Blame
| 8cd016 | uddr | 2025-04-02 17:24:54 | 1 | # Changes in 2.6.14 |
| 2 | ||||
| 3 | ``` |
|||
| 4 | Arne Schwabe (1): |
|||
| 5 | Allow tls-crypt-v2 to be setup only on initial packet of a session |
|||
| 6 | ||||
| 7 | Frank Lichtenheld (3): |
|||
| 8 | GHA: Drop Ubuntu 20.04 and other maintenance (2.6) |
|||
| 9 | crypto_backend: fix type of enc parameter |
|||
| 10 | Fix compatibility with mbedTLS 2.28.10+ and 3.6.3+ |
|||
| 11 | ||||
| 12 | Qingfang Deng (1): |
|||
| 13 | dco: fix source IP selection when multihome |
|||
| 14 | ``` |
|||
| 15 | ||||
| 16 | # Changes in 2.6.13 |
|||
| 17 | ||||
| 18 | ``` |
|||
| 19 | Arne Schwabe (2): |
|||
| 20 | Refuse clients if username or password is longer than USER_PASS_LEN |
|||
| 21 | Improve peer fingerprint documentation |
|||
| 22 | ||||
| 23 | Ben Boeckel (1): |
|||
| 24 | console_systemd: remove the timeout when using 'systemd-ask-password' |
|||
| 25 | ||||
| 26 | Frank Lichtenheld (5): |
|||
| 27 | Fix missing spaces in various messages |
|||
| 28 | GHA: Update macOS runners |
|||
| 29 | GHA: Simplify macOS builds |
|||
| 30 | Various typo fixes |
|||
| 31 | forward: Fix potential unaligned access in drop_if_recursive_routing |
|||
| 32 | ||||
| 33 | Gert Doering (2): |
|||
| 34 | send uname() release as IV_PLAT_VER= on non-windows versions |
|||
| 35 | preparing release 2.6.13 |
|||
| 36 | ||||
| 37 | Gianmarco De Gregori (1): |
|||
| 38 | Route: remove incorrect routes on exit |
|||
| 39 | ||||
| 40 | Lev Stipakov (1): |
|||
| 41 | Use a more robust way to get dco-win version |
|||
| 42 | ||||
| 43 | Ralf Lici (1): |
|||
| 44 | Fix check_addr_clash argument order |
|||
| 45 | ||||
| 46 | Rémi Farault (1): |
|||
| 47 | Add calls to nvlist_destroy to avoid leaks |
|||
| 48 | ||||
| 49 | Selva Nair (3): |
|||
| 50 | proxy.c: Clear sensitive data after use |
|||
| 51 | Protect cached username, password and token on client |
|||
| 52 | Fix more of uninitialized struct user_pass local vars |
|||
| 53 | ||||
| 54 | corubba (2): |
|||
| 55 | Fix IPv6 in port-share journal |
|||
| 56 | Fix port-share journal doc |
|||
| 57 | ``` |
|||
| 58 | ||||
| 9752b9 | Samuli Seppänen | 2025-02-11 09:49:00 | 59 | # Changes in 2.6.12 |
| 60 | ||||
| 61 | ``` |
|||
| 62 | Arne Schwabe (1): |
|||
| 63 | Allow trailing \r and \n in control channel message |
|||
| 64 | ||||
| 65 | Frank Lichtenheld (1): |
|||
| 66 | configure: Try to detect LZO with pkg-config |
|||
| 67 | ||||
| 68 | Gert Doering (1): |
|||
| 69 | preparing release 2.6.12 |
|||
| 70 | ||||
| 71 | Gianmarco De Gregori (1): |
|||
| 72 | Http-proxy: fix bug preventing proxy credentials caching |
|||
| 73 | ``` |
|||
| 74 | ||||
| 75 | # Changes in 2.6.11 |
|||
| 76 | ||||
| 77 | ``` |
|||
| 78 | 5andr0 (1): |
|||
| 79 | Implement server_poll_timeout for socks |
|||
| 80 | ||||
| 81 | Arne Schwabe (6): |
|||
| 82 | Use snprintf instead of sprintf for get_ssl_library_version |
|||
| 83 | Add bracket in fingerprint message and do not warn about missing verification |
|||
| 84 | Replace macos11 with macos14 in github runners |
|||
| 85 | Only run coverity scan in OpenVPN/OpenVPN repository |
|||
| 86 | Workaround issue in LibreSSL crashing when enumerating digests/ciphers |
|||
| 87 | Properly handle null bytes and invalid characters in control messages |
|||
| 88 | ||||
| 89 | Franco Fichtner (1): |
|||
| 90 | Allow to set ifmode for existing DCO interfaces in FreeBSD |
|||
| 91 | ||||
| 92 | Frank Lichtenheld (6): |
|||
| 93 | samples: Update sample configurations |
|||
| 94 | documentation: make section levels consistent |
|||
| 95 | phase2_tcp_server: fix Coverity issue 'Dereference after null check' |
|||
| 96 | script-options.rst: Update ifconfig_* variables |
|||
| 97 | LZO: do not use lzoutils.h macros |
|||
| 98 | Remove "experimental" denotation for --fast-io |
|||
| 99 | ||||
| 100 | Gert Doering (1): |
|||
| 101 | preparing release 2.6.11 |
|||
| 102 | ||||
| 103 | Heiko Wundram (1): |
|||
| 104 | Implement Windows CA template match for Crypto-API selector |
|||
| 105 | ||||
| 106 | Lev Stipakov (2): |
|||
| 107 | misc.c: remove unused code |
|||
| 108 | interactive.c: Improve access control for gui<->service pipe |
|||
| 109 | ||||
| 110 | Reynir Björnsson (1): |
|||
| 111 | Only schedule_exit() once |
|||
| 112 | ``` |
|||
| 113 | ||||
| 114 | # Changes in 2.6.10 |
|||
| 115 | ||||
| 116 | ``` |
|||
| 117 | Christoph Schug (1): |
|||
| 118 | Update documentation references in systemd unit files |
|||
| 119 | ||||
| 120 | Frank Lichtenheld (6): |
|||
| 121 | Fix typo --data-cipher-fallback |
|||
| 122 | samples: Remove tls-*.conf |
|||
| 123 | check_compression_settings_valid: Do not test for LZ4 in LZO check |
|||
| 124 | t_client.sh: Allow to skip tests |
|||
| 125 | Update Copyright statements to 2024 |
|||
| 126 | GHA: general update March 2024 |
|||
| 127 | ||||
| 128 | Gert Doering (1): |
|||
| 129 | preparing release 2.6.10 |
|||
| 130 | ||||
| 131 | Lev Stipakov (4): |
|||
| 132 | win32: Enforce loading of plugins from a trusted directory |
|||
| 133 | interactive.c: disable remote access to the service pipe |
|||
| 134 | interactive.c: Fix potential stack overflow issue |
|||
| 135 | Disable DCO if proxy is set via management |
|||
| 136 | ||||
| 137 | Martin Rys (1): |
|||
| 138 | openvpn-[client|server].service: Remove syslog.target |
|||
| 139 | ||||
| 140 | Max Fillinger (1): |
|||
| 141 | Remove license warning from README.mbedtls |
|||
| 142 | ||||
| 143 | Selva Nair (1): |
|||
| 144 | Document that auth-user-pass may be inlined |
|||
| 145 | ||||
| 146 | wellweek (1): |
|||
| 147 | remove repetitive words in documentation and comments |
|||
| 148 | ``` |
|||
| 149 | ||||
| 150 | # Changes in 2.6.9 |
|||
| 151 | ||||
| 152 | ``` |
|||
| 153 | Arne Schwabe (15): |
|||
| 154 | Remove unused function prototype crypto_adjust_frame_parameters |
|||
| 155 | Log SSL alerts more prominently |
|||
| 156 | Document tls-exit option mainly as test option |
|||
| 157 | Remove TEST_GET_DEFAULT_GATEWAY as it duplicates --show-gateway |
|||
| 158 | Fix check_session_buf_not_used using wrong index |
|||
| 159 | Add missing check for nl_socket_alloc failure |
|||
| 160 | Add check for nice in cmake config |
|||
| 161 | Remove compat versionhelpers.h and remove cmake/configure check for it |
|||
| 162 | Extend the error message when TLS 1.0 PRF fails |
|||
| 163 | Fix unaligned access in macOS, FreeBSD, Solaris hwaddr |
|||
| 164 | Check PRF availability on initialisation and add --force-tls-key-material-export |
|||
| 165 | Make it more explicit and visible when pkg-config is not found |
|||
| 166 | Clarify that the tls-crypt-v2-verify has a very limited env set |
|||
| 167 | Implement the --tls-export-cert feature |
|||
| 168 | Remove conditional text for Apache2 linking exception |
|||
| 169 | ||||
| 170 | David Sommerseth (2): |
|||
| 171 | Remove --tls-export-cert |
|||
| 172 | Remove superfluous x509_write_pem() |
|||
| 173 | ||||
| 174 | Frank Lichtenheld (14): |
|||
| 175 | sample-keys: renew for the next 10 years |
|||
| 176 | GHA: clean up libressl builds with newer libressl |
|||
| 177 | configure.ac: Remove unused AC_TYPE_SIGNAL macro |
|||
| 178 | documentation: remove reference to removed option --show-proxy-settings |
|||
| 179 | unit_tests: remove includes for mock_msg.h |
|||
| 180 | documentation: improve documentation of --x509-track |
|||
| 181 | NTLM: add length check to add_security_buffer |
|||
| 182 | NTLM: increase size of phase 2 response we can handle |
|||
| 183 | proxy-options.rst: Add proper documentation for --http-proxy-user-pass |
|||
| 184 | buf_string_match_head_str: Fix Coverity issue 'Unsigned compared against 0' |
|||
| 185 | --http-proxy-user-pass: allow to specify in either order with --http-proxy |
|||
| 186 | README.cmake.md: Document minimum required CMake version for --preset |
|||
| 187 | documentation: Update and fix documentation for --push-peer-info |
|||
| 188 | documentation: Fixes for previous fixes to --push-peer-info |
|||
| 189 | ||||
| 190 | Gert Doering (4): |
|||
| 191 | OpenBSD: repair --show-gateway |
|||
| 192 | get_default_gateway() HWADDR overhaul |
|||
| 193 | fix uncrustify complaints about previous patch |
|||
| 194 | preparing release 2.6.9 |
|||
| 195 | ||||
| 196 | Kristof Provost (1): |
|||
| 197 | dco-freebsd: dynamically re-allocate buffer if it's too small |
|||
| 198 | ||||
| 199 | Lev Stipakov (1): |
|||
| 200 | tun.c: don't attempt to delete DNS and WINS servers if they're not set |
|||
| 201 | ||||
| 202 | Marc Becker (1): |
|||
| 203 | vcpkg-ports/pkcs11-helper: bump to version 1.30 |
|||
| 204 | ||||
| 205 | Max Fillinger (4): |
|||
| 206 | Add support for mbedtls 3.X.Y |
|||
| 207 | Update README.mbedtls |
|||
| 208 | Disable TLS 1.3 support with mbed TLS |
|||
| 209 | Enable key export with mbed TLS 3.x.y |
|||
| 210 | ||||
| 211 | Reynir Bjoernsson (1): |
|||
| 212 | protocol_dump: tls-crypt support |
|||
| 213 | ||||
| 214 | Steffan Karger (1): |
|||
| 215 | Fix IPv6 route add/delete message log level |
|||
| 216 | ||||
| 217 | yatta (1): |
|||
| 218 | fix(ssl): init peer_id when init tls_multi |
|||
| 219 | ``` |
|||
| 220 | ||||
| 221 | # Changes in 2.6.8 |
|||
| 222 | ||||
| 223 | ``` |
|||
| 224 | Aquila Macedo (1): |
|||
| 225 | doc: Correct typos in multiple documentation files |
|||
| 226 | ||||
| 227 | Arne Schwabe (1): |
|||
| 228 | Do not check key_state buffers that are in S_UNDEF state |
|||
| 229 | ||||
| 230 | Frank Lichtenheld (1): |
|||
| 231 | platform.c: Do not depend Windows build on HAVE_CHDIR |
|||
| 232 | ||||
| 233 | Gert Doering (1): |
|||
| 234 | preparing release 2.6.8 |
|||
| 235 | ||||
| 236 | Lev Stipakov (3): |
|||
| 237 | config.h: fix incorrect defines for _wopen() |
|||
| 238 | Make --dns options apply for tap-windows6 driver |
|||
| 239 | Warn if pushed options require DHCP |
|||
| 240 | ``` |
|||
| 241 | ||||
