Blame

d91829 Samuli Seppänen 2025-02-11 09:50:59 1
# Changes in 2.5.11
2
3
```
4
Arne Schwabe (2):
5
Properly handle null bytes and invalid characters in control messages
6
Allow trailing \r and \n in control channel message
7
8
Gert Doering (1):
9
Preparing release 2.5.11
10
```
11
12
# Changes in 2.5.10
13
14
```
15
Arne Schwabe (1):
16
Add Apache2 linking with for new commits
17
18
George Pchelkin (1):
19
fix typo: dhcp-options to dhcp-option in vpn-network-options.rst
20
21
Gert Doering (1):
22
Preparing release 2.5.10
23
24
Lev Stipakov (3):
25
win32: Enforce loading of plugins from a trusted directory
26
interactive.c: disable remote access to the service pipe
27
interactive.c: Fix potential stack overflow issue
28
```
29
30
# Changes in 2.5.9
31
32
```
33
Arne Schwabe (6):
34
Implement optional cipher in --data-ciphers prefixed with ?
35
Fix handling an optional invalid cipher at the end of data-ciphers
36
Ensure that argument to parse_line has always space for final sentinel
37
Improve documentation on user/password requirement and unicodize function
38
Remove unused gc_arena
39
Fix corner case that might lead to leaked file descriptor
40
41
Frank Lichtenheld (1):
42
msvc: always call git-version.py
43
44
Gert Doering (1):
45
Preparing release 2.5.9
46
47
Lev Stipakov (1):
48
git-version.py: proper support for tags
49
50
Max Fillinger (1):
51
Check if pkcs11_cert is NULL before freeing it
52
53
Selva Nair (3):
54
Do not add leading space to pushed options
55
pull-filter: ignore leading "spaces" in option names
56
Do not include auth-token in pulled option digest
57
```
58
59
# Changes in 2.5.8
60
61
```
62
Antonio Quartulli (1):
63
tls-crypt-v2: bail out if the client key is too small
64
65
Arne Schwabe (4):
66
Remove useless empty line from CR_RESPONSE message
67
Allow running a default configuration with TLS libraries without BF-CBC
68
Change command help to match man page and implementation
69
Fix OpenVPN querying user/password if auth-token with user expires
70
71
Frank Lichtenheld (2):
72
t_client: Allow to force FAIL on prerequisite fails
73
t_client.sh: do not require fping6
74
75
Gert Doering (1):
76
Preparing release 2.5.8
77
78
Lev Stipakov (1):
79
msvc: add branch name and commit hash to version output
80
81
Martin Janů (1):
82
Update the replay-window backtrack log message
83
84
Selva Nair (6):
85
Do not skip ERROR:/SUCCESS: response from management interface
86
Fix auth-token usage with management-def-auth
87
Allow a few levels of recursion in virtual_output_callback()
88
Ensure --auth-nocache is handled during renegotiation
89
Purge auth-token as well while purging passwords
90
Do not copy auth_token username to itself
91
```
92
93
# Changes in 2.5.7
94
95
```
96
Antonio Quartulli (4):
97
networking: use OPENVPN_ETH_ALEN instead of ETH_ALEN
98
networking_iproute2: don't pass M_WARN to openvpn_execve_check()
99
t_net.sh: delete dummy iface using iproute command
100
auth-pam.c: add missing include limits.h
101
102
Arne Schwabe (11):
103
Add insecure tls-cert-profile options
104
Refactor early initialisation and uninitialisation into methods
105
Allow loading of non default providers
106
Add ubuntu 22.04 to Github Actions
107
Add macos OpenSSL 3.0 and ASAN builds
108
Add --with-openssl-engine autoconf option (auto|yes|no)
109
Fix allowing/showing unsupported ciphers and digests
110
Remove dependency on BF-CBC existance from test_ncp
111
Add message when decoding PKCS12 file fails.
112
Translate OpenSSL 3.0 digest names to OpenSSL 1.1 digest names
113
Fix client-pending-auth error message to say ERROR instead of SUCCESS
114
115
Gert Doering (1):
116
Preparing release 2.5.7
117
118
Jan Mikkelsen (1):
119
cipher-negotiation.rst missing from doc/Makefile.am
120
121
Lev Stipakov (5):
122
vcpkg-ports\pkcs11-helper: shorten patch filename
123
msvc: adjust build options to harden binaries
124
vcpkg-ports: remove openssl port
125
vcpkg: switch to manifest
126
Fix M_ERRNO behavior on Windows
127
128
Marc Becker (1):
129
vcpkg-ports/pkcs11-helper: bump to release 1.29
130
131
Simon Rozman (1):
132
tapctl: Resolve MSVC C4996 warnings
133
```
134
135
# Changes in 2.5.6
136
137
```
138
Antonio Quartulli (4):
139
GitHub Actions: update script to same version as master
140
update copyright year to 2022
141
keyingmaterialexporter.c: include strings.h
142
remove unused sitnl.h file
143
144
David Sommerseth (2):
145
sample-plugin: New plugin for testing multiple auth plugins
146
plug-ins: Disallow multiple deferred authentication plug-ins
147
148
Frank Lichtenheld (2):
149
doc/Makefile: rebuild rst docs if input files change
150
doc/options: clean up documentation for --proto and related options
151
152
Gert Doering (4):
153
fix Changes.rst errors in 2.5.3 and 2.5.5 announcement
154
Repair --inactive with 'bytes' argument larger 2Gbytes.
155
Fix --mtu-disc maybe|yes on Linux.
156
Preparing release 2.5.6
157
158
Ilya Shipitsin (1):
159
CI: github actions: keep "pdb" in artifacts
160
161
Lev Stipakov (7):
162
auth_token.c: add NULL initialization
163
vcpkg-ports/pkcs11-helper: bump to release 1.28
164
vcpkg-ports/pkcs11-helper: indicate OpenSSL EC support
165
msvc: cleanup
166
vcpkg: link lzo statically
167
vcpkg-ports/pkcs11-helper: adapt to new upstream URL
168
vcpkg-ports: add openssl 1.1.1n
169
```
170
171
# Changes in 2.5.5
172
173
```
174
Adrian (1):
175
Fix error in example firewall.sh script
176
177
Antonio Quartulli (1):
178
configure: remove useless -Wno-* from default CFLAGS
179
180
Arne Schwabe (2):
181
Add argv_insert_head__empty_argv__head_only to argv tests
182
Move deprecation of SWEET32/64bit block size ciphers to 2.7
183
184
Gert Doering (4):
185
Include --push-remove in the output of --help.
186
Move '--push-peer-info' documentation from 'server' to 'client options'
187
add test case(s) to notice 'openvpn --show-cipher' crashing
188
Preparing release 2.5.5
189
190
Ilya Shipitsin (1):
191
BUILD: enable CFG and Spectre mitigation for MSVC
192
193
Lev Stipakov (12):
194
Fix loading PKCS12 files on Windows
195
msvc: fix product version display
196
msvc: add missing header to project file
197
config-msvc.h: fix OpenSSL-related defines
198
contrib/vcpkg-ports: remove openssl port
199
GitHub Actions: use latest working lukka/run-vcpkg
200
Use network address for emulated DHCP server as a default
201
Load OpenSSL config on Windows from trusted location
202
ring_buffer.h: fix GCC warning about unused function
203
ssh_openssl.h: remove unused declaration
204
vcpkg/pkcs11-helper: compatibility with latest vcpkg
205
config-msvc.h: indicate key material export support
206
207
Max Fillinger (2):
208
Don't use BF-CBC in unit tests if we don't have it
209
Define have_blowfish variable in ncp unit tests
210
211
Richard T Bonhomme (1):
212
doc link-options.rst: Use free open-source dynamic-DNS provider URL
213
214
Selva Nair (3):
215
Fix some more wrong defines in config-msvc.h
216
Ensure the current common_name is in the environment for scripts
217
Require EC key support in Windows builds
218
219
Sergio E. Nemirowski (1):
220
resolvconf fails with -p
221
222
Todd Zullinger (2):
223
Update IRC information in CONTRIBUTING.rst
224
doc/man (vpn-network-options): fix foreign_option_{n} typo
225
226
Ville Skyttä (1):
227
README.down-root: Fix plugin module name
228
```
229
230
231
# Changes in 2.5.4
232
233
```
234
Antonio Quartulli (3):
235
route.c: pass the right parameter to IN6_IS_ADDR_UNSPECIFIED
236
configure: search also for rst2{man, html}.py
237
networking: add networking API net_addr_ll_set() and use it on Linux
238
239
Arne Schwabe (1):
240
Move examples into openvpn-examples(5) man page
241
242
David Korczynski (1):
243
Fix argv leaks in add_route() and add_route_ipv6()
244
245
David Sommerseth (2):
246
doc: Use generic rules for man/html generation
247
man: Clarify IV_HWADDR
248
249
Gert Doering (2):
250
Add error reporting to get_console_input_win32().
