Blame
| d91829 | Samuli Seppänen | 2025-02-11 09:50:59 | 1 | # Changes in 2.5.11 |
| 2 | ||||
| 3 | ``` |
|||
| 4 | Arne Schwabe (2): |
|||
| 5 | Properly handle null bytes and invalid characters in control messages |
|||
| 6 | Allow trailing \r and \n in control channel message |
|||
| 7 | ||||
| 8 | Gert Doering (1): |
|||
| 9 | Preparing release 2.5.11 |
|||
| 10 | ``` |
|||
| 11 | ||||
| 12 | # Changes in 2.5.10 |
|||
| 13 | ||||
| 14 | ``` |
|||
| 15 | Arne Schwabe (1): |
|||
| 16 | Add Apache2 linking with for new commits |
|||
| 17 | ||||
| 18 | George Pchelkin (1): |
|||
| 19 | fix typo: dhcp-options to dhcp-option in vpn-network-options.rst |
|||
| 20 | ||||
| 21 | Gert Doering (1): |
|||
| 22 | Preparing release 2.5.10 |
|||
| 23 | ||||
| 24 | Lev Stipakov (3): |
|||
| 25 | win32: Enforce loading of plugins from a trusted directory |
|||
| 26 | interactive.c: disable remote access to the service pipe |
|||
| 27 | interactive.c: Fix potential stack overflow issue |
|||
| 28 | ``` |
|||
| 29 | ||||
| 30 | # Changes in 2.5.9 |
|||
| 31 | ||||
| 32 | ``` |
|||
| 33 | Arne Schwabe (6): |
|||
| 34 | Implement optional cipher in --data-ciphers prefixed with ? |
|||
| 35 | Fix handling an optional invalid cipher at the end of data-ciphers |
|||
| 36 | Ensure that argument to parse_line has always space for final sentinel |
|||
| 37 | Improve documentation on user/password requirement and unicodize function |
|||
| 38 | Remove unused gc_arena |
|||
| 39 | Fix corner case that might lead to leaked file descriptor |
|||
| 40 | ||||
| 41 | Frank Lichtenheld (1): |
|||
| 42 | msvc: always call git-version.py |
|||
| 43 | ||||
| 44 | Gert Doering (1): |
|||
| 45 | Preparing release 2.5.9 |
|||
| 46 | ||||
| 47 | Lev Stipakov (1): |
|||
| 48 | git-version.py: proper support for tags |
|||
| 49 | ||||
| 50 | Max Fillinger (1): |
|||
| 51 | Check if pkcs11_cert is NULL before freeing it |
|||
| 52 | ||||
| 53 | Selva Nair (3): |
|||
| 54 | Do not add leading space to pushed options |
|||
| 55 | pull-filter: ignore leading "spaces" in option names |
|||
| 56 | Do not include auth-token in pulled option digest |
|||
| 57 | ``` |
|||
| 58 | ||||
| 59 | # Changes in 2.5.8 |
|||
| 60 | ||||
| 61 | ``` |
|||
| 62 | Antonio Quartulli (1): |
|||
| 63 | tls-crypt-v2: bail out if the client key is too small |
|||
| 64 | ||||
| 65 | Arne Schwabe (4): |
|||
| 66 | Remove useless empty line from CR_RESPONSE message |
|||
| 67 | Allow running a default configuration with TLS libraries without BF-CBC |
|||
| 68 | Change command help to match man page and implementation |
|||
| 69 | Fix OpenVPN querying user/password if auth-token with user expires |
|||
| 70 | ||||
| 71 | Frank Lichtenheld (2): |
|||
| 72 | t_client: Allow to force FAIL on prerequisite fails |
|||
| 73 | t_client.sh: do not require fping6 |
|||
| 74 | ||||
| 75 | Gert Doering (1): |
|||
| 76 | Preparing release 2.5.8 |
|||
| 77 | ||||
| 78 | Lev Stipakov (1): |
|||
| 79 | msvc: add branch name and commit hash to version output |
|||
| 80 | ||||
| 81 | Martin Janů (1): |
|||
| 82 | Update the replay-window backtrack log message |
|||
| 83 | ||||
| 84 | Selva Nair (6): |
|||
| 85 | Do not skip ERROR:/SUCCESS: response from management interface |
|||
| 86 | Fix auth-token usage with management-def-auth |
|||
| 87 | Allow a few levels of recursion in virtual_output_callback() |
|||
| 88 | Ensure --auth-nocache is handled during renegotiation |
|||
| 89 | Purge auth-token as well while purging passwords |
|||
| 90 | Do not copy auth_token username to itself |
|||
| 91 | ``` |
|||
| 92 | ||||
| 93 | # Changes in 2.5.7 |
|||
| 94 | ||||
| 95 | ``` |
|||
| 96 | Antonio Quartulli (4): |
|||
| 97 | networking: use OPENVPN_ETH_ALEN instead of ETH_ALEN |
|||
| 98 | networking_iproute2: don't pass M_WARN to openvpn_execve_check() |
|||
| 99 | t_net.sh: delete dummy iface using iproute command |
|||
| 100 | auth-pam.c: add missing include limits.h |
|||
| 101 | ||||
| 102 | Arne Schwabe (11): |
|||
| 103 | Add insecure tls-cert-profile options |
|||
| 104 | Refactor early initialisation and uninitialisation into methods |
|||
| 105 | Allow loading of non default providers |
|||
| 106 | Add ubuntu 22.04 to Github Actions |
|||
| 107 | Add macos OpenSSL 3.0 and ASAN builds |
|||
| 108 | Add --with-openssl-engine autoconf option (auto|yes|no) |
|||
| 109 | Fix allowing/showing unsupported ciphers and digests |
|||
| 110 | Remove dependency on BF-CBC existance from test_ncp |
|||
| 111 | Add message when decoding PKCS12 file fails. |
|||
| 112 | Translate OpenSSL 3.0 digest names to OpenSSL 1.1 digest names |
|||
| 113 | Fix client-pending-auth error message to say ERROR instead of SUCCESS |
|||
| 114 | ||||
| 115 | Gert Doering (1): |
|||
| 116 | Preparing release 2.5.7 |
|||
| 117 | ||||
| 118 | Jan Mikkelsen (1): |
|||
| 119 | cipher-negotiation.rst missing from doc/Makefile.am |
|||
| 120 | ||||
| 121 | Lev Stipakov (5): |
|||
| 122 | vcpkg-ports\pkcs11-helper: shorten patch filename |
|||
| 123 | msvc: adjust build options to harden binaries |
|||
| 124 | vcpkg-ports: remove openssl port |
|||
| 125 | vcpkg: switch to manifest |
|||
| 126 | Fix M_ERRNO behavior on Windows |
|||
| 127 | ||||
| 128 | Marc Becker (1): |
|||
| 129 | vcpkg-ports/pkcs11-helper: bump to release 1.29 |
|||
| 130 | ||||
| 131 | Simon Rozman (1): |
|||
| 132 | tapctl: Resolve MSVC C4996 warnings |
|||
| 133 | ``` |
|||
| 134 | ||||
| 135 | # Changes in 2.5.6 |
|||
| 136 | ||||
| 137 | ``` |
|||
| 138 | Antonio Quartulli (4): |
|||
| 139 | GitHub Actions: update script to same version as master |
|||
| 140 | update copyright year to 2022 |
|||
| 141 | keyingmaterialexporter.c: include strings.h |
|||
| 142 | remove unused sitnl.h file |
|||
| 143 | ||||
| 144 | David Sommerseth (2): |
|||
| 145 | sample-plugin: New plugin for testing multiple auth plugins |
|||
| 146 | plug-ins: Disallow multiple deferred authentication plug-ins |
|||
| 147 | ||||
| 148 | Frank Lichtenheld (2): |
|||
| 149 | doc/Makefile: rebuild rst docs if input files change |
|||
| 150 | doc/options: clean up documentation for --proto and related options |
|||
| 151 | ||||
| 152 | Gert Doering (4): |
|||
| 153 | fix Changes.rst errors in 2.5.3 and 2.5.5 announcement |
|||
| 154 | Repair --inactive with 'bytes' argument larger 2Gbytes. |
|||
| 155 | Fix --mtu-disc maybe|yes on Linux. |
|||
| 156 | Preparing release 2.5.6 |
|||
| 157 | ||||
| 158 | Ilya Shipitsin (1): |
|||
| 159 | CI: github actions: keep "pdb" in artifacts |
|||
| 160 | ||||
| 161 | Lev Stipakov (7): |
|||
| 162 | auth_token.c: add NULL initialization |
|||
| 163 | vcpkg-ports/pkcs11-helper: bump to release 1.28 |
|||
| 164 | vcpkg-ports/pkcs11-helper: indicate OpenSSL EC support |
|||
| 165 | msvc: cleanup |
|||
| 166 | vcpkg: link lzo statically |
|||
| 167 | vcpkg-ports/pkcs11-helper: adapt to new upstream URL |
|||
| 168 | vcpkg-ports: add openssl 1.1.1n |
|||
| 169 | ``` |
|||
| 170 | ||||
| 171 | # Changes in 2.5.5 |
|||
| 172 | ||||
| 173 | ``` |
|||
| 174 | Adrian (1): |
|||
| 175 | Fix error in example firewall.sh script |
|||
| 176 | ||||
| 177 | Antonio Quartulli (1): |
|||
| 178 | configure: remove useless -Wno-* from default CFLAGS |
|||
| 179 | ||||
| 180 | Arne Schwabe (2): |
|||
| 181 | Add argv_insert_head__empty_argv__head_only to argv tests |
|||
| 182 | Move deprecation of SWEET32/64bit block size ciphers to 2.7 |
|||
| 183 | ||||
| 184 | Gert Doering (4): |
|||
| 185 | Include --push-remove in the output of --help. |
|||
| 186 | Move '--push-peer-info' documentation from 'server' to 'client options' |
|||
| 187 | add test case(s) to notice 'openvpn --show-cipher' crashing |
|||
| 188 | Preparing release 2.5.5 |
|||
| 189 | ||||
| 190 | Ilya Shipitsin (1): |
|||
| 191 | BUILD: enable CFG and Spectre mitigation for MSVC |
|||
| 192 | ||||
| 193 | Lev Stipakov (12): |
|||
| 194 | Fix loading PKCS12 files on Windows |
|||
| 195 | msvc: fix product version display |
|||
| 196 | msvc: add missing header to project file |
|||
| 197 | config-msvc.h: fix OpenSSL-related defines |
|||
| 198 | contrib/vcpkg-ports: remove openssl port |
|||
| 199 | GitHub Actions: use latest working lukka/run-vcpkg |
|||
| 200 | Use network address for emulated DHCP server as a default |
|||
| 201 | Load OpenSSL config on Windows from trusted location |
|||
| 202 | ring_buffer.h: fix GCC warning about unused function |
|||
| 203 | ssh_openssl.h: remove unused declaration |
|||
| 204 | vcpkg/pkcs11-helper: compatibility with latest vcpkg |
|||
| 205 | config-msvc.h: indicate key material export support |
|||
| 206 | ||||
| 207 | Max Fillinger (2): |
|||
| 208 | Don't use BF-CBC in unit tests if we don't have it |
|||
| 209 | Define have_blowfish variable in ncp unit tests |
|||
| 210 | ||||
| 211 | Richard T Bonhomme (1): |
|||
| 212 | doc link-options.rst: Use free open-source dynamic-DNS provider URL |
|||
| 213 | ||||
| 214 | Selva Nair (3): |
|||
| 215 | Fix some more wrong defines in config-msvc.h |
|||
| 216 | Ensure the current common_name is in the environment for scripts |
|||
| 217 | Require EC key support in Windows builds |
|||
| 218 | ||||
| 219 | Sergio E. Nemirowski (1): |
|||
| 220 | resolvconf fails with -p |
|||
| 221 | ||||
| 222 | Todd Zullinger (2): |
|||
| 223 | Update IRC information in CONTRIBUTING.rst |
|||
| 224 | doc/man (vpn-network-options): fix foreign_option_{n} typo |
|||
| 225 | ||||
| 226 | Ville Skyttä (1): |
|||
