Blame

9916b6 Samuli Seppänen 2025-02-11 09:58:20 1
# OpenVPN 2.4.11
2
3
```
4
Arne Schwabe (1):
5
Ensure key state is authenticated before sending push reply
6
7
Gert Doering (3):
8
clean up / rewrite sample-plugins/defer/simple.c
9
Fix potential NULL ptr crash if compiled with DMALLOC
10
Preparing release v2.4.11 (ChangeLog, version.m4, Changes.rst)
11
12
Greg Cox (5):
13
Fix naming error in sample-plugins/defer/simple.c
14
Documentation fixes around openvpn_plugin_func_v3 in openvpn-plugin.h.in
15
Update openvpn_plugin_func_v2 to _v3 in sample-plugins/defer/simple.c
16
More explicit versioning compatibility in sample-plugins/defer/simple.c
17
Explain structver usage in sample defer plugin.
18
```
19
20
# OpenVPN 2.4.10
21
22
```
23
Antonio Quartulli (1):
24
pool: prevent IPv6 pools to be larger than 2^16 addresses
25
26
Arne Schwabe (5):
27
Fix tls_ctx_client/server_new leaving error on OpenSSL error stack
28
Normalise ncp-ciphers option and restrict it to 127 bytes
29
Also announce IV_CIPHERS as client in OpenVPN 2.4
30
Fix auth-token not being updated if auth-nocache is set
31
Remove auth_user_pass.wait_for_push variable
32
33
David Sommerseth (1):
34
compat/lz4: Update to v1.9.2
35
36
Gert Doering (13):
37
Fix stack overflow in OpenSolaris NEXTADDR()
38
Document that --push-remove is generally more suitable than --push-reset
39
Fix error detection / abort in --inetd corner case.
40
Fix TUNSETGROUP compatibility with very old Linux systems.
41
Fix handling of 'route remote_host' for IPv6 transport case.
42
Fix description of --client-disconnect calling convention in manpage.
43
Handle NULL returns from calloc() in sample plugins.
44
Fix --show-gateway for IPv6 on NetBSD/i386.
45
socks.c: fix alen for DOMAIN type addresses, bump up buffer sizes
46
Fix redirecting of IPv4 default gateway if connecting over IPv6.
47
Change travis build scripts to use https when fetching prerequisites.
48
Fix line number reporting on config file errors after <inline> segments
49
Preparing release v2.4.10 (ChangeLog, version.m4, Changes.rst)
50
51
Jeremy Evans (1):
52
Switch assertion failure to returning false
53
54
Matthias Andree (1):
55
Fix stack buffer overruns in NEXTADDR() macro:
56
57
Selva Nair (3):
58
Parse static challenge response in auth-pam plugin
59
Accept empty password and/or response in auth-pam plugin
60
Persist management-query-remote and proxy prompts
61
62
Vladislav Grishenko (2):
63
Log serial number of revoked certificate
64
Fix fatal error at switching remotes (#629)
65
```
66
67
68
# OpenVPN 2.4.9
69
70
```
71
Antonio Quartulli (1):
72
socks: use the right function when printing struct openvpn_sockaddr
73
74
Arne Schwabe (3):
75
Fetch OpenSSL versions via source/old links
76
Fix OpenSSL error stack handling of tls_ctx_add_extra_certs
77
Fix OpenSSL 1.1.1 not using auto elliptic curve selection
78
79
Gert Doering (1):
80
Preparing release v2.4.9 (ChangeLog, version.m4, Changes.rst)
81
82
Lev Stipakov (4):
83
Fix broken fragmentation logic when using NCP
84
Fix building with --enable-async-push in FreeBSD
85
Fix broken async push with NCP is used
86
Fix illegal client float (CVE-2020-11810)
87
88
Maxim Plotnikov (1):
89
OpenSSL: Fix --crl-verify not loading multiple CRLs in one file
90
91
Santtu Lakkala (1):
92
Fix OpenSSL private key passphrase notices
93
94
Selva Nair (7):
95
Swap the order of checks for validating interactive service user
96
Move querying username/password from management interface to a function
97
When auth-user-pass file has no password query the management interface (if available).
98
Fix possibly uninitialized return value in GetOpenvpnSettings()
99
Fix possible access of uninitialized pipe handles
100
Skip expired certificates in Windows certificate store
101
Allow unicode search string in --cryptoapicert option
102
103
Tom van Leeuwen (1):
104
mbedTLS: Make sure TLS session survives move
105
106
WGH (1):
107
docs: Add reference to X509_LOOKUP_hash_dir(3)
108
```
109
110
# OpenVPN 2.4.8
111
112
```
113
Antonio Quartulli (1):
114
mbedtls: fix segfault by calling mbedtls_cipher_free() in cipher_ctx_free()
115
116
Arne Schwabe (1):
117
Remove -no-cpp-precomp flag from Darwin builds
118
119
David Sommerseth (3):
120
cleanup: Remove RPM openvpn.spec build approach
121
docs: Update INSTALL
122
build: Package missing mock_msg.h
123
124
Gert Doering (5):
125
repair windows builds (2.4)
126
Increase listen() backlog queue to 32
127
Force combinationation of --socks-proxy and --proto UDP to use IPv4.
128
Fix IPv6 routes on tap interfaces on OpenSolaris/OpenIndiana
129
preparing release v2.4.8 (ChangeLog, version.m4, Changes.rst)
130
131
Gisle Vanem (1):
132
Wrong FILETYPE in .rc files
133
134
Hilko Bengen (1):
135
Do not set pkcs11-helper 'safe fork mode'
136
137
Ilya Shipitsin (2):
138
travis-ci: add "linux-ppc64le" to build matrix, change trusty image to xenial, update osx to xcode9.4 and modernize brew management
139
travis-ci: fix osx builds
140
141
Kyle Evans (1):
142
tests/t_lpback.sh: Switch sed(1) to POSIX-compatible regex.
143
144
Lev Stipakov (1):
145
Fix various compiler warnings
146
147
Matthias Andree (1):
148
Fix regression, reinstate LibreSSL support.
149
150
Michal Soltys (1):
151
man: correct the description of --capath and --crl-verify regarding CRLs
152
153
Mykola Baibuz (1):
154
Fix typo in NTLM proxy debug message
155
156
Richard Bonhomme (1):
157
Ignore --pull-filter for --mode server
158
159
Rosen Penev (1):
160
openssl: Fix compilation without deprecated OpenSSL 1.1 APIs
161
162
Selva Nair (3):
163
Better error message when script fails due to script-security setting
164
Correct the return value of cryptoapi RSA signature callbacks
165
Handle PSS padding in cryptoapicert
166
167
Steffan Karger (1):
168
cmocka: use relative paths
169
170
Thomas Quinot (1):
171
Fix documentation of tls-verify script argument
172
```
173
174
# OpenVPN 2.4.7
175
176
```
177
Adam Ciarciński (1):
178
Fix subnet topology on NetBSD (2.4).
179
180
Antonio Quartulli (3):
181
add support for %lu in argv_printf and prevent ASSERT
182
buffer_list: add functions documentation
183
ifconfig-ipv6(-push): allow using hostnames
184
185
Arne Schwabe (7):
186
Properly free tuntap struct on android when emulating persist-tun
187
Add OpenSSL compat definition for RSA_meth_set_sign
188
Add support for tls-ciphersuites for TLS 1.3
189
Add better support for showing TLS 1.3 ciphersuites in --show-tls
190
Use right function to set TLS1.3 restrictions in show-tls
191
Add message explaining early TLS client hello failure
192
Fallback to password authentication when auth-token fails
193
194
Christian Ehrhardt (1):
195
systemd: extend CapabilityBoundingSet for auth_pam
196
197
David Sommerseth (1):
198
plugin: Export base64 encode and decode functions
199
200
Gert Doering (4):
201
Add %d, %u and %lu tests to test_argv unit tests.
202
Fix combination of --dev tap and --topology subnet across multiple platforms.
203
Add 'printing of port number' to mroute_addr_print_ex() for v4-mapped v6.
204
preparing release v2.4.7 (ChangeLog, version.m4, Changes.rst)
205
206
Gert van Dijk (1):
207
Minor reliability layer documentation fixes
208
209
James Bekkema (1):
210
Resolves small IV_GUI_VER typo in the documentation.
211
212
Jonathan K. Bullard (1):
213
Clarify and expand management interface documentation
214
215
Lev Stipakov (5):
216
Refactor NCP-negotiable options handling
217
init.c: refine functions names and description
218
interactive.c: fix usage of potentially uninitialized variable
219
options.c: fix broken unary minus usage
220
Remove extra token after #endif
221
222
Richard van den Berg via Openvpn-devel (1):
223
Fix error message when using RHEL init script
224
225
Samy Mahmoudi (1):
226
man: correct a --redirection-gateway option flag
227
228
Selva Nair (7):
229
Replace M_DEBUG with D_LOW as the former is too verbose
230
Correct the declaration of handle in 'struct openvpn_plugin_args_open_return'
231
Bump version of openvpn plugin argument structs to 5
232
Move get system directory to a separate function
233
Enable dhcp on tap adapter using interactive service
234
Pass the hash without the DigestInfo header to NCryptSignHash()
235
White-list pull-filter and script-security in interactive service
236
237
Simon Rozman (2):
238
Add Interactive Service developer documentation
239
Detect TAP interfaces with root-enumerated hardware ID
240
241
Steffan Karger (7):
242
man: add security considerations to --compress section
243
mbedtls: print warning if random personalisation fails
244
Fix memory leak after sighup
245
travis: add OpenSSL 1.1 Windows build
246
Fix --disable-crypto build
247
Don't print OCC warnings about 'key-method', 'keydir' and 'tls-auth'
248
buffer_list_aggregate_separator(): simplify code
249
```
250
251
# OpenVPN 2.4.6
252
253
```
254
David Sommerseth (1):
255
management: Warn if TCP port is used without password
256
257
Gert Doering (3):
258
Correct version in ChangeLog - should be 2.4.5, was mistyped as 2.4.4
259
Fix potential double-free() in Interactive Service (CVE-2018-9336)
260
preparing release v2.4.6 (ChangeLog, version.m4, Changes.rst)
261
262
Gert van Dijk (1):
263
manpage: improve description of --status and --status-version
264
265
Joost Rijneveld (1):
266
Make return code external tls key match docs
267
268
Selva Nair (3):
269
Delete the IPv6 route to the "connected" network on tun close
270
Management: warn about password only when the option is in use
271
Avoid overflow in wakeup time computation
272
273
Simon Matter (1):
274
Add missing #ifdef SSL_OP_NO_TLSv1_1/2
275
276
Steffan Karger (1):
277
Check for more data in control channel
278
```
279
280
# OpenVPN 2.4.5
281
282
```
283
Antonio Quartulli (4):
284
reload HTTP proxy credentials when moving to the next connection profile
285
Allow learning iroutes with network made up of all 0s (only if netbits < 8)
286
mbedtls: fix typ0 in comment
287
manpage: fix simple typ0
288
289
Arne Schwabe (2):
290
Treat dhcp-option DNS6 and DNS identical
291
show the right string for key-direction
292
293
Bertrand Bonnefoy-Claudet (1):
294
Fix typo in error message: "optione" -> "option"
295
296
David Sommerseth (8):
297
lz4: Fix confused version check
298
lz4: Fix broken builds when pkg-config is not present but system library is
299
Remove references to keychain-mcd in Changes.rst
300
lz4: Rebase compat-lz4 against upstream v1.7.5
301
systemd: Add and ship README.systemd
302
Update copyright to include 2018 plus company name change
303
man: Add .TQ groff support macro
304
man: Reword --management to prefer unix sockets over TCP
305
306
Emmanuel Deloget (1):
307
OpenSSL: check EVP_PKEY key types before returning the pkey
308
309
Gert Doering (3):
310
Remove warning on pushed tun-ipv6 option.