251
Preparing release 2.5.4
252
253
Lev Stipakov (3):
254
Fix console prompts with redirected log
255
Add building man page on Windows
256
GitHub Actions: remove Ubuntu 16.04 environment
257
258
Max Fillinger (1):
259
Update Fox e-mail address in copyright notices
260
261
Selva Nair (1):
262
Minor doc correction: tls-crypt-v2 key generation
263
```
264
265
# Changes in 2.5.3
266
267
```
268
Arne Schwabe (3):
269
Add missing free_key_ctx for auth_token
270
Add github actions
271
Implement auth-token-user
272
273
David Sommerseth (1):
274
Update copyrights
275
276
Gert Doering (1):
277
Preparing release 2.5.3
278
279
Lev Stipakov (8):
280
openvpnmsica: properly schedule reboot in the end of installation
281
msvc: add ARM64 configuration
282
msvc: standalone building
283
contrib/vcpkg-ports: add pkcs11-helper port
284
vcpkg-ports: restore trailing whitespaces in .patch files
285
GitHub actions: add MSVC build
286
crypto_openssl.c: disable explicit initialization on Windows (CVE-2121-3606)
287
contrib/vcpkg-ports: add openssl port with --no-autoload-config option set (CVE-2121-3606)
288
289
Matthias Andree (1):
290
Fix SIGSEGV (NULL deref) receiving push "echo"
291
292
Max Fillinger (1):
293
Fix build with mbedtls w/o SSL renegotiation support
294
295
Selva Nair (2):
296
Improve documentation of AUTH_PENDING related directives
297
Apply the connect-retry backoff to only one side of a connection
298
```
299
300
# Changes in 2.5.2
301
302
```
303
Arne Schwabe (10):
304
Avoid generating unecessary mbed debug messages
305
Restore also ping related options on a reconnect
306
Cleanup print_details and add signature/ED certificate print
307
Always disable TLS renegotiations
308
Also restore/save route-gateway options on SIGUSR1 reconnects
309
Move context_auth from context_2 to tls_multi and name it multi_state
310
Fix condition to generate session keys
311
Move auth_token_state from multi to key_state
312
Ensure auth-token is only sent on a fully authenticated session
313
Ensure key state is authenticated before sending push reply
314
315
Gert Doering (2):
316
Fix potential NULL ptr crash if compiled with DMALLOC
317
Preparing release 2.5.2
318
319
Max Fillinger (2):
320
In init_ssl, open the correct CRL path pre-chroot
321
Abort if CRL file can't be stat-ed in ssl_init
322
323
Richard Bonhomme (1):
324
Do not print Diffie Hellman parameters file to log file
325
326
Simon Rozman (1):
327
openvpnserv: Cache last error before it is overridden
328
329
Vladislav Grishenko (1):
330
Fix IPv4 default gateway with multiple route tables
331
```
332
333
# Changes in 2.5.1
334
335
```
336
Arne Schwabe (5):
337
Fix auth-token not being updated if auth-nocache is set
338
Remove auth_user_pass.wait_for_push variable
339
Fix port-share option with TLS-Crypt v2
340
Zero initialise msghdr prior to calling sendmesg
341
Fix tls-auth mismatch OCC message when tls-cryptv2 is used.
342
343
David Sommerseth (1):
344
build: Fix missing install of man page in certain environments
345
346
Domagoj Pensa (3):
347
Fix too early argv freeing when registering DNS
348
Remove 1 second delay before running netsh
349
Skip DHCP renew with Wintun adapter
350
351
Gert Doering (7):
352
Change travis build scripts to use https when fetching prerequisites.
353
Fix line number reporting on config file errors after <inline> segments
354
Clarify --block-ipv6 intent and direction.
355
Document common uses of 'echo' directive, re-enable logging for 'echo'.
356
Make OPENVPN_PLUGIN_ENABLE_PF failures FATAL
357
clean up / rewrite sample-plugins/defer/simple.c
358
Preparing release 2.5.1
359
360
Greg Cox (5):
361
Fix naming error in sample-plugins/defer/simple.c
362
Documentation fixes around openvpn_plugin_func_v3 in openvpn-plugin.h.in
363
Update openvpn_plugin_func_v2 to _v3 in sample-plugins/defer/simple.c
364
More explicit versioning compatibility in sample-plugins/defer/simple.c
365
Explain structver usage in sample defer plugin.
366
367
Richard Bonhomme (1):
368
Man page sections corrections
369
370
Selva Nair (1):
371
Quote the domain name argument passed to the wmic command
372
373
Steffan Karger (2):
374
tls-crypt-v2: fix server memory leak
375
tls-crypt-v2: also preload tls-crypt-v2 keys (if --persist-key)
376
```
377
378
# Changes in 2.5.0
379
380
```
381
Gert Doering (1):
382
Preparing release 2.5.0
383
```
384
385
# Changes in 2.5_rc3
386
387
```
388
Arne Schwabe (2):
389
Allow 'none' cipher being specified in --data-ciphers
390
Add function for common env setting of verify user/pass calls
391
392
David Sommerseth (1):
393
compat/lz4: Update to v1.9.2
394
395
Gert Doering (3):
396
Fix redirecting of IPv4 default gateway if connecting over IPv6.
397
Avoid passing NULL to argv_printf_cat() in temp_file error case.
398
Preparing release 2.5_rc3
399
400
Jan Seeger (1):
401
Added 'route_ipv6_metric_NN' environment variable for IPv6 route metric.
402
403
Richard Bonhomme (1):
404
Improve error msg when all TAP adapters are in use 'or disabled'
405
406
Steffan Karger (1):
407
networking_iproute2: fix memory leak in net_iface_mtu_set()
408
409
Vladislav Grishenko (2):
410
Selectively reformat too long lines
411
Speedup TCP remote hosts connections
412
```
413
414
# Changes in 2.5_rc2
415
416
```
417
Gert Doering (1):
418
Preparing release 2.5_rc2
419
420
Lev Stipakov (1):
421
Alias ADAPTER_DOMAIN_SUFFIX to DOMAIN
422
423
Selva Nair (2):
424
Set DNS Domain using iservice
425
Improve documentation of --username-as-common-name
426
427
Simon Rozman via Openvpn-devel (4):
428
netsh: Specify interfaces by index rather than name
429
netsh: Clear existing IPv6 DNS servers before configuring new ones
430
netsh: Delete WINS servers on TUN close
431
openvpnmsica: Simplify find_adapters() to void return
432
433
Vladislav Grishenko (1):
434
Fix update_time() and openvpn_gettimeofday() coexistence
435
```
436
437
# Changes in 2.5_rc1
438
439
```
440
David Sommerseth (4):
441
man: Add missing --server-ipv6
442
man: Improve --remote entry
443
sample-plugins: Partially autotoolize the sample-plugins build
444
build: Fix make distclean/distcheck
445
446
Gert Doering (11):
447
Fix handling of 'route remote_host' for IPv6 transport case.
448
Replace 'echo -n' with 'printf' in tests/t_lpback.sh
449
Fix description of --client-disconnect calling convention in manpage.
450
Handle NULL returns from calloc() in sample plugins.
451
Fix --show-gateway for IPv6 on NetBSD/i386.
452
socks.c: fix alen for DOMAIN type addresses, bump up buffer sizes
453
Fix netbits setting (in TAP mode) for IPv6 on Windows.
454
If IPv6 pool specification sets pool start to ::0 address, increment.