| 242 | # Changes in 2.6.7 |
|||
| 243 | ||||
| 244 | ``` |
|||
| 245 | Antonio Quartulli (1): |
|||
| 246 | dco: fix crash when --multihome is used with --proto tcp |
|||
| 247 | ||||
| 248 | Arne Schwabe (8): |
|||
| 249 | Mock openvpn_exece on win32 also for test_tls_crypt |
|||
| 250 | Add warning for the --show-groups command that some groups are missing |
|||
| 251 | Print peer temporary key details |
|||
| 252 | Add warning if a p2p NCP client connects to a p2mp server |
|||
| 253 | Remove openssl engine method for loading the key |
|||
| 254 | Remove saving initial frame code |
|||
| 255 | Double check that we do not use a freed buffer when freeing a session |
|||
| 256 | Fix using to_link buffer after freed |
|||
| 257 | ||||
| 258 | Frank Lichtenheld (7): |
|||
| 259 | GHA: do not trigger builds in openvpn-build anymore |
|||
| 260 | GHA: new workflow to submit scan to Coverity Scan service |
|||
| 261 | buffer: use memcpy in buf_catrunc |
|||
| 262 | vcpkg-ports/pkcs11-helper: Backport MinGW series from master to release/2.6 |
|||
| 263 | CMake: backport CMake buildsystem from master to release/2.6 |
|||
| 264 | Remove all traces of the previous MSVC build system |
|||
| 265 | doc: fix argument name in --route-delay documentation |
|||
| 266 | ||||
| 267 | Gert Doering (1): |
|||
| 268 | preparing release 2.6.7 |
|||
| 269 | ||||
| 270 | Heiko Hund (1): |
|||
| 271 | dns option: remove support for exclude-domains |
|||
| 272 | ||||
| 273 | Lev Stipakov (3): |
|||
| 274 | Warn user if INFO control command is too long |
|||
| 275 | dco-win: get driver version |
|||
| 276 | dco: warn if DATA_V1 packets are sent to userspace |
|||
| 277 | ||||
| 278 | Selva Nair (2): |
|||
| 279 | Make cert_data.h and test_cryptoapi/pkcs11.c MSVC compliant |
|||
| 280 | Log OpenSSL errors on failure to set certificate |
|||
| 281 | ||||
| 282 | orbea (1): |
|||
| 283 | configure: disable engines if OPENSSL_NO_ENGINE is defined |
|||
| 284 | ``` |
|||
| 285 | ||||
| 286 | # Changes in 2.6.6 |
|||
| 287 | ||||
| 288 | ``` |
|||
| 289 | Antonio Quartulli (1): |
|||
| 290 | configure.ac: fix typ0 in LIBCAPNG_CFALGS |
|||
| 291 | ||||
| 292 | Arne Schwabe (8): |
|||
| 293 | Avoid unused function warning/error on FreeBSD (and potientially others) |
|||
| 294 | fix warning with gcc 12.2.0 (compiler bug?) |
|||
| 295 | Fix CR_RESPONSE mangaement message using wrong key_id |
|||
| 296 | Print a more user-friendly error when tls-crypt-v2 client auth fails |
|||
| 297 | Ignore Ipv6 route delete request on Android and set ipv4 verbosity to 7 |
|||
| 298 | Revert commit 423ced962d |
|||
| 299 | Implement using --peer-fingerprint without CA certificates |
|||
| 300 | show extra info for OpenSSL errors |
|||
| 301 | ||||
| 302 | David Sommerseth (1): |
|||
| 303 | ntlm: Clarify details on NTLM phase 3 decoding |
|||
| 304 | ||||
| 305 | Frank Lichtenheld (8): |
|||
| 306 | dist: add more missing files only used in the MSVC build |
|||
| 307 | dist: Include all documentation in distribution |
|||
| 308 | unit_tests: Add missing cert_data.h to source list for unit tests |
|||
| 309 | test_tls_crypt: Improve mock() usage to be more portable |
|||
| 310 | Remove old Travis CI related files |
|||
| 311 | options: Do not hide variables from parent scope |
|||
| 312 | pkcs11_openssl: Disable unused code |
|||
| 313 | route: Fix overriding return value of add_route3 |
|||
| 314 | ||||
| 315 | George Pchelkin (1): |
|||
| 316 | fix typo: dhcp-options to dhcp-option in vpn-network-options.rst |
|||
| 317 | ||||
| 318 | Gert Doering (2): |
|||
| 319 | Make received OCC exit messages more visible in log. |
|||
| 320 | preparing release 2.6.6 |
|||
| 321 | ||||
| 322 | Heiko Hund (1): |
|||
| 323 | work around false positive warning with mingw 12 |
|||
| 324 | ||||
| 325 | Lev Stipakov (3): |
|||
| 326 | tun.c: enclose DNS domain in single quotes in WMIC call |
|||
| 327 | manage.c: document missing KID parameter |
|||
| 328 | Set WINS servers via interactice service |
|||
| 329 | ||||
| 330 | Sergey Korolev (1): |
|||
| 331 | dco-linux: fix counter print format |
|||
| 332 | ``` |
|||
| 333 | ||||
| 334 | # Changes in 2.6.5 |
|||
| 335 | ||||
| 336 | ``` |
|||
| 337 | Arne Schwabe (1): |
|||
| 338 | Fix use-after-free with EVP_CIPHER_free |
|||
| 339 | ||||
| 340 | Frank Lichtenheld (6): |
|||
| 341 | dco_linux: properly close dco version file |
|||
| 342 | DCO: fix memory leak in dco_get_peer_stats_multi for Linux |
|||
| 343 | Fix two unused assignments |
|||
| 344 | sample-plugins: Fix memleak in client-connect example plugin |
|||
| 345 | options: remove --key-method from usage message |
|||
| 346 | msvc-generate: include version.m4.in in tarball |
|||
| 347 | ||||
| 348 | Gert Doering (1): |
|||
| 349 | preparing release 2.6.5 |
|||
| 350 | ||||
| 351 | Ilya Shipitsin (1): |
|||
| 352 | src/openvpn/dco_freebsd.c: handle malloc failure |
|||
| 353 | ||||
| 354 | Lev Stipakov (2): |
|||
| 355 | dco-win: support for --dev-node |
|||
| 356 | tapctl: generate driver-specific adapter names |
|||
| 357 | ||||
| 358 | Selva Nair (2): |
|||
| 359 | Correctly handle Unicode names for exit event |
|||
| 360 | Interactive service: do not force a target desktop for openvpn.exe |
|||
| 361 | ``` |
|||
| 362 | ||||
| 363 | # Changes in 2.6.4 |
|||
| 364 | ||||
| 365 | ``` |
|||
| 366 | Arne Schwabe (3): |
|||
| 367 | Remove unused variable line |
|||
| 368 | Add Apache2 linking with for new commits |
|||
| 369 | Fix compile error on TARGET_ANDROID |
|||
| 370 | ||||
| 371 | Frank Lichtenheld (2): |
|||
| 372 | man page: Remove cruft from --topology documentation |
|||
| 373 | tests: do not include t_client.sh in dist |
|||
| 374 | ||||
| 375 | Kristof Provost (1): |
|||
| 376 | DCO: support key rotation notifications |
|||
| 377 | ||||
| 378 | Michael Nix (1): |
|||
| 379 | fix typo in help text: --ignore-unknown-option |
|||
| 380 | ||||
| 381 | Selva Nair (2): |
|||
| 382 | Format Windows error message in Unicode |
|||
| 383 | Bugfix: dangling pointer passed to pkcs11-helper |
|||
| 384 | ``` |
|||
| 385 | ||||
| 386 | # Changes in 2.6.3 |
|||
| 387 | ||||
| 388 | ``` |
|||
| 389 | Frank Lichtenheld (3): |
|||
| 390 | GHA: remove Ubuntu 18.04 builds |
|||
| 391 | vcpkg: request "tools" feature of openssl for MSVC build |
|||
| 392 | doc: run rst2* with --strict to catch warnings |
|||
| 393 | ||||
| 394 | Lev Stipakov (1): |
|||
| 395 | Support of DNS domain for DHCP-less drivers |
|||
| 396 | ||||
| 397 | Selva Nair (1): |
|||
| 398 | Bug-fix: segfault in dco_get_peer_stats() |
|||
| 399 | ``` |
|||
| 400 | ||||
| 401 | # Changes in 2.6.2 |
|||
| 402 | ||||
| 403 | ``` |
|||
| 404 | Antonio Quartulli (6): |
|||
| 405 | dco: don't use NetLink to exchange control packets |
|||
| 406 | dco: print version to log if available |
|||
| 407 | dco-linux: remove M_ERRNO flag when printing netlink error message |
|||
| 408 | multi: don't call DCO APIs if DCO is disabled |
|||
| 409 | dco-freebsd: use m->instances[] instead of m->hash |
|||
| 410 | dco-linux: implement dco_get_peer_stats{, multi} API |
|||
| 411 | ||||
| 412 | Arne Schwabe (12): |
|||
| 413 | Set netlink socket to be non-blocking |
|||
| 414 | Ensure n = 2 is set in key2 struct in tls_crypt_v2_unwrap_client_key |
|||
| 415 | Fix memory leaks in open_tun_dco() |
|||
| 416 | Fix memory leaks in HMAC initial packet generation |
|||
| 417 | Use key_state instead of multi for tls_send_payload parameter |
|||
| 418 | Make sending plain text control message session aware |
|||
| 419 | Only update frame calculation if we have a valid link sockets |
|||
| 420 | Improve description of compat-mode |
|||
| 421 | Simplify --compress parsing in options.c |
|||
| 422 | Refuse connection if server pushes an option contradicting allow-compress |
|||
| 423 | Add 'allow-compression stub-only' internally for DCO |
|||
| 424 | Parse compression options and bail out when compression is disabled |
|||
| 425 | ||||
| 426 | Frank Lichtenheld (1): |
|||
| 427 | tests/unit_tests: Fix 'make distcheck' with subdir-objects enabled |
|||
| 428 | ||||
| 429 | Gert Doering (1): |
|||
| 430 | preparing release 2.6.2 |
|||
| 431 | ||||
| 432 | Heiko Hund (1): |
|||
| 433 | dns option: allow up to eight addresses per server |
|||
| 434 | ||||
| 435 | Kristof Provost (1): |
|||
| 436 | dco: print FreeBSD version |
|||
| 437 | ||||
| 438 | Lev Stipakov (4): |
|||
| 439 | Support --inactive option for DCO |
|||
| 440 | Fix '--inactive <time> 0' behavior for DCO |
|||
| 441 | Print DCO client stats on SIGUSR2 |
|||
| 442 | Don't overwrite socket flags when using DCO on Windows |
|||
| 443 | ||||
| 444 | Michael Baentsch (1): |
|||
| 445 | using OpenSSL3 API for EVP PKEY type name reporting |
|||
| 446 | ||||
| 447 | Selva Nair (8): |
|||
| 448 | Bugfix: Convert ECDSA signature form pkcs11-helper to DER encoded form |
|||
| 449 | Import some sample certificates into Windows store for testing |
|||
| 450 | Add tests for finding certificates in Windows cert store |
|||
| 451 | Refactor SSL_CTX_use_CryptoAPI_certificate() |
|||
| 452 | Add a test for signing with certificates in Windows store |
|||
| 453 | Unit tests: add test for SSL_CTX_use_Cryptoapi_certificate() |
|||
| 454 | Improve error message on short read from socks proxy |
|||
| 455 | Make error in setting metric for IPv6 interface non-fatal |
|||
| 456 | ``` |
|||
| 457 | ||||
| 458 | # Changes in 2.6.1 |
|||
| 459 | ||||
| 460 | ``` |
|||
| 461 | Antonio Quartulli (1): |
|||
| 462 | Avoid warning about missing braces when initialising key struct |
|||
| 463 | ||||
| 464 | Arne Schwabe (13): |
|||
| 465 | Fix unaligned access in auth-token |
|||
| 466 | Update LibreSSL to 3.7.0 in Github actions |
|||
| 467 | Add printing USAN stack trace on github actions |
|||
| 468 | Fix LibreSSL not building in Github Actions |
|||
| 469 | Add missing stdint.h includes in unit tests files |
|||