| 227 | README.down-root: Fix plugin module name |
|||
| 228 | ``` |
|||
| 229 | ||||
| 230 | ||||
| 231 | # Changes in 2.5.4 |
|||
| 232 | ||||
| 233 | ``` |
|||
| 234 | Antonio Quartulli (3): |
|||
| 235 | route.c: pass the right parameter to IN6_IS_ADDR_UNSPECIFIED |
|||
| 236 | configure: search also for rst2{man, html}.py |
|||
| 237 | networking: add networking API net_addr_ll_set() and use it on Linux |
|||
| 238 | ||||
| 239 | Arne Schwabe (1): |
|||
| 240 | Move examples into openvpn-examples(5) man page |
|||
| 241 | ||||
| 242 | David Korczynski (1): |
|||
| 243 | Fix argv leaks in add_route() and add_route_ipv6() |
|||
| 244 | ||||
| 245 | David Sommerseth (2): |
|||
| 246 | doc: Use generic rules for man/html generation |
|||
| 247 | man: Clarify IV_HWADDR |
|||
| 248 | ||||
| 249 | Gert Doering (2): |
|||
| 250 | Add error reporting to get_console_input_win32(). |
|||
| 251 | Preparing release 2.5.4 |
|||
| 252 | ||||
| 253 | Lev Stipakov (3): |
|||
| 254 | Fix console prompts with redirected log |
|||
| 255 | Add building man page on Windows |
|||
| 256 | GitHub Actions: remove Ubuntu 16.04 environment |
|||
| 257 | ||||
| 258 | Max Fillinger (1): |
|||
| 259 | Update Fox e-mail address in copyright notices |
|||
| 260 | ||||
| 261 | Selva Nair (1): |
|||
| 262 | Minor doc correction: tls-crypt-v2 key generation |
|||
| 263 | ``` |
|||
| 264 | ||||
| 265 | # Changes in 2.5.3 |
|||
| 266 | ||||
| 267 | ``` |
|||
| 268 | Arne Schwabe (3): |
|||
| 269 | Add missing free_key_ctx for auth_token |
|||
| 270 | Add github actions |
|||
| 271 | Implement auth-token-user |
|||
| 272 | ||||
| 273 | David Sommerseth (1): |
|||
| 274 | Update copyrights |
|||
| 275 | ||||
| 276 | Gert Doering (1): |
|||
| 277 | Preparing release 2.5.3 |
|||
| 278 | ||||
| 279 | Lev Stipakov (8): |
|||
| 280 | openvpnmsica: properly schedule reboot in the end of installation |
|||
| 281 | msvc: add ARM64 configuration |
|||
| 282 | msvc: standalone building |
|||
| 283 | contrib/vcpkg-ports: add pkcs11-helper port |
|||
| 284 | vcpkg-ports: restore trailing whitespaces in .patch files |
|||
| 285 | GitHub actions: add MSVC build |
|||
| 286 | crypto_openssl.c: disable explicit initialization on Windows (CVE-2121-3606) |
|||
| 287 | contrib/vcpkg-ports: add openssl port with --no-autoload-config option set (CVE-2121-3606) |
|||
| 288 | ||||
| 289 | Matthias Andree (1): |
|||
| 290 | Fix SIGSEGV (NULL deref) receiving push "echo" |
|||
| 291 | ||||
| 292 | Max Fillinger (1): |
|||
| 293 | Fix build with mbedtls w/o SSL renegotiation support |
|||
| 294 | ||||
| 295 | Selva Nair (2): |
|||
| 296 | Improve documentation of AUTH_PENDING related directives |
|||
| 297 | Apply the connect-retry backoff to only one side of a connection |
|||
| 298 | ``` |
|||
| 299 | ||||
| 300 | # Changes in 2.5.2 |
|||
| 301 | ||||
| 302 | ``` |
|||
| 303 | Arne Schwabe (10): |
|||
| 304 | Avoid generating unecessary mbed debug messages |
|||
| 305 | Restore also ping related options on a reconnect |
|||
| 306 | Cleanup print_details and add signature/ED certificate print |
|||
| 307 | Always disable TLS renegotiations |
|||
| 308 | Also restore/save route-gateway options on SIGUSR1 reconnects |
|||
| 309 | Move context_auth from context_2 to tls_multi and name it multi_state |
|||
| 310 | Fix condition to generate session keys |
|||
| 311 | Move auth_token_state from multi to key_state |
|||
| 312 | Ensure auth-token is only sent on a fully authenticated session |
|||
| 313 | Ensure key state is authenticated before sending push reply |
|||
| 314 | ||||
| 315 | Gert Doering (2): |
|||
| 316 | Fix potential NULL ptr crash if compiled with DMALLOC |
|||
| 317 | Preparing release 2.5.2 |
|||
| 318 | ||||
| 319 | Max Fillinger (2): |
|||
| 320 | In init_ssl, open the correct CRL path pre-chroot |
|||
| 321 | Abort if CRL file can't be stat-ed in ssl_init |
|||
| 322 | ||||
| 323 | Richard Bonhomme (1): |
|||
| 324 | Do not print Diffie Hellman parameters file to log file |
|||
| 325 | ||||
| 326 | Simon Rozman (1): |
|||
| 327 | openvpnserv: Cache last error before it is overridden |
|||
| 328 | ||||
| 329 | Vladislav Grishenko (1): |
|||
| 330 | Fix IPv4 default gateway with multiple route tables |
|||
| 331 | ``` |
|||
| 332 | ||||
| 333 | # Changes in 2.5.1 |
|||
| 334 | ||||
| 335 | ``` |
|||
| 336 | Arne Schwabe (5): |
|||
| 337 | Fix auth-token not being updated if auth-nocache is set |
|||
| 338 | Remove auth_user_pass.wait_for_push variable |
|||
| 339 | Fix port-share option with TLS-Crypt v2 |
|||
| 340 | Zero initialise msghdr prior to calling sendmesg |
|||
| 341 | Fix tls-auth mismatch OCC message when tls-cryptv2 is used. |
|||
| 342 | ||||
| 343 | David Sommerseth (1): |
|||
| 344 | build: Fix missing install of man page in certain environments |
|||
| 345 | ||||
| 346 | Domagoj Pensa (3): |
|||
| 347 | Fix too early argv freeing when registering DNS |
|||
| 348 | Remove 1 second delay before running netsh |
|||
| 349 | Skip DHCP renew with Wintun adapter |
|||
| 350 | ||||
| 351 | Gert Doering (7): |
|||
| 352 | Change travis build scripts to use https when fetching prerequisites. |
|||
| 353 | Fix line number reporting on config file errors after <inline> segments |
|||
| 354 | Clarify --block-ipv6 intent and direction. |
|||
| 355 | Document common uses of 'echo' directive, re-enable logging for 'echo'. |
|||
| 356 | Make OPENVPN_PLUGIN_ENABLE_PF failures FATAL |
|||
| 357 | clean up / rewrite sample-plugins/defer/simple.c |
|||
| 358 | Preparing release 2.5.1 |
|||
| 359 | ||||
| 360 | Greg Cox (5): |
|||
| 361 | Fix naming error in sample-plugins/defer/simple.c |
|||
| 362 | Documentation fixes around openvpn_plugin_func_v3 in openvpn-plugin.h.in |
|||
| 363 | Update openvpn_plugin_func_v2 to _v3 in sample-plugins/defer/simple.c |
|||
| 364 | More explicit versioning compatibility in sample-plugins/defer/simple.c |
|||
| 365 | Explain structver usage in sample defer plugin. |
|||
| 366 | ||||
| 367 | Richard Bonhomme (1): |
|||
| 368 | Man page sections corrections |
|||
| 369 | ||||
| 370 | Selva Nair (1): |
|||
| 371 | Quote the domain name argument passed to the wmic command |
|||
| 372 | ||||
| 373 | Steffan Karger (2): |
|||
| 374 | tls-crypt-v2: fix server memory leak |
|||
| 375 | tls-crypt-v2: also preload tls-crypt-v2 keys (if --persist-key) |
|||
| 376 | ``` |
|||
| 377 | ||||
| 378 | # Changes in 2.5.0 |
|||
| 379 | ||||
| 380 | ``` |
|||
| 381 | Gert Doering (1): |
|||
| 382 | Preparing release 2.5.0 |
|||
| 383 | ``` |
|||
| 384 | ||||
| 385 | # Changes in 2.5_rc3 |
|||
| 386 | ||||
| 387 | ``` |
|||
| 388 | Arne Schwabe (2): |
|||
| 389 | Allow 'none' cipher being specified in --data-ciphers |
|||
| 390 | Add function for common env setting of verify user/pass calls |
|||
| 391 | ||||
| 392 | David Sommerseth (1): |
|||
| 393 | compat/lz4: Update to v1.9.2 |
|||
| 394 | ||||
| 395 | Gert Doering (3): |
|||
| 396 | Fix redirecting of IPv4 default gateway if connecting over IPv6. |
|||
| 397 | Avoid passing NULL to argv_printf_cat() in temp_file error case. |
|||
| 398 | Preparing release 2.5_rc3 |
|||
| 399 | ||||
| 400 | Jan Seeger (1): |
|||
| 401 | Added 'route_ipv6_metric_NN' environment variable for IPv6 route metric. |
|||
| 402 | ||||
| 403 | Richard Bonhomme (1): |
|||
| 404 | Improve error msg when all TAP adapters are in use 'or disabled' |
|||
| 405 | ||||
| 406 | Steffan Karger (1): |
|||
| 407 | networking_iproute2: fix memory leak in net_iface_mtu_set() |
|||
| 408 | ||||
| 409 | Vladislav Grishenko (2): |
|||
| 410 | Selectively reformat too long lines |
|||
| 411 | Speedup TCP remote hosts connections |
|||
| 412 | ``` |
|||
| 413 | ||||
| 414 | # Changes in 2.5_rc2 |
|||
| 415 | ||||
| 416 | ``` |
|||
| 417 | Gert Doering (1): |
|||
| 418 | Preparing release 2.5_rc2 |
|||
| 419 | ||||
| 420 | Lev Stipakov (1): |
|||
| 421 | Alias ADAPTER_DOMAIN_SUFFIX to DOMAIN |
|||
| 422 | ||||
| 423 | Selva Nair (2): |
|||
| 424 | Set DNS Domain using iservice |
|||
| 425 | Improve documentation of --username-as-common-name |
|||
| 426 | ||||
| 427 | Simon Rozman via Openvpn-devel (4): |
|||
| 428 | netsh: Specify interfaces by index rather than name |
|||
| 429 | netsh: Clear existing IPv6 DNS servers before configuring new ones |
|||
| 430 | netsh: Delete WINS servers on TUN close |
|||
| 431 | openvpnmsica: Simplify find_adapters() to void return |
|||
| 432 | ||||
| 433 | Vladislav Grishenko (1): |
|||
| 434 | Fix update_time() and openvpn_gettimeofday() coexistence |
|||
| 435 | ``` |
|||
| 436 | ||||
| 437 | # Changes in 2.5_rc1 |
|||
| 438 | ||||
| 439 | ``` |
|||
| 440 | David Sommerseth (4): |
|||
| 441 | man: Add missing --server-ipv6 |
|||
| 442 | man: Improve --remote entry |
|||
| 443 | sample-plugins: Partially autotoolize the sample-plugins build |
|||
| 444 | build: Fix make distclean/distcheck |
|||
| 445 | ||||
| 446 | Gert Doering (11): |
|||
| 447 | Fix handling of 'route remote_host' for IPv6 transport case. |
|||
| 448 | Replace 'echo -n' with 'printf' in tests/t_lpback.sh |
|||
| 449 | Fix description of --client-disconnect calling convention in manpage. |
|||
| 450 | Handle NULL returns from calloc() in sample plugins. |
|||
| 451 | Fix --show-gateway for IPv6 on NetBSD/i386. |
|||
| 452 | socks.c: fix alen for DOMAIN type addresses, bump up buffer sizes |
|||
| 453 | Fix netbits setting (in TAP mode) for IPv6 on Windows. |
|||
| 454 | If IPv6 pool specification sets pool start to ::0 address, increment. |