455
Add demo plugin that excercises "CLIENT_CONNECT" and "CLIENT_CONNECT_V2" paths
456
Fix combination of --dev tap and --topology subnet across multiple platforms.
457
Preparing release 2.5_rc1
458
459
Lev Stipakov (1):
460
msvc: better support for 32bit architecture
461
462
Selva Nair (2):
463
Add a remark on dropping privileges when --mlock is used
464
Allow --dhcp-option in config file when windows-driver is wintun
465
466
Vladislav Grishenko (1):
467
Fix fatal error at switching remotes (#629)
468
```
469
470
# Changes in 2.5_beta4
471
472
```
473
Gert Doering (4):
474
Document that --push-remove is generally more suitable than --push-reset
475
Fix error detection / abort in --inetd corner case.
476
Fix TUNSETGROUP compatibility with very old Linux systems.
477
Preparing release 2.5_beta4
478
479
Lev Stipakov (1):
480
openvpnmsica: make adapter renaming non-fatal
481
482
Selva Nair (1):
483
In tap.c use DiInstallDevice to install the driver on a new adapter
484
485
Vladislav Grishenko (1):
486
Fix best gateway selection over netlink
487
```
488
489
# Changes in 2.5_beta3
490
491
```
492
Arne Schwabe (1):
493
Fix client NCP OCC fallback when server and client cipher are identical
494
495
Gert Doering (1):
496
Preparing release 2.5_beta3
497
```
498
499
# Changes in 2.5_beta2
500
501
```
502
Arne Schwabe (1):
503
Fix client's poor man NCP fallback
504
505
Eric Thorpe (1):
506
Fixes a bug in management_callback_send_cc_message, should be strlen instead of sizeof
507
508
Gert Doering (3):
509
Fix stack overflow in OpenSolaris NEXTADDR()
510
Workaround FreeBSD 12+ race condition on tun/tap open with IPv6.
511
Preparing release 2.5_beta2
512
513
Lev Stipakov (1):
514
tun.c: enable using wintun driver under SYSTEM
515
516
Magnus Kroken (2):
517
doc: fix typos in cipher-negotiation.rst
518
Changes.rst: fix mistyped option names
519
520
Selva Nair (1):
521
Improve the documentation for --dhcp-option
522
```
523
524
# Changes in 2.5_beta1
525
526
Changes since OpenVPN 2.4.0:
527
528
```
529
Adam Ciarciński (1):
530
Fix subnet topology on NetBSD.
531
532
Antonio Quartulli (113):
533
attempt to add IPv6 route even when no IPv6 address was configured
534
fix redirect-gateway behaviour when an IPv4 default route does not exist
535
CRL: use time_t instead of struct timespec to store last mtime
536
ignore remote-random-hostname if a numeric host is provided
537
Ignore auth-nocache for auth-user-pass if auth-token is pushed
538
crypto: correct typ0 in error message
539
use M_ERRNO instead of explicitly printing errno
540
don't print errno twice
541
ntlm: avoid useless cast
542
ntlm: unwrap multiple function calls
543
route: improve error message
544
management: preserve wait_for_push field when asking for user/pass
545
tls-crypt: avoid warnings when --disable-crypto is used
546
ntlm: convert binary buffers to uint8_t *
547
ntlm: restyle compressed multiple function calls
548
ntlm: improve code style and readability
549
OpenSSL: remove unreachable call to SSL_CTX_get0_privatekey()
550
make function declarations C99 compliant
551
remove unused functions
552
use NULL instead of 0 when assigning pointers
553
add missing static attribute to functions
554
ntlm: avoid breaking anti-aliasing rules
555
remove the --disable-multi config switch
556
rename mroute_extract_addr_ipv4 to mroute_extract_addr_ip
557
route: avoid definition of unused variables in certain configurations
558
fix a couple of typ0s in comments and strings
559
fragment.c: simplify boolean expression
560
tcp-server: ensure AF family is propagated to child context
561
Remove ENABLE_CRYPTO
562
Remove option to disable crypto engine
563
Remove ENABLE_PUSH_PEER_INFO
564
Remove SSL_LIB_VER_STR
565
Remove MD5SUM
566
reload HTTP proxy credentials when moving to the next connection profile
567
Allow learning iroutes with network made up of all 0s (only if netbits < 8)
568
mbedtls: fix typ0 in comment
569
manpage: fix simple typ0
570
pool: restyle ipv4/ipv6 members to improve readability
571
pool: convert pool 'type' to enum
572
tun: ensure gc and argv are properly handled
573
tun: always pass a valid tt pointer
574
tun: get rid of tt->did_ifconfig member
575
tun: ensure interface can be configured with IPv6 only
576
add support for %lu in argv_printf and prevent ASSERT
577
windows: properly configure TAP driver when no IPv4 is configured
578
socket: make stream_buf_* functions static
579
crypto: always reload tls-auth/crypt key contexts
580
make tls-auth and tls-crypt per-connection-block options
581
pf: restyle pf_c2c/addr_test() to make them 'struct context' agnostic
582
merge *-inline.h files with their main header
583
ensure function declarations are compiled with their definitions
584
buffer_list: add functions documentation
585
ifconfig-ipv6(-push): allow using hostnames
586
tls-crypt: properly cast time_t to uint64_t
587
implement platform generic networking API
588
implement networking API for iproute2
589
introduce sitnl: Simplified Interface To NetLink
590
tun.c: use new networking API to handle tun interface on Linux
591
travis.yml: add test for iproute2 net implementation
592
route.c: use new networking API to handle routing table on Linux
593
unit tests: implement test for sitnl
594
t_net.sh: make bash dep explicit and run only if SITNL is compiled
595
t_net.sh: properly perform sudo check and print test steps
596
route.c: fix windows build by removing mismatching function parameter
597
t_net.sh: fixes for the networking test script
598
route.c: use sitnl to implement get_default_gateway_ipv6()
599
networking/best_gw: remove useless prefixlen parameter
600
sitnl: harden strncpy() by forcing arguments to have the same length
601
mbedtls: fix segfault by calling mbedtls_cipher_free() in cipher_ctx_free()
602
networking: extend API for better memory management
603
tun.c: undo_ifconfig_ipv4/6 remove useless gc argument
604
networking_sitnl.c: uncrustify file
605
route.c: simplify ifdef logic
606
t_net.sh: wait for NO-CARRIER bit to settle before starting test
607
t_net.sh: execute sleep after checking exit code of previous command
608
maddr: create helper function to populate maddr object from eth_addr
609
VLAN: add basic VLAN tagging support
610
maddr: export VLAN ID from client context to maddr object
611
VLAN: filter multicast and client-to-client unicast traffic
612
is_ipv_X: add support for parsing IP header inside a 802.1q frame
613
VLAN: implement support for forwarding only pre-tagged VLAN packets
614
VLAN: allow forwarding tagged and untagged packets on the server TAP device
615
VLAN: add documentation to manpage
616
socks: use the right function when printing struct openvpn_sockaddr
617
add -Wno-stringop-truncation to CFLAGS on linux
618
get rid of 'broadcast' argument when configuring the tun device
619
auth_token_kt: ensure key_type object is initialized
620
auth.c: make cast explicit in the crypto API
621
travis: compile with -Werror on Linux
622
travis: fix CFLAGS assignment error and add -Werror only when compiling on Linux for Linux
623
sitnl: fix failure reporting by keeping error negative
624
sitnl: fix TUN/TAP confusion in error messages
625
sitnl: fix ignoring EEXIST when sending a netlink command
626
t_net.sh: use dummy interface instead of tun
627
remove bogus file check on --genkey argument
628
t_net.sh: assign MAC address directly during interface creation
629
convert *_inline attributes to bool
630
options: fix inlining auth-gen-token-secret file
631
tls-crypt-v2: fix testing of inline key
632
get rid of INLINE_FILE_TAG constant
633
pool: prevent IPv6 pools to be larger than 2^16 addresses
634
pool: allow to configure an IPv6-only ifconfig-pool
635
allow usage of --server-ipv6 even when no --server is specified
636
pool: add support for ifconfig-pool-persist with IPv6 only
637
route: warn on IPv4 routes installation when no IPv4 is configured
638
options: enable IPv4 redirection logic only if really required
639
ipv6-pool: get rid of size constraint
640
pool: remove useless 'options.h' include
641