| 470 | Combine extra_tun/frame parameter of frame_calculate_payload_overhead |
|||
| 471 | Update the last sections in the man page to a be a bit less outdated |
|||
| 472 | Add building unit tests with mingw to github actions |
|||
| 473 | Revise the cipher negotiation info about OpenVPN3 in the man page |
|||
| 474 | Exit if a proper message instead of segfault on Android without management |
|||
| 475 | Use proper print format/casting when converting msg_channel handle |
|||
| 476 | Reduce initialisation spam from verb <= 3 and print summary instead |
|||
| 477 | Dynamic tls-crypt for secure soft_reset/session renegotiation |
|||
| 478 | ||||
| 479 | Frank Lichtenheld (8): |
|||
| 480 | Changes.rst: document removal of --keysize |
|||
| 481 | Windows: fix unused function setenv_foreign_option |
|||
| 482 | Windows: fix unused variables in delete_route_ipv6 |
|||
| 483 | Windows: fix wrong printf format in x_check_status |
|||
| 484 | Windows: fix unused variable in win32_get_arch |
|||
| 485 | configure: enable DCO by default on FreeBSD/Linux |
|||
| 486 | Windows: fix signedness errors with recv/send |
|||
| 487 | configure: fix formatting of --disable-lz4 and --enable-comp-stub |
|||
| 488 | ||||
| 489 | Gert Doering (3): |
|||
| 490 | Get rid of unused 'bool tuntap_buffer' arguments. |
|||
| 491 | FreeBSD 12.x workaround for IPv6 ifconfig is needed on 12.4 as well |
|||
| 492 | preparing release 2.6.1 |
|||
| 493 | ||||
| 494 | Kristof Provost (3): |
|||
| 495 | options.c: enforce a minimal fragment size |
|||
| 496 | configure: improve FreeBSD DCO check |
|||
| 497 | dco: define OVPN_DEL_PEER_REASON_TRANSPORT_DISCONNECT on FreeBSD |
|||
| 498 | ||||
| 499 | Lev Stipakov (6): |
|||
| 500 | Allow certain DHCP options to be used without DHCP server |
|||
| 501 | dco-win: use proper calling convention on x86 |
|||
| 502 | Improve format specifier for socket handle in Windows |
|||
| 503 | Disable DCO if proxy is set via management |
|||
| 504 | Add logging for windows driver selection process |
|||
| 505 | Avoid management log loop with verb >= 6 |
|||
| 506 | ||||
| 507 | Matthias Andree (1): |
|||
| 508 | make dist: Ship ovpn_dco_freebsd.h, too |
|||
| 509 | ||||
| 510 | Selva Nair (9): |
|||
| 511 | block-dns using iservice: fix a potential double free |
|||
| 512 | Conditionally add subdir-objects option to automake |
|||
| 513 | Build unit tests in mingw Windows build |
|||
| 514 | cyryptapi.c: log the selected certificate's name |
|||
| 515 | cryptoapi.c: remove pre OpenSSL-3.01 support |
|||
| 516 | cryptoapi.c: simplify parsing of thumbprint hex string |
|||
| 517 | Option --cryptoapicert: support issuer name as a selector |
|||
| 518 | Add a unit test for functions in cryptoapi.c |
|||
| 519 | Do not save pointer to 'struct passwd' returned by getpwnam etc. |
|||
| 520 | ``` |
|||
| 521 | ||||
| 522 | # Changes in 2.6.0 |
|||
| 523 | ||||
| 524 | ``` |
|||
| 525 | Antonio Quartulli (1): |
|||
| 526 | dco_linux: update license for ovpn_dco_linux.h |
|||
| 527 | ||||
| 528 | Arne Schwabe (1): |
|||
| 529 | Workaround: make ovpn-dco more reliable |
|||
| 530 | ||||
| 531 | Gert Doering (3): |
|||
| 532 | Fix OVPN_DEL_PEER_REASON_TRANSPORT_DISCONNECT breakage on FreeBSD+DCO |
|||
| 533 | Repair special-casing of EEXIST for Linux/SITNL route install |
|||
| 534 | preparing release 2.6.0 |
|||
| 535 | ||||
| 536 | Lev Stipakov (3): |
|||
| 537 | openvpnmsica: remove dco installer custom actions |
|||
| 538 | openvpnmsica: remove unused declarations |
|||
| 539 | openvpnmsica: fix adapters discovery logic for DCO |
|||
| 540 | ||||
| 541 | Selva Nair (4): |
|||
| 542 | Define and use macros for route addition status code |
|||
| 543 | Warn when pkcs11-id or pkcs11-id-management options are ignored |
|||
| 544 | Cleanup route error and debug logging on Windows |
|||
| 545 | Fix one more 'existing route may get deleted' case |
|||
| 546 | ||||
| 547 | Timo Rothenpieler (1): |
|||
| 548 | Don't clear capability bounding set on capng_change_id |
|||
| 549 | ``` |
|||
| 550 | ||||
| 551 | # Changes in 2.6_rc2 |
|||
| 552 | ||||
| 553 | ``` |
|||
| 554 | Antonio Quartulli (4): |
|||
| 555 | dco: properly re-initialize dco_del_peer_reason |
|||
| 556 | dco: bail out when no peer-specific message is delivered |
|||
| 557 | dco: improve comment about hidden debug message |
|||
| 558 | dco: print proper message in case of transport disconnection |
|||
| 559 | ||||
| 560 | Arne Schwabe (3): |
|||
| 561 | Add connect-freq-initial option to limit initial connection responses |
|||
| 562 | Log peer-id if loglevel is D_DCO_DEBUG and dco is enabled |
|||
| 563 | Deprecate OCC checking |
|||
| 564 | ||||
| 565 | Frank Lichtenheld (7): |
|||
| 566 | options.c: fix format security error when compiling without optimization |
|||
| 567 | options.c: update usage description of --cipher |
|||
| 568 | Update copyright year to 2023 |
|||
| 569 | xkey_pkcs11h_sign: fix dangling pointer |
|||
| 570 | options: Always define options->management_flags |
|||
| 571 | check_engine_keys: make pass with OpenSSL 3 |
|||
| 572 | documentation: update 'unsupported options' section |
|||
| 573 | ||||
| 574 | Gert Doering (3): |
|||
| 575 | Undo FreeBSD 12.x workaround on IPv6 ifconfig for 12.4 and up |
|||
| 576 | Reduce logspam about 'dco_update_keys: peer_id=-1' in p2p server mode |
|||
| 577 | preparing release 2.6_rc2 |
|||
| 578 | ||||
| 579 | Lev Stipakov (1): |
|||
| 580 | tun: move print_windows_driver() out of tun.h |
|||
| 581 | ||||
| 582 | Selva Nair (11): |
|||
| 583 | Properly unmap ring buffer file-map in interactive service |
|||
| 584 | Use undo_lists for saving ring-buffer handles in interactive service |
|||
| 585 | Cleanup: Close duplicated handles in interactive service |
|||
| 586 | Preparing for better signal handling: some code refactoring |
|||
| 587 | Refactor signal handling in openvpn_getaddrinfo |
|||
| 588 | Use IPAPI for setting ipv6 routes when iservice not available |
|||
| 589 | Fix signal handling on Windows |
|||
| 590 | Assign and honour signal priority order |
|||
| 591 | Distinguish route addition errors from route already exists |
|||
| 592 | Propagate route error to initialization_completed() |
|||
| 593 | Include CE_DISABLED status of remote in "remote-entry-get" response |
|||
| 594 | ``` |
|||
| 595 | ||||
| 596 | # Changes in 2.6_rc1 |
|||
| 597 | ||||
| 598 | ``` |
|||
| 599 | Arne Schwabe (17): |
|||
| 600 | Ensure that argument to parse_line has always space for final sentinel |
|||
| 601 | Improve documentation on user/password requirement and unicodize function |
|||
| 602 | Eliminate or comment empty blocks and switch fallthrough |
|||
| 603 | Remove unused gc_arena |
|||
| 604 | Fix corner case that might lead to leaked file descriptor |
|||
| 605 | Deprecate NTLMv1 proxy auth method. |
|||
| 606 | Use include "buffer.h" instead of include <buffer.h> |
|||
| 607 | Ensure that dco keepalive and mssfix options are also set in pure p2p mode |
|||
| 608 | Make management password check constant time |
|||
| 609 | Rename TM_UNTRUSTED to TM_INITIAL, always start session in TM_INITIAL rather than TM_ACTIVE or TM_INITIAL |
|||
| 610 | Move dco_installed back to link_socket from link_socket.info.actual |
|||
| 611 | Do not set nl socket buffer size |
|||
| 612 | Also drop incoming dco packet content when dropping the packet |
|||
| 613 | Improve logging when seeing a message for an unkown peer |
|||
| 614 | Ignore OVPN_DEL_PEER_REASON_USERSPACE to avoid race conditions |
|||
| 615 | Replace custom min macro and use more C99 style in man_remote_entry_get |
|||
| 616 | Replace realloc with new gc_realloc function |
|||
| 617 | ||||
| 618 | David Sommerseth (1): |
|||
| 619 | ssl_verify: Fix memleak if creating deferred auth control files fails |
|||
| 620 | ||||
| 621 | Gert Doering (2): |
|||
| 622 | bandaid fix for TCP multipoint server crash with Linux-DCO |
|||
| 623 | Preparing release 2.6_rc1 |
|||
| 624 | ||||
| 625 | Lev Stipakov (2): |
|||
| 626 | git-version.py: proper support for tags |
|||
| 627 | msvc: upgrade to Visual Studio 2022 |
|||
| 628 | ||||
| 629 | Selva Nair (7): |
|||
| 630 | Reduce default restart pause to 1 second |
|||
| 631 | Do not include auth-token in pulled option digest |
|||
| 632 | Persist DCO client data channel traffic stats on restart |
|||
| 633 | Add remote-count and remote-entry query via management |
|||
| 634 | Permit unlimited connection entries and remotes |
|||
| 635 | Use a template for 'unsupported management commands' error |
|||
| 636 | Allow skipping multple remotes via management interface |
|||
| 637 | ``` |
|||
| 638 | ||||
| 639 | # Changes in 2.6_beta2 |
|||
| 640 | ||||
| 641 | ``` |
|||
| 642 | Antonio Quartulli (1): |
|||
| 643 | disable DCO if --secret is specified |
|||
| 644 | ||||
| 645 | Arne Schwabe (7): |
|||
| 646 | Fix connection cookie not including address and fix endianness in test |
|||
| 647 | Fix unit test of test_pkt on little endian Linux |
|||
| 648 | Disable DCO when TLS mode is not used |
|||
| 649 | Ignore connection attempts while server is shutting down |
|||
| 650 | Improve debug logging of DCO swap key message and Linux dco_new_peer |
|||
| 651 | Trigger a USR1 if dco_update_keys fails |
|||
| 652 | Set DCO_NOT_INSTALLED also for keys not in the get_key_scan range |
|||
| 653 | ||||
| 654 | Frank Lichtenheld (1): |
|||
| 655 | ChangeLog: Fix encoding |
|||
| 656 | ||||
| 657 | Gert Doering (1): |
|||
| 658 | Preparing release 2.6_beta2 |
|||
| 659 | ||||
| 660 | Kristof Provost (4): |
|||
| 661 | Read DCO traffic stats from the kernel |
|||
| 662 | dco: Update counters when a client disconnects |
|||
| 663 | Read the peer deletion reason from the kernel |
|||
| 664 | dco: cleanup FreeBSD dco_do_read() |
|||
| 665 | ||||
| 666 | Lev Stipakov (3): |
|||
| 667 | Rename dco_get_peer_stats to dco_get_peer_stats_multi |
|||
| 668 | management: add timer to output BYTECOUNT |
|||