|||
| 455 | Add demo plugin that excercises "CLIENT_CONNECT" and "CLIENT_CONNECT_V2" paths |
|||
| 456 | Fix combination of --dev tap and --topology subnet across multiple platforms. |
|||
| 457 | Preparing release 2.5_rc1 |
|||
| 458 | ||||
| 459 | Lev Stipakov (1): |
|||
| 460 | msvc: better support for 32bit architecture |
|||
| 461 | ||||
| 462 | Selva Nair (2): |
|||
| 463 | Add a remark on dropping privileges when --mlock is used |
|||
| 464 | Allow --dhcp-option in config file when windows-driver is wintun |
|||
| 465 | ||||
| 466 | Vladislav Grishenko (1): |
|||
| 467 | Fix fatal error at switching remotes (#629) |
|||
| 468 | ``` |
|||
| 469 | ||||
| 470 | # Changes in 2.5_beta4 |
|||
| 471 | ||||
| 472 | ``` |
|||
| 473 | Gert Doering (4): |
|||
| 474 | Document that --push-remove is generally more suitable than --push-reset |
|||
| 475 | Fix error detection / abort in --inetd corner case. |
|||
| 476 | Fix TUNSETGROUP compatibility with very old Linux systems. |
|||
| 477 | Preparing release 2.5_beta4 |
|||
| 478 | ||||
| 479 | Lev Stipakov (1): |
|||
| 480 | openvpnmsica: make adapter renaming non-fatal |
|||
| 481 | ||||
| 482 | Selva Nair (1): |
|||
| 483 | In tap.c use DiInstallDevice to install the driver on a new adapter |
|||
| 484 | ||||
| 485 | Vladislav Grishenko (1): |
|||
| 486 | Fix best gateway selection over netlink |
|||
| 487 | ``` |
|||
| 488 | ||||
| 489 | # Changes in 2.5_beta3 |
|||
| 490 | ||||
| 491 | ``` |
|||
| 492 | Arne Schwabe (1): |
|||
| 493 | Fix client NCP OCC fallback when server and client cipher are identical |
|||
| 494 | ||||
| 495 | Gert Doering (1): |
|||
| 496 | Preparing release 2.5_beta3 |
|||
| 497 | ``` |
|||
| 498 | ||||
| 499 | # Changes in 2.5_beta2 |
|||
| 500 | ||||
| 501 | ``` |
|||
| 502 | Arne Schwabe (1): |
|||
| 503 | Fix client's poor man NCP fallback |
|||
| 504 | ||||
| 505 | Eric Thorpe (1): |
|||
| 506 | Fixes a bug in management_callback_send_cc_message, should be strlen instead of sizeof |
|||
| 507 | ||||
| 508 | Gert Doering (3): |
|||
| 509 | Fix stack overflow in OpenSolaris NEXTADDR() |
|||
| 510 | Workaround FreeBSD 12+ race condition on tun/tap open with IPv6. |
|||
| 511 | Preparing release 2.5_beta2 |
|||
| 512 | ||||
| 513 | Lev Stipakov (1): |
|||
| 514 | tun.c: enable using wintun driver under SYSTEM |
|||
| 515 | ||||
| 516 | Magnus Kroken (2): |
|||
| 517 | doc: fix typos in cipher-negotiation.rst |
|||
| 518 | Changes.rst: fix mistyped option names |
|||
| 519 | ||||
| 520 | Selva Nair (1): |
|||
| 521 | Improve the documentation for --dhcp-option |
|||
| 522 | ``` |
|||
| 523 | ||||
| 524 | # Changes in 2.5_beta1 |
|||
| 525 | ||||
| 526 | Changes since OpenVPN 2.4.0: |
|||
| 527 | ||||
| 528 | ``` |
|||
| 529 | Adam Ciarciński (1): |
|||
| 530 | Fix subnet topology on NetBSD. |
|||
| 531 | ||||
| 532 | Antonio Quartulli (113): |
|||
| 533 | attempt to add IPv6 route even when no IPv6 address was configured |
|||
| 534 | fix redirect-gateway behaviour when an IPv4 default route does not exist |
|||
| 535 | CRL: use time_t instead of struct timespec to store last mtime |
|||
| 536 | ignore remote-random-hostname if a numeric host is provided |
|||
| 537 | Ignore auth-nocache for auth-user-pass if auth-token is pushed |
|||
| 538 | crypto: correct typ0 in error message |
|||
| 539 | use M_ERRNO instead of explicitly printing errno |
|||
| 540 | don't print errno twice |
|||
| 541 | ntlm: avoid useless cast |
|||
| 542 | ntlm: unwrap multiple function calls |
|||
| 543 | route: improve error message |
|||
| 544 | management: preserve wait_for_push field when asking for user/pass |
|||
| 545 | tls-crypt: avoid warnings when --disable-crypto is used |
|||
| 546 | ntlm: convert binary buffers to uint8_t * |
|||
| 547 | ntlm: restyle compressed multiple function calls |
|||
| 548 | ntlm: improve code style and readability |
|||
| 549 | OpenSSL: remove unreachable call to SSL_CTX_get0_privatekey() |
|||
| 550 | make function declarations C99 compliant |
|||
| 551 | remove unused functions |
|||
| 552 | use NULL instead of 0 when assigning pointers |
|||
| 553 | add missing static attribute to functions |
|||
| 554 | ntlm: avoid breaking anti-aliasing rules |
|||
| 555 | remove the --disable-multi config switch |
|||
| 556 | rename mroute_extract_addr_ipv4 to mroute_extract_addr_ip |
|||
| 557 | route: avoid definition of unused variables in certain configurations |
|||
| 558 | fix a couple of typ0s in comments and strings |
|||
| 559 | fragment.c: simplify boolean expression |
|||
| 560 | tcp-server: ensure AF family is propagated to child context |
|||
| 561 | Remove ENABLE_CRYPTO |
|||
| 562 | Remove option to disable crypto engine |
|||
| 563 | Remove ENABLE_PUSH_PEER_INFO |
|||
| 564 | Remove SSL_LIB_VER_STR |
|||
| 565 | Remove MD5SUM |
|||
| 566 | reload HTTP proxy credentials when moving to the next connection profile |
|||
| 567 | Allow learning iroutes with network made up of all 0s (only if netbits < 8) |
|||
| 568 | mbedtls: fix typ0 in comment |
|||
| 569 | manpage: fix simple typ0 |
|||
| 570 | pool: restyle ipv4/ipv6 members to improve readability |
|||
| 571 | pool: convert pool 'type' to enum |
|||
| 572 | tun: ensure gc and argv are properly handled |
|||
| 573 | tun: always pass a valid tt pointer |
|||
| 574 | tun: get rid of tt->did_ifconfig member |
|||
| 575 | tun: ensure interface can be configured with IPv6 only |
|||
| 576 | add support for %lu in argv_printf and prevent ASSERT |
|||
| 577 | windows: properly configure TAP driver when no IPv4 is configured |
|||
| 578 | socket: make stream_buf_* functions static |
|||
| 579 | crypto: always reload tls-auth/crypt key contexts |
|||
| 580 | make tls-auth and tls-crypt per-connection-block options |
|||
| 581 | pf: restyle pf_c2c/addr_test() to make them 'struct context' agnostic |
|||
| 582 | merge *-inline.h files with their main header |
|||
| 583 | ensure function declarations are compiled with their definitions |
|||
| 584 | buffer_list: add functions documentation |
|||
| 585 | ifconfig-ipv6(-push): allow using hostnames |
|||
| 586 | tls-crypt: properly cast time_t to uint64_t |
|||
| 587 | implement platform generic networking API |
|||
| 588 | implement networking API for iproute2 |
|||
| 589 | introduce sitnl: Simplified Interface To NetLink |
|||
| 590 | tun.c: use new networking API to handle tun interface on Linux |
|||
| 591 | travis.yml: add test for iproute2 net implementation |
|||
| 592 | route.c: use new networking API to handle routing table on Linux |
|||
| 593 | unit tests: implement test for sitnl |
|||
| 594 | t_net.sh: make bash dep explicit and run only if SITNL is compiled |
|||
| 595 | t_net.sh: properly perform sudo check and print test steps |
|||
| 596 | route.c: fix windows build by removing mismatching function parameter |
|||
| 597 | t_net.sh: fixes for the networking test script |
|||
| 598 | route.c: use sitnl to implement get_default_gateway_ipv6() |
|||
| 599 | networking/best_gw: remove useless prefixlen parameter |
|||
| 600 | sitnl: harden strncpy() by forcing arguments to have the same length |
|||
| 601 | mbedtls: fix segfault by calling mbedtls_cipher_free() in cipher_ctx_free() |
|||
| 602 | networking: extend API for better memory management |
|||
| 603 | tun.c: undo_ifconfig_ipv4/6 remove useless gc argument |
|||
| 604 | networking_sitnl.c: uncrustify file |
|||
| 605 | route.c: simplify ifdef logic |
|||
| 606 | t_net.sh: wait for NO-CARRIER bit to settle before starting test |
|||
| 607 | t_net.sh: execute sleep after checking exit code of previous command |
|||
| 608 | maddr: create helper function to populate maddr object from eth_addr |
|||
| 609 | VLAN: add basic VLAN tagging support |
|||
| 610 | maddr: export VLAN ID from client context to maddr object |
|||
| 611 | VLAN: filter multicast and client-to-client unicast traffic |
|||
| 612 | is_ipv_X: add support for parsing IP header inside a 802.1q frame |
|||
| 613 | VLAN: implement support for forwarding only pre-tagged VLAN packets |
|||
| 614 | VLAN: allow forwarding tagged and untagged packets on the server TAP device |
|||
| 615 | VLAN: add documentation to manpage |
|||
| 616 | socks: use the right function when printing struct openvpn_sockaddr |
|||
| 617 | add -Wno-stringop-truncation to CFLAGS on linux |
|||
| 618 | get rid of 'broadcast' argument when configuring the tun device |
|||
| 619 | auth_token_kt: ensure key_type object is initialized |
|||
| 620 | auth.c: make cast explicit in the crypto API |
|||
| 621 | travis: compile with -Werror on Linux |
|||
| 622 | travis: fix CFLAGS assignment error and add -Werror only when compiling on Linux for Linux |
|||
| 623 | sitnl: fix failure reporting by keeping error negative |
|||
| 624 | sitnl: fix TUN/TAP confusion in error messages |
|||
| 625 | sitnl: fix ignoring EEXIST when sending a netlink command |
|||
| 626 | t_net.sh: use dummy interface instead of tun |
|||
| 627 | remove bogus file check on --genkey argument |
|||
| 628 | t_net.sh: assign MAC address directly during interface creation |
|||
| 629 | convert *_inline attributes to bool |
|||
| 630 | options: fix inlining auth-gen-token-secret file |
|||
| 631 | tls-crypt-v2: fix testing of inline key |
|||
| 632 | get rid of INLINE_FILE_TAG constant |
|||
| 633 | pool: prevent IPv6 pools to be larger than 2^16 addresses |
|||
| 634 | pool: allow to configure an IPv6-only ifconfig-pool |
|||