multi: skip IPv4 logic in multi_select_virtual_addr() if no pool is configured
642
multi.c: use mi->cc_config instead of config variable
643
options: don't leak inline'd key material in logfile
644
t_net.sh: drop hard dependency on t_client.rc
645
travis: don't run t_net.sh test
646
647
Arne Schwabe (124):
648
Set tls-cipher restriction before loading certificates
649
Print ec bit details, refuse management-external-key if key is not RSA
650
Replace buffer backed strings for management_android_control with simple stack variables
651
Treat dhcp-option DNS6 and DNS identical
652
show the right string for key-direction
653
Add MTU to Android IFCONFIG6 control command
654
Properly free tuntap struct on android when emulating persist-tun
655
Add OpenSSL compat definition for RSA_meth_set_sign
656
Skip error about ioctl(SIOCGIFCONF) failed on Android
657
Factor out convert_tls_list_to_openssl method
658
Remove AUTO_USERID feature
659
Remove MANAGMENT_EXTERNAL_KEY, MANAGMENT_IN_EXTRA, ENABLE_CLIENT_CR
660
Add support for tls-ciphersuites for TLS 1.3
661
Add better support for showing TLS 1.3 ciphersuites in --show-tls
662
Use right function to set TLS1.3 restrictions in show-tls
663
Refuse mbed TLS external key with non RSA certificates
664
Add message explaining early TLS client hello failure
665
Add tls-crypt-v2 to the list of supported inline options
666
Implement block-ipv6
667
Fallback to password authentication when auth-token fails
668
Fix loading inline tls-crypt-v2 keys with mbed TLS
669
Refactor tls_crypt_v2_write_server_key_file into crypto.c
670
Add send_control_channel_string_dowork variant
671
Rename tls_crypt_v2_read_keyfile into generic pem_read_key_file
672
Fix poll.h logic in syshead.h
673
Write key to stdout if filename is not given
674
Implement --genkey type keyfile syntax and migrate tls-crypt-v2
675
Add generate_ephemeral_key that allows a random ephermal key
676
Remove -no-cpp-precomp flag from Darwin builds
677
Fix check if iface name is set
678
Adjust Android code after sitnl patch merge
679
Rewrite auth-token-gen to be based on HMAC based tokens
680
Implement a permanent session id in auth-token
681
Sent indication that a session is expired to clients
682
Implement unit tests for auth-gen-token
683
Make tls_version_max return the actual maximum version
684
Add support for OpenSSL TLS 1.3 when using management-external-key
685
Document tls-ciphersuites also in --help output
686
Only announce IV_NCP=2 when we are willing to support these ciphers
687
Add strsep compat function
688
Implement dynamic NCP negotiation
689
Warn about insecure ciphers also in init_key_type
690
Move NCP related function into a seperate file and add unit tests
691
Normalise ncp-ciphers option and restrict it to 127 bytes
692
Fetch OpenSSL versions via source/old links
693
Fix OpenSSL error stack handling of tls_ctx_add_extra_certs
694
Fix off-by-one in tls-crypt-v2 client wrapping with custom metadata
695
Fix OpenSSL 1.1.1 not using auto elliptic curve selection
696
Refactor counting number of element in a : delimited list into function
697
Minor style change to improve code style
698
Another round of uncrustify code cleanup.
699
Fix tls_ctx_client/server_new leaving error on OpenSSL error stack
700
Add tls-crypt-v2 test writing metadata
701
Use crypto library functions for const time memcmp when possible
702
Fix session id in env missing first byte
703
Document reneweal mechanic of auth-token in manual
704
Fix session id and initial timestamp not being preserved
705
Do not write extra 0 byte for --gen-key with auth-token/tls-crypt-v2
706
Refuse server mode on Android
707
Add .git-blame-ignore-revs with reformat commits
708
Make cipher_kt_name always return normalised cipher name
709
Make cipher_kt_get also accept OpenVPN config cipher name
710
Implement parsing and sending INFO and INFO_PRE control messages
711
Implement support for signalling IV_SSO to server
712
Implement sending response to challenge via CR_RESPONSE
713
Implement sending AUTH_PENDING challenges to clients
714
Implement forwarding client CR_RESPONSE messages to management
715
Add unit test for cipher name translations
716
Make compression asymmetric by default and add warnings
717
Reformat files using uncrustify
718
Remove parameter config from multi_client_connect_mda
719
Remove push_reply_deferred variable
720
Remove did_open_context, defined and connection_established_flag
721
merge key_state->authenticated and key_state->auth_deferred
722
Simplify multi_connection_established.
723
Deprecate ncp-disable and add improved ncp to Changes.rst
724
Make key_state->authenticated more state machine like
725
Extract process_incoming_push_reply from process_incoming_push_msg
726
Removed unused definition
727
Code cleanup: remove superflous variable
728
Move protocol option negotiation from push_prepare to new function
729
Generate data channel keys after connect options have been parsed
730
Cleanup: Remove special case code for old poor man's NCP.
731
Allow changing fallback cipher from ccd files/client-connect
732
client-connect: Change cas_context from int to enum
733
client-connect: Move adding inotify watch into its own function
734
reformat multi_client_generate_tls_keys according to uncrustify
735
client-connect: Add CC_RET_DEFERRED and cope with deferred client-connect
736
Remove CAS_PARTIAL state
737
client-connect: Use inotify for the deferred client-connect status file
738
client-connect: Implement deferred connect support for plugin API v2
739
Drop support for OpenSSL 1.0.1
740
Require AEAD support in the crypto library
741
Remove key-method 1
742
Remove ENABLE_OCC #define
743
Implement tls-groups option to specify eliptic curves/groups
744
Avoid sending --cipher to clients not supporting NCP
745
Indicate that a client is in pull mode in IV_PROTO
746
Deprecate --inetd
747
Include utun device number in utun error messages
748
Simplify calling logic of check_connection_established_dowork
749
Avoid sending push request after receving push reply
750
Rename ncp-ciphers to data-ciphers
751
Add a note that ncp-ciphers is replaced by data-ciphers
752
client-connect: Add documentation for the deferred client connect feature
753
Rework NCP compability logic and drop BF-CBC support by default
754
Document different behaviour of dynamic cipher negotiation
755
Minor cleanup in push.c
756
Clean up a number of leftover C89 initialisations in ssl.c
757
Remove buf argument from link_socket_set_outgoing_addr
758
Remove a number of check/do_work wrapper calls from coarse_timers
759
Split pf_check_reload check and check timer in process_coarse_timers
760
Rename check_ping_restart_dowork to trigger_ping_timeout_signal
761
Eliminate check_fragment function
762
Eliminate check_incoming_control_channel wrapper function
763
Eliminate check_tls wrapper function
764
Merge check_coarse_timers and check_coarse_timers_dowork
765
Skip existing interfaces on opening the first available utun on macOS
766
Move parsing IV_PROTO to separate function
767
Remove S_OP_NORMAL key state.
768
Document comp-lzo no and compress being incompatible
769
Refactor/Reformat tls_pre_decrypt
770
Cleanup tls_pre_decrypt_lite and tls_pre_encrypt
771
Improve sections about older OpenVPN clients in cipher-negotiation.rst
772
773
Bertrand Bonnefoy-Claudet (1):
774
Fix typo in error message: "optione" -> "option"
775
776
Christian Ehrhardt (1):
777
systemd: extend CapabilityBoundingSet for auth_pam
778
779
Christian Hesse (7):
780
man: fix formatting for alternative option
781
systemd: Use automake tools to install unit files
782
systemd: Do not race on RuntimeDirectory
783
systemd: Add more security feature for systemd units
784
Clean up plugin path handling
785
plugin: Remove GNUism in openvpn-plugin.h generation
786
fix typo in notification message
787
788
Christopher Schenk (3):
789
Set the correct mtu on windows based systems
790
Log a note if someone wants to set a MTU below 1280 on IPv6
791
Unified success messages for setting mtu
792
793
Conrad Hoffmann (2):
794
Use provided env vars in up/down script.
