated, RSA_generate_key() |
|||
| 702 | Also update TLSv1_method() calls in support code to SSLv23_method() calls. |
|||
| 703 | Update TLSv1 error messages to SSLv23 to reflect changes from commit 4b67f98 |
|||
| 704 | If --tls-cipher is supplied, make --show-tls parse the list. |
|||
| 705 | Add openssl-specific common cipher list names to ssl.c. |
|||
| 706 | ||||
| 707 | Tamas TEVESZ (1): |
|||
| 708 | Add support for client-cert-not-required for PolarSSL. |
|||
| 709 | ||||
| 710 | Thomas Veerman (1): |
|||
| 711 | Fix "." in description of utun. |
|||
| 712 | ``` |
|||
| 713 | ||||
| 714 | # OpenVPN 2.3.2 |
|||
| 715 | ||||
| 716 | ``` |
|||
| 717 | Arne Schwabe (3): |
|||
| 718 | Only print script warnings when a script is used. Remove stray mention of script-security system. |
|||
| 719 | Move settings of user script into set_user_script function |
|||
| 720 | Move checking of script file access into set_user_script |
|||
| 721 | ||||
| 722 | Davide Brini (1): |
|||
| 723 | Provide more accurate warning message |
|||
| 724 | ||||
| 725 | Gert Doering (3): |
|||
| 726 | Fix NULL-pointer crash in route_list_add_vpn_gateway(). |
|||
| 727 | Fix problem with UDP tunneling due to mishandled pktinfo structures. |
|||
| 728 | Preparing for v2.3.2 (ChangeLog, version.m4) |
|||
| 729 | ||||
| 730 | James Yonan (1): |
|||
| 731 | Always push basic set of peer info values to server. |
|||
| 732 | ||||
| 733 | Jan Just Keijser (1): |
|||
| 734 | make 'explicit-exit-notify' pullable again |
|||
| 735 | ||||
| 736 | Josh Cepek (2): |
|||
| 737 | Fix proto tcp6 for server & non-P2MP modes |
|||
| 738 | Fix Windows script execution when called from script hooks |
|||
| 739 | ||||
| 740 | Steffan Karger (2): |
|||
| 741 | Fixed tls-cipher translation bug in openssl-build |
|||
| 742 | Fixed usage of stale define USE_SSL to ENABLE_SSL |
|||
| 743 | ||||
| 744 | svimik (1): |
|||
| 745 | Fix segfault when enabling pf plug-ins |
|||
| 746 | ``` |
|||
| 747 | ||||
| 748 | # OpenVPN 2.3.1 |
|||
| 749 | ||||
| 750 | ``` |
|||
| 751 | Arne Schwabe (4): |
|||
| 752 | Remove dead code path and putenv functionality |
|||
| 753 | Remove unused function xor |
|||
| 754 | Move static prototype definition from header into c file |
|||
| 755 | Remove unused function no_tap_ifconfig |
|||
| 756 | ||||
| 757 | Christian Hesse (1): |
|||
| 758 | fix build with automake 1.13(.1) |
|||
| 759 | ||||
| 760 | Christian Niessner (1): |
|||
| 761 | Fix corner case in NTLM authentication (trac #172) |
|||
| 762 | ||||
| 763 | Gert Doering (6): |
|||
| 764 | Update README.IPv6 to match what is in 2.3.0 |
|||
| 765 | Repair "tcp server queue overflow" brokenness, more <stdbool.h> fallout. |
|||
| 766 | Permit pool size of /64.../112 for ifconfig-ipv6-pool |
|||
| 767 | Add MIN() compatibility macro |
|||
| 768 | Fix directly connected routes for "topology subnet" on Solaris. |
|||
| 769 | Preparing for v2.3.1 (ChangeLog, version.m4) |
|||
| 770 | ||||
| 771 | Heiko Hund (5): |
|||
| 772 | close more file descriptors on exec |
|||
| 773 | Ignore UTF-8 byte order mark |
|||
| 774 | reintroduce --no-name-remapping option |
|||
| 775 | make --tls-remote compatible with pre 2.3 configs |
|||
| 776 | add new option for X.509 name verification |
|||
| 777 | ||||
| 778 | Jan Just Keijser (1): |
|||
| 779 | man page patch for missing options |
|||
| 780 | ||||
| 781 | Josh Cepek (2): |
|||
| 782 | Fix parameter listing in non-debug builds at verb 4 |
|||
| 783 | (updated) [PATCH] Warn when using verb levels >=7 without debug |
|||
| 784 | ||||
| 785 | Matthias Andree (1): |
|||
| 786 | Enable TCP_NODELAY configuration on FreeBSD. |
|||
| 787 | ||||
| 788 | Samuli Seppänen (4): |
|||
| 789 | Removed ChangeLog.IPv6 |
|||
| 790 | Added cross-compilation information INSTALL-win32.txt |
|||
| 791 | Updated README |
|||
| 792 | Cleaned up and updated INSTALL |
|||
| 793 | ||||
| 794 | Steffan Karger (7): |
|||
| 795 | PolarSSL-1.2 support |
|||
| 796 | Improve PolarSSL key_state_read_{cipher, plain}text messages |
|||
| 797 | Improve verify_callback messages |
|||
| 798 | Config compatibility patch. Added translate_cipher_name. |
|||
| 799 | Switch to IANA names for TLS ciphers. |
|||
| 800 | Fixed autoconf script to properly detect missing pkcs11 with polarssl. |
|||
| 801 | Use constant time memcmp when comparing HMACs in openvpn_decrypt. |
|||
| 802 | ``` |
|||
| 803 | ||||
| 804 | # OpenVPN 2.3.0 |
|||
| 805 | ||||
| 806 | This release fixes two bugs present in 2.3-rc2 and earlier: |
|||
| 807 | ||||
| 808 | ``` |
|||
| 809 | David Sommerseth (1): |
|||
| 810 | Preparing for v2.3.0 |
|||
| 811 | ||||
| 812 | Gert Doering (2): |
|||
| 813 | Fix parameter type for IP_TOS setsockopt on non-Linux systems. |
|||
| 814 | Fix client crash on double PUSH_REPLY. |
|||
| 815 | ``` |
|||
| 816 | ||||
| 817 | It includes major changes compared to latest 2.2.x ("oldstable") release: |
|||
| 818 | ||||
| 819 | * Full IPv6 support |
|||
| 820 | * SSL layer modularised, enabling easier implementation for other SSL libraries |
|||
| 821 | * PolarSSL support as a drop-in replacement for OpenSSL |
|||
| 822 | * New plug-in API providing direct certificate access, improved logging API and easier to extend in the future |
|||
| 823 | * Added 'dev_type' environment variable to scripts and plug-ins - which is set to 'TUN' or 'TAP' |
|||
| 824 | * New feature: --management-external-key - to provide access to the encryption keys via the management interface |
|||
| 825 | * New feature: --x509-track option, more fine grained access to X.509 fields in scripts and plug-ins |
|||
| 826 | * New feature: --client-nat support |
|||
| 827 | * New feature: --mark which can mark encrypted packets from the tunnel, suitable for more advanced routing and firewalling |
|||
| 828 | * New feature: --management-query-proxy - manage proxy settings via the management interface (supercedes --http-proxy-fallback) |
|||
| 829 | * New feature: --stale-routes-check, which cleans up the internal routing table |
|||
| 830 | * New feature: --x509-username-field, where other X.509v3 fields can be used for the authentication instead of Common Name |
|||
| 831 | * Improved client-kill management interface command |
|||
| 832 | * Improved UTF-8 support - and added --compat-names to provide backwards compatibility with older scripts/plug-ins |
|||
| 833 | * Improved auth-pam with COMMONNAME support, passing the certificate's common name in the PAM conversation |
|||