| 635 | allow usage of --server-ipv6 even when no --server is specified |
|||
| 636 | pool: add support for ifconfig-pool-persist with IPv6 only |
|||
| 637 | route: warn on IPv4 routes installation when no IPv4 is configured |
|||
| 638 | options: enable IPv4 redirection logic only if really required |
|||
| 639 | ipv6-pool: get rid of size constraint |
|||
| 640 | pool: remove useless 'options.h' include |
|||
| 641 | multi: skip IPv4 logic in multi_select_virtual_addr() if no pool is configured |
|||
| 642 | multi.c: use mi->cc_config instead of config variable |
|||
| 643 | options: don't leak inline'd key material in logfile |
|||
| 644 | t_net.sh: drop hard dependency on t_client.rc |
|||
| 645 | travis: don't run t_net.sh test |
|||
| 646 | ||||
| 647 | Arne Schwabe (124): |
|||
| 648 | Set tls-cipher restriction before loading certificates |
|||
| 649 | Print ec bit details, refuse management-external-key if key is not RSA |
|||
| 650 | Replace buffer backed strings for management_android_control with simple stack variables |
|||
| 651 | Treat dhcp-option DNS6 and DNS identical |
|||
| 652 | show the right string for key-direction |
|||
| 653 | Add MTU to Android IFCONFIG6 control command |
|||
| 654 | Properly free tuntap struct on android when emulating persist-tun |
|||
| 655 | Add OpenSSL compat definition for RSA_meth_set_sign |
|||
| 656 | Skip error about ioctl(SIOCGIFCONF) failed on Android |
|||
| 657 | Factor out convert_tls_list_to_openssl method |
|||
| 658 | Remove AUTO_USERID feature |
|||
| 659 | Remove MANAGMENT_EXTERNAL_KEY, MANAGMENT_IN_EXTRA, ENABLE_CLIENT_CR |
|||
| 660 | Add support for tls-ciphersuites for TLS 1.3 |
|||
| 661 | Add better support for showing TLS 1.3 ciphersuites in --show-tls |
|||
| 662 | Use right function to set TLS1.3 restrictions in show-tls |
|||
| 663 | Refuse mbed TLS external key with non RSA certificates |
|||
| 664 | Add message explaining early TLS client hello failure |
|||
| 665 | Add tls-crypt-v2 to the list of supported inline options |
|||
| 666 | Implement block-ipv6 |
|||
| 667 | Fallback to password authentication when auth-token fails |
|||
| 668 | Fix loading inline tls-crypt-v2 keys with mbed TLS |
|||
| 669 | Refactor tls_crypt_v2_write_server_key_file into crypto.c |
|||
| 670 | Add send_control_channel_string_dowork variant |
|||
| 671 | Rename tls_crypt_v2_read_keyfile into generic pem_read_key_file |
|||
| 672 | Fix poll.h logic in syshead.h |
|||
| 673 | Write key to stdout if filename is not given |
|||
| 674 | Implement --genkey type keyfile syntax and migrate tls-crypt-v2 |
|||
| 675 | Add generate_ephemeral_key that allows a random ephermal key |
|||
| 676 | Remove -no-cpp-precomp flag from Darwin builds |
|||
| 677 | Fix check if iface name is set |
|||
| 678 | Adjust Android code after sitnl patch merge |
|||
| 679 | Rewrite auth-token-gen to be based on HMAC based tokens |
|||
| 680 | Implement a permanent session id in auth-token |
|||
| 681 | Sent indication that a session is expired to clients |
|||
| 682 | Implement unit tests for auth-gen-token |
|||
| 683 | Make tls_version_max return the actual maximum version |
|||
| 684 | Add support for OpenSSL TLS 1.3 when using management-external-key |
|||
| 685 | Document tls-ciphersuites also in --help output |
|||
| 686 | Only announce IV_NCP=2 when we are willing to support these ciphers |
|||
| 687 | Add strsep compat function |
|||
| 688 | Implement dynamic NCP negotiation |
|||
| 689 | Warn about insecure ciphers also in init_key_type |
|||
| 690 | Move NCP related function into a seperate file and add unit tests |
|||
| 691 | Normalise ncp-ciphers option and restrict it to 127 bytes |
|||
| 692 | Fetch OpenSSL versions via source/old links |
|||
| 693 | Fix OpenSSL error stack handling of tls_ctx_add_extra_certs |
|||
| 694 | Fix off-by-one in tls-crypt-v2 client wrapping with custom metadata |
|||
| 695 | Fix OpenSSL 1.1.1 not using auto elliptic curve selection |
|||
| 696 | Refactor counting number of element in a : delimited list into function |
|||
| 697 | Minor style change to improve code style |
|||
| 698 | Another round of uncrustify code cleanup. |
|||
| 699 | Fix tls_ctx_client/server_new leaving error on OpenSSL error stack |
|||
| 700 | Add tls-crypt-v2 test writing metadata |
|||
| 701 | Use crypto library functions for const time memcmp when possible |
|||
| 702 | Fix session id in env missing first byte |
|||
| 703 | Document reneweal mechanic of auth-token in manual |
|||
| 704 | Fix session id and initial timestamp not being preserved |
|||
| 705 | Do not write extra 0 byte for --gen-key with auth-token/tls-crypt-v2 |
|||
| 706 | Refuse server mode on Android |
|||
| 707 | Add .git-blame-ignore-revs with reformat commits |
|||
| 708 | Make cipher_kt_name always return normalised cipher name |
|||
| 709 | Make cipher_kt_get also accept OpenVPN config cipher name |
|||
| 710 | Implement parsing and sending INFO and INFO_PRE control messages |
|||
| 711 | Implement support for signalling IV_SSO to server |
|||
| 712 | Implement sending response to challenge via CR_RESPONSE |
|||
| 713 | Implement sending AUTH_PENDING challenges to clients |
|||
| 714 | Implement forwarding client CR_RESPONSE messages to management |
|||
| 715 | Add unit test for cipher name translations |
|||
| 716 | Make compression asymmetric by default and add warnings |
|||
| 717 | Reformat files using uncrustify |
|||
| 718 | Remove parameter config from multi_client_connect_mda |
|||
| 719 | Remove push_reply_deferred variable |
|||
| 720 | Remove did_open_context, defined and connection_established_flag |
|||
| 721 | merge key_state->authenticated and key_state->auth_deferred |
|||
| 722 | Simplify multi_connection_established. |
|||
| 723 | Deprecate ncp-disable and add improved ncp to Changes.rst |
|||
| 724 | Make key_state->authenticated more state machine like |
|||
| 725 | Extract process_incoming_push_reply from process_incoming_push_msg |
|||
| 726 | Removed unused definition |
|||
| 727 | Code cleanup: remove superflous variable |
|||
| 728 | Move protocol option negotiation from push_prepare to new function |
|||
| 729 | Generate data channel keys after connect options have been parsed |
|||
| 730 | Cleanup: Remove special case code for old poor man's NCP. |
|||
| 731 | Allow changing fallback cipher from ccd files/client-connect |
|||
| 732 | client-connect: Change cas_context from int to enum |
|||
| 733 | client-connect: Move adding inotify watch into its own function |
|||
| 734 | reformat multi_client_generate_tls_keys according to uncrustify |
|||
| 735 | client-connect: Add CC_RET_DEFERRED and cope with deferred client-connect |
|||
| 736 | Remove CAS_PARTIAL state |
|||
| 737 | client-connect: Use inotify for the deferred client-connect status file |
|||
| 738 | client-connect: Implement deferred connect support for plugin API v2 |
|||
| 739 | Drop support for OpenSSL 1.0.1 |
|||
| 740 | Require AEAD support in the crypto library |
|||
| 741 | Remove key-method 1 |
|||
| 742 | Remove ENABLE_OCC #define |
|||
| 743 | Implement tls-groups option to specify eliptic curves/groups |
|||
| 744 | Avoid sending --cipher to clients not supporting NCP |
|||
| 745 | Indicate that a client is in pull mode in IV_PROTO |
|||
| 746 | Deprecate --inetd |
|||
| 747 | Include utun device number in utun error messages |
|||
| 748 | Simplify calling logic of check_connection_established_dowork |
|||
| 749 | Avoid sending push request after receving push reply |
|||
| 750 | Rename ncp-ciphers to data-ciphers |
|||
| 751 | Add a note that ncp-ciphers is replaced by data-ciphers |
|||
| 752 | client-connect: Add documentation for the deferred client connect feature |
|||
| 753 | Rework NCP compability logic and drop BF-CBC support by default |
|||
| 754 | Document different behaviour of dynamic cipher negotiation |
|||
| 755 | Minor cleanup in push.c |
|||
| 756 | Clean up a number of leftover C89 initialisations in ssl.c |
|||
| 757 | Remove buf argument from link_socket_set_outgoing_addr |
|||
| 758 | Remove a number of check/do_work wrapper calls from coarse_timers |
|||
| 759 | Split pf_check_reload check and check timer in process_coarse_timers |
|||
| 760 | Rename check_ping_restart_dowork to trigger_ping_timeout_signal |
|||
| 761 | Eliminate check_fragment function |
|||
| 762 | Eliminate check_incoming_control_channel wrapper function |
|||
| 763 | Eliminate check_tls wrapper function |
|||
| 764 | Merge check_coarse_timers and check_coarse_timers_dowork |
|||
| 765 | Skip existing interfaces on opening the first available utun on macOS |
|||
| 766 | Move parsing IV_PROTO to separate function |
|||
| 767 | Remove S_OP_NORMAL key state. |
|||
| 768 | Document comp-lzo no and compress being incompatible |
|||
| 769 | Refactor/Reformat tls_pre_decrypt |
|||
| 770 | Cleanup tls_pre_decrypt_lite and tls_pre_encrypt |
|||
| 771 | Improve sections about older OpenVPN clients in cipher-negotiation.rst |
|||
| 772 | ||||
| 773 | Bertrand Bonnefoy-Claudet (1): |
|||
| 774 | Fix typo in error message: "optione" -> "option" |
|||
| 775 | ||||
| 776 | Christian Ehrhardt (1): |
|||
| 777 | systemd: extend CapabilityBoundingSet for auth_pam |
|||
| 778 | ||||
| 779 | Christian Hesse (7): |
|||
| 780 | man: fix formatting for alternative option |
|||
| 781 | systemd: Use automake tools to install unit files |
|||
| 782 | systemd: Do not race on RuntimeDirectory |
|||
| 783 | systemd: Add more security feature for systemd units |