311
Fix removal of on-link prefix on windows with netsh
312
Preparing for release v2.4.5 (ChangeLog, version.m4, Changes.rst)
313
314
Ilya Shipitsin (2):
315
travis-ci: add brew cache, remove ccache
316
travis-ci: modify openssl build script to support openssl-1.1.0
317
318
James Bottomley (1):
319
autoconf: Fix engine checks for openssl 1.1
320
321
Jeremie Courreges-Anglas (2):
322
Cast time_t to long long in order to print it.
323
Fix build with LibreSSL
324
325
Selva Nair (14):
326
Check whether in pull_mode before warning about previous connection blocks
327
Avoid illegal memory access when malformed data is read from the pipe
328
Fix missing check for return value of malloc'd buffer
329
Return NULL if GetAdaptersInfo fails
330
Use RSA_meth_free instead of free
331
Bring cryptoapi.c upto speed with openssl 1.1
332
Add SSL_CTX_get_max_proto_version() not in openssl 1.0
333
TLS v1.2 support for cryptoapicert -- RSA only
334
Refactor get_interface_metric to return metric and auto flag separately
335
Ensure strings read from registry are null-terminated
336
Make most registry values optional
337
Use lowest metric interface when multiple interfaces match a route
338
Adapt to RegGetValue brokenness in Windows 7
339
Fix format spec errors in Windows builds
340
341
Simon Rozman (11):
342
Local functions are not supported in MSVC. Bummer.
343
Mixing wide and regular strings in concatenations is not allowed in MSVC.
344
RtlIpv6AddressToStringW() and RtlIpv4AddressToStringW() require mstcpip.h
345
Simplify iphlpapi.dll API calls
346
Fix local #include to use quoted form
347
Document ">PASSWORD:Auth-Token" real-time message
348
Fix typo in "verb" command examples
349
Uniform swprintf() across MinGW and MSVC compilers
350
MSVC meta files added to .gitignore list
351
openvpnserv: Add support for multi-instances
352
Document missing OpenVPN states
353
354
Steffan Karger (21):
355
make struct key * argument of init_key_ctx const
356
buffer_list_aggregate_separator(): add unit tests
357
Add --tls-cert-profile option.
358
Use P_DATA_V2 for server->client packets too
359
Fix memory leak in buffer unit tests
360
buffer_list_aggregate_separator(): update list size after aggregating
361
buffer_list_aggregate_separator(): don't exceed max_len
362
buffer_list_aggregate_separator(): prevent 0-byte malloc
363
Fix types around buffer_list_push(_data)
364
ssl_openssl: fix compiler warning by removing getbio() wrapper
365
travis: use clang's -fsanitize=address to catch more bugs
366
Fix --tls-version-min and --tls-version-max for OpenSSL 1.1+
367
Add support for TLS 1.3 in --tls-version-{min, max}
368
Plug memory leak if push is interrupted
369
Fix format errors when cross-compiling for Windows
370
Log pre-handshake packet drops using D_MULTI_DROPPED
371
Enable stricter compiler warnings by default
372
Get rid of ax_check_compile_flag.m4
373
mbedtls: don't use API deprecated in mbed 2.7
374
Warn if tls-version-max < tls-version-min
375
Don't throw fatal errors from create_temp_file()
376
377
hashiz (1):
378
Fix '--bind ipv6only'
379
```
380
381
# OpenVPN 2.4.4
382
383
```
384
Antonio Quartulli (23):
385
crypto: correct typ0 in error message
386
use M_ERRNO instead of explicitly printing errno
387
don't print errno twice
388
ntlm: avoid useless cast
389
ntlm: unwrap multiple function calls
390
route: improve error message
391
management: preserve wait_for_push field when asking for user/pass
392
tls-crypt: avoid warnings when --disable-crypto is used
393
ntlm: convert binary buffers to uint8_t *
394
ntlm: restyle compressed multiple function calls
395
ntlm: improve code style and readability
396
OpenSSL: remove unreachable call to SSL_CTX_get0_privatekey()
397
make function declarations C99 compliant
398
remove unused functions
399
use NULL instead of 0 when assigning pointers
400
add missing static attribute to functions
401
ntlm: avoid breaking anti-aliasing rules
402
remove the --disable-multi config switch
403
rename mroute_extract_addr_ipv4 to mroute_extract_addr_ip
404
route: avoid definition of unused variables in certain configurations
405
fix a couple of typ0s in comments and strings
406
fragment.c: simplify boolean expression
407
tcp-server: ensure AF family is propagated to child context
408
409
Arne Schwabe (2):
410
Set tls-cipher restriction before loading certificates
411
Print ec bit details, refuse management-external-key if key is not RSA
412
413
Conrad Hoffmann (2):
414
Use provided env vars in up/down script.
415
Document down-root plugin usage in client.down
416
417
David Sommerseth (12):
418
doc: The CRL processing is not a deprecated feature
419
cleanup: Move write_pid() to where it is being used
420
contrib: Remove keychain-mcd code
421
cleanup: Move init_random_seed() to where it is being used
422
sample-plugins: fix ASN1_STRING_to_UTF8 return value checks
423
Highlight deprecated features
424
Use consistent version references
425
docs: Replace all PolarSSL references to mbed TLS
426
systemd: Ensure systemd shuts down OpenVPN in a proper way
427
systemd: Enable systemd's auto-restart feature for server profiles
428
lz4: Move towards a newer LZ4 API
429
Prepare the release of OpenVPN 2.4.4
430
431
Emmanuel Deloget (3):
432
OpenSSL: remove pre-1.1 function from the OpenSSL compat interface
433
OpenSSL: remove EVP_CIPHER_CTX_new() from the compat layer
434
OpenSSL: remove EVP_CIPHER_CTX_free() from the compat layer
435
436
Gert van Dijk (1):
437
Warn that DH config option is only meaningful in a tls-server context
438
439
Ilya Shipitsin (3):
440
travis-ci: add 3 missing patches from master to release/2.4
441
travis-ci: update openssl to 1.0.2l, update mbedtls to 2.5.1
442
travis-ci: update pkcs11-helper to 1.22
443
444
Richard Bonhomme (1):
445
man: Corrections to doc/openvpn.8
446
447
Steffan Karger (17):
448
Fix typo in extract_x509_extension() debug message
449
Move adjust_power_of_2() to integer.h
450
Undo cipher push in client options state if cipher is rejected
451
Remove strerror_ts()
452
Move openvpn_sleep() to manage.c
453
fixup: also change missed openvpn_sleep() occurrences
454
Always use default keysize for NCP'd ciphers
455
Move create_temp_file() out of #ifdef ENABLE_CRYPTO
456
Deprecate --keysize
457
Deprecate --no-replay
458
Move run_up_down() to init.c
459
tls-crypt: introduce tls_crypt_kt()
460
crypto: create function to initialize encrypt and decrypt key
461
Add coverity static analysis to Travis CI config
462
tls-crypt: don't leak memory for incorrect tls-crypt messages
463
travis: reorder matrix to speed up build
464
Fix bounds check in read_key()
465
466
Szilárd Pfeiffer (1):
467
OpenSSL: Always set SSL_OP_CIPHER_SERVER_PREFERENCE flag
468
469
Thomas Veerman via Openvpn-devel (1):
470
Fix socks_proxy_port pointing to invalid data
471
```
472
473
# OpenVPN 2.4.3
474
475
```
476
Antonio Quartulli (1):
477
Ignore auth-nocache for auth-user-pass if auth-token is pushed
478
479
David Sommerseth (3):
480
crypto: Enable SHA256 fingerprint checking in --verify-hash
481
copyright: Update GPLv2 license texts
482
auth-token with auth-nocache fix broke --disable-crypto builds
483
484
Emmanuel Deloget (8):
485
OpenSSL: don't use direct access to the internal of X509
486
OpenSSL: don't use direct access to the internal of EVP_PKEY
487
OpenSSL: don't use direct access to the internal of RSA
488
OpenSSL: don't use direct access to the internal of DSA
489
OpenSSL: force meth->name as non-const when we free() it
490
OpenSSL: don't use direct access to the internal of EVP_MD_CTX
491
OpenSSL: don't use direct access to the internal of EVP_CIPHER_CTX
492
OpenSSL: don't use direct access to the internal of HMAC_CTX
493
494
Gert Doering (6):
495
Fix NCP behaviour on TLS reconnect.
496
Remove erroneous limitation on max number of args for --plugin
497
Fix edge case with clients failing to set up cipher on empty PUSH_REPLY.