| 834 | * More options can now be used inside <connection> blocks |
|||
| 835 | * Completely new build system, enabling easier cross-compilation and Windows builds |
|||
| 836 | * Much of the code has been better documented |
|||
| 837 | * Many documentation updates |
|||
| 838 | * Plenty of bug fixes and other code clean-ups |
|||
| 839 | ||||
| 840 | # OpenVPN 2.3_rc2 |
|||
| 841 | ||||
| 842 | ``` |
|||
| 843 | Adriaan de Jong (1): |
|||
| 844 | Fix --show-pkcs11-ids (Bug #239) |
|||
| 845 | ||||
| 846 | Arne Schwabe (4): |
|||
| 847 | Error message if max-routes used incorrectly |
|||
| 848 | Properly require --key even if defined(MANAGMENT_EXTERNAL_KEY) |
|||
| 849 | Remove dnsflags_to_socktype, it is not used anywhere |
|||
| 850 | Fix the proto is used inconsistently warning |
|||
| 851 | ||||
| 852 | David Sommerseth (4): |
|||
| 853 | Fix double-free issue in pf_destroy_context() |
|||
| 854 | The get_default_gateway() function uses warn() instead of msg() |
|||
| 855 | Avoid recursion in virtual_output_callback_func() |
|||
| 856 | Preparing for v2.3_rc2 |
|||
| 857 | ||||
| 858 | Gert Doering (2): |
|||
| 859 | Implement --mssfix handling for IPv6 packets. |
|||
| 860 | Fix option inconsistency warnings about "proto" and "tun-ipv6" |
|||
| 861 | ||||
| 862 | Joachim Schipper (2): |
|||
| 863 | doc/management-notes.txt: fix typo |
|||
| 864 | Fix typo in ./configure message |
|||
| 865 | ``` |
|||
| 866 | ||||
| 867 | # OpenVPN 2.3_rc1 |
|||
| 868 | ||||
| 869 | ``` |
|||
| 870 | Adriaan de Jong (1): |
|||
| 871 | Fixed a bug where PolarSSL gave an error when using an inline file tag. |
|||
| 872 | ||||
| 873 | Arne Schwabe (2): |
|||
| 874 | Document man agent-external-key |
|||
| 875 | Options parsing demands unnecessary configuration if PKCS11 is used |
|||
| 876 | ||||
| 877 | David Sommerseth (3): |
|||
| 878 | Make git ignore some more files |
|||
| 879 | Remove the support for using system() when executing external programs or scripts |
|||
| 880 | Preparing for v2.3_rc1 |
|||
| 881 | ||||
| 882 | Heiko Hund (2): |
|||
| 883 | Fix display of plugin hook types |
|||
| 884 | Support UTF-8 --client-config-dir |
|||
| 885 | ||||
| 886 | Kenneth Rose (1): |
|||
| 887 | Fix v3 plugins to support returning values back to OpenVPN. |
|||
| 888 | ``` |
|||
| 889 | ||||
| 890 | ||||
| 891 | # OpenVPN 2.3_beta1 |
|||
| 892 | ||||
| 893 | ``` |
|||
| 894 | Arne Schwabe (7): |
|||
| 895 | Fixes error: --key fails with EXTERNAL_PRIVATE_KEY: No such file or directory if --management-external-key is used |
|||
| 896 | Merge almost identical create_socket_tcp and create_socket_tcp6 |
|||
| 897 | Document the inlining of files in openvpn and document key-direction |
|||
| 898 | Merge getaddr_multi and getaddr6 into one function |
|||
| 899 | Document --management-client and --management-signal a bit better |
|||
| 900 | Document that keep alive will double the second value in server mode and give a short explanation why the value is chosen. |
|||
| 901 | Add checks for external-key-managements |
|||
| 902 | ||||
| 903 | David Sommerseth (1): |
|||
| 904 | Fix reconnect issues when --push and UDP is used on the server |
|||
| 905 | ||||
| 906 | Gert Doering (4): |
|||
| 907 | Reduce --version string detail about IPv6 to just "[IPv6]". |
|||
| 908 | Put actual OpenVPN command line on top of corresponding log file. |
|||
| 909 | Keep pre-existing tun/tap devices around on *BSD |
|||
| 910 | make "ipv6 ifconfig" on linux compatible with busybox ifconfig |
|||
| 911 | ||||
| 912 | Heiko Hund (6): |
|||
| 913 | fix regression with --http-proxy[-*] options |
|||
| 914 | add x_msg_va() log function |
|||
| 915 | add API for plug-ins to write to openvpn log |
|||
| 916 | remove stale _openssl_get_subject() prototype |
|||
| 917 | remove unused flag SSLF_NO_NAME_REMAPPING |
|||
| 918 | Add --compat-names option |
|||
| 919 | ``` |
|||
| 920 | ||||
| 921 | # OpenVPN 2.3-alpha3 |
|||
| 922 | ||||
| 923 | This release fixes a major problem in "tap server" mode (Trac #216), adds support for querying proxy information via the management interface and fixes some smaller issues. In addition, the Windows installer comes with tap-windows-9.9.2 (fixes the "DHCP NAK bomb on Windows 7" bug, Trac #97) and openvpn-gui-1.0.5. |
|||
| 924 | ||||
| 925 | '''Full list of changes''' |
|||
| 926 | ||||
| 927 | ``` |
|||
| 928 | 2012.07.20 -- Version 2.3_alpha3 |
|||
| 929 | Arne Schwabe (1): |
|||
| 930 | Fix compiling with --disable-management |
|||
| 931 | ||||
| 932 | Gert Doering (1): |
|||
| 933 | Repair "tap server" mode brokenness caused by <stdbool.h> fallout |
|||
| 934 | ||||
| 935 | Heiko Hund (4): |
|||
| 936 | make non-blocking connect work on Windows |
|||
| 937 | don't treat socket related errors special anymore |
|||
| 938 | remove unused show_connection_list debug function |
|||
| 939 | add option --management-query-proxy |
|||
| 940 | ``` |
|||
| 941 | ||||
| 942 | ||||
| 943 | # OpenVPN 2.3-alpha2 |
|||
| 944 | ||||
| 945 | The largest change in OpenVPN 2.3-alpha2 is the split into several subprojects: |
|||
| 946 | ||||
| 947 | * [https://github.com/OpenVPN/openvpn openvpn] (the core project) |
|||
| 948 | * [https://github.com/OpenVPN/tap-windows tap-windows] (Windows TAP-driver) |
|||
| 949 | * [https://github.com/OpenVPN/easy-rsa easy-rsa] (PKI management package) |
|||
| 950 | * [https://github.com/OpenVPN/openvpn-build openvpn-build] (external buildsystem) |
|||
| 951 | * "generic": cross-compile on *NIX platforms (e.g. Linux -> Windows) |
|||
| 952 | * "msvc": build using MSVC on Windows |
|||
| 953 | * "windows-nsis": generate Windows installers on *NIX |
|||
| 954 | ||||
| 955 | These changes have resulted in a number of user-visible changes: |
|||
| 956 | ||||
| 957 | * Separate 32- and 64-bit installers for Windows (see ''INSTALL-win32.txt'') |
|||
| 958 | * Old "domake-win" and Python-based buildsystems have been removed |
|||
| 959 | * "easy-rsa" and "tap-windows" removed from the OpenVPN Git tree |
|||
| 960 | * All Windows executables and libraries cross-compiled with mingw_w64 and signed |
|||
| 961 | * Rewrite of the openvpn autotools buildsystem |
|||
| 962 | ||||
| 963 | In addition, there a number of changes not related to the above: |
|||
| 964 | ||||
| 965 | * Many bugfixes |
|||
| 966 | * Stabilized the PolarSSL support |
|||
| 967 | * Enabled IPv6 support on OSX |
|||
| 968 | * General code cleanup |
|||
| 969 | * Improved UTF-8 support in Windows |
|||
| 970 | ||||
| 971 | '''Full list of changes''' |
|||
| 972 | ||||