|||
| 784 | Clean up plugin path handling |
|||
| 785 | plugin: Remove GNUism in openvpn-plugin.h generation |
|||
| 786 | fix typo in notification message |
|||
| 787 | ||||
| 788 | Christopher Schenk (3): |
|||
| 789 | Set the correct mtu on windows based systems |
|||
| 790 | Log a note if someone wants to set a MTU below 1280 on IPv6 |
|||
| 791 | Unified success messages for setting mtu |
|||
| 792 | ||||
| 793 | Conrad Hoffmann (2): |
|||
| 794 | Use provided env vars in up/down script. |
|||
| 795 | Document down-root plugin usage in client.down |
|||
| 796 | ||||
| 797 | David Sommerseth (72): |
|||
| 798 | dev-tools: Added script for updating copyright years in files |
|||
| 799 | dev-tools: Added script for updating copyright years in files |
|||
| 800 | Update copyrights |
|||
| 801 | Update copyrights |
|||
| 802 | docs: Further enhance the documentation related to SWEET32 |
|||
| 803 | docs: Further enhance the documentation related to SWEET32 |
|||
| 804 | man: Remove references to no longer present IV_RGI6 peer-info |
|||
| 805 | man: Remove references to no longer present IV_RGI6 peer-info |
|||
| 806 | build: Ensure Changes.rst is shipped and installed as a doc file |
|||
| 807 | build: Ensure Changes.rst is shipped and installed as a doc file |
|||
| 808 | Preparing OpenVPN v2.4.0 release |
|||
| 809 | management: >REMOTE operation would overwrite ce change indicator |
|||
| 810 | management: Remove a redundant #ifdef block |
|||
| 811 | git: Merge .gitignore files into a single file |
|||
| 812 | systemd: Move the READY=1 signalling to an earlier point |
|||
| 813 | dev-tools: Simple tool which automates rebasing LZ4 compat library |
|||
| 814 | dev-tools: lz4-rebaser tool carried a typo |
|||
| 815 | plugin: Improve the handling of default plug-in directory |
|||
| 816 | cleanup: Remove faulty env processing functions |
|||
| 817 | auth-token: Ensure tokens are always wiped on de-auth |
|||
| 818 | docs: Fixed man-page warnings discoverd by rpmlint |
|||
| 819 | Make --cipher/--auth none more explicit on the risks |
|||
| 820 | Require minimum OpenSSL 1.0.1 |
|||
| 821 | Fix broken ./configure on systems without openssl.pc |
|||
| 822 | plugin: Fix documentation typo for type_mask |
|||
| 823 | plugin: Export secure_memzero() to plug-ins |
|||
| 824 | crypto: Enable SHA256 fingerprint checking in --verify-hash |
|||
| 825 | copyright: Update GPLv2 license texts |
|||
| 826 | dev-tools: Script generating the source releases in an automated fashion |
|||
| 827 | auth-token with auth-nocache fix broke --disable-crypto builds |
|||
| 828 | doc: The CRL processing is not a deprecated feature |
|||
| 829 | cleanup: Move write_pid() to where it is being used |
|||
| 830 | contrib: Remove keychain-mcd code |
|||
| 831 | cleanup: Move init_random_seed() to where it is being used |
|||
| 832 | Highlight deprecated features |
|||
| 833 | Use consistent version references |
|||
| 834 | docs: Replace all PolarSSL references to mbed TLS |
|||
| 835 | systemd: Ensure systemd shuts down OpenVPN in a proper way |
|||
| 836 | systemd: Enable systemd's auto-restart feature for server profiles |
|||
| 837 | lz4: Move towards a newer LZ4 API |
|||
| 838 | lz4: Fix confused version check |
|||
| 839 | lz4: Fix broken builds when pkg-config is not present but system library is |
|||
| 840 | Remove references to keychain-mcd in Changes.rst |
|||
| 841 | lz4: Rebase compat-lz4 against upstream v1.7.5 |
|||
| 842 | systemd: Add and ship README.systemd |
|||
| 843 | Update copyright to include 2018 plus company name change |
|||
| 844 | man: Add .TQ groff support macro |
|||
| 845 | man: Reword --management to prefer unix sockets over TCP |
|||
| 846 | management: Warn if TCP port is used without password |
|||
| 847 | plugin: Export base64 encode and decode functions |
|||
| 848 | build: Fix build warnings related to get_random() |
|||
| 849 | build: Fix another compile warning in console_systemd.c |
|||
| 850 | cleanup: Remove RPM openvpn.spec build approach |
|||
| 851 | docs: Update INSTALL |
|||
| 852 | build: Package missing mock_msg.h |
|||
| 853 | auth-token: Fix building with --disable-server |
|||
| 854 | auth-token: Fix compiler complaints with --disable-management |
|||
| 855 | Improve the comments related to auth-token-hmac patches |
|||
| 856 | Documented all the argv related code with minor refactoring |
|||
| 857 | build: Remove --disable-server from ./configure |
|||
| 858 | options: Fix failing inline tls-auth/crypt with persist-key |
|||
| 859 | options: Restore --tls-crypt-v2 inline file capability |
|||
| 860 | doc/man: convert openvpn.8 to split-up .rst files |
|||
| 861 | doc/man: Mark compression options as deprecated |
|||
| 862 | doc/man: Adopt compression documentation |
|||
| 863 | doc/man: Documentation for --bind-dev / VRFs on Linux |
|||
| 864 | doc/man: Add misssing renegotiation.rst to Makefile.am |
|||
| 865 | Remove --no-iv |
|||
| 866 | doc/man: Do not install man *.rst files |
|||
| 867 | travis: Fix make distcheck failure |
|||
| 868 | Remove --ifconfig-pool-linear |
|||
| 869 | Remove --client-cert-not-required |
|||
| 870 | ||||
| 871 | Domagoj Pensa (2): |
|||
| 872 | Fix linking issues on MinGW |
|||
| 873 | Skip DNS address validation |
|||
| 874 | ||||
| 875 | Emmanuel Deloget (20): |
|||
| 876 | OpenSSL: check for the SSL reason, not the full error |
|||
| 877 | OpenSSL: don't use direct access to the internal of X509_STORE_CTX |
|||
| 878 | OpenSSL: don't use direct access to the internal of SSL_CTX |
|||
| 879 | OpenSSL: don't use direct access to the internal of X509_STORE |
|||
| 880 | OpenSSL: don't use direct access to the internal of X509_OBJECT |
|||
| 881 | OpenSSL: don't use direct access to the internal of RSA_METHOD |
|||
| 882 | OpenSSL: SSLeay symbols are no longer available in OpenSSL 1.1 |
|||
| 883 | OpenSSL: use EVP_CipherInit_ex() instead of EVP_CipherInit() |
|||
| 884 | OpenSSL: don't use direct access to the internal of X509 |
|||
| 885 | OpenSSL: don't use direct access to the internal of EVP_PKEY |
|||
| 886 | OpenSSL: don't use direct access to the internal of RSA |
|||
| 887 | OpenSSL: don't use direct access to the internal of DSA |
|||
| 888 | OpenSSL: force meth->name as non-const when we free() it |
|||
| 889 | OpenSSL: don't use direct access to the internal of EVP_MD_CTX |
|||
| 890 | OpenSSL: don't use direct access to the internal of EVP_CIPHER_CTX |
|||
| 891 | OpenSSL: don't use direct access to the internal of HMAC_CTX |
|||
| 892 | OpenSSL: remove pre-1.1 function from the OpenSSL compat interface |
|||
| 893 | OpenSSL: remove EVP_CIPHER_CTX_new() from the compat layer |
|||
| 894 | OpenSSL: remove EVP_CIPHER_CTX_free() from the compat layer |
|||
| 895 | OpenSSL: check EVP_PKEY key types before returning the pkey |
|||
| 896 | ||||
| 897 | Eric Thorpe (1): |
|||
| 898 | Fix Building Using MSVC |
|||
| 899 | ||||
| 900 | Fabian Knittel (7): |
|||
| 901 | client-connect: Split multi_connection_established into separate functions |
|||
| 902 | client-connect: Refactor multi_client_connect_source_ccd |
|||
| 903 | client-connect: Move multi_client_connect_setenv into early_setup |
|||
| 904 | client-connect: Refactor to use return values instead of modifying a passed-in flag |
|||
| 905 | client-connect: Refactor client-connect handling to calling a bunch of hooks in a loop |
|||
| 906 | client-connect: Add deferred support to the client-connect script handler |
|||
| 907 | client-connect: Add deferred support to the client-connect v1 plugin handler |
|||
| 908 | ||||
| 909 | Gert Doering (51): |
|||
| 910 | Remove IV_RGI6=1 peer-info signalling. |
|||
| 911 | Remove IV_RGI6=1 peer-info signalling. |
|||
| 912 | Add openssl_compat.h to openvpn_SOURCES |
|||
| 913 | Fix '--dev null' |
|||
| 914 | Fix installation of IPv6 host route to VPN server when using iservice. |
|||
| 915 | Make ENABLE_OCC no longer depend on !ENABLE_SMALL |
|||
| 916 | Fix NCP behaviour on TLS reconnect. |
|||
| 917 | Remove erroneous limitation on max number of args for --plugin |
|||
| 918 | proxy.c refactoring: remove always-NULL gc parameter |
|||
| 919 | Fix edge case with clients failing to set up cipher on empty PUSH_REPLY. |
|||
| 920 | Fix potential 1-byte overread in TCP option parsing. |
|||
| 921 | Fix remotely-triggerable ASSERT() on malformed IPv6 packet. |
|||
| 922 | Update Changes.rst with relevant info for 2.4.3 release. |
|||
| 923 | Remove warning on pushed tun-ipv6 option. |
|||
| 924 | Fix removal of on-link prefix on windows with netsh |
|||
| 925 | Fix potential double-free() in Interactive Service (CVE-2018-9336) |
|||
| 926 | Add %d, %u and %lu tests to test_argv unit tests. |
|||
| 927 | Extend push-remove to also handle 'ifconfig'. |
|||
| 928 | Print lzo_init() return code in case of errors |
|||
| 929 | Uncrustify sample-plugin sources according to code style |
|||
| 930 | uncrustify openvpnserv/ sources |
|||
| 931 | uncrustify openvpn/ sources |
|||
| 932 | Add 'printing of port number' to mroute_addr_print_ex() for v4-mapped v6. |
|||
| 933 | Stop complaining about IPv6 routes without gateway address. |
|||
| 934 | Copy one byte less in strncpynt() |
|||
| 935 | Remove cmocka submodule, rely on system-wide installation instead. |
|||
| 936 | Increase listen() backlog queue to 32 |
|||
| 937 | repair tap mode on OpenSolaris/OpenIndiana |
|||
| 938 | Fix IPv6 routes on tap interfaces on OpenSolaris/OpenIndiana |