498
Fix potential 1-byte overread in TCP option parsing.
499
Fix remotely-triggerable ASSERT() on malformed IPv6 packet.
500
Preparing for release v2.4.3 (ChangeLog, version.m4, Changes.rst)
501
502
Guido Vranken (6):
503
refactor my_strupr
504
Fix 2 memory leaks in proxy authentication routine
505
Fix memory leak in add_option() for option 'connection'
506
Ensure option array p[] is always NULL-terminated
507
Fix a null-pointer dereference in establish_http_proxy_passthru()
508
Prevent two kinds of stack buffer OOB reads and a crash for invalid input data
509
510
Jérémie Courrèges-Anglas (2):
511
Fix an unaligned access on OpenBSD/sparc64
512
Missing include for socket-flags TCP_NODELAY on OpenBSD
513
514
Matthias Andree (1):
515
Make openvpn-plugin.h self-contained again.
516
517
Selva Nair (1):
518
Pass correct buffer size to GetModuleFileNameW()
519
520
Steffan Karger (11):
521
Log the negotiated (NCP) cipher
522
Avoid a 1 byte overcopy in x509_get_subject (ssl_verify_openssl.c)
523
Skip tls-crypt unit tests if required crypto mode not supported
524
openssl: fix overflow check for long --tls-cipher option
525
Add a DSA test key/cert pair to sample-keys
526
Fix mbedtls fingerprint calculation
527
mbedtls: fix --x509-track post-authentication remote DoS (CVE-2017-7522)
528
mbedtls: require C-string compatible types for --x509-username-field
529
Fix remote-triggerable memory leaks (CVE-2017-7521)
530
Restrict --x509-alt-username extension types
531
Fix potential double-free in --x509-alt-username (CVE-2017-7521)
532
533
Steven McDonald (1):
534
Fix gateway detection with OpenBSD routing domains
535
```
536
537
# OpenVPN 2.4.2
538
539
```
540
David Sommerseth (6):
541
auth-token: Ensure tokens are always wiped on de-auth
542
docs: Fixed man-page warnings discoverd by rpmlint
543
Make --cipher/--auth none more explicit on the risks
544
plugin: Fix documentation typo for type_mask
545
plugin: Export secure_memzero() to plug-ins
546
Preparing v2.4.2 release
547
548
Hristo Venev (1):
549
Fix extract_x509_field_ssl for external objects, v2
550
551
Selva Nair (1):
552
In auth-pam plugin clear the password after use
553
554
Steffan Karger (10):
555
cleanup: merge packet_id_alloc_outgoing() into packet_id_write()
556
Don't run packet_id unit tests for --disable-crypto builds
557
Fix Changes.rst layout
558
Fix memory leak in x509_verify_cert_ku()
559
mbedtls: correctly check return value in pkcs11_certificate_dn()
560
Restore pre-NCP frame parameters for new sessions
561
Always clear username/password from memory on error
562
Document tls-crypt security considerations in man page
563
Don't assert out on receiving too-large control packets (CVE-2017-7478)
564
Drop packets instead of assert out if packet id rolls over (CVE-2017-7479)
565
566
ValdikSS (1):
567
Set a low interface metric for tap adapter when block-outside-dns is in use
568
```
569
570
# OpenVPN 2.4.1
571
572
Changes in OpenVPN:
573
574
```
575
Antonio Quartulli (4):
576
attempt to add IPv6 route even when no IPv6 address was configured
577
fix redirect-gateway behaviour when an IPv4 default route does not exist
578
CRL: use time_t instead of struct timespec to store last mtime
579
ignore remote-random-hostname if a numeric host is provided
580
581
Christian Hesse (7):
582
man: fix formatting for alternative option
583
systemd: Use automake tools to install unit files
584
systemd: Do not race on RuntimeDirectory
585
systemd: Add more security feature for systemd units
586
Clean up plugin path handling
587
plugin: Remove GNUism in openvpn-plugin.h generation
588
fix typo in notification message
589
590
David Sommerseth (6):
591
management: >REMOTE operation would overwrite ce change indicator
592
management: Remove a redundant #ifdef block
593
git: Merge .gitignore files into a single file
594
systemd: Move the READY=1 signalling to an earlier point
595
plugin: Improve the handling of default plug-in directory
596
cleanup: Remove faulty env processing functions
597
598
Emmanuel Deloget (8):
599
OpenSSL: check for the SSL reason, not the full error
600
OpenSSL: don't use direct access to the internal of X509_STORE_CTX
601
OpenSSL: don't use direct access to the internal of SSL_CTX
602
OpenSSL: don't use direct access to the internal of X509_STORE
603
OpenSSL: don't use direct access to the internal of X509_OBJECT
604
OpenSSL: don't use direct access to the internal of RSA_METHOD
605
OpenSSL: SSLeay symbols are no longer available in OpenSSL 1.1
606
OpenSSL: use EVP_CipherInit_ex() instead of EVP_CipherInit()
607
608
Eric Thorpe (1):
609
Fix Building Using MSVC
610
611
Gert Doering (5):
612
Add openssl_compat.h to openvpn_SOURCES
613
Fix '--dev null'
614
Fix installation of IPv6 host route to VPN server when using iservice.
615
Make ENABLE_OCC no longer depend on !ENABLE_SMALL
616
Preparing for release v2.4.1 (ChangeLog, version.m4)
617
618
Gisle Vanem (1):
619
Crash in options.c
620
621
Ilya Shipitsin (2):
622
Resolve several travis-ci issues
623
travis-ci: remove unused files
624
625
Olivier Wahrenberger (1):
626
Fix building with LibreSSL 2.5.1 by cleaning a hack.
627
628
Selva Nair (4):
629
Fix push options digest update
630
Always release dhcp address in close_tun() on Windows.
631
Add a check for -Wl, --wrap support in linker
632
Fix user's group membership check in interactive service to work with domains
633
634
Simon Matter (1):
635
Fix segfault when using crypto lib without AES-256-CTR or SHA256
636
637
Steffan Karger (8):
638
More broadly enforce Allman style and braces-around-conditionals
639
Use SHA256 for the internal digest, instead of MD5
640
OpenSSL: 1.1 fallout - fix configure on old autoconf
641
Fix types in WIN32 socket_listen_accept()
642
Remove duplicate X509 env variables
643
Fix non-C99-compliant builds: don't use const size_t as array length
644
Deprecate --ns-cert-type
645
Be less picky about keyUsage extensions
646
```
647
648
Changes in OpenVPN GUI v11.5.0.0 bundled with I601 Windows installers:
649
650
```
651
Ashus (2):
652
Czech translation added
653
Translation corrected by another developer, Elieux.
654
655
Chocobo1 (7):
656
Enable DEP
657
Add title and TravisCI badge to README.rst
658
Enable ASLR. Closes #119.
659
Use high entropy ASLR
660
Address review comments
661
AppVeyor: add shebang
662
Readme: add AppVeyor badge
663
664
Erwin Bronkhorst (1):
665
Translate missing Dutch strings and minor changes
666
667
Hexabitt (2):
668
Completed all the missing translations
669
Update openvpn-gui-res-fr.rc
670
671
Ilya Shipitsin (5):
672
added Windows Vista/Win7/Win8/Win8.1/Win10 to compatibility manifest
673
travis-ci: update openssl, add "builds from release tarballs"
674
AppVeyor support
675
AppVeyor: temporarily stick to mingw64-%ARCH%-gcc-core-5.4.0-3
676
AppVeyor: switch to preinstalled mingw64-%ARCH%-gcc-core
677
678
Peter Chen (2):
679
Update and fix localization in openvpn-gui-res-zh-hant.rc
680
UI clipping fix, and misc wording fix/redundant punc removed
681
682
Samuli Seppänen (13):
683
Documentation improvements
684
Merge pull request #124 from Chocobo1/badge
685
Merge pull request #108 from selvanair/win32-vista
686
Fix builds from release tarballs
687
Merge pull request #132 from mattock/master
688
Merge pull request #133 from chipitsine/master
689
Merge pull request #135 from chipitsine/master
690
Merge pull request #140 from chipitsine/master
691
Merge pull request #146 from Chocobo1/pr_109
692
Merge pull request #145 from Chocobo1/appveyor
693
Merge pull request #143 from chipitsine/master
694
Merge pull request #136 from Hexabitt/patch-1
695
Bump version to 11.5.0.0
696
697
Selva Nair (18):
698
Mark status as connected only if openvpn reports CONNECTED,SUCCESS
699
Suppress warning popups if silent_connection is set
700
Merge pull request #112 from selvanair/master
701
Close service pipe in case of startup error
702
Merge pull request #121 from mattock/docfixes
703
Merge pull request #123 from Chocobo1/ldflags
704
Fix truncation of usage message shown when --help is used
705
Merge pull request #116 from chipitsine/manifest
706
Merge pull request #126 from Ashus/master
707
Update _WIN32_WINNT to _WIN32_WINNT_VISTA
708
Merge pull request #110 from EagleErwin/patch-1
709
Check group membership without needing connection to DC
710
Parse ECHO directives from openvpn
711
Merge pull request #128 from selvanair/help-msg
712
Merge pull request #118 from selvanair/validate-user
713
Add a system-wide option to disable the password save feature
714
Merge pull request #117 from selvanair/nay-to-savepass
715
Merge pull request #137 from selvanair/echo
716
```
717
718
# OpenVPN 2.4.0
719
720
Changes in OpenVPN:
721
722
```
723
David Sommerseth (4):
724
dev-tools: Added script for updating copyright years in files
725
Update copyrights
726
docs: Further enhance the documentation related to SWEET32
727
man: Remove references to no longer present IV_RGI6 peer-info
728
729
Gert Doering (1):
730
Remove IV_RGI6=1 peer-info signalling.