| 669 | Introduce dco_get_peer_stats API and Windows implementation |
|||
| 670 | ||||
| 671 | Marc Becker (4): |
|||
| 672 | unify code path for adding PKCS#11 providers |
|||
| 673 | use new pkcs11-helper interface to add providers |
|||
| 674 | special handling for PKCS11 providers on win32 |
|||
| 675 | vcpkg-ports/pkcs11-helper: support loader flags |
|||
| 676 | ||||
| 677 | Max Fillinger (2): |
|||
| 678 | Correct tls-crypt-v2 metadata length in man page |
|||
| 679 | Fix message for too long tls-crypt-v2 metadata |
|||
| 680 | ``` |
|||
| 681 | ||||
| 682 | # Changes in 2.6_beta1 |
|||
| 683 | ||||
| 684 | ``` |
|||
| 685 | Adrian (1): |
|||
| 686 | Fix error in example firewall.sh script |
|||
| 687 | ||||
| 688 | Antonio Quartulli (99): |
|||
| 689 | tun.c: remove unused variable |
|||
| 690 | openssl: fix EVP_PKEY_CTX memory leak |
|||
| 691 | openssl: avoid NULL pointer dereference |
|||
| 692 | ssl: remove unneeded if block |
|||
| 693 | options: check for blanks in fingerprints and reject string if found |
|||
| 694 | crypto: respect ECB argument type from prototype |
|||
| 695 | Add documentation on EVENT_READ/EVENT_WRITE constants |
|||
| 696 | windows: use appropriate and portable format specifier for 64bit pointer |
|||
| 697 | windows: define variable only where used |
|||
| 698 | windows: list all enum values in switch block |
|||
| 699 | forward: get rid of useless declarations for actually static functions |
|||
| 700 | mbedtls: do not define mbedtls_ctr_drbg_update_ret when not needed |
|||
| 701 | route.c: pass the right parameter to IN6_IS_ADDR_UNSPECIFIED |
|||
| 702 | man/protocol-options: add missing ending metachar |
|||
| 703 | compat-mode: allow user to specify version to be compatible with |
|||
| 704 | reject compression by default |
|||
| 705 | Remove support for PF (Packet Filter) |
|||
| 706 | configure: search also for rst2{man, html}.py |
|||
| 707 | multi: remove extra brackets in multi_process_incoming_link() |
|||
| 708 | do not include --cipher value in data-ciphers |
|||
| 709 | compat-mode: add --data-cipher-fallback auomatically if requested |
|||
| 710 | Set TLS 1.2 as minimum by default |
|||
| 711 | doc: fix indentation in protocol-options.rst |
|||
| 712 | networking: add and implement net_addr_ll_set() API |
|||
| 713 | networking: add missing brackets |
|||
| 714 | set_lladdr: use networking API net_addr_ll_set() on Linux |
|||
| 715 | configure: remove useless -Wno-* from default CFLAGS |
|||
| 716 | options.c: fix version reported in --cipher warning message |
|||
| 717 | doc/cipher-negotiation.rst: avoid warning by fixing indentation |
|||
| 718 | doc: remove PF leftovers from documentation |
|||
| 719 | sig.c: define signal_handler on non-windows only |
|||
| 720 | GitHub Actions: ensure Ubuntu builds are made with the chosen SSL library |
|||
| 721 | ssl.c: use arrow operator to access object member |
|||
| 722 | use 'static inline' instead of 'inline static' |
|||
| 723 | GitHub Actions: add other config flavours |
|||
| 724 | unit-test: fix test_crypto when USE_COMP is not defined |
|||
| 725 | update copyright year to 2022 |
|||
| 726 | keyingmaterialexporter.c: include strings.h |
|||
| 727 | crypto: move validation logic from cipher_get to cipher_valid |
|||
| 728 | crypto: move OpenSSL specific FIPS check to its backend |
|||
| 729 | Get rid of README.IPv6 and TODO.IPv6 |
|||
| 730 | auth_token/tls_crypt: fix usage of md_valid() |
|||
| 731 | crypto: unify key_type creation code |
|||
| 732 | remove unused sitnl.h file |
|||
| 733 | options: drop useless netmask variable |
|||
| 734 | networking: use OPENVPN_ETH_ALEN instead of ETH_ALEN |
|||
| 735 | networking: silence warnings about unused arguments |
|||
| 736 | networking_iproute2: don't pass M_WARN to openvpn_execve_check() |
|||
| 737 | networking: implement net_iface_new and net_iface_del APIs |
|||
| 738 | t_net.sh: delete dummy iface using iproute command |
|||
| 739 | auth-pam.c: add missing include limits.h |
|||
| 740 | dco: introduce low-level code for handling ovpn-dco in the Linux kernel |
|||
| 741 | dco: add helper function to detect if DCO is enabled or not |
|||
| 742 | dco: create DCO interface using SITNL |
|||
| 743 | tls-crypt-v2: bail out if the client key is too small |
|||
| 744 | dco: use specific metric when installing routes |
|||
| 745 | networking: fix doc for net_iface_new() API |
|||
| 746 | options: don't export local function pre_connect_save() |
|||
| 747 | networking_sitnl: always return negative error code in case of failure |
|||
| 748 | networking: add net_iface_type API |
|||
| 749 | tun: create tun_name_is_fixed helper |
|||
| 750 | dco: add option check - disable DCO if conflict is detected |
|||
| 751 | dco: allow user to disable it at runtime |
|||
| 752 | GitHub Actions: add Linux DCO build (on Ubuntu 20.04) |
|||
| 753 | dco: introduce open_tun_dco_generic() to open dynamic or fixed-name DCO devices |
|||
| 754 | dco: initialize context and save pointer in TLS object |
|||
| 755 | dco: configure keys in DCO right after generating them |
|||
| 756 | disable DCO if no --dev was specified |
|||
| 757 | dco: periodically check and possibly rotate/delete keys |
|||
| 758 | dco: split option parsing routines |
|||
| 759 | push: fix compilation with --disable-management and --enable-werror |
|||
| 760 | dco: check that pulled options are compatible |
|||
| 761 | dco: implement dco support for p2p/client code path |
|||
| 762 | dco: add documentation for ovpn-dco-linux |
|||
| 763 | dco: implement dco support for p2mp/server code path |
|||
| 764 | dco: perform pull options check only if we pulled any option |
|||
| 765 | dco: disable DCO if --allow-compress yes/asym was specified |
|||
| 766 | dco: turn supported ciphers list into a function |
|||
| 767 | do_open_tun: restyle 'can preserve TUN' check |
|||
| 768 | do_close_tun: get rid of one level of indentation |
|||
| 769 | ovpn-dco: print some netlink messages to debug level |
|||
| 770 | dco: move message to DCO debug level and reword a bit |
|||
| 771 | dco: properly name variables |
|||
| 772 | dco: don't pass VPN IPs to NEW_PEER API in P2P mode |
|||
| 773 | dco-win: ensure the DCO API is not used when running on Windows |
|||
| 774 | ssl_util: fix prototype style |
|||
| 775 | dco: move availability check to the end of check_option_conflict() function |
|||
| 776 | dco-win: introduce low-level code for handling ovpn-dco-win in Windows |
|||
| 777 | dco-win: check for incompatible options |
|||
| 778 | dco-win: implement ovpn-dco support in P2P Windows code path |
|||
| 779 | dco-win: add documentation to README.dco.md |
|||
| 780 | dco-win: update GH Actions config file |
|||
| 781 | dco: trigger ping timeout event only if the peer expired |
|||
| 782 | delete_routes(_ipv6): avoid memleak if RT_DEFINED is not set |
|||
| 783 | solaris/open_tun: prevent crash when dev is empty string |
|||
| 784 | do not push route-ipv6 entries that are also in the iroute-ipv6 list |
|||
| 785 | auth-user-pass: add support for inline credentials |
|||
| 786 | get_user_pass_cr: get password from stdin if missing inline |
|||
| 787 | close_tun: print interface type consistently in message |
|||
| 788 | ||||
| 789 | Arne Schwabe (289): |
|||
| 790 | Fix client's poor man NCP fallback |
|||
| 791 | Refactor key_state_export_keying_material functions |
|||
| 792 | Fix compilation with older mbed TLS versions (mbedtls_tls_prf_types undefined) |
|||
| 793 | Fix client NCP OCC fallback when server and client cipher are identical |
|||
| 794 | Move openvpn specific key expansion into its own function |
|||
| 795 | Allow 'none' cipher being specified in --data-ciphers |
|||
| 796 | Implement generating data channel keys via EKM/RFC 5705 |
|||
| 797 | Ignore deprecation warning for daemon on macOS |
|||
| 798 | Add function for common env setting of verify user/pass calls |
|||
| 799 | Inline function tls_get_peer_info |
|||
| 800 | Align reliable_free with other free methods to accept NULL |
|||
| 801 | Remove NULL checks before calling free |
|||
| 802 | Remove explicit setting of peer_id to false |
|||
| 803 | Remove --disable-def-auth configure argument |
|||
| 804 | Replace key_scan array of static pointers with inline function |
|||
| 805 | Add more documentation about our internal TLS functions |
|||
| 806 | Improve keys out of sync message |
|||
| 807 | Clean up tls_authentication_status and document it |
|||
| 808 | Rename DECRYPT_KEY_ENABLED to TLS_AUTHENTICATED |
|||
| 809 | Send AUTH_FAILED message to clients on renegotiation failures |
|||
| 810 | Make any auth failure tls_authentication_status return auth failed |
|||
| 811 | Fix auth-token not being updated if auth-nocache is set |
|||
| 812 | Remove auth_user_pass.wait_for_push variable |
|||
| 813 | Fix port-share option with TLS-Crypt v2 |
|||
| 814 | Zero initialise msghdr prior to calling sendmesg |
|||
| 815 | Fix tls-auth mismatch OCC message when tls-cryptv2 is used. |
|||
| 816 | Remove inetd support from OpenVPN |
|||
| 817 | Change pull request timeout use a timeout rather than a number |
|||
| 818 | Check return values in md_ctx_init and hmac_ctx_init |
|||
| 819 | Implement client side handling of AUTH_PENDING message |
|||
| 820 | Introduce management client state for AUTH_PENDING notifications |
|||
| 821 | Add S_EXITCODE flag for openvpn_run_script to report exit code |
|||
| 822 | Prefer TLS libraries TLS PRF function, fix OpenVPN in FIPS mode |
|||
| 823 | Implement server side of AUTH_PENDING with extending timeout |
|||
| 824 | Refactor extract_var_peer_info into standalone function and add ssl_util.c |
|||
| 825 | Change parameter of send_auth_pending_messages from context to tls_multi |
|||
| 826 | Allow pending auth to be send from a auth plugin |
|||
| 827 | Avoid generating unecessary mbed debug messages |
|||
| 828 | Add README.wolfssl documentating the state of WolfSSL in OpenVPN |