| 973 | ``` |
|||
| 974 | tag v2.3_alpha2 |
|||
| 975 | Tagger: David Sommerseth <davids@redhat.com> |
|||
| 976 | Date: Fri Jun 29 10:36:38 2012 +0200 |
|||
| 977 | ||||
| 978 | 2012.06.29 -- Version 2.3_alpha2 |
|||
| 979 | Adriaan de Jong (11): |
|||
| 980 | Fixed off-by-one in serial length calculation |
|||
| 981 | Migrated x509_get_subject to use of the garbage collector |
|||
| 982 | Migrated x509_get_serial to use the garbage collector |
|||
| 983 | Migrated x509_get_sha1_hash to use the garbage collector |
|||
| 984 | Ensure sys/un.h autoconf detection includes sys/socket.h |
|||
| 985 | Added support for new PolarSSL 1.1 RNG |
|||
| 986 | Added a configuration option to enable prediction resistance in the PolarSSL random number generator. |
|||
| 987 | Use POLARSSL_CFLAGS instead of POLARSSL_CRYPTO_CFLAGS in configure.ac |
|||
| 988 | Removed support for PolarSSL < 1.1 |
|||
| 989 | Updated README.polarssl with build system changes. |
|||
| 990 | Removed stray "Fox-IT hardening" string. |
|||
| 991 | ||||
| 992 | Alon Bar-Lev (94): |
|||
| 993 | build: version should not contain '-' |
|||
| 994 | package: rpm: strip should be handled by package management |
|||
| 995 | cleanup: options.c: remove redundant include |
|||
| 996 | cleanup: remove C++ warnings |
|||
| 997 | cleanup: win32.c: wrong printf format |
|||
| 998 | cleanup: remove redundant ';' |
|||
| 999 | cleanup: crypto_openssl.c: remove support for pre-openssl-0.9.6 |
|||
| 1000 | cleanup: tun.c: fix incorrect option in message (ip-win32) |
|||
| 1001 | cleanup: memcmp.c: remove unused source |
|||
| 1002 | fixup: init.c: add missing conditional for ENABLE_CLIENT_CR |
|||
| 1003 | build: correct place to alter WINVER is at build system |
|||
| 1004 | Update .gitignore |
|||
| 1005 | build: handle printf style format in mingw |
|||
| 1006 | build: rename plugin directory to plugins |
|||
| 1007 | build: plugins: properly use CC, CFLAGS and LDFLAGS |
|||
| 1008 | build: we need the sample.ovpn in future |
|||
| 1009 | Remove install-win32 |
|||
| 1010 | Remove easy-rsa |
|||
| 1011 | Remove tap-win32 |
|||
| 1012 | cleanup: rename tap-windows function from win32 to win |
|||
| 1013 | build: remove windows specific build system |
|||
| 1014 | build: split acinclude.m4 into m4/* |
|||
| 1015 | build: m4/ax_varargs.m4: cleanup |
|||
| 1016 | build: m4/ax_emptyarray.m4: cleanup |
|||
| 1017 | build: m4/ax_socklen_t.m4: cleanup |
|||
| 1018 | build: autotools: first pass of trivial autotools changes |
|||
| 1019 | build: autoconf: remove OPENVPN_ADD_LIBS useless macro |
|||
| 1020 | build: remove awk and non-standard autoconf output processing |
|||
| 1021 | build: standard directory layout |
|||
| 1022 | build: add libtool + windows resources for executables |
|||
| 1023 | build: autoconf: commands as environment |
|||
| 1024 | build: libdl usage |
|||
| 1025 | build: properly detect and use socket libs |
|||
| 1026 | build: autoconf: minor cleanups |
|||
| 1027 | build: proper selinux detection and usage |
|||
| 1028 | build: distribute pkg.m4 |
|||
| 1029 | build: proper pkcs11-helper detection and usage |
|||
| 1030 | build: properly process lzo-stub |
|||
| 1031 | build: proper lzo detection and usage |
|||
| 1032 | build: proper crypto detection and usage |
|||
| 1033 | build: autoconf: update defaults for options |
|||
| 1034 | build: win-msvc: msbuild format |
|||
| 1035 | build: move out config.h include from syshead |
|||
| 1036 | build: split out compat |
|||
| 1037 | build: move gettimeofday() emulation to compat |
|||
| 1038 | build: move daemon() emulation into compat |
|||
| 1039 | build: move inet_ntop(), inet_pton() emulation into compat |
|||
| 1040 | cleanup: move console related function into its own module |
|||
| 1041 | build: move wrappers into platform module |
|||
| 1042 | build: windows: install version.sh to allow installer read version |
|||
| 1043 | build: distribute samples in windows |
|||
| 1044 | build: use tap-windows.h as external dependency |
|||
| 1045 | build: ax_varargs.m4: fixups |
|||
| 1046 | build: autoconf: misc sockets fixups |
|||
| 1047 | build: enable lzo by default |
|||
| 1048 | build: windows: set vendor to openvpn project + cleanups |
|||
| 1049 | build: assume dlfcn is available on all supported platforms |
|||
| 1050 | build: openbsd: detect netinet/ip.h correctly |
|||
| 1051 | build: tap: search for tap header |
|||
| 1052 | build: msvc: upgrade to Visual Studio 2010 + fixups |
|||
| 1053 | Enable pedantic in windows compilation |
|||
| 1054 | cleanup: flags should not be bool |
|||
| 1055 | cleanup: avoid using ~0 - generic |
|||
| 1056 | cleanup: avoid using ~0 - ipv6 |
|||
| 1057 | cleanup: avoid using ~0 - netmask |
|||
| 1058 | cleanup: avoid using ~0 - windows |
|||
| 1059 | cleanup: gc usage |
|||
| 1060 | build: fix some statement left from conversion |
|||
| 1061 | build: properly detect netinet/ip.h structs |
|||
| 1062 | build: properly detect TUNSETPERSIST |
|||
| 1063 | cleanup: plugin: support C++ plugin |
|||
| 1064 | cleanup: remove C++ comments |
|||
| 1065 | cleanup: add .gitattributes to control eol style explicitly |
|||
| 1066 | crash: packet_id_debug_print: sl may be null |
|||
| 1067 | build: use stdbool.h if available |
|||
| 1068 | build: fix typo in --enable-save-password |
|||
| 1069 | build: windows: convert resources to UTF-8 |
|||
| 1070 | build: check minimum polarssl version |
|||
| 1071 | cleanup: update .gitignore |
|||
| 1072 | cleanup: spec: make space/tab consistent |
|||
| 1073 | build: spec: we support openssl >= 0.9.7 |
|||
| 1074 | build: insall README* document using build system |
|||
| 1075 | build: detect sys/wait.h required for *bsd |
|||
| 1076 | build: add git revision to --version output if build from git repository |
|||
| 1077 | build: cleanup: yet another forgotten brackets |
|||
| 1078 | build: update INSTALL to recent changes |
|||
| 1079 | build: support platforms that does not need explicit tun headers |
|||
| 1080 | build: do not support <polarssl-1.1.0 |
|||
| 1081 | build: add --with-special-build to provide special build string |
|||
| 1082 | cleanup: pkcs11.c: resolve wanings |
|||
| 1083 | build: integrate plugins build into core build |
|||
| 1084 | build: plugins: set defaults based on platform |
|||
| 1085 | cleanup: windows: convert argv (UCS-2 to UTF-8) at earliest |
|||
| 1086 | build: msvc: chdir with change drive to script location |
|||
| 1087 | ||||
| 1088 | Arne Schwabe (7): |
|||
| 1089 | Add the query to the error message. |