|||
| 939 | OpenSolaris/OpenIllumos: use /bin/bash if available for test scripts. |
|||
| 940 | Force combinationation of --socks-proxy and --proto UDP to use IPv4. |
|||
| 941 | Uncrustify the tests/unit_tests/ part of our tree. |
|||
| 942 | Change client side of t_lpback.sh configs to use inline material. |
|||
| 943 | Simplify pool size handling, fix possible array overrun on pool reading. |
|||
| 944 | Change timestamps in file-based logging to ISO 8601 time format. |
|||
| 945 | Depreciation warning for --topology net30 on servers with IPv4 pools. |
|||
| 946 | Convert plugin/auth-pam.c from stderr logging to plugin_log(). |
|||
| 947 | Add c1ff8f247f91c88a2df5502eeedf42857f9a6831 (engine, pool, SSO) to .git-blame-ignore-revs |
|||
| 948 | Linux: do not change --txqueuelen OS default if not configured. |
|||
| 949 | Fix 'engine' unit test on FreeBSD (specifically 'not GNU make') |
|||
| 950 | t_client.sh: correctly report all failed instances in summary |
|||
| 951 | Remove --writepid file on program exit. |
|||
| 952 | Handle connecting clients without NCP or OCC without crashing. |
|||
| 953 | Add deferred authentication support to plugin-auth-pam |
|||
| 954 | Separate handling of non-deferred return values for client-connect-scripts. |
|||
| 955 | Repair --inetd |
|||
| 956 | Fix sequence of events for async plugin v1 handler. |
|||
| 957 | Abort client-connect handler loop after first handler sets 'disable'. |
|||
| 958 | Add depreciation notice for --ncp-disable to protocol-options.rst |
|||
| 959 | Changes.rst updates in preparation to 2.5_beta1 |
|||
| 960 | Preparing release 2.5_beta1 |
|||
| 961 | ||||
| 962 | Gert van Dijk (7): |
|||
| 963 | Warn that DH config option is only meaningful in a tls-server context |
|||
| 964 | Add generated openvpn.doxyfile to .gitignore |
|||
| 965 | manpage: improve description of --status and --status-version |
|||
| 966 | Add negotiated cipher to status file format 2 and 3 |
|||
| 967 | Minor reliability layer documentation fixes |
|||
| 968 | Make second parameter to reliable_send_purge() const |
|||
| 969 | Remove unneeded newline in debug message in reliable.c |
|||
| 970 | ||||
| 971 | Gisle Vanem (2): |
|||
| 972 | Crash in options.c |
|||
| 973 | Wrong FILETYPE in .rc files |
|||
| 974 | ||||
| 975 | Guido Vranken (6): |
|||
| 976 | refactor my_strupr |
|||
| 977 | Fix 2 memory leaks in proxy authentication routine |
|||
| 978 | Fix memory leak in add_option() for option 'connection' |
|||
| 979 | Ensure option array p[] is always NULL-terminated |
|||
| 980 | Fix a null-pointer dereference in establish_http_proxy_passthru() |
|||
| 981 | Prevent two kinds of stack buffer OOB reads and a crash for invalid input data |
|||
| 982 | ||||
| 983 | Heiko Hund (3): |
|||
| 984 | re-implement argv_printf_*() |
|||
| 985 | argv: do fewer memory re-allocations |
|||
| 986 | Add gc_arena to struct argv to save allocations |
|||
| 987 | ||||
| 988 | Hilko Bengen (1): |
|||
| 989 | Do not set pkcs11-helper 'safe fork mode' |
|||
| 990 | ||||
| 991 | Hristo Venev (1): |
|||
| 992 | Fix extract_x509_field_ssl for external objects, v2 |
|||
| 993 | ||||
| 994 | Ilya Shipitsin (18): |
|||
| 995 | Resolve several travis-ci issues |
|||
| 996 | github: Add PR template with contributor related information |
|||
| 997 | travis-ci: add 'make distcheck' to test scenario, V2 |
|||
| 998 | travis-ci: remove unused files |
|||
| 999 | v4, travis-ci: add 2 mingw "build only" configurations |
|||
| 1000 | travis-ci: added gcc and clang openssl-1.1.0 builds |
|||
| 1001 | travis-ci: update openssl to 1.0.2l, update mbedtls to 2.5.1 |
|||
| 1002 | travis-ci: update pkcs11-helper to 1.22 |
|||
| 1003 | travis-ci: add brew cache, remove ccache |
|||
| 1004 | travis-ci: modify openssl build script to support openssl-1.1.0 |
|||
| 1005 | travis-ci: cleanup, refactor, upgrade ssl libraries |
|||
| 1006 | travis-ci: add "linux-ppc64le" to build matrix |
|||
| 1007 | travis-ci: change trusty image to xenial |
|||
| 1008 | travis-ci: update osx to xcode9.4 and modernize brew management |
|||
| 1009 | configure.ac: fix compile-time error in argv_testdriver |
|||
| 1010 | travis-ci: fix osx builds |
|||
| 1011 | travis-ci: update components versions |
|||
| 1012 | travis-ci: add arm64, s390x builds. |
|||
| 1013 | ||||
| 1014 | James Bekkema (2): |
|||
| 1015 | Resolves small IV_GUI_VER typo in the documentation. |
|||
| 1016 | Adds support for setting the default IPv6 gateway for routes using the route-ipv6-gateway option. |
|||
| 1017 | ||||
| 1018 | James Bottomley (7): |
|||
| 1019 | autoconf: Fix engine checks for openssl 1.1 |
|||
| 1020 | openssl: add engine method for loading the key |
|||
| 1021 | crypto_openssl: add initialization to pick up local configuration |
|||
| 1022 | crypto_openssl: add include for openssl/conf.h |
|||
| 1023 | Add unit tests for engine keys |
|||
| 1024 | Fix make distcheck for new engine key unit test |
|||
| 1025 | engine-key tests: make check_engine_keys.sh work with --enable-small |
|||
| 1026 | ||||
| 1027 | Jan Just Keijser (1): |
|||
| 1028 | Added support for DHCP option 119 (dns search suffix list) for Windows. |
|||
| 1029 | ||||
| 1030 | Jeremie Courreges-Anglas (5): |
|||
| 1031 | Cast time_t to long long in order to print it. |
|||
| 1032 | Print time_t as long long and suseconds_t as long |
|||
| 1033 | Cast and print another suseconds_t as long |
|||
| 1034 | Use long long to format time_t-related environment variables |
|||
| 1035 | Fix build with LibreSSL |
|||
| 1036 | ||||
| 1037 | Jeremy Evans (1): |
|||
| 1038 | Switch assertion failure to returning false |
|||
| 1039 | ||||
| 1040 | Jonathan K. Bullard (1): |
|||
| 1041 | Clarify and expand management interface documentation |
|||
| 1042 | ||||
| 1043 | Jonathan Tooker (1): |
|||
| 1044 | Fix various spelling mistakes |
|||
| 1045 | ||||
| 1046 | Joost Rijneveld (1): |
|||
| 1047 | Make return code external tls key match docs |
|||
| 1048 | ||||
| 1049 | Jérémie Courrèges-Anglas (2): |
|||
| 1050 | Fix an unaligned access on OpenBSD/sparc64 |
|||
| 1051 | Missing include for socket-flags TCP_NODELAY on OpenBSD |
|||
| 1052 | ||||
| 1053 | Kyle Evans (1): |
|||
| 1054 | tests/t_lpback.sh: Switch sed(1) to POSIX-compatible regex. |
|||
| 1055 | ||||
| 1056 | Lev Stipakov (46): |
|||
| 1057 | win: support for Visual Studio 2017 |
|||
| 1058 | Refactor NCP-negotiable options handling |
|||
| 1059 | init.c: refine functions names and description |
|||
| 1060 | openvpnserv: clarify return values type |
|||
| 1061 | crypto.h: remove unused function declaration |
|||
| 1062 | interactive.c: fix usage of potentially uninitialized variable |
|||
| 1063 | options.c: fix broken unary minus usage |
|||
| 1064 | Introduce openvpn_swprintf() with nul termination guarantee |
|||
| 1065 | Wrap openvpn_swprintf into Windows define |
|||
| 1066 | test_tls_crypt.c: fix global-buffer-overflow found by AddressSanitizer |
|||
| 1067 | crypto_openssl.c: fix heap-buffer-overflow found by AddressSanitizer |
|||
| 1068 | Fix various compiler warnings |
|||
| 1069 | Fix broken fragment/mssfix with NCP |
|||
| 1070 | crypto.c: fix Visual Studio build |
|||
| 1071 | tun.h: change tun_set() return value type to void |
|||
| 1072 | tun.h: remove TUN_PASS_BUFFER define |
|||
| 1073 | tapctl: add optional 'hardware id' parameter |
|||
| 1074 | vcxproj: add missing source files |
|||
| 1075 | push.c: fix Visual Studio build |
|||
| 1076 | Visual Studio: make it easier to build with VS |
|||
| 1077 | msvc: OpenSSL 1.1.x support |
|||
| 1078 | travis: add Visual Studio build |
|||
| 1079 | Visual Studio: upgrade project files to VS2019 |
|||
| 1080 | wintun: add --windows-driver config option |
|||
| 1081 | wintun: implement opening wintun device |
|||
| 1082 | travis: bump MSVC to 2019 |
|||
| 1083 | travis: bump clang version |
|||
| 1084 | wintun: ring buffers based I/O |
|||
| 1085 | wintun: interactive service support |
|||
| 1086 | wintun: set adapter properties via interactive service |
|||
| 1087 | wintun: clear adapter settings on tun close |
|||
| 1088 | tun.c: refactor open_tun() implementation |
|||
| 1089 | tun.c: do not add/remove on-link IPv4 route on tun open/close |
|||
| 1090 | options.c: do not force route delay when not using DHCP |
|||
| 1091 | configure.ac: simplify AC_CHECK_FUNCS statements |
|||
| 1092 | cryptoapi.c: fix run-time check failure in msvc debugger |
|||
| 1093 | interactive.c: remove unused function |
|||
| 1094 | tun.c: fix 'use after free' error |
|||
| 1095 | Fix building with --enable-async-push in FreeBSD |
|||
| 1096 | Fix broken async push with NCP is used |
|||
| 1097 | Fix illegal client float (CVE-2020-11810) |
|||
| 1098 | msvc: fix various level2 warnings |
|||
| 1099 | tap.c: fix adapter renaming |
|||
| 1100 | Improve Windows version detection with manifest |
|||
| 1101 | wintun: remove SYSTEM elevation hack |
|||
| 1102 | Fix compilation with --disable-lzo and --disable-lz4 |
|||
| 1103 | ||||
| 1104 | Matthias Andree (3): |
|||
| 1105 | Make openvpn-plugin.h self-contained again. |
|||
| 1106 | Merge Makefile.am's AUTOMAKE_OPTIONS into configure.ac's AM_INIT_AUTOMAKE. |
|||
| 1107 | Fix stack buffer overruns in NEXTADDR() macro: |
|||
| 1108 | ||||
| 1109 | Maxim Plotnikov (1): |
|||
| 1110 | OpenSSL: Fix --crl-verify not loading multiple CRLs in one file |
|||
| 1111 | ||||
| 1112 | Maximilian Wilhelm (1): |
|||
| 1113 | Add --bind-dev option. |
|||