795
Document down-root plugin usage in client.down
796
797
David Sommerseth (72):
798
dev-tools: Added script for updating copyright years in files
799
dev-tools: Added script for updating copyright years in files
800
Update copyrights
801
Update copyrights
802
docs: Further enhance the documentation related to SWEET32
803
docs: Further enhance the documentation related to SWEET32
804
man: Remove references to no longer present IV_RGI6 peer-info
805
man: Remove references to no longer present IV_RGI6 peer-info
806
build: Ensure Changes.rst is shipped and installed as a doc file
807
build: Ensure Changes.rst is shipped and installed as a doc file
808
Preparing OpenVPN v2.4.0 release
809
management: >REMOTE operation would overwrite ce change indicator
810
management: Remove a redundant #ifdef block
811
git: Merge .gitignore files into a single file
812
systemd: Move the READY=1 signalling to an earlier point
813
dev-tools: Simple tool which automates rebasing LZ4 compat library
814
dev-tools: lz4-rebaser tool carried a typo
815
plugin: Improve the handling of default plug-in directory
816
cleanup: Remove faulty env processing functions
817
auth-token: Ensure tokens are always wiped on de-auth
818
docs: Fixed man-page warnings discoverd by rpmlint
819
Make --cipher/--auth none more explicit on the risks
820
Require minimum OpenSSL 1.0.1
821
Fix broken ./configure on systems without openssl.pc
822
plugin: Fix documentation typo for type_mask
823
plugin: Export secure_memzero() to plug-ins
824
crypto: Enable SHA256 fingerprint checking in --verify-hash
825
copyright: Update GPLv2 license texts
826
dev-tools: Script generating the source releases in an automated fashion
827
auth-token with auth-nocache fix broke --disable-crypto builds
828
doc: The CRL processing is not a deprecated feature
829
cleanup: Move write_pid() to where it is being used
830
contrib: Remove keychain-mcd code
831
cleanup: Move init_random_seed() to where it is being used
832
Highlight deprecated features
833
Use consistent version references
834
docs: Replace all PolarSSL references to mbed TLS
835
systemd: Ensure systemd shuts down OpenVPN in a proper way
836
systemd: Enable systemd's auto-restart feature for server profiles
837
lz4: Move towards a newer LZ4 API
838
lz4: Fix confused version check
839
lz4: Fix broken builds when pkg-config is not present but system library is
840
Remove references to keychain-mcd in Changes.rst
841
lz4: Rebase compat-lz4 against upstream v1.7.5
842
systemd: Add and ship README.systemd
843
Update copyright to include 2018 plus company name change
844
man: Add .TQ groff support macro
845
man: Reword --management to prefer unix sockets over TCP
846
management: Warn if TCP port is used without password
847
plugin: Export base64 encode and decode functions
848
build: Fix build warnings related to get_random()
849
build: Fix another compile warning in console_systemd.c
850
cleanup: Remove RPM openvpn.spec build approach
851
docs: Update INSTALL
852
build: Package missing mock_msg.h
853
auth-token: Fix building with --disable-server
854
auth-token: Fix compiler complaints with --disable-management
855
Improve the comments related to auth-token-hmac patches
856
Documented all the argv related code with minor refactoring
857
build: Remove --disable-server from ./configure
858
options: Fix failing inline tls-auth/crypt with persist-key
859
options: Restore --tls-crypt-v2 inline file capability
860
doc/man: convert openvpn.8 to split-up .rst files
861
doc/man: Mark compression options as deprecated
862
doc/man: Adopt compression documentation
863
doc/man: Documentation for --bind-dev / VRFs on Linux
864
doc/man: Add misssing renegotiation.rst to Makefile.am
865
Remove --no-iv
866
doc/man: Do not install man *.rst files
867
travis: Fix make distcheck failure
868
Remove --ifconfig-pool-linear
869
Remove --client-cert-not-required
870
871
Domagoj Pensa (2):
872
Fix linking issues on MinGW
873
Skip DNS address validation
874
875
Emmanuel Deloget (20):
876
OpenSSL: check for the SSL reason, not the full error
877
OpenSSL: don't use direct access to the internal of X509_STORE_CTX
878
OpenSSL: don't use direct access to the internal of SSL_CTX
879
OpenSSL: don't use direct access to the internal of X509_STORE
880
OpenSSL: don't use direct access to the internal of X509_OBJECT
881
OpenSSL: don't use direct access to the internal of RSA_METHOD
882
OpenSSL: SSLeay symbols are no longer available in OpenSSL 1.1
883
OpenSSL: use EVP_CipherInit_ex() instead of EVP_CipherInit()
884
OpenSSL: don't use direct access to the internal of X509
885
OpenSSL: don't use direct access to the internal of EVP_PKEY
886
OpenSSL: don't use direct access to the internal of RSA
887
OpenSSL: don't use direct access to the internal of DSA
888
OpenSSL: force meth->name as non-const when we free() it
889
OpenSSL: don't use direct access to the internal of EVP_MD_CTX
890
OpenSSL: don't use direct access to the internal of EVP_CIPHER_CTX
891
OpenSSL: don't use direct access to the internal of HMAC_CTX
892
OpenSSL: remove pre-1.1 function from the OpenSSL compat interface
893
OpenSSL: remove EVP_CIPHER_CTX_new() from the compat layer
894
OpenSSL: remove EVP_CIPHER_CTX_free() from the compat layer
895
OpenSSL: check EVP_PKEY key types before returning the pkey
896
897
Eric Thorpe (1):
898
Fix Building Using MSVC
899
900
Fabian Knittel (7):
901
client-connect: Split multi_connection_established into separate functions
902
client-connect: Refactor multi_client_connect_source_ccd
903
client-connect: Move multi_client_connect_setenv into early_setup
904
client-connect: Refactor to use return values instead of modifying a passed-in flag
905
client-connect: Refactor client-connect handling to calling a bunch of hooks in a loop
906
client-connect: Add deferred support to the client-connect script handler
907
client-connect: Add deferred support to the client-connect v1 plugin handler
908
909
Gert Doering (51):
910
Remove IV_RGI6=1 peer-info signalling.
911
Remove IV_RGI6=1 peer-info signalling.
912
Add openssl_compat.h to openvpn_SOURCES
913
Fix '--dev null'
914
Fix installation of IPv6 host route to VPN server when using iservice.
915
Make ENABLE_OCC no longer depend on !ENABLE_SMALL
916
Fix NCP behaviour on TLS reconnect.
917
Remove erroneous limitation on max number of args for --plugin
918
proxy.c refactoring: remove always-NULL gc parameter
919
Fix edge case with clients failing to set up cipher on empty PUSH_REPLY.
920
Fix potential 1-byte overread in TCP option parsing.
921
Fix remotely-triggerable ASSERT() on malformed IPv6 packet.
922
Update Changes.rst with relevant info for 2.4.3 release.
923
Remove warning on pushed tun-ipv6 option.
924
Fix removal of on-link prefix on windows with netsh
925
Fix potential double-free() in Interactive Service (CVE-2018-9336)
926
Add %d, %u and %lu tests to test_argv unit tests.
927
Extend push-remove to also handle 'ifconfig'.
928
Print lzo_init() return code in case of errors
929
Uncrustify sample-plugin sources according to code style
930
uncrustify openvpnserv/ sources
931
uncrustify openvpn/ sources
932
Add 'printing of port number' to mroute_addr_print_ex() for v4-mapped v6.
933
Stop complaining about IPv6 routes without gateway address.
934
Copy one byte less in strncpynt()
935
Remove cmocka submodule, rely on system-wide installation instead.
936
Increase listen() backlog queue to 32
937
repair tap mode on OpenSolaris/OpenIndiana
938
Fix IPv6 routes on tap interfaces on OpenSolaris/OpenIndiana
939
OpenSolaris/OpenIllumos: use /bin/bash if available for test scripts.
940
Force combinationation of --socks-proxy and --proto UDP to use IPv4.
941
Uncrustify the tests/unit_tests/ part of our tree.
942
Change client side of t_lpback.sh configs to use inline material.
943
Simplify pool size handling, fix possible array overrun on pool reading.
944
Change timestamps in file-based logging to ISO 8601 time format.
945
Depreciation warning for --topology net30 on servers with IPv4 pools.
946
Convert plugin/auth-pam.c from stderr logging to plugin_log().