|||
| 1090 | Explain that route-nopull also causes the client to ignore dhcp options. |
|||
| 1091 | Add the name of the context where option is not allowed to the error message. |
|||
| 1092 | Only use tmpdir if tmp_dir is really used. |
|||
| 1093 | Completely remove ancient IANA port warning. |
|||
| 1094 | Remove ENABLE_INLINE_FILES conditionals |
|||
| 1095 | Remove ENABLE_CONNECTIONS ifdefs |
|||
| 1096 | ||||
| 1097 | David Sommerseth (5): |
|||
| 1098 | Clean-up: Presume that Linux is always IPv6 capable at build time |
|||
| 1099 | Simplify check_cmd_access() function |
|||
| 1100 | Change version to indicate the master branch is not a version |
|||
| 1101 | Some filesystems don't like ':', which is a path 'make dist' would use |
|||
| 1102 | Remove two unused functions |
|||
| 1103 | ||||
| 1104 | Frank de Brabander (1): |
|||
| 1105 | Fix reported compile issues on OSX 10.6.8 |
|||
| 1106 | ||||
| 1107 | Gert Doering (10): |
|||
| 1108 | repair t_client.sh test after build system revolution |
|||
| 1109 | t_client.sh iproute2 script fixes |
|||
| 1110 | t_client.sh - fix for iproute2, print summary line |
|||
| 1111 | Implement search for "first free" tun/tap device on Solaris |
|||
| 1112 | cleanup and redefine metric handling for IPv6 routes |
|||
| 1113 | remove "*option" element in "struct route_ipv6" |
|||
| 1114 | Remove warning about explicit support for IPv6 support not provided MacOS X |
|||
| 1115 | Add missing pieces to IPv6 route gateway handling. |
|||
| 1116 | Update TODO.IPv6 list |
|||
| 1117 | Remove #include "config.h" from ssl_polarssl.h |
|||
| 1118 | ||||
| 1119 | Heiko Hund (3): |
|||
| 1120 | remove wrapper code for Windows CryptoAPI function |
|||
| 1121 | fix warnings in event.c when building for win32-64 |
|||
| 1122 | remove the --auto-proxy option from openvpn |
|||
| 1123 | ||||
| 1124 | Igor Novgorodov (1): |
|||
| 1125 | Remove calls to OpenSSL when building with --disable-ssl |
|||
| 1126 | ||||
| 1127 | Jonathan K. Bullard (2): |
|||
| 1128 | Fix file access checks on commands |
|||
| 1129 | Clarified the docs and help screen about what a 'cmd' is |
|||
| 1130 | ||||
| 1131 | Samuli Seppänen (1): |
|||
| 1132 | Added notes about upgrading from 2.3-alpha1 and earlier to INSTALL-win32.txt |
|||
| 1133 | -----BEGIN PGP SIGNATURE----- |
|||
| 1134 | Version: GnuPG v1.4.11 (GNU/Linux) |
|||
| 1135 | ||||
| 1136 | iEYEABECAAYFAk/taVIACgkQDC186MBRfrpdxQCfQ+jfqA5kujaoZ+1Vj6SUOoms |
|||
| 1137 | ljkAn1obwJrSAP7MYiVp944u6t2EQ3r7 |
|||
| 1138 | =uh6E |
|||
| 1139 | -----END PGP SIGNATURE----- |
|||
| 1140 | ``` |
|||
| 1141 | ||||
| 1142 | # OpenVPN 2.3-alpha1 |
|||
| 1143 | ||||
| 1144 | This release includes a large number of new features: |
|||
| 1145 | ||||
| 1146 | * Complete IPv6 support, both transport and payload |
|||
| 1147 | * Optional PolarSSL support (build time configuration) |
|||
| 1148 | * Improved plug-in API (v3) which can more easily be expanded in the future. Includes support for direct access to X.509 certificate data in plug-ins |
|||
| 1149 | * New build-time configuration option: --enable-lzo-stub - Clients tell the server if they support LZO or not, and server can automatically disable LZO for that client. |
|||
| 1150 | * [https://sourceforge.net/projects/openvpn-gui/ New OpenVPN-GUI] |
|||
| 1151 | ||||
| 1152 | * New options / updated options |
|||
| 1153 | * ''--stale-routes-check'': remove routes that haven't had activity recently |
|||
| 1154 | * ''--client-nat'': one-to-one NAT to avoid IP address conflicts between local and remote networks |
|||
| 1155 | * ''--extra-certs'': certificates which completes the CA chain, without trusting these certificates |
|||
| 1156 | * ''--verify-hash'': Fingerprint matching on level-1 certificates |
|||
| 1157 | * ''--memstats'': Write live usage stats to memory mapped binary files |
|||
| 1158 | * ''--crl-verify'' directory mode: file names in this dir which matching the serial numbers are treated as a revoked certificate. These files itself may be empty, as it is only done a match against the file name. |
|||
| 1159 | ||||
| 1160 | ||||
| 1161 | * Management interface improvements |
|||
| 1162 | * New option ''--management-external-key'': Load RSA keys via management interface |
|||
| 1163 | * New option ''--management-up-down'': notify management interface on tunnel up/down events |
|||
| 1164 | * New management command for servers: ''client-kill'' |
|||
| 1165 | * New management command for clients: ''auth-token'' provides a feature to avoid storing passwords in memory and use a temporary token as an alternative to passing the password. |
|||
| 1166 | * New management command for clients: ''remote'' which can override the configured --remote options |
|||
| 1167 | ||||
| 1168 | Many enhancements are also included: |
|||
| 1169 | ||||
| 1170 | * Management command for server, status, can report username for each connected user (requires status log version >= 2) |
|||
| 1171 | * UTF-8 support for certificate fields |
|||
| 1172 | * Windows UTF-8 support: Filenames may now contain wide characters and environment variables handled as UCS-2 characters |
|||
| 1173 | * Fixed client issues with DHCP Router option extraction/deletion with layer 2 DHCP proxies. |
|||
| 1174 | * Added "on-link" routes on Linux. This solves --redirect-gateway issues where routes are set up with devices instead of IP addresses |
|||
| 1175 | * Several configuration options are now supported inside <connection> blocks |
|||
| 1176 | * Add extv3 X509 field support to --x509-username-field |
|||
| 1177 | * Several man page updates |
|||
| 1178 | ||||
| 1179 | A few changes have been made which may affect existing installations: |
|||
| 1180 | ||||
| 1181 | * 'echo' options will no longer be written to log files and will only be available via the management interface. |
|||
| 1182 | * The certificate strings have changed syntax to the new standard provided newer OpenSSL APIs. Earlier the format was: |
|||
| 1183 | ||||
| 1184 | ```/CN=Common Name/O=Organisation/L=Location``` |
|||
| 1185 | ||||
| 1186 | The new format will look like: |
|||
| 1187 | ||||
| 1188 | ```CN=Common Name, O=Organisation, L=Location``` |
|||
| 1189 | ||||
| 1190 | This change impacts plug-ins, scripts and --tls-remote which parses these certificate strings. |
|||
| 1191 | ||||
| 1192 | '''Full list of changes''' |
|||
| 1193 | ||||
| 1194 | ``` |
|||
| 1195 | Adriaan de Jong (127): |
|||
| 1196 | Added Doxygen doxyfile |
|||