| 1114 | ||||
| 1115 | Michal Soltys (1): |
|||
| 1116 | man: correct the description of --capath and --crl-verify regarding CRLs |
|||
| 1117 | ||||
| 1118 | Mykola Baibuz (1): |
|||
| 1119 | Fix typo in NTLM proxy debug message |
|||
| 1120 | ||||
| 1121 | Olivier Wahrenberger (1): |
|||
| 1122 | Fix building with LibreSSL 2.5.1 by cleaning a hack. |
|||
| 1123 | ||||
| 1124 | Richard Bonhomme (3): |
|||
| 1125 | man: Corrections to doc/openvpn.8 |
|||
| 1126 | Ignore --pull-filter for --mode server |
|||
| 1127 | doc/man: Update --txqueuelen default setting (Now OS default) |
|||
| 1128 | ||||
| 1129 | Richard van den Berg via Openvpn-devel (1): |
|||
| 1130 | Fix error message when using RHEL init script |
|||
| 1131 | ||||
| 1132 | Rosen Penev (2): |
|||
| 1133 | Remove wrong poll.h include |
|||
| 1134 | openssl: Fix compilation without deprecated OpenSSL 1.1 APIs |
|||
| 1135 | ||||
| 1136 | Samy Mahmoudi (1): |
|||
| 1137 | man: correct a --redirection-gateway option flag |
|||
| 1138 | ||||
| 1139 | Santtu Lakkala (1): |
|||
| 1140 | Fix OpenSSL private key passphrase notices |
|||
| 1141 | ||||
| 1142 | Selva Nair (55): |
|||
| 1143 | Fix push options digest update |
|||
| 1144 | Always release dhcp address in close_tun() on Windows. |
|||
| 1145 | Add a check for -Wl, --wrap support in linker |
|||
| 1146 | Fix user's group membership check in interactive service to work with domains |
|||
| 1147 | In auth-pam plugin clear the password after use |
|||
| 1148 | Pass correct buffer size to GetModuleFileNameW() |
|||
| 1149 | Check whether in pull_mode before warning about previous connection blocks |
|||
| 1150 | Avoid illegal memory access when malformed data is read from the pipe |
|||
| 1151 | Fix missing check for return value of malloc'd buffer |
|||
| 1152 | Return NULL if GetAdaptersInfo fails |
|||
| 1153 | Use RSA_meth_free instead of free |
|||
| 1154 | Bring cryptoapi.c upto speed with openssl 1.1 |
|||
| 1155 | Add SSL_CTX_get_max_proto_version() not in openssl 1.0 |
|||
| 1156 | TLS v1.2 support for cryptoapicert -- RSA only |
|||
| 1157 | Refactor ssl_openssl.c in prep for external EC key support |
|||
| 1158 | Refactor get_interface_metric to return metric and auto flag separately |
|||
| 1159 | Add management client version |
|||
| 1160 | Prompt for signature using '>PK_SIGN' if the client supports it |
|||
| 1161 | Allow external EC key through --management-external-key |
|||
| 1162 | Ensure strings read from registry are null-terminated |
|||
| 1163 | Make most registry values optional |
|||
| 1164 | Use lowest metric interface when multiple interfaces match a route |
|||
| 1165 | Move code to free cd to a function CAPI_DATA_free() |
|||
| 1166 | Disable external ec key support when building with libressl |
|||
| 1167 | Adapt to RegGetValue brokenness in Windows 7 |
|||
| 1168 | Fix format spec errors in Windows builds |
|||
| 1169 | Move setting private key to a function in prep for EC support |
|||
| 1170 | Support EC certificates with cryptoapicert |
|||
| 1171 | Delete the IPv6 route to the "connected" network on tun close |
|||
| 1172 | Management: warn about password only when the option is in use |
|||
| 1173 | Avoid overflow in wakeup time computation |
|||
| 1174 | Replace M_DEBUG with D_LOW as the former is too verbose |
|||
| 1175 | Correct the declaration of handle in 'struct openvpn_plugin_args_open_return' |
|||
| 1176 | Parse static challenge response in auth-pam plugin |
|||
| 1177 | Bump version of openvpn plugin argument structs to 5 |
|||
| 1178 | Accept empty password and/or response in auth-pam plugin |
|||
| 1179 | Pass the hash without the DigestInfo header to NCryptSignHash() |
|||
| 1180 | Move get system directory to a separate function |
|||
| 1181 | Enable dhcp on tap adapter using interactive service |
|||
| 1182 | Refactor sending commands to interactive service |
|||
| 1183 | Declare Windows version of openvpn_execve() before use |
|||
| 1184 | White-list pull-filter and script-security in interactive service |
|||
| 1185 | Move OpenSSL vs CNG signature digest type mapping to a function |
|||
| 1186 | Handle PSS padding in cryptoapicert |
|||
| 1187 | Better error message when script fails due to script-security setting |
|||
| 1188 | Correct the return value of cryptoapi RSA signature callbacks |
|||
| 1189 | Fix ACL_CHECK_ADD_COMPILE_FLAGS to work with clang |
|||
| 1190 | Swap the order of checks for validating interactive service user |
|||
| 1191 | Skip expired certificates in Windows certificate store |
|||
| 1192 | Allow unicode search string in --cryptoapicert option |
|||
| 1193 | Fix possibly uninitialized return value in GetOpenvpnSettings() |
|||
| 1194 | Fix possible access of uninitialized pipe handles |
|||
| 1195 | Move querying username/password from management to a function |
|||
| 1196 | When auth-user-pass file has no password query the management interface (if available). |
|||
| 1197 | Persist management-query-remote and proxy prompts |
|||
| 1198 | ||||
| 1199 | Simon Matter (2): |
|||
| 1200 | Fix segfault when using crypto lib without AES-256-CTR or SHA256 |
|||
| 1201 | Add per session pseudo-random jitter to --reneg-sec intervals |
|||
| 1202 | ||||
| 1203 | Simon Rozman (67): |
|||
| 1204 | Local functions are not supported in MSVC. Bummer. |
|||
| 1205 | Mixing wide and regular strings in concatenations is not allowed in MSVC. |
|||
| 1206 | RtlIpv6AddressToStringW() and RtlIpv4AddressToStringW() require mstcpip.h |
|||
| 1207 | Simplify iphlpapi.dll API calls |
|||
| 1208 | Fix local #include to use quoted form |
|||
| 1209 | Document ">PASSWORD:Auth-Token" real-time message |
|||
| 1210 | Fix typo in "verb" command examples |
|||
| 1211 | Uniform swprintf() across MinGW and MSVC compilers |
|||
| 1212 | MSVC meta files added to .gitignore list |
|||
| 1213 | openvpnserv: Review MSVC down-casting warnings |
|||
| 1214 | openvpnserv: Add support for multi-instances |
|||
| 1215 | Document missing OpenVPN states |
|||
| 1216 | Add Interactive Service developer documentation |
|||
| 1217 | Change quoted to angled form when #including external .h files |
|||
| 1218 | Signed/unsigned warnings of MSVC resolved |
|||
| 1219 | Reference msvc-generate from compat to assure correct build order |
|||
| 1220 | msvc: Move common project settings to reusable property sheets |
|||
| 1221 | msvc: Unify Unicode/MultiByte string setting across all cfg|plat |
|||
| 1222 | Introduce tapctl.exe utility and openvpnmsica.dll MSI CA |
|||
| 1223 | Set output name to libopenvpnmsica.dll in MSVC builds too |
|||
| 1224 | Prevent __stdcall name mangling of MSVC |
|||
| 1225 | Define _WIN32_WINNT=_WIN32_WINNT_VISTA in MSVC |
|||
| 1226 | Add MSI custom action for reliable Windows 10 detection |
|||
| 1227 | Detect TAP interfaces with root-enumerated hardware ID |
|||
| 1228 | Change C++ to C comments |
|||
| 1229 | Make MSI custom action debug pop-up more informative |
|||
| 1230 | Delete TAP interface before the TAP driver is uninstalled |
|||
| 1231 | Add detection of active VPN connections for MSI packages |
|||
| 1232 | Add a MSI custom actions to close and relaunch OpenVPN GUI |
|||
| 1233 | Make DriverCertification MSI property public |
|||
| 1234 | Extend FindSystemInfo custom action to detect OpenVPNService state |
|||
| 1235 | Uncrustify tapctl and openvpnmsica |
|||
| 1236 | Strip _stdcall suffixes (@nn) for 32-bit builds |
|||
| 1237 | Detect missing TAP driver and bail out gracefully |
|||
| 1238 | Disambiguate thread local storage references from TLS |
|||
| 1239 | Add NULL checks |
|||
| 1240 | Add user manual and developer notes URL for tapctl.exe |
|||
| 1241 | Refactor OpenVPNService state detection code |
|||
| 1242 | Add developer notes URL for openvpnmsica.dll |
|||
| 1243 | Limit tapctl.exe and openvpnmsica.dll to TAP-Windows6 adapters only |
|||
| 1244 | msvc: Add vlan.c/h |
|||
| 1245 | tun.c: make Windows device lookup functions more general |
|||
| 1246 | tun.c: upgrade get_device_guid() to return the Windows driver type |
|||
| 1247 | tun.c: make wintun_register_ring_buffer() non-fatal on failures |
|||
| 1248 | wintun: register ring buffers when iterating adapters |
|||
| 1249 | wintun: add support for --dev-node |
|||
| 1250 | tun.c: reword the at_least_one_tap_win() error |
|||
| 1251 | wintun: stop sending TAP-Windows6 ioctls to NDIS device |
|||
| 1252 | wintun: refactor code to use enum driver type |
|||
| 1253 | tun.c: refactor driver detection and make it case-insensitive |
|||
| 1254 | tun.c: uncrustify |
|||
| 1255 | wintun: check for conflicting options |
|||
| 1256 | openvpnmsica: Remove required Windows driver certification detection |
|||
| 1257 | openvpnmsica: Fix TAPInterface.DisplayName field interpretation |
|||
| 1258 | tapctl: Update documentation |
|||
| 1259 | wintun: upgrade error message in case of ring registration failure |
|||
| 1260 | tun.c: reorder IPv6 ifconfig on Windows |
|||
| 1261 | tapctl: Add functions for enabling/disabling adapters |
|||
| 1262 | openvpnmsica: Revise MSI custom actions interop |
|||
| 1263 | openvpnmsica: Simplify static function names |
|||
| 1264 | openvpnmsica, tapctl: "interface" => "adapter" |
|||
| 1265 | openvpnmsica: "TAP" => "TUN/TAP" |
|||
| 1266 | openvpnmsica: Extend to support arbitrary HWID network adapters |
|||
| 1267 | openvpnmsica, tapctl: Revise default hardware ID management |
|||
| 1268 | openvpnmsica: Merge FindTUNTAPAdapters into FindSystemInfo |