947
Add c1ff8f247f91c88a2df5502eeedf42857f9a6831 (engine, pool, SSO) to .git-blame-ignore-revs
948
Linux: do not change --txqueuelen OS default if not configured.
949
Fix 'engine' unit test on FreeBSD (specifically 'not GNU make')
950
t_client.sh: correctly report all failed instances in summary
951
Remove --writepid file on program exit.
952
Handle connecting clients without NCP or OCC without crashing.
953
Add deferred authentication support to plugin-auth-pam
954
Separate handling of non-deferred return values for client-connect-scripts.
955
Repair --inetd
956
Fix sequence of events for async plugin v1 handler.
957
Abort client-connect handler loop after first handler sets 'disable'.
958
Add depreciation notice for --ncp-disable to protocol-options.rst
959
Changes.rst updates in preparation to 2.5_beta1
960
Preparing release 2.5_beta1
961
962
Gert van Dijk (7):
963
Warn that DH config option is only meaningful in a tls-server context
964
Add generated openvpn.doxyfile to .gitignore
965
manpage: improve description of --status and --status-version
966
Add negotiated cipher to status file format 2 and 3
967
Minor reliability layer documentation fixes
968
Make second parameter to reliable_send_purge() const
969
Remove unneeded newline in debug message in reliable.c
970
971
Gisle Vanem (2):
972
Crash in options.c
973
Wrong FILETYPE in .rc files
974
975
Guido Vranken (6):
976
refactor my_strupr
977
Fix 2 memory leaks in proxy authentication routine
978
Fix memory leak in add_option() for option 'connection'
979
Ensure option array p[] is always NULL-terminated
980
Fix a null-pointer dereference in establish_http_proxy_passthru()
981
Prevent two kinds of stack buffer OOB reads and a crash for invalid input data
982
983
Heiko Hund (3):
984
re-implement argv_printf_*()
985
argv: do fewer memory re-allocations
986
Add gc_arena to struct argv to save allocations
987
988
Hilko Bengen (1):
989
Do not set pkcs11-helper 'safe fork mode'
990
991
Hristo Venev (1):
992
Fix extract_x509_field_ssl for external objects, v2
993
994
Ilya Shipitsin (18):
995
Resolve several travis-ci issues
996
github: Add PR template with contributor related information
997
travis-ci: add 'make distcheck' to test scenario, V2
998
travis-ci: remove unused files
999
v4, travis-ci: add 2 mingw "build only" configurations
1000
travis-ci: added gcc and clang openssl-1.1.0 builds
1001
travis-ci: update openssl to 1.0.2l, update mbedtls to 2.5.1
1002
travis-ci: update pkcs11-helper to 1.22
1003
travis-ci: add brew cache, remove ccache
1004
travis-ci: modify openssl build script to support openssl-1.1.0
1005
travis-ci: cleanup, refactor, upgrade ssl libraries
1006
travis-ci: add "linux-ppc64le" to build matrix
1007
travis-ci: change trusty image to xenial
1008
travis-ci: update osx to xcode9.4 and modernize brew management
1009
configure.ac: fix compile-time error in argv_testdriver
1010
travis-ci: fix osx builds
1011
travis-ci: update components versions
1012
travis-ci: add arm64, s390x builds.
1013
1014
James Bekkema (2):
1015
Resolves small IV_GUI_VER typo in the documentation.
1016
Adds support for setting the default IPv6 gateway for routes using the route-ipv6-gateway option.
1017
1018
James Bottomley (7):
1019
autoconf: Fix engine checks for openssl 1.1
1020
openssl: add engine method for loading the key
1021
crypto_openssl: add initialization to pick up local configuration
1022
crypto_openssl: add include for openssl/conf.h
1023
Add unit tests for engine keys
1024
Fix make distcheck for new engine key unit test
1025
engine-key tests: make check_engine_keys.sh work with --enable-small
1026
1027
Jan Just Keijser (1):
1028
Added support for DHCP option 119 (dns search suffix list) for Windows.
1029
1030
Jeremie Courreges-Anglas (5):
1031
Cast time_t to long long in order to print it.
1032
Print time_t as long long and suseconds_t as long
1033
Cast and print another suseconds_t as long
1034
Use long long to format time_t-related environment variables
1035
Fix build with LibreSSL
1036
1037
Jeremy Evans (1):
1038
Switch assertion failure to returning false
1039
1040
Jonathan K. Bullard (1):
1041
Clarify and expand management interface documentation
1042
1043
Jonathan Tooker (1):
1044
Fix various spelling mistakes
1045
1046
Joost Rijneveld (1):
1047
Make return code external tls key match docs
1048
1049
Jérémie Courrèges-Anglas (2):
1050
Fix an unaligned access on OpenBSD/sparc64
1051
Missing include for socket-flags TCP_NODELAY on OpenBSD
1052
1053
Kyle Evans (1):
1054
tests/t_lpback.sh: Switch sed(1) to POSIX-compatible regex.
1055
1056
Lev Stipakov (46):
1057
win: support for Visual Studio 2017
1058
Refactor NCP-negotiable options handling
1059
init.c: refine functions names and description
1060
openvpnserv: clarify return values type
1061
crypto.h: remove unused function declaration
1062
interactive.c: fix usage of potentially uninitialized variable
1063
options.c: fix broken unary minus usage
1064
Introduce openvpn_swprintf() with nul termination guarantee
1065
Wrap openvpn_swprintf into Windows define
1066
test_tls_crypt.c: fix global-buffer-overflow found by AddressSanitizer
1067
crypto_openssl.c: fix heap-buffer-overflow found by AddressSanitizer
1068
Fix various compiler warnings
1069
Fix broken fragment/mssfix with NCP
1070
crypto.c: fix Visual Studio build
1071
tun.h: change tun_set() return value type to void
1072
tun.h: remove TUN_PASS_BUFFER define
1073
tapctl: add optional 'hardware id' parameter
1074
vcxproj: add missing source files
1075
push.c: fix Visual Studio build
1076
Visual Studio: make it easier to build with VS
1077
msvc: OpenSSL 1.1.x support
1078
travis: add Visual Studio build
1079
Visual Studio: upgrade project files to VS2019
1080
wintun: add --windows-driver config option
1081
wintun: implement opening wintun device
1082
travis: bump MSVC to 2019
1083
travis: bump clang version
1084
wintun: ring buffers based I/O
1085
wintun: interactive service support
1086
wintun: set adapter properties via interactive service
1087
wintun: clear adapter settings on tun close
1088
tun.c: refactor open_tun() implementation
1089
tun.c: do not add/remove on-link IPv4 route on tun open/close
1090
options.c: do not force route delay when not using DHCP
1091
configure.ac: simplify AC_CHECK_FUNCS statements
1092
cryptoapi.c: fix run-time check failure in msvc debugger
1093
interactive.c: remove unused function
1094
tun.c: fix 'use after free' error
1095
Fix building with --enable-async-push in FreeBSD
1096
Fix broken async push with NCP is used
1097
Fix illegal client float (CVE-2020-11810)
1098
msvc: fix various level2 warnings
1099
tap.c: fix adapter renaming
1100
Improve Windows version detection with manifest
1101
wintun: remove SYSTEM elevation hack
1102
Fix compilation with --disable-lzo and --disable-lz4
1103
1104
Matthias Andree (3):
1105
Make openvpn-plugin.h self-contained again.
1106
Merge Makefile.am's AUTOMAKE_OPTIONS into configure.ac's AM_INIT_AUTOMAKE.
1107
Fix stack buffer overruns in NEXTADDR() macro:
1108
1109
Maxim Plotnikov (1):
1110
OpenSSL: Fix --crl-verify not loading multiple CRLs in one file
1111
1112
Maximilian Wilhelm (1):
1113
Add --bind-dev option.
1114
1115
Michal Soltys (1):
1116
man: correct the description of --capath and --crl-verify regarding CRLs
1117
1118
Mykola Baibuz (1):
1119
Fix typo in NTLM proxy debug message
1120
1121
Olivier Wahrenberger (1):
1122
Fix building with LibreSSL 2.5.1 by cleaning a hack.