|||
| 829 | Fix multiple problems when compiling with LLVM/Windows (clang-cl) |
|||
| 830 | Move extract_iv_proto to ssl_util.c/h |
|||
| 831 | Extend verify-hash to allow multiple hashes |
|||
| 832 | Implement peer-fingerprint to check fingerprint of peer certificate |
|||
| 833 | Document the simple self-signed certificate setup in examples |
|||
| 834 | Deprecate the --verify-hash option |
|||
| 835 | Remove empty dummy functions |
|||
| 836 | Move restoring pre pull options to initialising of c2 context |
|||
| 837 | Move NCP saving and restore to the prepush restore code |
|||
| 838 | Restore also ping related options on a reconnect |
|||
| 839 | Make buffer related function conversion explicit when narrowing |
|||
| 840 | Fix socket related functions using int instead of socket_descriptor_t |
|||
| 841 | Use correct types for OpenSSL and Windows APIs |
|||
| 842 | Cleanup print_details and add signature/ED certificate print |
|||
| 843 | Remove flexible array member autoconf check |
|||
| 844 | Remove support for non ISO C99 vararg support |
|||
| 845 | Fix #elif TARGET_LINUX missing defined() call |
|||
| 846 | Remove superflous ifdefs around enum like defines |
|||
| 847 | Rename tunnel_server_udp_single_threaded to tunnel_server_udp |
|||
| 848 | Remove code for aligning non-swapped compression |
|||
| 849 | Remove pointless tun_adjust_frame_parameters function |
|||
| 850 | Remove unused field txqueuelen from struct tuntap |
|||
| 851 | Remove unused function tls_test_auth_deferred_interval |
|||
| 852 | Remove unused variable pass_config_info |
|||
| 853 | Move is_proto function to the socket.h header |
|||
| 854 | Implement '--compress migrate' to migrate to non-compression setup |
|||
| 855 | Remove thread_mode field of multi_context |
|||
| 856 | Extract multi_assign_peer_id into its own function |
|||
| 857 | Remove do_init_socket_2 and do_init_socket_1 wrapper function |
|||
| 858 | Always disable TLS renegotiations |
|||
| 859 | Allow running a default configuration with TLS libraries without BF-CBC |
|||
| 860 | Deprecate non TLS mode in OpenVPN |
|||
| 861 | Remove deprecated option '--keysize' |
|||
| 862 | Move auth deferred related members into its own struct |
|||
| 863 | log file descriptor in more socket related error messages |
|||
| 864 | Fix async push broken after auth deferred refactor |
|||
| 865 | Remove conditionals compilation for P2MP, ENABLE_SHAPER and TIME_BACKTRACK_PROTECTION |
|||
| 866 | Remove check for socket functions and Win XP compatbility code |
|||
| 867 | Remove checks for uint* types that are part of C99 |
|||
| 868 | Remove a number of checks for functions/headers that are always present |
|||
| 869 | Use EVP_CTRL_AEAD_* instead EVP_CTRL_GCM_* |
|||
| 870 | Remove OpenSSL configure checks |
|||
| 871 | Always save/restore pull options |
|||
| 872 | Also restore/save compress related options in reconnects |
|||
| 873 | Also restore/save route-gateway options on SIGUSR1 reconnects |
|||
| 874 | Remove LibreSSL specific defines not needed for modern LibreSSL |
|||
| 875 | Add parsing of dhcp-option PROXY_HTTP |
|||
| 876 | Ensure using const variables with EVP_PKEY_get0_* |
|||
| 877 | Move context_auth from context_2 to tls_multi and name it multi_state |
|||
| 878 | Fix condition to generate session keys |
|||
| 879 | Remove always enabled USE_64_BIT_COUNTERS define |
|||
| 880 | Fix a number of mingw warnings |
|||
| 881 | Move tls_select_primary_key into its own function |
|||
| 882 | Allow all GCM ciphers |
|||
| 883 | Change options->data_channel_use_ekm to flags |
|||
| 884 | Implement deferred auth for scripts |
|||
| 885 | Use functions to access key_state instead direct member access |
|||
| 886 | Avoid failing_test unused warning in example_test |
|||
| 887 | Move direct.h header where it is used |
|||
| 888 | Replace OS_SPECIFIC_DIRSEP with PATH_SEPARATOR |
|||
| 889 | Remove a number of platform specific checks in configure.ac |
|||
| 890 | Remove --disable-multihome option |
|||
| 891 | Remove support for blocking connect() |
|||
| 892 | Fix memory leak in misc unit test |
|||
| 893 | Fix binary and (&) used in auth-token check instead of logical and (&&) |
|||
| 894 | Add missing free_key_ctx for auth_token |
|||
| 895 | Remove explicit struct iovec check (HAVE_IOVEC) |
|||
| 896 | Remove getpeername, getpid check |
|||
| 897 | Inline do_init_auth_token_key |
|||
| 898 | Add noreturn attribute for MSVC to assert_failed method. |
|||
| 899 | Move utility function from win32.c to win32-util.c |
|||
| 900 | Document stub-v2 being basically an alias for no compression at all |
|||
| 901 | Return cached result in tls_authentication_status |
|||
| 902 | Use exponential backoff for caching in tls_authentication_status |
|||
| 903 | Add github actions |
|||
| 904 | Silence warning about format string in check_ca_required |
|||
| 905 | Implement auth-token-user |
|||
| 906 | Move auth_token_state from multi to key_state |
|||
| 907 | Add connection_established as state in tls_multi->context_auth |
|||
| 908 | Make waiting on auth an explicit state in the context state machine |
|||
| 909 | Ensure tls session is authenticated before sending push reply |
|||
| 910 | Extracting key_state deferred auth status update into function |
|||
| 911 | Move examples into openvpn-examples(5) man page |
|||
| 912 | Introduce S_GENERATED_KEYS state and generate keys only when authenticated |
|||
| 913 | Fix tls-cert-profile broken on OpenSSL 1.1+ |
|||
| 914 | Cleanup handling of initial auth token |
|||
| 915 | Remove --ncp-disable option |
|||
| 916 | Add detailed man page section to setup a OpenVPN setup with peer-fingerprint |
|||
| 917 | Support NCP in pure P2P VPN setups |
|||
| 918 | Remove unistd.h from unit test |
|||
| 919 | Introduce webauth auth pending method and deprecate openurl |
|||
| 920 | Include Chacha20-Poly1305 into default --data-ciphers when available |
|||
| 921 | Detect unusable ciphers on patched OpenSSL of RHEL/Centos |
|||
| 922 | Fix Ubuntu spelling and duplicate run in Github Actions |
|||
| 923 | Add message when decoding PKCS12 file fails. |
|||
| 924 | Add small unit test for testing HMAC |
|||
| 925 | Deprecate --ecdh-curve with OpenSSL 3.0 and adjust mbed TLS message |
|||
| 926 | Use EVP_PKEY based API for loading DH keys |
|||
| 927 | Remove DES check with OpenSSL 3.0 |
|||
| 928 | Remove DES key fixup code |
|||
| 929 | Do not allow CTS ciphers |
|||
| 930 | Use new EVP_MAC API for HMAC implementation |
|||
| 931 | Add --with-openssl-engine autoconf option (auto|yes|no) |
|||
| 932 | Use EVP_PKEY_get_group_name to query group name |
|||
| 933 | Replace EVP_get_cipherbyname with EVP_CIPHER_fetch |
|||
| 934 | Use EVP_MD_get0_name instead EV_MD_name |
|||
| 935 | Remove dependency on BF-CBC existance from test_ncp |
|||
| 936 | Implement DES ECB encrypt via EVP_CIPHER api |
|||
| 937 | Fix error when BF-CBC is not available |
|||
| 938 | Fix function name in DH error message |
|||
| 939 | Add insecure tls-cert-profile options |
|||
| 940 | Remove custom PRNG function |
|||
| 941 | Completely remove DES checks |
|||
| 942 | Refactor early initialisation and uninitialisation into methods |
|||
| 943 | Use TYPE_do_all_provided function for listing cipher/digest |
|||
| 944 | Add macos OpenSSL 3.0 and ASAN builds |
|||
| 945 | Allow loading of non default providers |
|||
| 946 | Move IV_TCPNL from comp_generate_peer_info_string to push_peer_info |
|||
| 947 | Implement optional cipher in --data-ciphers prefixed with ? |
|||
| 948 | Directly use hardcoed OPENVPN_AEAD_TAG_LENGTH instead lookup |
|||
| 949 | Remove cipher_kt_var_key_size and remaining --keysize documentation |
|||
| 950 | Remove cipher_ctx_get_cipher_kt and replace with direct context calls |
|||
| 951 | Remove key_type->cipher_length field |
|||
| 952 | Remove key_type->hmac_length |
|||
| 953 | Fix handling an optional invalid cipher at the end of data-ciphers |
|||
| 954 | Make --nobind default for --pull |
|||
| 955 | Remove ENABLE_CRYPTO_OPENSSL ifdef inside ENABLE_CRYPTO_OPENSSL ifdef |
|||
| 956 | Remove max_size from buffer_list_new |
|||
| 957 | Add argv_insert_head__empty_argv__head_only to argv tests |
|||
| 958 | Remove cipher_kt_t and change type to const char* in API |
|||
| 959 | Move deprecation of SWEET32/64bit block size ciphers to 2.7 |
|||
| 960 | Adjust cipher-negotiation.rst with compat-mode changes |
|||
| 961 | Remove md_kt_t and change crypto API to use const char* |
|||
| 962 | Initialise kt_cipher even when no crypto is enabled |
|||
| 963 | Remove align_adjust frame code |
|||
| 964 | Fix triggering assertion of ks->authenticated after tls_deauthenticate |
|||
| 965 | Document frame related function and variables a bit more |
|||
| 966 | Remove post_open_mtu code |
|||
| 967 | Make github actions names nicer, include Ubuntu18+OpenSSL 1.0.2 |
|||
| 968 | Add helper functions to calculate header/payload sizes |
|||
| 969 | Decouple MSS fix calculation from frame calculation |
|||
| 970 | Rework occ link-mtu calculation |
|||
| 971 | Remove pointless do_init_frame_tls function |
|||
| 972 | Remove BUFFER_LIST_AGGREGATE_TEST test code |
|||
| 973 | Deprecate link-mtu |
|||
| 974 | Fix mssfix and frame calculation in CBC mode |
|||
| 975 | Change buffer allocation calculation and checks to be more static |
|||
| 976 | Fix datagram_overhead and assorted functions |
|||
| 977 | Implement optional mtu parameter for mssfix |
|||
| 978 | Remove link_mtu parameter when running up/down scripts |
|||
| 979 | Replace TUN_MTU_SIZE with frame->tun_mtu |
|||
| 980 | Change the default for mssfix to mssfix 1492 mtu |
|||
| 981 | Add mtu paramter to --fragment and change fragment calculation |
|||
| 982 | Update fragment and mssfix related warnings |
|||
| 983 | Use new frame header methods to calculate OCC_MTU_LOAD payload size |
|||
| 984 | Remove extra_link from frame |
|||