| 1197 | Changed configure to accept --with-ssl-type=openssl |
|||
| 1198 | Refactored to rand_bytes for OpenSSL-independency |
|||
| 1199 | Refactored OpenSSL-specific constants |
|||
| 1200 | Refactored maximum cipher and hmac length constants |
|||
| 1201 | Refactored show_available_* functions |
|||
| 1202 | Refactored SSL_clear_error() |
|||
| 1203 | Refactored crypto initialisation functions |
|||
| 1204 | Refactored DES key manipulation functions |
|||
| 1205 | Refactored NTLM DES key generation |
|||
| 1206 | Refactored message digest type functions |
|||
| 1207 | Refactored message digest functions |
|||
| 1208 | Refactored HMAC functions |
|||
| 1209 | Refactored cipher key types |
|||
| 1210 | Refactored cipher functions |
|||
| 1211 | Added PRNG doxygen |
|||
| 1212 | Refactored: Moved crypto.h inline functions to end of file |
|||
| 1213 | Removed stale OpenSSL defines from crypto.h |
|||
| 1214 | Added a check for Openssl or PolarSSL defines |
|||
| 1215 | Refactored: Added stubs for new files |
|||
| 1216 | Refactored SSL initialisation functions |
|||
| 1217 | Refactored TLS_PRF to new hmac and md primitives |
|||
| 1218 | Refactored tls_show_available_ciphers |
|||
| 1219 | Refactored get_highest_preference_tls_cipher |
|||
| 1220 | Refactored root SSL context initialisation |
|||
| 1221 | Refactored new external key code |
|||
| 1222 | Refactored DH paramater loading |
|||
| 1223 | Refactored root TLS option settings |
|||
| 1224 | Refactored PKCS#12 key loading |
|||
| 1225 | Refactored PKCS#11 loading |
|||
| 1226 | Refactored windows cert loading |
|||
| 1227 | Refactored load certificate functions |
|||
| 1228 | Refactored private key loading code |
|||
| 1229 | Refactored external key loading from management |
|||
| 1230 | Refactored CA and extra certs code |
|||
| 1231 | Refactored cipher restriction code |
|||
| 1232 | Refactored tls_options, key_state, and key_source data structures |
|||
| 1233 | Refactored initalisation of key_states |
|||
| 1234 | Refactored key_state free code |
|||
| 1235 | Refactored print_details |
|||
| 1236 | Refactored key_state read code (including bio_read()) |
|||
| 1237 | Refactored key_state write functions |
|||
| 1238 | Refactored: Moved BIO debug functions to OpenSSL backend |
|||
| 1239 | Refactored: removed ks and ks_lame macro for clarity |
|||
| 1240 | Refactored: moved write_empty_string function back |
|||
| 1241 | Refactored Doxygen for tls_multi functions |
|||
| 1242 | Migrated data structures needed by verification functions to ssl_common.h |
|||
| 1243 | Refactored client_config_dir_exclusive function |
|||
| 1244 | Refactored certificate hash lock checks |
|||
| 1245 | Refactored common name locking functions |
|||
| 1246 | Refactored username and password authentication code |
|||
| 1247 | Add some extra comments |
|||
| 1248 | Refactored: split verify_callback into two parts |
|||
| 1249 | Added function to extract and verify the subject from a certificate |
|||
| 1250 | Added function to verify and extract the username |
|||
| 1251 | Refactored: removed global x509_username_field |
|||
| 1252 | Refactored: separated environment setup during verification |
|||
| 1253 | Refactored: Netscape certificate type verification |
|||
| 1254 | Refactored key usage verification code |
|||
| 1255 | Refactored EKU verification |
|||
| 1256 | Refactored tls-remote checking |
|||
| 1257 | Refactored tls-verify-plugin code |
|||
| 1258 | Refactored tls-verify script code |
|||
| 1259 | Refactored CRL checks |
|||
| 1260 | Minor cleanup in verify_cert: |
|||
| 1261 | Refactored: Moved verify_cert to ssl_verify |
|||
| 1262 | Cleaned up ssl.h |
|||
| 1263 | Refactored: made M_SSL dependent on USE_OPENSSL |
|||
| 1264 | Refactored: renamed X509 functions from verify_* |
|||
| 1265 | Separated OpenSSL-specific parts of the PKCS#11 driver |
|||
| 1266 | Modified base64 code in preparation for PolarSSL merge |
|||
| 1267 | Final cleanup before PolarSSL addition: |
|||
| 1268 | Refactored X509 track feature to be contained within the openssl backend |
|||
| 1269 | Added PolarSSL support: |
|||
| 1270 | Fixed a missing include in ssl_backend.h |
|||
| 1271 | Fixed a bug in the hash generation in ssl_verify_openssl.c |
|||
| 1272 | Added SHA_DIGEST_SIZE definition |
|||
| 1273 | Changed PolarSSL crypto backend to support v0.99-pre5 |
|||
| 1274 | Updated ssl_polarssl.c to work with 0.99-pre5 |
|||
| 1275 | Fixed a compilation warning for size_t key sizes |
|||
| 1276 | Added a warning that the PolarSSL library does not support pkcs12 files. |
|||
| 1277 | Added warning that --capath is not available with PolarSSL |
|||
| 1278 | Disable CryptoAPI when not using OpenSSL, and document that fact. |
|||
| 1279 | Removed support for management external keys in PolarSSL |
|||
| 1280 | Removed stray X509_free from ssl.c |
|||
| 1281 | Refactored (and disabled for PolarSSL) support for writing external cert files in scripts |
|||
| 1282 | Added an extra define to allow building without PKCS#11 |
|||
| 1283 | Added SSL library to title string |
|||
| 1284 | Disabled X.509 track and username selection for PolarSSL |
|||
| 1285 | Hardening: periodically reset the PRNG's nonce value |
|||
| 1286 | Fixes for the plugin system: |
|||
| 1287 | Further improvements to plugin support: |
|||
| 1288 | Fixed an unintentional change in the options calculated key size. |
|||
| 1289 | Moved print messages back to generic crypto.c from cipher backends |
|||
| 1290 | Moved HMAC prints back to main crypto module |
|||
| 1291 | Added back checks for ks->authenticated in verify_user_pass |
|||
| 1292 | Moved gc_new and gc_free to begin end of function |
|||
| 1293 | Fixed a bug in the return value of ssl_verify when pre_verify failed |
|||
| 1294 | Unified verification function return values: |
|||
| 1295 | Removed a stray Fox-IT tag |
|||
| 1296 | Fixed a typo: print the subject instead of the serial for verification errors |
|||
| 1297 | Made SSL_CIPHER const in print_details, to fix warning |
|||
| 1298 | Moved to PolarSSL 1.0.0: |
|||
| 1299 | Added missing #ifdef to allow --disable-managent to work again |
|||
| 1300 | Fixed disabling crypto and SSL |
|||
| 1301 | Got rid of a few magic numbers in ntlm.c |
|||
| 1302 | Removed obsolete des_cblock and des_keyschedule |
|||
| 1303 | Further removal of des_old.h based calls |
|||
| 1304 | Fixed missing comma in plugin.h |
|||
| 1305 | Moved prng_uninit out of crypto_uninit_lib |
|||
| 1306 | Moved CryptoAPI header include to the ssl_openssl.c |