731
732
Steffan Karger (2):
733
Document that RSA_SIGN can also request TLS 1.2 signatures
734
man: encourage user to read on about --tls-crypt
735
```
736
737
Changes in Windows installer (openvpn-build):
738
739
```
740
Samuli Seppänen (3):
741
Update build parameters to match openvpn-install-2.4_rc2
742
Merge pull request #63 from selvanair/less-choice-v2
743
Update build parameters to match openvpn-install-2.4.0
744
745
Selva Nair (2):
746
Simplifiy user choices and always install openvpn, dlls and services
747
Add missing /o to Section SecService
748
```
749
750
# OpenVPN 2.4_rc2
751
752
Changes in OpenVPN:
753
754
```
755
David Sommerseth (10):
756
Fix wrong configure.ac parsing of --enable-async-push
757
Changes: Further improve systemd unit file updates
758
systemd: Intermediate --chroot fix with the new sd_notify() implementation
759
Further enhance async-push feature description
760
Changes.rst: Mainatiner update on C99
761
dev-tools: Add reformat-all.sh for code style unification
762
The Great Reformatting - first phase
763
Merge 'reformatting' branch into master
764
auth-gen-token: Hardening memory cleanup on auth-token failuers
765
Preparing OpenVPN v2.4_rc2 release
766
767
Gert Doering (1):
768
Refactor setting close-on-exec for socket FDs
769
770
Lev Stipakov (2):
771
Arm inotify only in server mode
772
Add "async push" feature to Changes.rst
773
774
Magnus Kroken (1):
775
mbedtls: include correct net/net_sockets header according to version
776
777
Selva Nair (2):
778
Correctly state the default dhcp server address in man page
779
Unhide a line in man page by fixing a typo
780
781
Steffan Karger (4):
782
Fix (and cleanup) crypto flags in combination with NCP
783
Deprecate --no-iv
784
man: mention that --ecdh-curve does not work on mbed TLS builds
785
Don't reopen tun if cipher changes
786
```
787
788
Changes in OpenVPN GUI:
789
790
```
791
Samuli Seppänen (3):
792
Merge pull request #102 from mattock/master
793
Merge pull request #107 from selvanair/use-metric
794
Preparing for release with openvpn-2.4_rc2
795
796
Selva Nair (2):
797
Merge pull request #103 from aixxe/master
798
Load icons at sizes given by DPI-dependent system metric
799
800
aixxe (1):
801
Add 24x24 and 20x20 versions of each icon.
802
```
803
804
# OpenVPN 2.4_rc1
805
806
Changes in OpenVPN:
807
808
```
809
Antonio Quartulli (1):
810
reload CRL only if file was modified
811
812
Christian Hesse (3):
813
update year in copyright message
814
Use systemd service manager notification
815
Refuse to daemonize when running from systemd
816
817
David Sommerseth (1):
818
Preparing OpenVPN v2.4_rc1 release
819
820
Gert Doering (1):
821
Fix windows path in Changes.rst
822
823
Samuli Seppänen (1):
824
Mention that OpenVPN 2.4 requires Windows Vista or higher
825
826
Selva Nair (4):
827
Map restart signals from event loop to SIGTERM during exit-notification wait
828
When parsing '--setenv opt xx ..' make sure a third parameter is present
829
Force 'def1' method when --redirect-gateway is done through service
830
Do not restart dns client service as a part of --register-dns processing
831
832
Steffan Karger (4):
833
tls_process: don't set variable that's never read
834
Unconditionally enable TLS_AGGREGATE_ACK
835
Clean up format_hex_ex()
836
Introduce and use secure_memzero() to erase secrets
837
```
838
839
Changes in OpenVPN GUI:
840
841
```
842
Ilya Shipitsin (1):
843
travis-ci: upgraded to openssl-1.0.2i
844
845
Pavel Zhovner (1):
846
fix Ukrainian localization
847
848
Samuli Seppänen (8):
849
Merge pull request #96 from chipitsine/master
850
Merge pull request #98 from selvanair/version-info
851
Merge pull request #93 from ValdikSS/russian-fixes
852
Preparing for release with openvpn-2.4_beta2
853
Merge pull request #94 from zhovner/master
854
Merge pull request #99 from selvanair/dpi-aware
855
Merge pull request #91 from selvanair/pkcs11-pin-v3
856
Preparing for release with openvpn-2.4_rc1
857
858
Selva Nair (8):
859
Handle dynamic challenge/response
860
Support pkcs11 token insertion request and pin input
861
Update version-info resource
862
Make the program DPI aware
863
Merge pull request #85 from stigok/patch-1
864
Copy updated copyright to language files
865
Rendering/Positioning fix
866
Merge pull request #100 from selvanair/about-update
867
868
Stig Otnes Kolstad (1):
869
Update Norwegian translations
870
871
ValdikSS (2):
872
Russian translation updates
873
More Russian fixes
874
```
875
876
# OpenVPN 2.4_beta2
877
878
Changes in OpenVPN:
879
880
```
881
Arne Schwabe (5):
882
Document that tls-crypt also supports inline
883
Fix warning that RAND_bytes is undeclared
884
Remove compat-stdbool.h.
885
Fix various compiler warnings
886
Handle DNS6 option on Android
887
888
David Sommerseth (3):
889
Changes.rst: Fixing wrong formatting
890
Document the --auth-token option
891
Preparing OpenVPN v2.4_beta2 release
892
893
Gert Doering (2):
894
Remove remaining traces of compat-stdbool.h
895
Stub implementation of "--dhcp-option DNS6 <v6addr>"
896
897
Selva Nair (3):
898
Do not set ipv6 address if '--ip-win32 manual' is used
899
Handle --dhcp-option DNS6 on Windows using netsh
900
Set IPv6 DNS servers using interactive service
901
902
Steffan Karger (6):
903
multi_process_float: revert part of c14c4a9e
904
--tls-crypt fixes
905
Change cmocka remote to use https in stead of git protocol
906
generate_key_expansion: make assumption explicit, use C99 features
907
Poor man's NCP for non-NCP peers
908
Refactor data channel key generation API
909
```
910
911
Changes in OpenVPN GUI:
912
913
```
914
Ilya Shipitsin (1):
915
travis-ci: upgraded to openssl-1.0.2i
916
917
Samuli Seppänen (4):
918
Merge pull request #96 from chipitsine/master
919
Merge pull request #98 from selvanair/version-info
920
Merge pull request #93 from ValdikSS/russian-fixes
921
Preparing for release with openvpn-2.4_beta2
922
923
Selva Nair (1):
924
Update version-info resource
925
926
ValdikSS (2):
927
Russian translation updates
928
More Russian fixes
929
```
930
931
# OpenVPN 2.4_beta1
932
933
Changes in OpenVPN:
934
935
```
936
Arne Schwabe (1):
937
Make Changes.rst nicer for 2.4 release
938
939
David Sommerseth (16):
940
cleanup: Remove NOP code sections in ssl.c:tls_process()
941
Remove last rest of INSTALL-win32.txt references
942
auth-gen-token: Add --auth-gen-token option
943
auth-gen-token: Generate an auth-token per client
944
auth-gen-token: Push generated auth-tokens to the client
945
auth-gen-token: Authenticate generated auth-tokens when client re-authenticates
946
Fix builds with --disable-crypto
947
man: Improve the --keepalive section
948
console: Fix compiler warning
949
systemd: Improve the systemd unit files
950
tun: Fix compiler warnings
951
file checks: Merge warn_if_group_others_accessible() into check_file_access()
952
tun: Fix weird commit error causing a double assignment
953
options: Remove --tls-remote
954
Remove unused variable in argv_printf_arglist()
955
Preparing for release v2.4_beta1 (ChangeLog, version.m4)
956
957
Gert Doering (10):
958
openvpn version line: remove [IPv6], add [AEAD] if available
959
clean up *sig_info handling in link_socket_init_phase2()
960
check c->c2.link_socket before calling do_init_route_ipv6_list()
961
Check previously-unchecked buf_alloc_write() call in crypto self-test.
962
Fix potential division by zero in shaper_reset()
963
Repair topology subnet on FreeBSD 11
964
Repair topology subnet on OpenBSD
965
Add in_port_t check to configure.ac
966
Fix compilation on MinGW with -std=c99
967
Replace WIN32 by _WIN32
968
969
Heiko Hund (4):
970
put argv_* functions into own file, add unit tests
971
Remove unused and unecessary argv interfaces
972
remove unused system_str from struct argv
973
Factor out %sc handling from argv_printf()
974
975
Lev Stipakov (1):
976
Drop recursively routed packets
977
978
Samuli Seppänen (6):
979
Remove INSTALL-win32.txt that is now hosted in openvpn-build
980
Fix update_t_client_ips.sh for out of tree builds
981
Make sure that all relevant files under test go to release tarballs
982
Allow passing extra arguments to fping/fping6 in t_client.rc
983
Prevent generation of duplicate EXPECT_IFCONFIG entries
984
Fix a logic problem in handling of --up scripts in t_client.sh
985
986
Selva Nair (2):
987
Support --block-outside-dns on multiple tunnels
988
Unbreak windows build
989
990
Steffan Karger (18):
991
Remove verbose msg() from send_push_reply()
992
Limit --reneg-bytes to 64MB when using small block ciphers
993
Add a revoked cert to the sample keys
994
Fix --tls-version-max in mbed TLS builds
995
Don't deference type-punned pointers
996
Fix builds on compilers without anonymous union support
997
Refactor static/tls-auth key loading
998
Add missing includes in error.h
999
Make argv unit tests obey {MBEDTLS, OPENSSL}_{LIBS, CFLAGS}
1000
Move private file access checks to options_postprocess_filechecks()
1001
Deprecate key-method 1
1002
Refactor CRL handling
1003
Remove unneeded check for extra_certs_file_inline
1004
Fix missing return value checks in multi_process_float()
1005
Restore pre-NCP cipher options on SIGUSR1
1006
Remove unused variables from do_init_crypto_static()
1007
Add control channel encryption (--tls-crypt)
1008
Add --tls-crypt unit tests
1009
```
1010
1011
Changes in OpenVPN GUI:
1012
1013
```
1014
Samuli Seppänen (3):
1015
Update About page
1016
Merge pull request #90 from selvanair/mute-no-iservice-warning
1017
Merge pull request #97 from selvanair/master
1018
1019
Selva Nair (5):
1020
Merge pull request #89 from mattock/about_page
1021
Check for interactive service only if OpenVPN version is >= 2.4
1022
Add missing WINAPI in the definition of HandleServiceIO
1023
Merge pull request #95 from selvanair/trac-758
1024
Preparing for release with openvpn-2.4_beta1
1025
```
1026
1027
# OpenVPN 2.4_alpha2
1028
1029
Changes since 2.3_beta1:
1030
1031
```
1032
Adriaan de Jong (2):
1033
Fixed a bug where PolarSSL gave an error when using an inline file tag.