| 985 | Remove frame->link_mtu |
|||
| 986 | Remove frame.extra_frame and frame.extra_buffer |
|||
| 987 | Default to --cipher BF-CBC if not set and compat-mode < 2.4.0 |
|||
| 988 | Fix 'defined but not used' warnings with enable-small/disable-management |
|||
| 989 | Add Werror to github action ubuntu build |
|||
| 990 | Add better documentation for CAS_* states |
|||
| 991 | Add unit test for mssfix with compression involved |
|||
| 992 | Remove FRAME_HEADROOM, PAYLOAD_SIZE, EXTRA_FRAME and TUN_LINK_DELTA macros |
|||
| 993 | Fix mbed TLS compile if OpenSSL headers are not available |
|||
| 994 | Remove unused function cipher_var_key_size |
|||
| 995 | Implement fixed MSS value for mssfix and use it for non default MTUs |
|||
| 996 | networking: remove duplicate methods from networking_sitnl.c |
|||
| 997 | Remove dead PID_TEST code |
|||
| 998 | Remove inc_pid argument from reliable_mark_deleted that is always true |
|||
| 999 | Remove EXPONENTIAL_BACKOFF define |
|||
| 1000 | Remove tls_init_control_channel_frame_parameters wrapper function |
|||
| 1001 | Add documentation for swap_hmac function |
|||
| 1002 | Make buf_write_u8/16/32 take the type they pretend to take |
|||
| 1003 | Move pre decrypt lite check to its own function |
|||
| 1004 | Extend tls_pre_decrypt_lite to return type of packet and keep state |
|||
| 1005 | Move ssl function related to control channel wrap/unwrap to ssl_pkt.c/h |
|||
| 1006 | Add unit tests for test_tls_decrypt_lite |
|||
| 1007 | Split out reliable_ack_parse from reliable_ack_read |
|||
| 1008 | Refactor tls-auth/tls-crypt wrapping into into own function |
|||
| 1009 | Extract session_move_pre_start as own function, use local buffer variable |
|||
| 1010 | Change FULL_SYNC macro to no_pending_reliable_packets function |
|||
| 1011 | Extract session_move_active into its own function |
|||
| 1012 | Move tls_process_state into its own function |
|||
| 1013 | Remove pointless indentation from tls_process. |
|||
| 1014 | Move CRL reload to key_state_init from S_START transition |
|||
| 1015 | Change reliable_get_buf_sequenced to reliable_get_entry_sequenced |
|||
| 1016 | Implement constructing a control channel reset client as standalone function |
|||
| 1017 | Implement stateless HMAC-based sesssion-id three-way-handshake |
|||
| 1018 | Extract read_incoming_tls_ciphertext into function |
|||
| 1019 | Fix format specifier for printing size_t on 32bit size_t platforms |
|||
| 1020 | Remove workaround for Android 4.4 |
|||
| 1021 | Implement HMAC based session id for tls-crypt v2 |
|||
| 1022 | Optimise three-way handshake condition for S_PRE_START to S_START |
|||
| 1023 | Extract read_incoming_tls_plaintext into its own function |
|||
| 1024 | Add uncrustify check to github actions |
|||
| 1025 | Add ubuntu 22.04 to Github Actions |
|||
| 1026 | Implement ED448 and ED25519 support in xkey_provider |
|||
| 1027 | Translate OpenSSL 3.0 digest names to OpenSSL 1.1 digest names |
|||
| 1028 | Fix client-pending-auth error message to say ERROR instead of SUCCESS |
|||
| 1029 | Remove useless empty line from CR_RESPONSE message |
|||
| 1030 | Remove leftover frame_set_mtu_dynamic definitions in mtu.h |
|||
| 1031 | Inline frame_add_to_extra_tun function and remove frame_defined |
|||
| 1032 | tun: extract close_tun_handle into its own fucntion and print correct type |
|||
| 1033 | Error out if both remap-usr1 SIGHUP and config stdin are used |
|||
| 1034 | Fix segfault when no --config argument is given |
|||
| 1035 | Extract check_session_cipher into standalone function |
|||
| 1036 | Cleanup receive_auth_failed and simplify method |
|||
| 1037 | Fix IV_PLAT_VER and UV_ variables sent without push-peer-info |
|||
| 1038 | Rename OPT_P_IPWIN32 to OPT_P_DHCPDNS and include --dns in it |
|||
| 1039 | Include DCO status in GLOBAL_STATS status v2 output |
|||
| 1040 | Github Actions: Add libreSSL actions |
|||
| 1041 | Include libressl and macOS 12 to macOS github actions |
|||
| 1042 | Fix declaration of pubkeys in test_provider.c in MSVC builds |
|||
| 1043 | Change command help to match man page and implementation |
|||
| 1044 | Implement --client-crresponse script options and plugin interface |
|||
| 1045 | Add example script demonstrating TOTP via auth-pending |
|||
| 1046 | Add OpenSSL 3.0 to mingw build |
|||
| 1047 | Update android.txt to reflect more recent changes. |
|||
| 1048 | Allow scripts and plugins to set a custom AUTH_FAILED message |
|||
| 1049 | Implement exit notification via control channel |
|||
| 1050 | Implement AUTH_FAIL, TEMP message support |
|||
| 1051 | Document/cleanup event_timeout functions |
|||
| 1052 | Fix OpenVPN querying user/password if auth-token with user expires |
|||
| 1053 | Enable -Werror on macOS builds |
|||
| 1054 | Ensure only CBC, CFB, OFB and AEAD ciphers are considered valid data ciphers |
|||
| 1055 | Change exit signal in P2P to be a SIGUSR1 and delayed CC exit in P2MP |
|||
| 1056 | Allow Authtoken lifetime to be short than renegotiation time |
|||
| 1057 | Allows renegotiation only to start if session is fully established |
|||
| 1058 | Fix renewal spelling and actually allow external-auth with renewal time |
|||
| 1059 | Fix regression of ignoring --user |
|||
| 1060 | Refactor/optimise code sending TLS control channel messages |
|||
| 1061 | Add unit test for reliable_get_num_output_sequenced_available |
|||
| 1062 | Allow setting control channel packet size with max-packet-size |
|||
| 1063 | Always include ACKs for the last seen control packets |
|||
| 1064 | Add workaround for Softether server dropping P_ACK_V1 with >= 5 acks |
|||
| 1065 | Improve data key id not found error message |
|||
| 1066 | Add packet type in accept/reject messages for HMAC packet |
|||
| 1067 | Fix md_kt_size in mbed TLS when queried for size of "none" |
|||
| 1068 | Add algorithm and bits used in key_print2 method and refactor method |
|||
| 1069 | Remove unused addr_inet4or6, addr_guess_family and inline addr_copy_sa |
|||
| 1070 | Allow tun-mtu to be pushed |
|||
| 1071 | Push server mtu to client when supported and support occ mtu |
|||
| 1072 | Fix logic error in checking early negotiation support check |
|||
| 1073 | Move dco_installed from sock->info to sock->info.lsa.actual |
|||
| 1074 | Use dedicated multi->dco_peer_id for DCO instead of multi->peer_id |
|||
| 1075 | Add section about common error with OpenVPN 2.6 and OpenSSL 3.0 |
|||
| 1076 | Introduce connection state for reconnecting peer in p2p |
|||
| 1077 | Signal USR1 when connection initialising fails |
|||
| 1078 | Allow reconnecting in p2p mode work under FreeBSD |
|||
| 1079 | ||||
| 1080 | Camille Guérin (1): |
|||
| 1081 | Removed error message for an option flag not supported with --server-ipv6 |
|||
| 1082 | ||||
| 1083 | David Korczynski (1): |
|||
| 1084 | Fix argv leaks in add_route() and add_route_ipv6() |
|||
| 1085 | ||||
| 1086 | David Sommerseth (18): |
|||
| 1087 | man: Add missing --server-ipv6 |
|||
| 1088 | man: Improve --remote entry |
|||
| 1089 | sample-plugins: Partially autotoolize the sample-plugins build |
|||
| 1090 | build: Fix make distclean/distcheck |
|||
| 1091 | compat/lz4: Update to v1.9.2 |
|||
| 1092 | build: Fix missing install of man page in certain environments |
|||
| 1093 | build: Remove compat-lz4 |
|||
| 1094 | Update copyrights |
|||
| 1095 | doc: Use generic rules for man/html generation |
|||
| 1096 | man: Clarify IV_HWADDR |
|||
| 1097 | crypto: Fix OPENSSL_FIPS enabled builds |
|||
| 1098 | sample-plugin: New plugin for testing multiple auth plugins |
|||
| 1099 | plugins: Remove defer/simple.c sample plugin |
|||
| 1100 | plug-ins: Disallow multiple deferred authentication plug-ins |
|||
| 1101 | dev-tools: Remove no longer needed openvpn-plugin.h.in patching |
|||
| 1102 | dev-tools: Remove uncrustify -p |
|||
| 1103 | dev-tools: Avoid uncrustify mangling MAC_FMT macro |
|||
| 1104 | The Great Reformatting of 2022 |
|||
| 1105 | ||||
| 1106 | Dmitry Zelenkovsky (1): |
|||
| 1107 | implement --session-timeout |
|||
| 1108 | ||||
| 1109 | Domagoj Pensa (3): |
|||
| 1110 | Fix too early argv freeing when registering DNS |
|||
| 1111 | Remove 1 second delay before running netsh |
|||
| 1112 | Skip DHCP renew with Wintun adapter |
|||
| 1113 | ||||
| 1114 | Eric Thorpe (1): |
|||
| 1115 | Fixes a bug in management_callback_send_cc_message, should be strlen instead of sizeof |
|||
| 1116 | ||||
| 1117 | Frank Lichtenheld (18): |
|||
| 1118 | doc/Makefile: rebuild rst docs if input files change |
|||
| 1119 | doc: fix misc documentation issues |
|||
| 1120 | doc/options: clean up documentation for --proto and related options |
|||
| 1121 | Reformat for sp_after_comma=add |
|||
| 1122 | uncrustify: add sp_after_comma=add |
|||
| 1123 | uncrustify: have exactly one newline at the end of files |
|||
| 1124 | t_client: Allow to force FAIL on prerequisite fails |
|||
| 1125 | systemd: remove generated service files on clean |
|||
| 1126 | Reduce usage of __DATE__ |
|||
| 1127 | config-version.h: remove unused includes |
|||
| 1128 | t_client.sh: do not require fping6 |
|||
| 1129 | doc: cleanup for --data-ciphers and related |
|||
| 1130 | test_crypto: fix test_occ_mtu_calculation with --disable-fragment |
|||
| 1131 | msvc: always call git-version.py |
|||
| 1132 | GitHub Issues: add note to Changes as well |
|||
| 1133 | GitHub Issues: add new links to INSTALL and README |
|||
| 1134 | GitHub Issues: Create first issue template (Bug) |
|||
| 1135 | documentation: avoid recommending --user nobody |
|||
| 1136 | ||||
| 1137 | Gert Doering (67): |
|||
| 1138 | Change version.m4 to 2.6_git |
|||
| 1139 | Fix stack overflow in OpenSolaris NEXTADDR() |
|||
| 1140 | Workaround FreeBSD 12+ race condition on tun/tap open with IPv6. |
|||
| 1141 | Document that --push-remove is generally more suitable than --push-reset |
|||
| 1142 | Fix error detection / abort in --inetd corner case. |