|||
| 1307 | Reordered functions to ensure warning-free Windows build |
|||
| 1308 | Added options to switch between OpenSSL and PolarSSL and PKCS11... |
|||
| 1309 | Moved from strsep to strtok, for Windows compatibility |
|||
| 1310 | Minor cleanup to enable warning-free Windows build: |
|||
| 1311 | Fixed a typo when initialising cryptoapi certs |
|||
| 1312 | Minor code cleanup: cleaned up error handling in verify_cert. |
|||
| 1313 | Moved out of memory prototype to error.h, as the definition is in error.c |
|||
| 1314 | Removed support for calling gc_malloc with a NULL gc_arena struct |
|||
| 1315 | ||||
| 1316 | (The follwing patches from Adriaan was mistakenly merged with |
|||
| 1317 | the wrong commit author in the git tree) |
|||
| 1318 | Doxygen: Added data channel crypto docs |
|||
| 1319 | Added control channel crypto docs |
|||
| 1320 | Added compression docs |
|||
| 1321 | Added reliability layer documentation |
|||
| 1322 | Added memory management documentation |
|||
| 1323 | Added data channel fragmentation docs |
|||
| 1324 | Added main/control docs |
|||
| 1325 | Moved doxygen-specific files to a separate directory |
|||
| 1326 | ||||
| 1327 | Byron Ellacott (1): |
|||
| 1328 | autoconf fixes for building on OSX |
|||
| 1329 | ||||
| 1330 | David Sommerseth (50): |
|||
| 1331 | Provide 'dev_type' environment variable to plug-ins and script hooks |
|||
| 1332 | Define the new openvpn_plugin_{open,func}_v3() API |
|||
| 1333 | Implement the core v3 plug-in function calls. |
|||
| 1334 | Extend the v3 plug-in API to send over X509 certificates |
|||
| 1335 | Added a simple plug-in demonstrating the v3 plug-in API. |
|||
| 1336 | Separate the general plug-in version constant and v3 plug-in structs version |
|||
| 1337 | Use a version-less version identifier on the master branch |
|||
| 1338 | Fix the --client-cert-not-required feature |
|||
| 1339 | Change the default --tmp-dir path to a more suitable path |
|||
| 1340 | Improve the mysprintf() issue in openvpnserv.c |
|||
| 1341 | Add a simple comment regarding openvpn_snprintf() is duplicated |
|||
| 1342 | Merge branch 'feat_ipv6_transport' |
|||
| 1343 | Merge branch 'feat_ipv6_payload' |
|||
| 1344 | Merge branch 'svn-branch-2.1' into merge |
|||
| 1345 | Solved hidden merge conflicts between master and svn-branch-2.1 |
|||
| 1346 | Fix const declarations in plug-in v3 structs |
|||
| 1347 | Merge remote-tracking branch 'cron2/feat_ipv6_payload_2.3' |
|||
| 1348 | Don't define ENABLE_PUSH_PEER_INFO if SSL is not available |
|||
| 1349 | Fix compiling issues with pkcs11 when --disable-management is configured |
|||
| 1350 | Remove support for Linux 2.2 configuration fallback |
|||
| 1351 | Revert "Add new openssl.cnf to easy-rsa/Windows" |
|||
| 1352 | Merge remote branch SVN 2.1 into the git tree |
|||
| 1353 | Merge branch 'svn-merger' |
|||
| 1354 | Fix Microsoft Visual Studio incompatibility in plugin.c |
|||
| 1355 | Fixed compile issues on FreeBSD and Solaris |
|||
| 1356 | Fix PolarSSL and --pkcs12 option issues |
|||
| 1357 | Fix FreeBSD/OpenBSD/NetBSD compiler warnings in get_default_gateway() |
|||
| 1358 | Make '--win-sys env' default |
|||
| 1359 | Do some file/directory tests before really starting openvpn |
|||
| 1360 | Fix bug after removing Linux 2.2 support |
|||
| 1361 | Don't look for 'stdin' file when using --auth-user-pass |
|||
| 1362 | Fix compiling with --disable-crypto and/or --disable-ssl |
|||
| 1363 | Fix a couple of issues in openvpn_execve() |
|||
| 1364 | Move away from openvpn_basename() over to platform provided basename() |
|||
| 1365 | Enable access() when building in Visual Studio |
|||
| 1366 | New Windows build fixes |
|||
| 1367 | Fix compilation errors on Linux platforms without SO_MARK |
|||
| 1368 | autotools ./configure don't like compat.h |
|||
| 1369 | Fix pool logging when IPv6 is not enabled |
|||
| 1370 | Don't check for file presence on inline files |
|||
| 1371 | Add --route-pre-down/OPENVPN_PLUGIN_ROUTE_PREDOWN script/plug-in hook |
|||
| 1372 | Enhance the error handling in _openssl_get_subject() |
|||
| 1373 | Fix assert() situations where gc_malloc() is called without a gc_arena object |
|||
| 1374 | Fix compile issues when plug-ins are disabled. |
|||
| 1375 | Remove --show-gateway if debug info is not enabled (--disable-debug) |
|||
| 1376 | Fix compile issues with status.c |
|||
| 1377 | Connection entry {tun,link}_mtu_defined not set correctly |
|||
| 1378 | Makefile.am referenced a now non-existing config-win32.h |
|||
| 1379 | Makefile.am was missing ssl_common.h |
|||
| 1380 | Revamp check_file_access() checks in stdin scenarios |
|||
| 1381 | ||||
| 1382 | Davide Guerri (1): |
|||
| 1383 | New feauture: Add --stale-routes-check |
|||
| 1384 | ||||
| 1385 | Frank de Brabander (1): |
|||
| 1386 | Fixed wrong return type of cipher_kt_mode |
|||
| 1387 | ||||
| 1388 | Frederic Crozat (1): |
|||
| 1389 | Add support to forward console query to systemd |
|||
| 1390 | ||||
| 1391 | Gert Doering (45): |
|||
| 1392 | Add more detailed explanation regarding the function of "--rdns-internal" |
|||
| 1393 | Enable IPv6 Payload in OpenVPN p2mp tun server mode. 20100104-1 release. |
|||
| 1394 | remove NOTES file from commit - private scribbling |
|||
| 1395 | NetBSD fixes - on 4.0 and up, use multi-af mode. |
|||
| 1396 | new feature: "ifconfig-ipv6-push" (from ccd/ config) |
|||
| 1397 | add some TODOs to TODO.IPv6 |
|||
| 1398 | undo accidential duplication of existing "--iroute" line in the help text |
|||
| 1399 | basic documentation of IPv6 related options and their syntax |
|||
| 1400 | Enable IPv6 Payload in OpenVPN p2mp tun server mode. |
|||
| 1401 | remove NOTES file from commit - private scribbling |
|||
| 1402 | env_block(): if PATH is not set, add standard PATH setting to env |
|||
| 1403 | add IPv6 route add / route delete code for windows (using "netsh") |
|||
| 1404 | - Win32 IPv6 ifconfig support, using "netsh" calls |
|||
| 1405 | drop "book ipv6" from open_tun() and tuncfg() prototypes |
|||
| 1406 | document recent changes and open TODOs, adapt --version info, tag release |
|||
| 1407 | Win32: set next-hop for IPv6 routes according to TUN/TAP mode |
|||
| 1408 | when deleting a route on win32, also add gateway address |
|||
| 1409 | WIN32: if IPv6 requested in TUN mode, check if TUN/TAP driver < 9.7 |
|||
| 1410 | revert unconditionally-enabling of setenv_es() logging |
|||
| 1411 | implement IPv6 ifconfig + route setup/deletion on OpenBSD |