1123
1124
Richard Bonhomme (3):
1125
man: Corrections to doc/openvpn.8
1126
Ignore --pull-filter for --mode server
1127
doc/man: Update --txqueuelen default setting (Now OS default)
1128
1129
Richard van den Berg via Openvpn-devel (1):
1130
Fix error message when using RHEL init script
1131
1132
Rosen Penev (2):
1133
Remove wrong poll.h include
1134
openssl: Fix compilation without deprecated OpenSSL 1.1 APIs
1135
1136
Samy Mahmoudi (1):
1137
man: correct a --redirection-gateway option flag
1138
1139
Santtu Lakkala (1):
1140
Fix OpenSSL private key passphrase notices
1141
1142
Selva Nair (55):
1143
Fix push options digest update
1144
Always release dhcp address in close_tun() on Windows.
1145
Add a check for -Wl, --wrap support in linker
1146
Fix user's group membership check in interactive service to work with domains
1147
In auth-pam plugin clear the password after use
1148
Pass correct buffer size to GetModuleFileNameW()
1149
Check whether in pull_mode before warning about previous connection blocks
1150
Avoid illegal memory access when malformed data is read from the pipe
1151
Fix missing check for return value of malloc'd buffer
1152
Return NULL if GetAdaptersInfo fails
1153
Use RSA_meth_free instead of free
1154
Bring cryptoapi.c upto speed with openssl 1.1
1155
Add SSL_CTX_get_max_proto_version() not in openssl 1.0
1156
TLS v1.2 support for cryptoapicert -- RSA only
1157
Refactor ssl_openssl.c in prep for external EC key support
1158
Refactor get_interface_metric to return metric and auto flag separately
1159
Add management client version
1160
Prompt for signature using '>PK_SIGN' if the client supports it
1161
Allow external EC key through --management-external-key
1162
Ensure strings read from registry are null-terminated
1163
Make most registry values optional
1164
Use lowest metric interface when multiple interfaces match a route
1165
Move code to free cd to a function CAPI_DATA_free()
1166
Disable external ec key support when building with libressl
1167
Adapt to RegGetValue brokenness in Windows 7
1168
Fix format spec errors in Windows builds
1169
Move setting private key to a function in prep for EC support
1170
Support EC certificates with cryptoapicert
1171
Delete the IPv6 route to the "connected" network on tun close
1172
Management: warn about password only when the option is in use
1173
Avoid overflow in wakeup time computation
1174
Replace M_DEBUG with D_LOW as the former is too verbose
1175
Correct the declaration of handle in 'struct openvpn_plugin_args_open_return'
1176
Parse static challenge response in auth-pam plugin
1177
Bump version of openvpn plugin argument structs to 5
1178
Accept empty password and/or response in auth-pam plugin
1179
Pass the hash without the DigestInfo header to NCryptSignHash()
1180
Move get system directory to a separate function
1181
Enable dhcp on tap adapter using interactive service
1182
Refactor sending commands to interactive service
1183
Declare Windows version of openvpn_execve() before use
1184
White-list pull-filter and script-security in interactive service
1185
Move OpenSSL vs CNG signature digest type mapping to a function
1186
Handle PSS padding in cryptoapicert
1187
Better error message when script fails due to script-security setting
1188
Correct the return value of cryptoapi RSA signature callbacks
1189
Fix ACL_CHECK_ADD_COMPILE_FLAGS to work with clang
1190
Swap the order of checks for validating interactive service user
1191
Skip expired certificates in Windows certificate store
1192
Allow unicode search string in --cryptoapicert option
1193
Fix possibly uninitialized return value in GetOpenvpnSettings()
1194
Fix possible access of uninitialized pipe handles
1195
Move querying username/password from management to a function
1196
When auth-user-pass file has no password query the management interface (if available).
1197
Persist management-query-remote and proxy prompts
1198
1199
Simon Matter (2):
1200
Fix segfault when using crypto lib without AES-256-CTR or SHA256
1201
Add per session pseudo-random jitter to --reneg-sec intervals
1202
1203
Simon Rozman (67):
1204
Local functions are not supported in MSVC. Bummer.
1205
Mixing wide and regular strings in concatenations is not allowed in MSVC.
1206
RtlIpv6AddressToStringW() and RtlIpv4AddressToStringW() require mstcpip.h
1207
Simplify iphlpapi.dll API calls
1208
Fix local #include to use quoted form
1209
Document ">PASSWORD:Auth-Token" real-time message
1210
Fix typo in "verb" command examples
1211
Uniform swprintf() across MinGW and MSVC compilers
1212
MSVC meta files added to .gitignore list
1213
openvpnserv: Review MSVC down-casting warnings
1214
openvpnserv: Add support for multi-instances
1215
Document missing OpenVPN states
1216
Add Interactive Service developer documentation
1217
Change quoted to angled form when #including external .h files
1218
Signed/unsigned warnings of MSVC resolved
1219
Reference msvc-generate from compat to assure correct build order
1220
msvc: Move common project settings to reusable property sheets
1221
msvc: Unify Unicode/MultiByte string setting across all cfg|plat
1222
Introduce tapctl.exe utility and openvpnmsica.dll MSI CA
1223
Set output name to libopenvpnmsica.dll in MSVC builds too
1224
Prevent __stdcall name mangling of MSVC
1225
Define _WIN32_WINNT=_WIN32_WINNT_VISTA in MSVC
1226
Add MSI custom action for reliable Windows 10 detection
1227
Detect TAP interfaces with root-enumerated hardware ID
1228
Change C++ to C comments
1229
Make MSI custom action debug pop-up more informative
1230
Delete TAP interface before the TAP driver is uninstalled
1231
Add detection of active VPN connections for MSI packages
1232
Add a MSI custom actions to close and relaunch OpenVPN GUI
1233
Make DriverCertification MSI property public
1234
Extend FindSystemInfo custom action to detect OpenVPNService state
1235
Uncrustify tapctl and openvpnmsica
1236
Strip _stdcall suffixes (@nn) for 32-bit builds
1237
Detect missing TAP driver and bail out gracefully
1238
Disambiguate thread local storage references from TLS
1239
Add NULL checks
1240
Add user manual and developer notes URL for tapctl.exe
1241
Refactor OpenVPNService state detection code
1242
Add developer notes URL for openvpnmsica.dll
1243
Limit tapctl.exe and openvpnmsica.dll to TAP-Windows6 adapters only
1244
msvc: Add vlan.c/h
1245
tun.c: make Windows device lookup functions more general
1246
tun.c: upgrade get_device_guid() to return the Windows driver type
1247
tun.c: make wintun_register_ring_buffer() non-fatal on failures
1248
wintun: register ring buffers when iterating adapters
1249
wintun: add support for --dev-node
1250
tun.c: reword the at_least_one_tap_win() error
1251
wintun: stop sending TAP-Windows6 ioctls to NDIS device
1252
wintun: refactor code to use enum driver type
1253
tun.c: refactor driver detection and make it case-insensitive
1254
tun.c: uncrustify
1255
wintun: check for conflicting options
1256
openvpnmsica: Remove required Windows driver certification detection
1257
openvpnmsica: Fix TAPInterface.DisplayName field interpretation
1258
tapctl: Update documentation
1259
wintun: upgrade error message in case of ring registration failure
1260
tun.c: reorder IPv6 ifconfig on Windows
1261
tapctl: Add functions for enabling/disabling adapters
1262
openvpnmsica: Revise MSI custom actions interop
1263
openvpnmsica: Simplify static function names
1264
openvpnmsica, tapctl: "interface" => "adapter"
1265
openvpnmsica: "TAP" => "TUN/TAP"
1266
openvpnmsica: Extend to support arbitrary HWID network adapters
1267
openvpnmsica, tapctl: Revise default hardware ID management
1268
openvpnmsica: Merge FindTUNTAPAdapters into FindSystemInfo
1269
tapctl: Support multiple hardware IDs
1270
tun.c: revise the IPv4 ifconfig flow on Windows