1034
Fix --show-pkcs11-ids (Bug #239)
1035
1036
Alexander Pyhalov (1):
1037
Default gateway can't be determined on illumos/Solaris platforms
1038
1039
Alon Bar-Lev (1):
1040
pkcs11: use generic evp key instead of rsa
1041
1042
Andris Kalnozols (3):
1043
Fix some typos in the man page.
1044
Do not upcase x509-username-field for mixed-case arguments.
1045
extract_x509_extension(): hide status message during normal operation.
1046
1047
Arne Schwabe (100):
1048
Document man agent-external-key
1049
Options parsing demands unnecessary configuration if PKCS11 is used
1050
Error message if max-routes used incorrectly
1051
Properly require --key even if defined(MANAGMENT_EXTERNAL_KEY)
1052
Remove dnsflags_to_socktype, it is not used anywhere
1053
Fix the proto is used inconsistently warning
1054
Remove dead code path and putenv functionality
1055
Remove unused function xor
1056
Move static prototype definition from header into c file
1057
Remove unused function no_tap_ifconfig
1058
Add the client id (CID) to the output of the status command
1059
Print client id only if compiled with man agent support. Otherwise print an empty string.
1060
Allow routes to be set before opening tun, similar to ifconfig before opening tun
1061
Add ability to send/receive file descriptors via management interface
1062
Android platform specific changes.
1063
Emulate persist-tun on Android
1064
Document the Android implementation in OpenVPN
1065
Only print script warnings when a script is used. Remove stray mention of script-security system.
1066
Fix #ifdefs for P2MP_SERVER
1067
Move settings of user script into set_user_script function
1068
Move checking of script file access into set_user_script
1069
Fix another #ifdef/#if P2MP_SERVER
1070
PATCHv3 Remove unused variables or put them to the defines they are being used in
1071
Add support of utun devices under Mac OS X
1072
Add support to ignore specific options.
1073
Add a note what setenv opt does for OpenVPN < 2.3.3
1074
Implement custom HTTP header for http-proxy, and always send user-agent:
1075
Add reporting of UI version to basic push-peer-info set.
1076
Change the type of all ports in openvpn to const char* and let getaddrinfo resolve the port together with the hostname.
1077
Fix compile error in ssl_openssl introduced by polar external-management patch
1078
Simplify print_sockaddr_ex function, merge duplicate ipv4/ipv6 logic.
1079
Split the PROTO_UDP_xx options into AF_INET/AF_INET6 and PROTO_TCP/PROTO_UDP part.
1080
Fix two instances of asserting AF_INET
1081
Fix assertion when SIGUSR1 is received while getaddrinfo is successful
1082
Split link_socket_init_phase1 and link_socket_init_phase2 into smaller more managable/readable functions. No functional changes
1083
Change proto_remote() function to return a constant string
1084
Remove the ip-remote-hint option.
1085
change the type of 'remote' to addrinfo*, and rename to 'remote_list'.
1086
When resolving fails print the error message from socket layer
1087
Implement dual stack client support for OpenVPN
1088
Move ASSERT so external-key with OpenSSL works again
1089
Implement listing on IPv4/IPv6 dual socket on all platform
1090
Add warning for using connection block variables after connection blocks
1091
Update IPv6 related readme files
1092
Introduce safety check for http proxy options
1093
Fix warning for max-routes: do not quit when parsing an old configuration. Format the message to be more like the other deprecated options
1094
Fix connecting to localhost on Android
1095
Move the initialization of the environment to the top so c2.es is initialized
1096
Workaround broken Android 4.4 VpnService API for persist-tun mode
1097
Implement an easy parsable log output that allows access to flags of the log message
1098
Introduce an option to resolve dns names in advance for --remote, --local and --http-proxy
1099
Fix for server selecting address family
1100
Don't show the connection profile store in options->ce if there is a connection_list defined.
1101
Add gateway and device to android control messages
1102
Clean up of socket code.
1103
Fix assert when using port-share
1104
Work around Solaris getaddrinfo() returing ai_protocol=0
1105
Fix man page and OSCP script: tls_serial_{n} is decimal
1106
Remove ENABLE_BUFFER_LIST
1107
Fix server routes not working in topology subnet with --server [v3]
1108
Always enable http-proxy and socks-proxy
1109
Remove deprecated --max-routes option from manual
1110
Add documentation for PERSIST_TUN_ACTION (Android specific)
1111
Remove possibility of using --tls-auth with non OpenVPN Static key files
1112
Remove unused function sock_addr_set
1113
Document the default for tls-cipher.
1114
Report missing end-tags of inline files as errors
1115
Fix commit e473b7c if an inline file happens to have a line break exactly at buffer limit
1116
Show extra-certs in current parameters, fix clang warning and logic error in preresolve
1117
Remove unused function h_errno_msg
1118
Add support for requesting the fd again to rebind to the next interface.
1119
Don't redirect the gateway on Android even if requested
1120
Fix loglevel of protect socket message
1121
Extend network-change command to allow reprotecting on the same network (for short connection losses)
1122
Use pseudo gw as default gw on Android as a workaround for not being able to read /proc/net/route
1123
Remove #ifdefs for client nat support.
1124
Do not install a host route for the VPN on Android
1125
Fix commit c67acea173dc9ee37220f5b9ff14ede081181992
1126
Do not set the buffer size by default but rely on the operation system default.
1127
Start Changes.rst that lists changes in 2.4.0
1128
Remove --enable-password-save option
1129
Reflect enable-password-save change in documentation
1130
Also remove second instance of enable-password-save in the man page
1131
Detect config lines that are too long and give a warning/error
1132
Implement the compression V2 data format for stub and lz4.
1133
Fix assert when comp is called with unknown algorithm, always call comp init method
1134
Ignore stamp-h2 we generate during build process
1135
Implement inlining of crl files
1136
Complete push-peer-info documentation and allow IV_PLAT_VER for other platforms than Windows if the client UI supplies it.
1137
Remove http-proxy-timeout, socks timeout and set default of server-poll-timeout to 120s
1138
Add documentation for http-proxy-user-pass option
1139
Remove http-proxy-retry and socks-proxy-retry.
1140
Update android documentation to match source code
1141
Use AES ciphers in our sample configuration files and add a few modern 2.4 examples
1142
Fix ENABLE_CRYPTO_OPENSSL set to YES even with --disable-crypto set
1143
Prefer RECVDSTADDR to PKTINFO for IPv4 in OS X since it actually works (unlike PKTINFO)
1144
Incorporate the Debian typo fixes where appropriate and make show_opt default message clearer
1145
Enable TCP non-linear packet ID
1146
Change the hold command to communicate the time that OpenVPN would wait to the UI.
1147
Remove tun-ipv6 Option. Instead assume that IPv6 is always supported.
1148
1149
Boris Lytochkin (1):
1150
Log serial number of revoked certificate
1151
1152
Christian Hesse (1):
1153
fix build with automake 1.13(.1)
1154
1155
Christian Niessner (1):
1156
Fix corner case in NTLM authentication (trac #172)
1157
1158
Christos Trochalakis (1):
1159
Adjust server-ipv6 documentation
1160
1161
Cristian Rodriguez (1):
1162
Use SSL_MODE_RELEASE_BUFFERS if available
1163
1164
Daniel Hahler (1):
1165
options: fix option check for "plugin"
1166
1167
Daniel Kubec (4):
1168
Added support for TLS Keying Material Exporters [RFC-5705]
1169
Added document for TLS Keying Material Exporters [RFC-5705]
1170
sample-plugin: TLS Keying Material Exporter [RFC-5705] demonstration plug-in
1171
Fix buffer size parameter for exported keying material.
1172
1173
David Sommerseth (45):
1174
Make git ignore some more files
1175
Remove the support for using system() when executing external programs or scripts
1176
Fix double-free issue in pf_destroy_context()
1177
Reset the version.m4 version for the master branch
1178
Avoid recursion in virtual_output_callback_func()
1179
The get_default_gateway() function uses warn() instead of msg()
1180
Improve the git revision tracking
1181
man page: Update man page about the tls_digest_{n} environment variable
1182
Remove the --disable-eurephia configure option
1183
plugin: Extend the plug-in v3 API to identify the SSL implementation used
1184
autoconf: Fix typo
1185
t_client.sh: Check for fping/fping6 availability
1186
t_client.sh: Write errors to stderr and document requirements
1187
t_client.sh: Add prepare/cleanup possibilties for each test case
1188
Fix file checks when --chroot is being used
1189
Adjusted autotools files to build more cleanly on newer autoconf/automake versions
1190
Improve error reporting on file access to --client-config-dir and --ccd-exclusive
1191
Don't let openvpn_popen() keep zombies around
1192
Don't try to use systemd-ask-password if it is not available
1193
Clean up the pipe closing in openvpn_popen()
1194
Add systemd unit file for OpenVPN
1195
systemd: Use systemd functions to consider systemd availability
1196
systemd: Reworked the systemd unit file to handle server and client configs better
1197
autotools: Fix wrong ./configure help screen default values
1198
down-root plugin: Replaced system() calls with execve()
1199
down-root: Improve error messages
1200
plugin, down-root: Fix compiler warnings
1201
sockets: Remove the limitation of --tcp-nodelay to be server-only
1202
plugins, down-root: Code style clean-up
1203
Provide compile time OpenVPN version information to plug-ins
1204
Provide OpenVPN runtime version information to plug-ins
1205
Avoid partial authentication state when using --disabled in CCD configs
1206
Only build and run cmocka unit tests if its submodule is initialized
1207
Another fix related to unit test framework
1208
Remove NOP function and callers
1209
Revert "Drop recursively routed packets"
1210
Fix client connection instant timeout
1211
t_client.sh: Make OpenVPN write PID file to avoid various sudo issues
1212
t_client.sh: Add support for Kerberos/ksu
1213
t_client.sh: Improve detection if the OpenVPN process did start during tests
1214
Rework the user input interface to make it more modular
1215
Re-implement the systemd support using the new query user API
1216
systemd: Do not mask usernames when querying for it via systemd-ask-password
1217
Move memcmp_constant_time() to crypto.h
1218
Update .mailmap to unify and clean up odd names and e-mail addresses
1219
1220
David Woodhouse (2):
1221
pkcs11: Load p11-kit-proxy.so module by default
1222
Make 'provider' option to --show-pkcs11-ids optional where p11-kit is present
1223
1224
Davide Brini (2):
1225
Provide more accurate warning message
1226
Document authfile for socks server
1227
1228
Dmitrij Tejblum (1):
1229
Fix is_ipv6 in case of tap interface.