|||
| 1412 | full "VPN client connect" test framework for OpenVPN t_client.rc-sample |
|||
| 1413 | renamed t_client.sh to t_client.sh.in |
|||
| 1414 | 2.2-beta3 has a signed TAP driver with the IPv6 code - test for 9.8 |
|||
| 1415 | correct URL for "more information about IPv6 patch is *here*" |
|||
| 1416 | bugfix for linux/iproute2: IPv6 ifconfig code block was not called for "dev tun"+"topology subnet" |
|||
| 1417 | bump IPv6 version number (openvpn --version) to 20100922-1 |
|||
| 1418 | Implement "ipv6 ifconfig" for TAP interfaces on Solaris interfaces |
|||
| 1419 | rebased to 2.2RC2 (beta 2.2 branch) |
|||
| 1420 | Windows IPv6 cleanup - properly remove IPv6 routes and interface config |
|||
| 1421 | For all accesses to "struct route_list * rl", check first that rl is non-NULL |
|||
| 1422 | Replace 32-bit-based add_in6_addr() implementation by an 8-bit based one |
|||
| 1423 | Platform cleanup for NetBSD |
|||
| 1424 | Move block for "stale-routes-check" config inside #ifdef P2MP_SERVER block |
|||
| 1425 | add missing break between "case IPv4" and "case IPv6" |
|||
| 1426 | bump tap driver version from 9.8 to 9.9 |
|||
| 1427 | log error message and exit for "win32, tun mode, tap driver version 9.8" |
|||
| 1428 | work around inet_ntop/inet_pton problems for MSVC builds on WinXP |
|||
| 1429 | Fix build-up of duplicate IPv6 routes on reconnect. |
|||
| 1430 | Fix list-overrun checks in copy_route_[ipv6_]option_list() |
|||
| 1431 | add "print test titles" and "use sudo" functionality to t_client.rc |
|||
| 1432 | Platform cleanup for FreeBSD |
|||
| 1433 | Implement IPv6 interface config with non-/64 prefix lengths. |
|||
| 1434 | Fix RUN_SUDO functionality for t_client.sh |
|||
| 1435 | Document IPv6-related environment variables. |
|||
| 1436 | Platform cleanup for OpenBSD |
|||
| 1437 | ||||
| 1438 | Gisle Vanem (1): |
|||
| 1439 | Avoid re-defining uint32_t when using mingw compiler |
|||
| 1440 | ||||
| 1441 | Gustavo Zacarias (1): |
|||
| 1442 | Fix compile issues when using --enable-small and --disable-ssl/--disable-crypto |
|||
| 1443 | ||||
| 1444 | Heiko Hund (16): |
|||
| 1445 | add .gitignore to official repository |
|||
| 1446 | remove function is_proto_tcp() |
|||
| 1447 | remove legacy code to query IE proxy information |
|||
| 1448 | lowercase include header name in syshead.h |
|||
| 1449 | define IN6_ARE_ADDR_EQUAL macro for WIN32 |
|||
| 1450 | add --mark option to set SO_MARK sockopt |
|||
| 1451 | Windows UTF-8 input/output |
|||
| 1452 | UTF-8 X.509 distinguished names |
|||
| 1453 | set Windows environment variables as UCS-2 |
|||
| 1454 | handle Windows unicode paths |
|||
| 1455 | replace check for TARGET_WIN32 with WIN32 |
|||
| 1456 | do not use mode_t on Windows |
|||
| 1457 | use the underscore version of stat on Windows |
|||
| 1458 | make MSVC link against shell32 as well |
|||
| 1459 | move variable declaration to top of function |
|||
| 1460 | define access mode flag X_OK as 0 on Windows |
|||
| 1461 | ||||
| 1462 | Igor Novgorodov (1): |
|||
| 1463 | The code blocks enabled by ENABLE_CLIENT_CR depends on management |
|||
| 1464 | ||||
| 1465 | James Yonan (57): |
|||
| 1466 | Added "management-external-key" option. |
|||
| 1467 | Minor addition of logging info before and after execution of Windows net commands. |
|||
| 1468 | Misc fixes to r6708. |
|||
| 1469 | Added --x509-track option. |
|||
| 1470 | * added --management-up-down option to allow management interface to be notified of tunnel up/down events. |
|||
| 1471 | Fixed minor compile issue triggered on builds where MANAGEMENT_DEF_AUTH is not enabled. |
|||
| 1472 | Implemented get_default_gateway_mac_addr for Mac OS X |
|||
| 1473 | Fixes to r6925. |
|||
| 1474 | Properly handle certificate serial numbers > 32 bits. |
|||
| 1475 | Added "client-nat" option for stateless, one-to-one NAT on the client side. |
|||
| 1476 | Renamed branch to reflect that it is no longer beta. |
|||
| 1477 | env_filter_match now includes the serial number of all certs |
|||
| 1478 | Fixed issue where a client might receive multiple push replies from a server |
|||
| 1479 | Fixed bug introduced in r7031 that might cause this error message: |
|||
| 1480 | Extended "client-kill" management interface command (server-side) |
|||
| 1481 | Client will now try to reconnect if no push reply received within handshake-window seconds. |
|||
| 1482 | Version 2.1.3n |
|||
| 1483 | Fixed compiling issues when using --disable-crypto |
|||
| 1484 | Added "management-external-key" option. |
|||
| 1485 | Misc fixes to r6708. |
|||
| 1486 | win/sign.py now accepts an optional tap-dir argument. |
|||
| 1487 | Added "auth-token" client directive |
|||
| 1488 | Added ./configure --enable-osxipconfig option for Mac OS X |
|||
| 1489 | Added more packet ID debug info at debug level 3 for debugging false positive packet replays. |
|||
| 1490 | Fixed bug that incorrectly placed stricter TCP packet replay rules on UDP sessions |
|||
| 1491 | Fixed bug in port-share that could cause port share process to crash |
|||
| 1492 | For Mac OSX, when DARWIN_USE_IPCONFIG is defined, retry ipconfig command on failure |
|||
| 1493 | Version 2.1.3t |
|||
| 1494 | Revert r7092 and r7151, i.e. remove --enable-osxipconfig configure option. |
|||
| 1495 | Added 'dir' flag to "crl-verify" (see man page for info). |
|||
| 1496 | Added new "extra-certs" and "verify-hash" options |
|||
| 1497 | Fixed compile issues on Windows. |
|||
| 1498 | Added --enable-lzo-stub configure option to build an OpenVPN client without LZO |
|||
| 1499 | Added optional journal directory argument to "port-share" directive |
|||
| 1500 | Reduce log verbosity at level 3, with a focus on removing excessive log verbosity generated by port-share activity. |
|||
| 1501 | env_filter_match now includes the serial number of all certs in chain |
|||
| 1502 | Added support for static challenge/response protocol. |
|||
| 1503 | r7316 fixes. |
|||
| 1504 | Added redirect-gateway block-local flag, with support for Linux, Mac OS X |
|||
| 1505 | Extended x509-track to allow SHA1 certificate hash to be extracted |
|||
| 1506 | Added "management-query-remote" directive (client) to allow the management interface to override the "remote" directive. |
|||
| 1507 | Version 2.1.5. |
|||
| 1508 | Fixed MSVC compile error related to r7408. |
|||
| 1509 | Redact "echo" directive strings from log, since these strings (going forward) could conceivably contain security-sensitive data. |
|||