1271
1272
Stefan Strogin (1):
1273
Use correct ifdefs for LibreSSL support
1274
1275
Steffan Karger (126):
1276
Bump master to version 2.5_git
1277
Document that RSA_SIGN can also request TLS 1.2 signatures
1278
man: encourage user to read on about --tls-crypt
1279
Document that RSA_SIGN can also request TLS 1.2 signatures
1280
man: encourage user to read on about --tls-crypt
1281
Textual fixes for Changes.rst
1282
Textual fixes for Changes.rst
1283
Remove deprecated --no-iv option
1284
More broadly enforce Allman style and braces-around-conditionals
1285
Use SHA256 for the internal digest, instead of MD5
1286
OpenSSL: 1.1 fallout - fix configure on old autoconf
1287
Fix types in WIN32 socket_listen_accept()
1288
Remove duplicate X509 env variables
1289
Fix non-C99-compliant builds: don't use const size_t as array length
1290
Deprecate --ns-cert-type
1291
Be less picky about keyUsage extensions
1292
cleanup: merge packet_id_alloc_outgoing() into packet_id_write()
1293
Don't run packet_id unit tests for --disable-crypto builds
1294
Fix Changes.rst layout
1295
Fix memory leak in x509_verify_cert_ku()
1296
mbedtls: correctly check return value in pkcs11_certificate_dn()
1297
Restore pre-NCP frame parameters for new sessions
1298
Always clear username/password from memory on error
1299
Document tls-crypt security considerations in man page
1300
Don't assert out on receiving too-large control packets (CVE-2017-7478)
1301
Drop packets instead of assert out if packet id rolls over (CVE-2017-7479)
1302
Log the negotiated (NCP) cipher
1303
Avoid a 1 byte overcopy in x509_get_subject (ssl_verify_openssl.c)
1304
Skip tls-crypt unit tests if required crypto mode not supported
1305
openssl: fix overflow check for long --tls-cipher option
1306
Add a DSA test key/cert pair to sample-keys
1307
Fix mbedtls fingerprint calculation
1308
mbedtls: fix --x509-track post-authentication remote DoS (CVE-2017-7522)
1309
mbedtls: require C-string compatible types for --x509-username-field
1310
Fix remote-triggerable memory leaks (CVE-2017-7521)
1311
Restrict --x509-alt-username extension types
1312
Fix potential double-free in --x509-alt-username (CVE-2017-7521)
1313
Fix typo in extract_x509_extension() debug message
1314
init_key_ctx: key and iv arguments can (now) be const
1315
Move adjust_power_of_2() to integer.h
1316
Undo cipher push in client options state if cipher is rejected
1317
Remove strerror_ts()
1318
Move openvpn_sleep() to manage.c
1319
fixup: also change missed openvpn_sleep() occurrences
1320
Always use default keysize for NCP'd ciphers
1321
Move create_temp_file() out of #ifdef ENABLE_CRYPTO
1322
sample-plugins: fix ASN1_STRING_to_UTF8 return value checks
1323
Deprecate --keysize
1324
Move run_up_down() to init.c
1325
tls-crypt: introduce tls_crypt_kt()
1326
crypto: create function to initialize encrypt and decrypt key
1327
Add coverity static analysis to Travis CI config
1328
tls-crypt: don't leak memory for incorrect tls-crypt messages
1329
travis: reorder matrix to speed up build
1330
Fix bounds check in read_key()
1331
buffer_list_aggregate_separator(): add unit tests
1332
doxygen: add make target and use relative paths
1333
Simplify and inline clear_buf()
1334
Add --tls-cert-profile option.
1335
pf: clean up temporary files if plugin init fails
1336
pf: reject client if PF plugin is configured, but init fails
1337
Don't throw fatal errors from create_temp_file()
1338
create_temp_file/gen_path: prevent memory leak if gc == NULL
1339
Use P_DATA_V2 for server->client packets too
1340
Fix memory leak in buffer unit tests
1341
travis: use clang's -fsanitize=address to catch more bugs
1342
Don't throw fatal errors from verify_cert_export_cert()
1343
buffer_list_aggregate_separator(): update list size after aggregating
1344
buffer_list_aggregate_separator(): don't exceed max_len
1345
buffer_list_aggregate_separator(): prevent 0-byte malloc
1346
Fix types around buffer_list_push(_data)
1347
ssl_openssl: fix compiler warning by removing getbio() wrapper
1348
Fix --tls-version-min and --tls-version-max for OpenSSL 1.1+
1349
Add support for TLS 1.3 in --tls-version-{min, max}
1350
tls_ctx_set_tls_versions: move verify_flags to where it is used
1351
Plug memory leak if push is interrupted
1352
Log pre-handshake packet drops using D_MULTI_DROPPED
1353
Enable stricter compiler warnings by default
1354
reliable: remove reliable_unique_retry()
1355
Get rid of ax_check_compile_flag.m4
1356
mbedtls: don't use API deprecated in mbed 2.7
1357
Warn if tls-version-max < tls-version-min
1358
Check for more data in control channel
1359
Move env helper functions into their own module/file
1360
man: add security considerations to --compress section
1361
openssl: don't use deprecated SSLEAY/SSLeay symbols
1362
openssl: add missing #include statements
1363
Move file-related functions from misc.c to platform.c
1364
Move execve/run_script helper functions to run_command.c
1365
Add crypto_pem_{encode,decode}()
1366
Introduce buffer_write_file()
1367
mbedtls: print warning if random personalisation fails
1368
Fix memory leak after sighup
1369
Remove unused void_ptr_hash_function and void_ptr_compare_function
1370
Do not load certificate from tls_ctx_use_external_private_key()
1371
mbedtls: make external signing code generic
1372
mbedtls: remove dependency on mbedtls pkcs11 module
1373
Fix memory leak in SSL_CTX_use_certificate
1374
travis: add OpenSSL 1.1 Windows build
1375
Fix use-after-free in tls_ctx_use_management_external_key
1376
Simplify --genkey option syntax
1377
Don't print OCC warnings about 'key-method', 'keydir' and 'tls-auth'
1378
Add support for CHACHA20-POLY1305 in the data channel
1379
List ChaCha20-Poly1305 as stream cipher
1380
mbedtls: don't print unsupported ciphers in insecure cipher list
1381
Fix mbedtls unit tests
1382
buffer_list_aggregate_separator(): simplify code
1383
tls-crypt-v2: add specification to doc/
1384
tls-crypt-v2: generate tls-crypt-v2 keys
1385
tls-crypt-v2: add unwrap_client_key
1386
tls-crypt-v2: add P_CONTROL_HARD_RESET_CLIENT_V3 opcode
1387
tls-crypt-v2: implement tls-crypt-v2 handshake
1388
tls-crypt-v2: add script hook to verify metadata
1389
tls-crypt-v2: clarify --tls-crypt-v2-genkey man page section
1390
tls-crypt-v2: fix client reconnect bug
1391
Remove deprecated --compat-x509-names and --no-name-remapping
1392
Extend tls-crypt-v2 unit tests
1393
Fix tls-auth/crypt in connection blocks with --persist-key
1394
cmocka: use relative paths
1395
tests: remove dependency on base64
1396
configure.ac: add lzo CFLAGS/LIBS to the test flags
1397
Update sample configs to use modern cipher, remove static key examples
1398
mbedtls: add RFC 5705 keying material exporter support
1399
Move keying material exporter check from syshead.h to configure.ac
1400
Make openvpn --version exit with exit code 0
1401
Gently push users towards --data-ciphers in --show-ciphers output
1402
1403
Steven McDonald (1):
1404
Fix gateway detection with OpenBSD routing domains
1405
1406
Szilárd Pfeiffer (1):
1407
OpenSSL: Always set SSL_OP_CIPHER_SERVER_PREFERENCE flag
1408
1409
Thomas Quinot (1):
1410
Fix documentation of tls-verify script argument
1411
1412
Thomas Veerman via Openvpn-devel (1):
1413
Fix socks_proxy_port pointing to invalid data
1414
1415
Tom van Leeuwen (1):
1416
mbedTLS: Make sure TLS session survives move
1417
1418
ValdikSS (1):
1419
Set a low interface metric for tap adapter when block-outside-dns is in use
1420
1421
Vladislav Grishenko (1):
1422
Log serial number of revoked certificate
1423
1424
WGH (1):
1425
docs: Add reference to X509_LOOKUP_hash_dir(3)
1426
1427
hashiz (1):
1428
Fix '--bind ipv6only'
1429
1430
tincanteksup (1):
1431
Correct error message for --tls-crypt-v2-genkey client
1432
```