1230
1231
Dorian Harmans (1):
1232
Add CHACHA20-POLY1305 ciphersuite IANA name translations.
1233
1234
Felix Janda (1):
1235
Use OPENVPN_ETH_P_* so that <netinet/if_ether.h> is unecessary
1236
1237
Fish (1):
1238
Add lz4 support to MSVC.
1239
1240
Gert Doering (112):
1241
Implement --mssfix handling for IPv6 packets.
1242
Fix option inconsistency warnings about "proto" and "tun-ipv6"
1243
Fix parameter type for IP_TOS setsockopt on non-Linux systems.
1244
Fix client crash on double PUSH_REPLY.
1245
Update README.IPv6 to match what is in 2.3.0
1246
Repair "tcp server queue overflow" brokenness, more <stdbool.h> fallout.
1247
Permit pool size of /64.../112 for ifconfig-ipv6-pool
1248
Add MIN() compatibility macro
1249
Fix directly connected routes for "topology subnet" on Solaris.
1250
Print "Virtual IPv6 Address" on management interface queries [v4]
1251
Use constrain_int() instead of MIN()+syshead.c compat definition - v2.
1252
Fix NULL-pointer crash in route_list_add_vpn_gateway().
1253
Fix usage of 'compression ...' from global config.
1254
Make push-peer-info visible in "normal" per-instance environment.
1255
Fix problem with UDP tunneling due to mishandled pktinfo structures.
1256
Improve documentation and help text for --route-ipv6.
1257
Fix argument type warning introduced by http extra proxy header patch.
1258
Fix IPv6 examples in t_client.rc-sample
1259
Fix slow memory drain on each client renegotiation.
1260
t_client.sh: ignore fields from "ip -6 route show" output that distort results.
1261
Fix IPv6_V6ONLY logic.
1262
Implement LZ4 compression.
1263
Provide LZ4 sources in src/compat/ and use if no system lz4 library found.
1264
Document "lz4" argument to "compress" config option.
1265
Make code and documentation for --remote-random-hostname consistent.
1266
Reduce IV_OPENVPN_GUI_VERSION= to IV_GUI_VER=
1267
remove some 'unused variable' warnings
1268
Cleanup ir6->netbits handling.
1269
Document issue with --chroot, /dev/urandom and PolarSSL.
1270
Rename 'struct route' to 'struct route_ipv4'
1271
Replace copied structure elements with including <net/route.h>
1272
Add "test-driver" and "compile" to .gitignore
1273
Fix crash when using --inetd.
1274
IPv6 address/route delete fix for Win8
1275
Add SSL library version reporting.
1276
Minor t_client.sh cleanups
1277
Repair --multihome on FreeBSD for IPv4 sockets.
1278
Rewrite manpage section about --multihome
1279
More IPv6-related updates to the openvpn man page.
1280
Conditionalize calls to print_default_gateway on !ENABLE_SMALL
1281
Merge get_default_gateway() implementation for all 4+1 BSD variants.
1282
Drop incoming fe80:: packets silently now.
1283
Recognize AIX, define TARGET_AIX
1284
Add tap driver initialization and ifconfig for AIX.
1285
implement adding/deleting routes on AIX, for IPv4 and IPv6
1286
Make t_client.sh work on AIX.
1287
Fix t_lpback.sh platform-dependent failures
1288
Call init script helpers with explicit path (./)
1289
Fix windows build on older mingw versions.
1290
New approach to handle peer-id related changes to link-mtu.
1291
Print remote IPv4 address on a dual-stack v6 socket in IPv4 format
1292
Fix incorrect use of get_ipv6_addr() for iroute options.
1293
Remove count_netmask_bits(), convert users to use netmask_to_netbits2()
1294
Fix leftover 'if (false) ;' statements
1295
Print helpful error message on --mktun/--rmtun if not available.
1296
explain effect of --topology subnet on --ifconfig
1297
Add note about file permissions and --crl-verify to manpage.
1298
repair --dev null breakage caused by db950be85d37
1299
assume res_init() is always there.
1300
Correct note about DNS randomization in openvpn.8
1301
Disallow usage of --server-poll-timeout in --secret key mode.
1302
slightly enhance documentation about --cipher
1303
Enforce "serial-tests" behaviour for tests/Makefile
1304
Revert "Enforce "serial-tests" behaviour for tests/Makefile"
1305
On signal reception, return EAI_SYSTEM from openvpn_getaddrinfo().
1306
Use configure.ac hack to apply serial_test AM option only if supported.
1307
Use EAI_AGAIN instead of EAI_SYSTEM for openvpn_getaddrinfo().
1308
Move res_init() call to inner openvpn_getaddrinfo() loop
1309
Fix FreeBSD ifconfig for topology subnet tunnels.
1310
Produce a meaningful error message if --daemon gets in the way of asking for passwords.
1311
Document --daemon changes and consequences (--askpass, --auth-nocache).
1312
Fix build on OpenSolaris (non-gmake)
1313
Un-break --auth-user-pass on windows
1314
refactor struct route_ipv6, bring in line with struct route_ipv4 again
1315
refactor struct route_ipv6_list, bring in line with struct route_list again
1316
Add route_ipv6_gateway* data structures for rgi6 support.
1317
Create basic infrastructure for IPv6 default gateway handling / redirection.
1318
Make client delay less before sending PUSH_REQUEST
1319
get_default_gateway_ipv6(): Linux / Netlink implementation.
1320
Implement handling of overlapping IPv6 routes with IPv6 remote VPN server address
1321
Implement '--redirect-gateway ipv6'
1322
get_default_gateway_ipv6(): *BSD / MacOS / Solaris PF_ROUTE implementation
1323
Fix IPv6 host routes to LAN gateway on OpenSolaris
1324
Replace unaligned 16bit access to TCP MSS value with bytewise access
1325
Repair test_local_addr() on WIN32
1326
Add custom check for inet_pton()/inet_ntop() on MinGW/WIN32
1327
get_default_gateway_ipv6(): Win32 implementation using GetBestRoute2()
1328
Remove support for snappy compression.
1329
Fix info.af == AF_UNSPEC case for server with --mtu-disc
1330
Fix FreeBSD-specific mishandling of gc arena pointer in create_arbitrary_remote()
1331
remove unused gc_arena in FreeBSD close_tun()
1332
Un-break compilation on *BSD
1333
Fix isatty() check for good.
1334
Fix openserv/validate.o linking issues on mingw.
1335
Fix library order in -lmbedtls test.
1336
Implement push-remove option to selectively remove pushed options.
1337
Upgrade bundled compat-lz4 to upstream release r131.
1338
Change --enable-pedantic to use -std=c99 and not -ansi (C90).
1339
Fix problems with NCP and --inetd.
1340
Do not abort t_client run if OpenVPN instance does not start.
1341
Fix IP_PKTINFO related compilation failure on NetBSD 7.0
1342
Show compile-time variant for --multihome in --version output.
1343
Fix win32 building with C99 mode
1344
Fix t_client runs on OpenSolaris
1345
make t_client robust against sudoers misconfiguration
1346
add POSTINIT_CMD_suf to t_client.sh and sample config
1347
Fix --multihome for IPv6 on 64bit BSD systems.
1348
Enable -D_SVR4_2 for compilation on Solaris
1349
Revert "Enable -D_SVR4_2 for compilation on Solaris"
1350
Enable -D_XPG4_2 for compilation on Solaris
1351
Preparing for release v2.4_alpha1 (ChangeLog, version.m4)
1352
Preparing for release v2.4_alpha2 (ChangeLog, version.m4)
1353
1354
Guy Yur (1):
1355
Fix --redirect-private in --dev tap mode.
1356
1357
Heikki Hannikainen (1):
1358
Always load intermediate certificates from a PKCS#12 file
1359
1360
Heiko Hund (20):
1361
Fix display of plugin hook types
1362
Support UTF-8 --client-config-dir
1363
close more file descriptors on exec
1364
Ignore UTF-8 byte order mark
1365
reintroduce --no-name-remapping option
1366
make --tls-remote compatible with pre 2.3 configs
1367
add new option for X.509 name verification
1368
Support non-ASCII TAP adapter names on Windows
1369
Support non-ASCII characters in Windows tmp path
1370
make sure sa_family_t is defined
1371
convert struct signal_info element
1372
grow route lists dynamically
1373
fix route struct name
1374
refine assertion to allow other modes than CBC
1375
Fix compilation on Windows
1376
fix warnings on Windows
1377
extend management interface command "state"
1378
put virtual IPv6 addresses into env
1379
interactive service v3
1380
Windows: do_ifconfig() after open_tun()
1381
1382
Holger Kummert (1):
1383
Del ipv6 addr on close of linux tun interface
1384
1385
Hubert Kario (2):
1386
ocsp_check - signature verification and cert staus results are separate
1387
ocsp_check - double check if ocsp didn't report any errors in execution
1388
1389
Ilya Shipitsin (3):
1390
initial travis-ci support
1391
skip t_lpback.sh and t_cltsrv.sh if openvpn configured --disable-crypto
1392
enable "--disable-crypto" build configuration for travis
1393
1394
Ivo Manca (1):
1395
Plug memory leak in mbedTLS backend
1396
1397
James Bekkema (1):
1398
Fix socket-flag/TCP_NODELAY on Mac OS X
1399
1400
James Geboski (1):
1401
Fix --askpass not allowing for password input via stdin
1402
1403
James Yonan (14):
1404
Added support for the Snappy compression algorithm
1405
Always push basic set of peer info values to server.