|||
| 1269 | tapctl: Support multiple hardware IDs |
|||
| 1270 | tun.c: revise the IPv4 ifconfig flow on Windows |
|||
| 1271 | ||||
| 1272 | Stefan Strogin (1): |
|||
| 1273 | Use correct ifdefs for LibreSSL support |
|||
| 1274 | ||||
| 1275 | Steffan Karger (126): |
|||
| 1276 | Bump master to version 2.5_git |
|||
| 1277 | Document that RSA_SIGN can also request TLS 1.2 signatures |
|||
| 1278 | man: encourage user to read on about --tls-crypt |
|||
| 1279 | Document that RSA_SIGN can also request TLS 1.2 signatures |
|||
| 1280 | man: encourage user to read on about --tls-crypt |
|||
| 1281 | Textual fixes for Changes.rst |
|||
| 1282 | Textual fixes for Changes.rst |
|||
| 1283 | Remove deprecated --no-iv option |
|||
| 1284 | More broadly enforce Allman style and braces-around-conditionals |
|||
| 1285 | Use SHA256 for the internal digest, instead of MD5 |
|||
| 1286 | OpenSSL: 1.1 fallout - fix configure on old autoconf |
|||
| 1287 | Fix types in WIN32 socket_listen_accept() |
|||
| 1288 | Remove duplicate X509 env variables |
|||
| 1289 | Fix non-C99-compliant builds: don't use const size_t as array length |
|||
| 1290 | Deprecate --ns-cert-type |
|||
| 1291 | Be less picky about keyUsage extensions |
|||
| 1292 | cleanup: merge packet_id_alloc_outgoing() into packet_id_write() |
|||
| 1293 | Don't run packet_id unit tests for --disable-crypto builds |
|||
| 1294 | Fix Changes.rst layout |
|||
| 1295 | Fix memory leak in x509_verify_cert_ku() |
|||
| 1296 | mbedtls: correctly check return value in pkcs11_certificate_dn() |
|||
| 1297 | Restore pre-NCP frame parameters for new sessions |
|||
| 1298 | Always clear username/password from memory on error |
|||
| 1299 | Document tls-crypt security considerations in man page |
|||
| 1300 | Don't assert out on receiving too-large control packets (CVE-2017-7478) |
|||
| 1301 | Drop packets instead of assert out if packet id rolls over (CVE-2017-7479) |
|||
| 1302 | Log the negotiated (NCP) cipher |
|||
| 1303 | Avoid a 1 byte overcopy in x509_get_subject (ssl_verify_openssl.c) |
|||
| 1304 | Skip tls-crypt unit tests if required crypto mode not supported |
|||
| 1305 | openssl: fix overflow check for long --tls-cipher option |
|||
| 1306 | Add a DSA test key/cert pair to sample-keys |
|||
| 1307 | Fix mbedtls fingerprint calculation |
|||
| 1308 | mbedtls: fix --x509-track post-authentication remote DoS (CVE-2017-7522) |
|||
| 1309 | mbedtls: require C-string compatible types for --x509-username-field |
|||
| 1310 | Fix remote-triggerable memory leaks (CVE-2017-7521) |
|||
| 1311 | Restrict --x509-alt-username extension types |
|||
| 1312 | Fix potential double-free in --x509-alt-username (CVE-2017-7521) |
|||
| 1313 | Fix typo in extract_x509_extension() debug message |
|||
| 1314 | init_key_ctx: key and iv arguments can (now) be const |
|||
| 1315 | Move adjust_power_of_2() to integer.h |
|||
| 1316 | Undo cipher push in client options state if cipher is rejected |
|||
| 1317 | Remove strerror_ts() |
|||
| 1318 | Move openvpn_sleep() to manage.c |
|||
| 1319 | fixup: also change missed openvpn_sleep() occurrences |
|||
| 1320 | Always use default keysize for NCP'd ciphers |
|||
| 1321 | Move create_temp_file() out of #ifdef ENABLE_CRYPTO |
|||
| 1322 | sample-plugins: fix ASN1_STRING_to_UTF8 return value checks |
|||
| 1323 | Deprecate --keysize |
|||
| 1324 | Move run_up_down() to init.c |
|||
| 1325 | tls-crypt: introduce tls_crypt_kt() |
|||
| 1326 | crypto: create function to initialize encrypt and decrypt key |
|||
| 1327 | Add coverity static analysis to Travis CI config |
|||
| 1328 | tls-crypt: don't leak memory for incorrect tls-crypt messages |
|||
| 1329 | travis: reorder matrix to speed up build |
|||
| 1330 | Fix bounds check in read_key() |
|||
| 1331 | buffer_list_aggregate_separator(): add unit tests |
|||
| 1332 | doxygen: add make target and use relative paths |
|||
| 1333 | Simplify and inline clear_buf() |
|||
| 1334 | Add --tls-cert-profile option. |
|||
| 1335 | pf: clean up temporary files if plugin init fails |
|||
| 1336 | pf: reject client if PF plugin is configured, but init fails |
|||
| 1337 | Don't throw fatal errors from create_temp_file() |
|||
| 1338 | create_temp_file/gen_path: prevent memory leak if gc == NULL |
|||
| 1339 | Use P_DATA_V2 for server->client packets too |
|||
| 1340 | Fix memory leak in buffer unit tests |
|||
| 1341 | travis: use clang's -fsanitize=address to catch more bugs |
|||
| 1342 | Don't throw fatal errors from verify_cert_export_cert() |
|||
| 1343 | buffer_list_aggregate_separator(): update list size after aggregating |
|||
| 1344 | buffer_list_aggregate_separator(): don't exceed max_len |
|||
| 1345 | buffer_list_aggregate_separator(): prevent 0-byte malloc |
|||
| 1346 | Fix types around buffer_list_push(_data) |
|||
| 1347 | ssl_openssl: fix compiler warning by removing getbio() wrapper |
|||
| 1348 | Fix --tls-version-min and --tls-version-max for OpenSSL 1.1+ |
|||
| 1349 | Add support for TLS 1.3 in --tls-version-{min, max} |
|||
| 1350 | tls_ctx_set_tls_versions: move verify_flags to where it is used |
|||
| 1351 | Plug memory leak if push is interrupted |
|||
| 1352 | Log pre-handshake packet drops using D_MULTI_DROPPED |
|||
| 1353 | Enable stricter compiler warnings by default |
|||
| 1354 | reliable: remove reliable_unique_retry() |
|||
| 1355 | Get rid of ax_check_compile_flag.m4 |
|||
| 1356 | mbedtls: don't use API deprecated in mbed 2.7 |
|||
| 1357 | Warn if tls-version-max < tls-version-min |
|||
| 1358 | Check for more data in control channel |
|||
| 1359 | Move env helper functions into their own module/file |
|||
| 1360 | man: add security considerations to --compress section |
|||
| 1361 | openssl: don't use deprecated SSLEAY/SSLeay symbols |
|||
| 1362 | openssl: add missing #include statements |
|||
| 1363 | Move file-related functions from misc.c to platform.c |
|||
| 1364 | Move execve/run_script helper functions to run_command.c |
|||
| 1365 | Add crypto_pem_{encode,decode}() |
|||
| 1366 | Introduce buffer_write_file() |
|||
| 1367 | mbedtls: print warning if random personalisation fails |
|||
| 1368 | Fix memory leak after sighup |
|||
| 1369 | Remove unused void_ptr_hash_function and void_ptr_compare_function |
|||
| 1370 | Do not load certificate from tls_ctx_use_external_private_key() |
|||
| 1371 | mbedtls: make external signing code generic |
|||
| 1372 | mbedtls: remove dependency on mbedtls pkcs11 module |
|||
| 1373 | Fix memory leak in SSL_CTX_use_certificate |
|||
| 1374 | travis: add OpenSSL 1.1 Windows build |
|||
| 1375 | Fix use-after-free in tls_ctx_use_management_external_key |
|||
| 1376 | Simplify --genkey option syntax |
|||
| 1377 | Don't print OCC warnings about 'key-method', 'keydir' and 'tls-auth' |
|||
| 1378 | Add support for CHACHA20-POLY1305 in the data channel |
|||
| 1379 | List ChaCha20-Poly1305 as stream cipher |
|||
| 1380 | mbedtls: don't print unsupported ciphers in insecure cipher list |
|||
| 1381 | Fix mbedtls unit tests |
|||
| 1382 | buffer_list_aggregate_separator(): simplify code |
|||
| 1383 | tls-crypt-v2: add specification to doc/ |
|||
| 1384 | tls-crypt-v2: generate tls-crypt-v2 keys |
|||
| 1385 | tls-crypt-v2: add unwrap_client_key |
|||
| 1386 | tls-crypt-v2: add P_CONTROL_HARD_RESET_CLIENT_V3 opcode |
|||
| 1387 | tls-crypt-v2: implement tls-crypt-v2 handshake |
|||
| 1388 | tls-crypt-v2: add script hook to verify metadata |
|||
| 1389 | tls-crypt-v2: clarify --tls-crypt-v2-genkey man page section |
|||
| 1390 | tls-crypt-v2: fix client reconnect bug |
|||
| 1391 | Remove deprecated --compat-x509-names and --no-name-remapping |
|||
| 1392 | Extend tls-crypt-v2 unit tests |
|||
| 1393 | Fix tls-auth/crypt in connection blocks with --persist-key |
|||
| 1394 | cmocka: use relative paths |
|||
| 1395 | tests: remove dependency on base64 |
|||
| 1396 | configure.ac: add lzo CFLAGS/LIBS to the test flags |
|||
| 1397 | Update sample configs to use modern cipher, remove static key examples |
|||
| 1398 | mbedtls: add RFC 5705 keying material exporter support |
|||
| 1399 | Move keying material exporter check from syshead.h to configure.ac |
|||
| 1400 | Make openvpn --version exit with exit code 0 |
|||
| 1401 | Gently push users towards --data-ciphers in --show-ciphers output |
|||
| 1402 | ||||
| 1403 | Steven McDonald (1): |
|||
| 1404 | Fix gateway detection with OpenBSD routing domains |
|||
| 1405 | ||||
| 1406 | Szilárd Pfeiffer (1): |
|||
| 1407 | OpenSSL: Always set SSL_OP_CIPHER_SERVER_PREFERENCE flag |
|||
| 1408 | ||||
| 1409 | Thomas Quinot (1): |
|||
| 1410 | Fix documentation of tls-verify script argument |
|||
| 1411 | ||||
| 1412 | Thomas Veerman via Openvpn-devel (1): |
|||
| 1413 | Fix socks_proxy_port pointing to invalid data |
|||
| 1414 | ||||
| 1415 | Tom van Leeuwen (1): |
|||
| 1416 | mbedTLS: Make sure TLS session survives move |
|||
| 1417 | ||||
| 1418 | ValdikSS (1): |
|||
| 1419 | Set a low interface metric for tap adapter when block-outside-dns is in use |
|||
| 1420 | ||||
| 1421 | Vladislav Grishenko (1): |
|||
| 1422 | Log serial number of revoked certificate |
|||
| 1423 | ||||
| 1424 | WGH (1): |
|||
| 1425 | docs: Add reference to X509_LOOKUP_hash_dir(3) |
|||
| 1426 | ||||
| 1427 | hashiz (1): |
|||
| 1428 | Fix '--bind ipv6only' |
|||
| 1429 | ||||
| 1430 | tincanteksup (1): |
|||
| 1431 | Correct error message for --tls-crypt-v2-genkey client |
|||
| 1432 | ``` |