|||
| 1143 | Fix TUNSETGROUP compatibility with very old Linux systems. |
|||
| 1144 | Fix handling of 'route remote_host' for IPv6 transport case. |
|||
| 1145 | Replace 'echo -n' with 'printf' in tests/t_lpback.sh |
|||
| 1146 | Fix description of --client-disconnect calling convention in manpage. |
|||
| 1147 | Handle NULL returns from calloc() in sample plugins. |
|||
| 1148 | Fix --show-gateway for IPv6 on NetBSD/i386. |
|||
| 1149 | socks.c: fix alen for DOMAIN type addresses, bump up buffer sizes |
|||
| 1150 | Fix netbits setting (in TAP mode) for IPv6 on Windows. |
|||
| 1151 | If IPv6 pool specification sets pool start to ::0 address, increment. |
|||
| 1152 | Add demo plugin that excercises "CLIENT_CONNECT" and "CLIENT_CONNECT_V2" paths |
|||
| 1153 | Fix combination of --dev tap and --topology subnet across multiple platforms. |
|||
| 1154 | Fix redirecting of IPv4 default gateway if connecting over IPv6. |
|||
| 1155 | Fix compilation on pre-EKM mbedTLS libraries. |
|||
| 1156 | Avoid passing NULL to argv_printf_cat() in temp_file error case. |
|||
| 1157 | Change travis build scripts to use https when fetching prerequisites. |
|||
| 1158 | Fix line number reporting on config file errors after <inline> segments |
|||
| 1159 | Clarify --block-ipv6 intent and direction. |
|||
| 1160 | Document common uses of 'echo' directive, re-enable logging for 'echo'. |
|||
| 1161 | Make OPENVPN_PLUGIN_ENABLE_PF failures FATAL |
|||
| 1162 | clean up / rewrite sample-plugins/defer/simple.c |
|||
| 1163 | Fix EVP_PKEY_CTX_... compilation with LibreSSL |
|||
| 1164 | Require at least 100MB of mlock()-able memory if --mlock is used. |
|||
| 1165 | Get rid of last PLUGIN_DEF_AUTH #ifdef |
|||
| 1166 | Fix 'compress migrate' for 2.2 clients. |
|||
| 1167 | Fix potential NULL ptr crash if compiled with DMALLOC |
|||
| 1168 | Repair --secret deprecation warning. |
|||
| 1169 | rewrite parse_hash_fingerprint() |
|||
| 1170 | Ignore leading whitespace and comment lines for peer-fingerprint. |
|||
| 1171 | Add error reporting to get_console_input_win32(). |
|||
| 1172 | Ignore --explicit-exit-notify in TCP mode. |
|||
| 1173 | Use more C99 initialization in add_route/add_route_ipv6(). |
|||
| 1174 | Include --push-remove in the output of --help. |
|||
| 1175 | Move '--push-peer-info' documentation from 'server' to 'client options' |
|||
| 1176 | add test case(s) to notice 'openvpn --show-cipher' crashing |
|||
| 1177 | Repair --inactive with 'bytes' argument larger 2Gbytes. |
|||
| 1178 | Fix --mtu-disc maybe|yes on Linux. |
|||
| 1179 | Fix trailing-whitespace errors in last patch. |
|||
| 1180 | Exclude the last two whitespace-only uncrustify fixes from git blame output. |
|||
| 1181 | Implement --mtu-disc for IPv6 UDP sockets. |
|||
| 1182 | Fix non-compliant whitespace introduced by commit 54800aa975418fe35. |
|||
| 1183 | Pass proper sockaddr_* structure for IPv6 socket errors. |
|||
| 1184 | Fix error message about extended errors for IPv4-only sockets. |
|||
| 1185 | Break 'try 256 dco devices' loop on EPERM |
|||
| 1186 | Cleanup: get rid of 'dynamic' argument of open_tun_generic() |
|||
| 1187 | Remove outdated information from ChangeLog, point at release branches. |
|||
| 1188 | Apply uncrustify changes that were forgotten in the last patch. |
|||
| 1189 | Apply uncrustify changes that were forgotten in the FreeBSD DCO 1/2 patch. |
|||
| 1190 | FreeBSD-DCO: repair device iteration to find first free interface. |
|||
| 1191 | DCO: require valid netbits setting for non-primary iroutes. |
|||
| 1192 | Adjust Linux+FreeBSD DCO device name handling to 'non DCO linux style' |
|||
| 1193 | cleanup open_tun() for TARGET_NETBSD |
|||
| 1194 | t_client: add per-instance arguments to fping |
|||
| 1195 | introduce V= level to manage t_client.sh output verbosity |
|||
| 1196 | un-break undo_ifconfig_ipv4()/_ipv6() on all non-linux/non-win32 platforms |
|||
| 1197 | use boolean '||' to join two bools, not bitwise '|' |
|||
| 1198 | denoise tests/t_lpback.sh |
|||
| 1199 | FreeBSD: for topology subnet, put tun interface into IFF_BROADCAST mode |
|||
| 1200 | FreeBSD DCO: introduce real subnet mode |
|||
| 1201 | Improve documentation for --dev and --dev-node. |
|||
| 1202 | Update PORTS |
|||
| 1203 | rework INSTALL and README to prepare for 2.6 release |
|||
| 1204 | Preparing release 2.6_beta1 |
|||
| 1205 | ||||
| 1206 | Greg Cox (5): |
|||
| 1207 | Fix naming error in sample-plugins/defer/simple.c |
|||
| 1208 | Documentation fixes around openvpn_plugin_func_v3 in openvpn-plugin.h.in |
|||
| 1209 | Update openvpn_plugin_func_v2 to _v3 in sample-plugins/defer/simple.c |
|||
| 1210 | More explicit versioning compatibility in sample-plugins/defer/simple.c |
|||
| 1211 | Explain structver usage in sample defer plugin. |
|||
| 1212 | ||||
| 1213 | Heiko Hund (10): |
|||
| 1214 | add support for --dns option |
|||
| 1215 | Add git pre-commit hook script to uncrustify |
|||
| 1216 | pre-commit: uncrustify based on staged changes |
|||
| 1217 | remove foreign_option() call for IPv6 DNS servers |
|||
| 1218 | remove dead foreign-option parsing code |
|||
| 1219 | rename foreign_option() and move it up |
|||
| 1220 | doc: fix literal block in tls-options.rst |
|||
| 1221 | dns: also (re)place foreign dhcp options in env |
|||
| 1222 | signal --dns support in peer info |
|||
| 1223 | make %x destination unsigned |
|||
| 1224 | ||||
| 1225 | Ilya Ponetayev (1): |
|||
| 1226 | fix compilation issues with small and w/o debug |
|||
| 1227 | ||||
| 1228 | Ilya Shipitsin (2): |
|||
| 1229 | CI: github actions: keep "pdb" in artifacts |
|||
| 1230 | BUILD: enable CFG and Spectre mitigation for MSVC |
|||
| 1231 | ||||
| 1232 | Jan Mikkelsen (1): |
|||
| 1233 | cipher-negotiation.rst missing from doc/Makefile.am |
|||
| 1234 | ||||
| 1235 | Jan Seeger (1): |
|||
| 1236 | Added 'route_ipv6_metric_NN' environment variable for IPv6 route metric. |
|||
| 1237 | ||||
| 1238 | Jason A. Donenfeld (1): |
|||
| 1239 | Support fingerprint authentication without CA certificate |
|||
| 1240 | ||||
| 1241 | Jeff (1): |
|||
| 1242 | duplicate function declaration. |
|||
| 1243 | ||||
| 1244 | Juliusz Sosinowicz (4): |
|||
| 1245 | EVP_DigestSignFinal siglen parameter correction |
|||
| 1246 | Support for wolfSSL in OpenVPN |
|||
| 1247 | build: Add support for pkg-config < 0.28 for old autoconf versions |
|||
| 1248 | README.wolfssl Update |
|||
| 1249 | ||||
| 1250 | Kristof Provost (6): |
|||
| 1251 | Handle exceeding 'max-clients' |
|||
| 1252 | ovpn-dco: introduce FreeBSD data-channel offload support |
|||
| 1253 | Support creating iroute route entries on FreeBSD |
|||
| 1254 | FreeBSD networking cleanup |
|||
| 1255 | FreeBSD DCO: support AES-192-GCM |
|||
| 1256 | dco: pass control packets through the socket on FreeBSD |
|||
| 1257 | ||||
| 1258 | Lev Stipakov (68): |
|||
| 1259 | tun.c: enable using wintun driver under SYSTEM |
|||
| 1260 | openvpnmsica: make adapter renaming non-fatal |
|||
| 1261 | msvc: better support for 32bit architecture |
|||
| 1262 | Alias ADAPTER_DOMAIN_SUFFIX to DOMAIN |
|||
| 1263 | ssl_common.h: fix 'not all control paths return a value' msvc warning |
|||
| 1264 | Remove compat-lz4 references from VS project files |
|||
| 1265 | tapctl: support for ovpn-dco Windows driver |
|||
| 1266 | msvc: add ARM64 configuration |
|||
| 1267 | win32: add missing include header |
|||
| 1268 | openvpnmsica: properly schedule reboot in the end of installation |
|||
| 1269 | options.c: fix msvc build error |
|||
| 1270 | msvc: standalone building |
|||
| 1271 | contrib/vcpkg-ports: add pkcs11-helper port |
|||
| 1272 | vcpkg-ports: restore trailing whitespaces in .patch files |
|||
| 1273 | GitHub actions: add MSVC build |
|||
| 1274 | crypto_openssl.c: disable explicit initialization on Windows (CVE-2121-3606) |
|||
| 1275 | contrib/vcpkg-ports: add openssl port with --no-autoload-config option set (CVE-2121-3606) |
|||
| 1276 | Fix console prompts with redirected log |
|||
| 1277 | GitHub Actions: fix MSVC builds |
|||
| 1278 | contrib/vcpkg-ports: remove openssl port |
|||
| 1279 | Add building man page on Windows |
|||
| 1280 | GitHub Actions: remove Ubuntu 16.04 environment |
|||
| 1281 | Fix loading PKCS12 files on Windows |
|||
| 1282 | msvc: fix product version display |
|||
| 1283 | config-msvc.h: fix OpenSSL-related defines |
|||
| 1284 | GitHub Actions: use latest working lukka/run-vcpkg |
|||
| 1285 | Use network address for emulated DHCP server as a default |
|||
| 1286 | Load OpenSSL config on Windows from trusted location |
|||
| 1287 | ring_buffer.h: fix GCC warning about unused function |
|||
| 1288 | ssh_openssl.h: remove unused declaration |
|||
| 1289 | vcpkg/pkcs11-helper: compatibility with latest vcpkg |
|||
| 1290 | config-msvc.h: indicate key material export support |
|||
| 1291 | auth_token.c: add NULL initialization |
|||
| 1292 | tun: remove tun_finalize() |
|||
| 1293 | vcpkg-ports/pkcs11-helper: bump to release 1.28 |
|||
| 1294 | vcpkg-ports/pkcs11-helper: indicate OpenSSL EC support |
|||
| 1295 | xkey: fix msvc build |
|||
| 1296 | msvc: switch to openssl3 |
|||
| 1297 | msvc: cleanup |
|||
| 1298 | vcpkg: link lzo statically |
|||
| 1299 | openvpnmsica: add ovpn-dco custom actions |
|||
| 1300 | vcpkg-ports/pkcs11-helper: adapt to new upstream URL |
|||
| 1301 | vcpkg-ports\pkcs11-helper: shorten patch filename |
|||
| 1302 | vcpkg-ports\openssl3: update to 3.0.2 |
|||
| 1303 | Fix incorrect default mssfix value in server mode |
|||
| 1304 | msvc: adjust build options to harden binaries |
|||
| 1305 | vcpkg: switch to manifest |
|||
| 1306 | Fix M_ERRNO behavior on Windows |
|||
| 1307 | GitHub Actions: trigger openvpn-build GHA on success |
|||
| 1308 | Set o->use_peer_id flag for p2p mode |
|||
| 1309 | openvpnmsica: remove OpenVPNService state check code |
|||
| 1310 | tun.c: remove unused gc_arena from init_tun() |