| 1510 | Modified sanitize_control_message to remove redacted data from control string rather than blotting it out with "_" chars. |
|||
| 1511 | Changed CC_PRINT character class to allow UTF-8 chars. |
|||
| 1512 | Increased the --verb threshold for "PID_ERR replay" messages to 4 from 3. |
|||
| 1513 | Fixed issue where redirect-gateway block-local code was not correctly calculating... |
|||
| 1514 | CC_PRINT character class now allows any 8-bit character value >= 32. |
|||
| 1515 | "status" management interface command (version >= 2) will now include the username for each connected user. |
|||
| 1516 | Minor fix to CC_PRINT char class |
|||
| 1517 | Fixed management interface bug where >FATAL notifications were not being output properly |
|||
| 1518 | Raised D_PID_DEBUG_LOW from level 3 to 4 to reduce replay error verbosity at level 3. |
|||
| 1519 | Added "memstats" option to maintain real-time operating stats in a memory-mapped file. |
|||
| 1520 | Fixed client issues with DHCP Router option extraction/deletion when using layer 2 with DHCP proxy: |
|||
| 1521 | Allow "tap-win32 dynamic <offset>" to be used in topology subnet mode. |
|||
| 1522 | Added support for "on-link" routes on Linux client |
|||
| 1523 | ||||
| 1524 | Jan Just Keijser (1): |
|||
| 1525 | Made some options connection-entry specific |
|||
| 1526 | ||||
| 1527 | Joe Patterson (1): |
|||
| 1528 | common_name passing in auth_pam plugin |
|||
| 1529 | ||||
| 1530 | JuanJo Ciarlante (40): |
|||
| 1531 | * rebased openvpn-2.1_rc1b.jjo.20061206.d.patch |
|||
| 1532 | * created getaddr6(), use it from resolve_remote() |
|||
| 1533 | * migrated all getaddrinfo() to getaddr6 |
|||
| 1534 | * socket.c: use USE_PF_INET6 in switch constructs to actually toss them out, |
|||
| 1535 | * support --disable-ipv6 build properly: |
|||
| 1536 | * important fix for tcp6 reconnection was incorrectly creating a PF_INET socket |
|||
| 1537 | * added README.ipv6.txt |
|||
| 1538 | * fixed win32 non-ipv6 build |
|||
| 1539 | * ipv6 on win32 "milestone": 1st snapshot that passes all unittests |
|||
| 1540 | * document ipv6 milestone status |
|||
| 1541 | * doc update w/unittests results |
|||
| 1542 | * make possible to x-compile openvpn/win32 in Linux |
|||
| 1543 | * correctly setup hints.ai_socktype for getaddrinfo(), althought sorta hacky, see TODO.ipv6. |
|||
| 1544 | * renamed README.ipv6{.txt,} |
|||
| 1545 | * updated {README,TODO}.ipv6 from feedback at openvpn-devel mlist |
|||
| 1546 | * init.c: document the ENABLE_MANAGEMENT place to work on |
|||
| 1547 | * init.c: small in-doc tweaks |
|||
| 1548 | * fix multi-tcp crash (corrected assertion) |
|||
| 1549 | * TODO.ipv6 update |
|||
| 1550 | * socket.c: better buf logic in print_sockaddr_ex |
|||
| 1551 | * fixed segfault for undef address family in print_sockaddr_ex (thanks Marcel!) |
|||
| 1552 | * doc updates |
|||
| 1553 | * openbsd: no IFF_MULTICAST, #ifdef around it |
|||
| 1554 | * no new funcionality, just small cleanups |
|||
| 1555 | * (prototype) fix for supporting "redirect-gateway" for tunneled ipv4 over ipv6 endpoints |
|||
| 1556 | * polished redirect-gateway (ipv4 on ipv6 endpoints) support |
|||
| 1557 | * updated doc |
|||
| 1558 | * fix --disable-ipv6 build |
|||
| 1559 | * doc updates |
|||
| 1560 | * rebased to v2.1.1 release |
|||
| 1561 | * undo mroute.c changes related to ipv6 payload |
|||
| 1562 | * fix --multihome for ipv4 |
|||
| 1563 | * fix --multihome for ipv6 |
|||
| 1564 | * ipv6-0.4.14: fix xinetd usage |
|||
| 1565 | * ipv6-0.4.15: add --multihome support to xBSD |
|||
| 1566 | * ipv6-0.4.15b: rebase over openvpn-testing-master |
|||
| 1567 | * ipv6-0.4.16: fix mingw32 build |
|||
| 1568 | * make ipv6_payload compile under windowze |
|||
| 1569 | USE_PF_INET6 by default for v2.3 |
|||
| 1570 | fix ipv6 compilation under macosx >= 1070 - v3 |
|||
| 1571 | ||||
| 1572 | Markus Koetter (1): |
|||
| 1573 | Add extv3 X509 field support to --x509-username-field |
|||
| 1574 | ||||
| 1575 | Matthew L. Creech (1): |
|||
| 1576 | Fix 2.2.0 build failure when management interface disabled |
|||
| 1577 | ||||
| 1578 | Matthias Andree (1): |
|||
| 1579 | Skip rather than fail test in addressless FreeBSD jails. |
|||
| 1580 | ||||
| 1581 | Robert Fischer (8): |
|||
| 1582 | Update man page with info about --capath |
|||
| 1583 | Update man page with info about --connect-timeout |
|||
| 1584 | Added info about --show-proxy-settings |
|||
| 1585 | Documented --x509-username-field option |
|||
| 1586 | Documented --errors-to-stderr option |
|||
| 1587 | Documented --push-peer-info option |
|||
| 1588 | Update man page with info about --remote-random-hostname |
|||
| 1589 | Added man page entry for --management-client |
|||
| 1590 | ||||
| 1591 | Samuli Seppänen (19): |
|||
| 1592 | Add man page entry for --redirect-private |
|||
| 1593 | Change all CRLF linefeeds to LF linefeeds |
|||
| 1594 | Fix a bug in devcon source code handling |
|||
| 1595 | Removed Win2k from supported platforms list in INSTALL and win/openvpn.nsi |
|||
| 1596 | Fixed copying of tapinstall.exe to dist/bin when using prebuilt TAP-drivers |
|||
| 1597 | Fixed a bug with GUI icon deletion on upgrade from 2.2-RC or earlier |
|||
| 1598 | Fix a build-ca issue on Windows |
|||
| 1599 | Add new openssl.cnf to easy-rsa/Windows |
|||
| 1600 | Updated "easy-rsa" for OpenSSL 1.0.0 |
|||
| 1601 | Made domake-win builds to use easy-rsa/2.0/openssl-1.0.0.cnf |
|||
| 1602 | Fixes to easy-rsa/2.0 |
|||
| 1603 | Merged TODO.IPv6 with TODO.ipv6 and README.IPv6 with README.ipv6 |
|||
| 1604 | Fixed a number of fatal build errors on Visual Studio 2008 |
|||
| 1605 | Fix a Visual Studio 2008 build issue in socket.c |
|||
| 1606 | Additional Visual Studio 2008 build fixes to tun.c |
|||
| 1607 | Fixed a typo in win32.h that prevented building with Visual Studio |
|||
| 1608 | Fixed a regression causing VS2008/Python build failure |
|||
| 1609 | Fix a Visual Studio 2008 build error in tun.c |
|||
| 1610 | Fix a Visual Studio 2008 build error in options.c |
|||
| 1611 | ||||
| 1612 | Simon Matter (1): |
|||
| 1613 | Fix issues with some older GCC compilers |
|||
| 1614 | ||||
| 1615 | Stefan Hellermann (2): |
|||
| 1616 | plugin.h: update prototype of plugin_call dummy in !ENABLE_PLUGIN case |
|||
| 1617 | Fixed typo in plugin.h |
|||
| 1618 | ||||
| 1619 | chantra (1): |
|||
| 1620 | Clarify --tmp-dir option |
|||
| 1621 | ||||
| 1622 | smos (1): |
|||
| 1623 | Change the netsh.exe command from "add" to "set". |
|||
| 1624 | ``` |