1406
TLS version negotiation
1407
Added "setenv opt" directive prefix. If present, and if the directive that follows is recognized, it will be processed as if the "setenv opt" prefix was absent. If present and if the directive that follows is not recognized, the directive will be ignored rather than cause a fatal error.
1408
MSVC fixes
1409
Set SSL_OP_NO_TICKET flag in SSL context for OpenSSL builds, to disable TLS stateless session resumption.
1410
Use native strtoull() with MSVC 2013.
1411
Define PATH_SEPARATOR for MSVC builds.
1412
Fixed some compile issues with show_library_versions()
1413
Added flags parameter to format_hex_ex.
1414
Extended x509-track for OpenSSL to report SHA1 fingerprint.
1415
Fixed port-share bug with DoS potential
1416
Added directive to specify HTTP proxy credentials in config.
1417
Bind to local socket before dropping privileges
1418
1419
Jan Just Keijser (6):
1420
man page patch for missing options
1421
make 'explicit-exit-notify' pullable again
1422
include ifconfig_ environment variables in --up-restart env set
1423
Fix "White space before end tags can break the config parser"
1424
Author: Jan Just Keijser <janjust@nikhef.nl>
1425
Make certificate expiry warning patch (091edd8e299686) work on OpenSSL 1.0.1 and earlier.
1426
1427
Jann Horn (1):
1428
Remove quadratic complexity from openvpn_base64_decode()
1429
1430
Jeffrey Cutter (1):
1431
Update contrib/pull-resolv-conf/client.up for no DOMAIN
1432
1433
Jens Neuhalfen (6):
1434
Make intent of utun device name validation clear
1435
Fix buffer overflow by user supplied data
1436
ignore the local config file t_client.rc in git
1437
Prevent integration test timeout bc. of sudo
1438
Add unit testing support via cmocka
1439
Add a test for auth-pam searchandreplace
1440
1441
Jens Wagner (1):
1442
Fix spurious ignoring of pushed config options (trac#349).
1443
1444
Jesse Glick (1):
1445
Allow use of NetBeans without saving nbproject/ directory.
1446
1447
Joachim Schipper (5):
1448
doc/management-notes.txt: fix typo
1449
Fix typo in ./configure message
1450
Refactor tls_ctx_use_external_private_key()
1451
--management-external-key for PolarSSL
1452
external_pkcs1_sign: Support non-RSA_SIG_RAW hash_ids
1453
1454
Jonathan K. Bullard (3):
1455
Fix mismatch of fprintf format specifier and argument type
1456
Fix null pointer dereference in options.c
1457
Fail if options have extra parameters [v2]
1458
1459
Josh Cepek (7):
1460
Fix parameter listing in non-debug builds at verb 4
1461
(updated) [PATCH] Warn when using verb levels >=7 without debug
1462
Fix proto tcp6 for server & non-P2MP modes
1463
Fix Windows script execution when called from script hooks
1464
Correct error text when no Windows TAP device is present
1465
Require a 1.2.x PolarSSL version
1466
Push an IPv6 CIDR mask used by the server, not the pool's size
1467
1468
Julien Muchembled (1):
1469
Fix --mtu-disc option with IPv6 transport
1470
1471
Kenneth Rose (1):
1472
Fix v3 plugins to support returning values back to OpenVPN.
1473
1474
Klee Dienes (1):
1475
tls_ctx_load_ca: Improve certificate error messages
1476
1477
Leon Klingele (1):
1478
Add link to bug tracker
1479
1480
Leonardo Basilio (1):
1481
Correctly report TCP connection timeout on windows.
1482
1483
Lev Stipakov (26):
1484
Peer-id patch v7
1485
Add the peer-id to the output of the status command
1486
Prevent memory drain for long lasting floating sessions
1487
Disallow lameduck's float to an address taken by another client
1488
Fix NULL dereferencing
1489
Fix mssfix default value in connection_list context
1490
This fixes MSVS 2013 compilation.
1491
Continuation of MSVS fixes
1492
Fast recovery when host is in unreachable network
1493
Fix compilation error with --disable-crypto
1494
Send push reply right after async auth complete
1495
Fix compilation with --disable-server
1496
Refine float logging
1497
Generate openvpn-plugin.h for MSVC build
1498
Replace variable length array with malloc
1499
Use adapter index instead of name for windows IPv6 interface config
1500
Notify clients about server's exit/restart
1501
Use adapter index for add/delete_route_ipv6
1502
Pass adapter index to up/down scripts
1503
Detecting and logging Windows versions
1504
Report Windows bitness
1505
Fix "implicit declaration" compiler warning
1506
Drop recursively routed packets
1507
Support for disabled peer-id
1508
Exclude peer-id from pulled options digest
1509
Use separate list for per-client push options
1510
1511
Lukasz Kutyla (1):
1512
Fix privilege drop if first connection attempt fails
1513
1514
Matthias Andree (1):
1515
Enable TCP_NODELAY configuration on FreeBSD.
1516
1517
Max Muster (1):
1518
Remove duplicate cipher entries from TLS translation table.
1519
1520
Michael McConville (1):
1521
Fix undefined signed shift overflow
1522
1523
Michal Ludvig (1):
1524
Support for username-only auth file.
1525
1526
Mike Gilbert (2):
1527
Add configure check for the path to systemd-ask-password
1528
Include systemd units in the source tarball (make dist)
1529
1530
Niels Ole Salscheider (1):
1531
Fix build with libressl
1532
1533
Peter Sagerson (1):
1534
Fix configure interaction with static OpenSSL libraries
1535
1536
Philipp Hagemeister (2):
1537
Add topology in sample server configuration file
1538
Implement on-link route adding for iproute2
1539
1540
Phillip Smith (1):
1541
Use bob.example.com and alice.example.com to improve clarity of documentation
1542
1543
Robert Fischer (1):
1544
Updated manpage for --rport and --lport
1545
1546
Samuel Thibault (1):
1547
Ensure that client-connect files are always deleted
1548
1549
Samuli Seppänen (15):
1550
Removed ChangeLog.IPv6
1551
Added cross-compilation information INSTALL-win32.txt
1552
Updated README
1553
Cleaned up and updated INSTALL
1554
Fix to --shaper documentation on the man-page
1555
Properly escape dashes on the man-page
1556
Improve documentation in --script-security section of the man-page
1557
Add CONTRIBUTING.rst
1558
Update CONTRIBUTING.rst to allow GitHub PRs for code review purposes
1559
Clarify the fact that build instructions in README are for release tarballs
1560
Mention tap-windows6 in INSTALL file
1561
Use an up-to-date easy-rsa URL on the man-page
1562
Clarify which Windows versions require which TUN/TAP driver
1563
Deprecate the automatic part of openvpnserv.exe in favor of openvpnserv2.exe
1564
Automatically cache expected IPs for t_client.sh on the first run
1565
1566
Selva Nair (26):
1567
Fix termination when windows suspends/sleeps
1568
Do not hard-code windows systemroot in env_block
1569
Handle ctrl-C and ctrl-break events on Windows
1570
Unbreak read username password from management
1571
Restrict options/configs for startup through interactive service
1572
Send stdout and stderr of OpenVPN started by interactive service to NUL
1573
Handle localized Administrators group name in windows
1574
Fix interactive service ignoring stop command if openvpn is running
1575
Use appropriate buffer size for WideCharToMultiByte output in interactive.c
1576
Refactor and move the block-outside-dns code to a new file (block_dns.[ch])
1577
Add support for block-outside-dns through the interactive service
1578
Ensure input read using systemd-ask-password is null terminated
1579
Support reading the challenge-response from console
1580
Make error non-fatal while deleting address using netsh
1581
Add support for register-dns through interactive service
1582
Fix handling of out of memory error in interactive service
1583
Fix the comparison of pull options hash on restart
1584
Set WFP engine handle to NULL in win_wfp_uninit()
1585
Make block-outside-dns work with persist-tun
1586
Add an option to filter options received from server
1587
Ignore SIGUSR1/SIGHUP during exit notification
1588
Fix management-external-cert option parsing error
1589
Return process id of openvpn from interactive service to client
1590
Exponentially back off on repeated connect retries
1591
Promptly close the netcmd_semaphore handle after use
1592
Avoid format specifier %zu for Windows compatibility
1593
1594
Steffan Karger (181):
1595
PolarSSL-1.2 support
1596
Improve PolarSSL key_state_read_{cipher, plain}text messages
1597
Improve verify_callback messages
1598
Config compatibility patch. Added translate_cipher_name.
1599
Switch to IANA names for TLS ciphers.
1600
Fixed autoconf script to properly detect missing pkcs11 with polarssl.
1601
Use constant time memcmp when comparing HMACs in openvpn_decrypt.
1602
Fixed tls-cipher translation bug in openssl-build
1603
Fixed usage of stale define USE_SSL to ENABLE_SSL
1604
Do not pass struct tls_session* as void* in key_state_ssl_init().
1605
Require polarssl >= 1.2.10 for polarssl-builds, which fixes CVE-2013-5915.
1606
Also update TLSv1_method() calls in support code to SSLv23_method() calls.
1607
Update TLSv1 error messages to SSLv23 to reflect changes from commit 4b67f98
1608
If --tls-cipher is supplied, make --show-tls parse the list.
1609
Remove OpenSSL tmp_rsa_callback. Removes support for ephemeral RSA in TLS.
1610
Make tls_ctx_restrict_ciphers accept NULL as char *cipher_list.
1611
Disable export ciphers by default for OpenSSL builds.
1612
Fix compiler warning for unused result of write()
1613
Remove unused variables from ssl_verify_polarssl.c's x509_get_serial()
1614
Fix compiler warnings in ssl_polarssl.c
1615
Bump minimum OpenSSL version to 0.9.8
1616
Add openssl-specific common cipher list names to ssl.c.
1617
Disable unsupported TLS cipher modes by default, cleans --show-tls output.
1618
configure.ac: check for SSL_OP_NO_TICKET flag in OpenSSL
1619
configure.ac: use CPPFLAGS for SSL_OP_NO_TICKET check
1620
Upgrade to PolarSSL 1.3
1621
Improve error reporting during key/cert loading with PolarSSL.
1622
Update openvpn-plugin.h for PolarSSL 1.3.
1623
Add support for elliptic curve diffie-hellmann key exchange (ECDH)
1624
Add an elliptic curve testing cert chain to the sample keys
1625
Change signedness of hash in x509_get_sha1_hash(), fixes compiler warning.
1626
Fix OCSP_check.sh to also use decimal for stdout verification.
1627
Make serial env exporting consistent amongst OpenSSL and PolarSSL builds.
1628
Fix build system to accept non-system crypto library locations for plugins.
1629
Remove function without effect (cipher_ok() always returned true).
1630
Remove unneeded wrapper functions in crypto_openssl.c
1631
Remove unneeded defines (were needed for pre-0.9.7 OpenSSL).
1632
Fix merge error in a6c573d, the ssl ctx is now abstracted.
1633
Use generic openvpn_x509_cert_t in ssl_verify_polarssl.c
1634
Fix ssl.c, ssl_verify_* includes
1635
Move #include "ssl_verify.h" from ssl.h to the source files that need it.
1636
Remove dependency on manage.h from ssl_verify.h
1637
Remove unused variable 'proxy' from socket_restart_pause()
1638
Add (default disabled) --enable-werror option to configure
1639
Fix --disable-ssl builds, were broken by cleanup in 63dc03d.
1640
configure.ac: fix SSL_OP_NO_TICKET check
1641
Fix bug that incorrectly refuses oid representation eku's in polar builds
1642
Update README.polarssl
1643
cleanup: remove #if 0'ed function initiate_untrusted_session() from ssl.c.
1644
Rename ALLOW_NON_CBC_CIPHERS to ENABLE_OFB_CFB_MODE, and add to configure.
1645
Add proper check for crypto modes (CBC or OFB/CFB)
1646
Improve --show-ciphers to show if a cipher can be used in static key mode
1647
Extend t_lpback tests to test all ciphers reported by --show-ciphers
1648
Don't issue warning for 'translate to self' tls-ciphers
1649
Don't exit daemon if opening or parsing the CRL fails.
1650
Define dummy SSL_OP_NO_TICKET flag if not present in OpenSSL.
1651
Fix typo in cipher_kt_mode_{cbc, ofb_cfb}() doxygen.
1652
Fix some unintialized variable warnings
1653
Fix clang warning in options.c
1654
Fix compiler warnings in ssl_polarssl.c.
1655
Fix regression with password protected private keys (polarssl)
1656
Remove unused variables from ssl_verify_openssl.c extract_x509_extension()
1657
Fix assertion error when using --cipher none
1658
Add --tls-version-max
1659
Modernize sample keys and sample configs
1660
Drop too-short control channel packets instead of asserting out.
1661
Really fix '--cipher none' regression
1662
Update doxygen (a bit)
1663
Set tls-version-max to 1.1 if cryptoapicert is used
1664
openssl: add crypto_msg(), to easily log openssl errors
1665
openssl: add more descriptive message for 'no shared cipher' error
1666
Remove ENABLE_SSL define (and --disable-ssl configure option)
1667
openssl: use crypto_msg(), get rid of openssl-specific code in error.c
1668
Add option to disable Diffie Hellman key exchange by setting '--dh none'
1669
Account for peer-id in frame size calculation
1670
Disable SSL compression
1671
Use tls-auth in sample config files
1672
Fix frame size calculation for non-CBC modes.
1673
Get rid of old OpenSSL workarounds.
1674
polarssl: make sure to always null-terminate the cn
1675
Allow for CN/username of 64 characters (fixes off-by-one)
1676
Change float log message to include common name, if available.
1677
Remove unneeded parameter 'first_time' from possibly_become_daemon()
1678
Remove size limit for files inlined in config
1679
polarssl: remove code duplication in key_state_write_plaintext{, _const}()
1680
Improve --tls-cipher and --show-tls man page description
1681
polarssl: disable 1/n-1 record splitting
1682
cleanup: remove md5 helper functions
1683
Re-read auth-user-pass file on (re)connect if required
1684
Clarify --capath option in manpage
1685
Call daemon() before initializing crypto library
1686
write pid file immediately after daemonizing
1687
Increase control channel packet size for faster handshakes
1688
Make __func__ work with Visual Studio too
1689
fix regression: query password before becoming daemon
1690
Fix using management interface to get passwords.
1691
reintroduce md5_digest wrapper struct to fix gcc warnings
1692
Fix out-of-tree builds; openvpn-plugin.h should be in AC_CONFIG_HEADERS
1693
Fix overflow check in openvpn_decrypt()
1694
Replace strdup() calls for string_alloc() calls
1695
Check return value of ms_error_text()
1696
polarssl: add easy logging for PolarSSL errors
1697
polarssl: Improve PolarSSL logging
1698
openssl: be less verbose about cipher translation errors
1699
hardening: add insurance to exit on a failed ASSERT()
1700
Fix memory leak in auth-pam plugin
1701
openssl: remove usage of OPENSSL_malloc() from show_available_curves
1702
polarssl: fix --client-cert-not-required
1703
polarssl: add --verify-client-cert optional support
1704
Fix (potential) memory leak in init_route_list()
1705
Add macro to ensure we exit on fatal errors
1706
polarssl: also allocate PKCS#11 certificate object on demand
1707
polarssl: don't use deprecated functions anymore
1708
polarssl: require >= 1.3.8
1709
Fix memory leak in add_option() by simplifying get_ipv6_addr
1710
remove nonsense const specifier in nonfatal() return value
1711
openssl: properly check return value of RAND_bytes()
1712
Fix rand_bytes return value checking
1713
Fix openssl builds with custom-built library: specify most-dependent first
1714
Support duplicate x509 field values in environment
1715
Warn user if their certificate has expired
1716
Disable certificate notBefore/notAfter sanity check on OpenSSL < 1.0.2
1717
Make assert_failed() print the failed condition
1718
cleanup: get rid of httpdigest.c type warnings
1719
Fix regression in setups without a client certificate
1720
polarssl: actually use polarssl debug logging
1721
polarssl: optimize polar_ok() for non-errors
1722
Update manpage: OpenSSL might also need /dev/urandom inside chroot
1723
polarssl: use wrappers to access md_info_t member functions
1724
polarssl: remove now redundant 128-bit blowfish key override
1725
socks.c: fix check on get_user_pass() return value(s)
1726
configure.ac: simplify crypto library configuration
1727
configure.ac: fix polarssl autodetection
1728
Allow NULL argument in cipher_ctx_get_cipher_kt()
1729
Remove reuse of key_type during init of data channel auth and tls-auth
1730
Move crypto_options into key_state and stop using context in SSL-mode.
1731
Move key_ctx_bi into crypto_options
1732
Move packet_id into crypto_options
1733
Change openvpn_encrypt() to append to work buffer only
1734
Create separate function for replay check
1735
Add AEAD cipher support (GCM)
1736
Add cipher name translation for OpenSSL.
1737
Add preliminary server-side support for negotiable crypto parameters
1738
Minor AEAD patch cleanup
1739
Clean up get_tls_handhake_key()
1740
Fix OCSP_check.sh
1741
Make AEAD modes work with OpenSSL 1.0.1-1.0.1c
1742
hardening: add safe FD_SET() wrapper openvpn_fd_set()
1743
Only include aead encrypt/decrypt functions if AEAD modes are supported
1744
Fix potential null-pointer dereference
1745
Fix memory leak in argv_extract_cmd_name()
1746
Replace MSG_TEST() macro for static inline msg_test()
1747
fixup: change init_key_type() param name in declaration too
1748
Further restrict default cipher list
1749
PolarSSL x509_get_sha1_hash now returns correct SHA1 fingerprint.
1750
Implemented x509-track for PolarSSL.
1751
Migrate to mbed TLS 2.x
1752
Rename files with 'polarssl' in the name to 'mbedtls'
1753
configure.ac: link to all mbed TLS libs during library detection
1754
mbedtls: check that private key and certificate match on start
1755
mbedtls: improve error reporting in tls verify callback
1756
Remove trailing newline from verify callback error messages
1757
Don't limit max incoming message size based on c2->frame
1758
cleanup: remove alloc_buffers argument from multi_top_init()
1759
mbedtls: don't set debug threshold if compiled without MBEDTLS_DEBUG_C
1760
Add client-side support for cipher negotiation
1761
Add options to restrict cipher negotiation
1762
Add server-side support for cipher negotiation
1763
Allow ncp-disable and ncp-ciphers to be specified in ccd files
1764
Fix '--cipher none --cipher' crash
1765
Discourage using 64-bit block ciphers
1766
Fix unittests for out-of-source builds
1767
Fix --mssfix when using NCP
1768
Drop gnu89/c89 support, switch to c99
1769
cleanup: remove code duplication in msg_test()
1770
Add SHA256 fingerprint support
1771
Make sure options->ciphername and options->authname are always defined
1772
Update cipher-related man page text
1773
Fix duplicate PUSH_REPLY options
1774
Check --ncp-ciphers list on startup
1775
Fix use-after-free bug in prepare_push_reply()
1776
1777
TDivine (1):
1778
Fix "code=995" bug with windows NDIS6 tap driver.
1779
1780
Tamas TEVESZ (1):
1781
Add support for client-cert-not-required for PolarSSL.
1782
1783
Thomas Veerman (2):
1784
Fix "." in description of utun.
1785
Update expiry date in management event loop
1786
1787
ValdikSS (4):
1788
Add Windows DNS Leak fix using WFP ('block-outside-dns')
1789
Clarify mssfix documentation
1790
Clarify --block-outside-dns documentation
1791
Update --block-outside-dns to work on Windows Vista
1792
1793
Vasily Kulikov (1):
1794
Mac OS X Keychain management client
1795
1796
Yawning Angel (1):
1797
Fix SOCKSv5 method selection
1798
1799
Yegor Yefremov (3):
1800
socket: remove duplicate expression
1801
polarssl: fix unreachable code
1802
cert_data: fix memory leak
1803
1804
kangsterizer (1):
1805
Fix typo in sample build script to use LDFLAGS
1806
1807
svimik (1):
1808
Fix segfault when enabling pf plug-ins
1809
```