|||
| 1311 | error.c: remove unused crash() function |
|||
| 1312 | tun: properly handle device interface list |
|||
| 1313 | dco.h: fix return type when DCO is not enabled |
|||
| 1314 | dco-win: use run-time dynamic linking for GetOverlappedResultEx |
|||
| 1315 | vcpkg: bump baseline version |
|||
| 1316 | do_persist_tuntap: remove indentation level |
|||
| 1317 | msvc: remove .filters files |
|||
| 1318 | dco.c: check certain options only on startup |
|||
| 1319 | Use DCO on Windows by default |
|||
| 1320 | doc: add "ovpn-dco" to usage and man page |
|||
| 1321 | dco-win: support for --persist-tun |
|||
| 1322 | msvc: add branch name and commit hash to version output |
|||
| 1323 | vcpkg: use the latest versions of dependency ports |
|||
| 1324 | win32: detect arm64 architecture and emulations |
|||
| 1325 | INSTALL: update Windows notes |
|||
| 1326 | dco: disable dco on Windows if --remote is not defined |
|||
| 1327 | ||||
| 1328 | Magnus Kroken (2): |
|||
| 1329 | doc: fix typos in cipher-negotiation.rst |
|||
| 1330 | Changes.rst: fix mistyped option names |
|||
| 1331 | ||||
| 1332 | Marc Becker (2): |
|||
| 1333 | vcpkg-ports/pkcs11-helper: bump to release 1.29 |
|||
| 1334 | fix GitHub workflow working directories in MinGW builds |
|||
| 1335 | ||||
| 1336 | Martin Janů (1): |
|||
| 1337 | Update the replay-window backtrack log message |
|||
| 1338 | ||||
| 1339 | Matthias Andree (1): |
|||
| 1340 | Fix SIGSEGV (NULL deref) receiving push "echo" |
|||
| 1341 | ||||
| 1342 | Max Fillinger (15): |
|||
| 1343 | Wipe Socks5 credentials after use |
|||
| 1344 | Fix build with mbedtls w/o SSL renegotiation support |
|||
| 1345 | In init_ssl, open the correct CRL path pre-chroot |
|||
| 1346 | Abort if CRL file can't be stat-ed in ssl_init |
|||
| 1347 | Update Fox e-mail address in copyright notices |
|||
| 1348 | Replace deprecated mbedtls DRBG update function |
|||
| 1349 | Fix build with compression disabled |
|||
| 1350 | Don't manually free DH params in OpenSSL 3 |
|||
| 1351 | Remove unused havege.h header |
|||
| 1352 | Don't use BF-CBC in unit tests if we don't have it |
|||
| 1353 | Add warning about mbed TLS licensing problem |
|||
| 1354 | Don't "undo" ifconfig on exit if it wasn't done |
|||
| 1355 | Update openssl_compat.h for newer LibreSSL |
|||
| 1356 | Handle EVP_MD_CTX as an opaque struct |
|||
| 1357 | Check if pkcs11_cert is NULL before freeing it |
|||
| 1358 | ||||
| 1359 | Michael Baentsch (1): |
|||
| 1360 | Enable usage of TLS groups not identified by a NID in OpenSSL 3 |
|||
| 1361 | ||||
| 1362 | Paolo Cerrito (1): |
|||
| 1363 | Insert client connection data into PAM environment |
|||
| 1364 | ||||
| 1365 | Richard Bonhomme (6): |
|||
| 1366 | Improve error msg when all TAP adapters are in use 'or disabled' |
|||
| 1367 | Man page sections corrections |
|||
| 1368 | Do not print Diffie Hellman parameters file to log file |
|||
| 1369 | Log messages: Replace NCP with --data-ciphers (NFC) |
|||
| 1370 | doc link-options.rst: Use free open-source dynamic-DNS provider URL |
|||
| 1371 | doc/protocol-options.rst: Correct default for --allow-compression |
|||
| 1372 | ||||
| 1373 | Saifur Rahman Mohsin (1): |
|||
| 1374 | Ignore deprecation warning for daemon() on macOS (plugin/auth-pam) |
|||
| 1375 | ||||
| 1376 | Selva Nair (64): |
|||
| 1377 | Improve the documentation for --dhcp-option |
|||
| 1378 | In tap.c use DiInstallDevice to install the driver on a new adapter |
|||
| 1379 | Add a remark on dropping privileges when --mlock is used |
|||
| 1380 | Allow --dhcp-option in config file when windows-driver is wintun |
|||
| 1381 | Set DNS Domain using iservice |
|||
| 1382 | Improve documentation of --username-as-common-name |
|||
| 1383 | Quote the domain name argument passed to the wmic command |
|||
| 1384 | Remove automatic service |
|||
| 1385 | tun.c on WIN32: remove more unused variables |
|||
| 1386 | Make it explicit that WIndows build requires UNICODE support |
|||
| 1387 | Use C standard compliant format specs in wprintf functions |
|||
| 1388 | Print format spec changes for tapctl and openvpnmscia |
|||
| 1389 | Replace TEXT(__FUNCTION__) by __FUNCTION__ in openvpnmscia.c |
|||
| 1390 | Fix parsing of IV_SSO string |
|||
| 1391 | Do not require CA when peer-fingerprint is used |
|||
| 1392 | Improve documentation of AUTH_PENDING related directives |
|||
| 1393 | Apply the connect-retry backoff to only one side of a connection |
|||
| 1394 | Fix client-pending-auth help message in management interface |
|||
| 1395 | Minor doc correction: tls-crypt-v2 key generation |
|||
| 1396 | Fix the "default" tls-version-min setting |
|||
| 1397 | Fix some more wrong defines in config-msvc.h |
|||
| 1398 | Require Windows CNG keys for cryptoapicert |
|||
| 1399 | Remove error injection into OpenSSL from cryptoapi.c |
|||
| 1400 | Require EC key support in Windows builds |
|||
| 1401 | Ensure the current common_name is in the environment for scripts |
|||
| 1402 | Avoid memory leak in hmac_ctx_new (OpenSSL 3.0 only) |
|||
| 1403 | Fix tls-version-min default once again |
|||
| 1404 | A built-in provider for using external key with OpenSSL 3.0 |
|||
| 1405 | Implement KEYMGMT in the xkey provider |
|||
| 1406 | Implement SIGNATURE operations in xkey provider |
|||
| 1407 | Implement import of custom external keys |
|||
| 1408 | Initialize the xkey provider and use it in SSL context |
|||
| 1409 | A helper function to import private key for management-external-key |
|||
| 1410 | Add xkey_provider sources and includes to MSVC project |
|||
| 1411 | Enable signing via provider for management-external-key |
|||
| 1412 | Add a function to encode digests with PKCS1 DigestInfo wrapper |
|||
| 1413 | Allow management client to announce pss padding support |
|||
| 1414 | Respect algorithm support announced by management client |
|||
| 1415 | Support sending DigestSign request to management client |
|||
| 1416 | Increase ERR_BUF_SIZE when management interface support is enabled |
|||
| 1417 | Add a generic key loading helper function for xkey provider |
|||
| 1418 | pkcs11: Interface the xkey provider with pkcs11-helper |
|||
| 1419 | Enable signing using CNG through xkey provider |
|||
| 1420 | Add a unit test for external key provider |
|||
| 1421 | xkey: Use a custom error level for debug messages |
|||
| 1422 | Fix max saltlen calculation in cryptoapi.c |
|||
| 1423 | Support PSS signing using pkcs11-helper >= 1.28 |
|||
| 1424 | Do not error when md_kt_size() is called with mdname="none" |
|||
| 1425 | Fix a potential memory leak in tls_ctx_use_management_external_key |
|||
| 1426 | pkcs11_openssl.c: check EVP_get_digestbyname() != NULL |
|||
| 1427 | Fix crash in xkey-provider in msvc builds |
|||
| 1428 | Remove management_write_peer_info_file and related code |
|||
| 1429 | Log the actual management interface port in use |
|||
| 1430 | Log address of management client on accept |
|||
| 1431 | In x_check_status() read errno early |
|||
| 1432 | xkey_provider: fix building with --disable-management |
|||
| 1433 | Do not skip ERROR:/SUCCESS: response from management interface |
|||
| 1434 | Allow a few levels of recursion in virtual_output_callback() |
|||
| 1435 | Fix auth-token usage with management-def-auth |
|||
| 1436 | Ensure --auth-nocache is handled during renegotiation |
|||
| 1437 | Purge auth-token as well while purging passwords |
|||
| 1438 | Do not copy auth_token username to itself |
|||
| 1439 | Do not add leading space to pushed options |
|||
| 1440 | pull-filter: ignore leading "spaces" in option names |
|||
| 1441 | ||||
| 1442 | Sergio E. Nemirowski (1): |
|||
| 1443 | resolvconf fails with -p |
|||
| 1444 | ||||
| 1445 | Simon Rozman (9): |
|||
| 1446 | iservice: Resolve MSVC C4996 warnings |
|||
| 1447 | openvpnserv: Cache last error before it is overridden |
|||
| 1448 | netsh: Specify interfaces by index rather than name |
|||
| 1449 | netsh: Clear existing IPv6 DNS servers before configuring new ones |
|||
| 1450 | netsh: Delete WINS servers on TUN close |
|||
| 1451 | openvpnmsica: Simplify find_adapters() to void return |
|||
| 1452 | tun.c: Remove dead code |
|||
| 1453 | interactive.c: Resolve MSVC C4996 warning |
|||
| 1454 | tapctl: Resolve MSVC C4996 warnings |
|||
| 1455 | ||||
| 1456 | Steffan Karger (5): |
|||
| 1457 | networking_iproute2: fix memory leak in net_iface_mtu_set() |
|||
| 1458 | Simplify key material exporter backend API |
|||
| 1459 | tls-crypt-v2: fix server memory leak |
|||
| 1460 | tls-crypt-v2: also preload tls-crypt-v2 keys (if --persist-key) |
|||
| 1461 | reliable: retransmit if 3 follow-up ACKs are received |
|||
| 1462 | ||||
| 1463 | Timo Rothenpieler (5): |
|||
| 1464 | Linux: Retain CAP_NET_ADMIN when dropping privileges |
|||
| 1465 | GitHub Actions: Add new libcap-ng-dev dependency |
|||
| 1466 | Github Actions: update used actions |
|||
| 1467 | dco: disable DCO if --user specified but unable to retain capabilities |
|||
| 1468 | dco: turn platform config checks into separate function |
|||
| 1469 | ||||
| 1470 | Todd Zullinger (2): |
|||
| 1471 | Update IRC information in CONTRIBUTING.rst |
|||
| 1472 | doc/man (vpn-network-options): fix foreign_option_{n} typo |
|||
| 1473 | ||||
| 1474 | Tõivo Leedjärv (1): |
|||
| 1475 | Stop using deprecated getpass() |
|||
| 1476 | ||||
| 1477 | Ville Skyttä (1): |
|||
| 1478 | README.down-root: Fix plugin module name |
|||
| 1479 | ||||
| 1480 | Vladislav Grishenko (8): |
|||
| 1481 | Fix best gateway selection over netlink |
|||
| 1482 | Fix fatal error at switching remotes (#629) |
|||
| 1483 | Fix update_time() and openvpn_gettimeofday() coexistence |
|||
| 1484 | Selectively reformat too long lines |
|||
| 1485 | Speedup TCP remote hosts connections |
|||
| 1486 | Support X509 field list to be username |
|||
| 1487 | Fix IPv4 default gateway with multiple route tables |
|||
| 1488 | Add CRL extractor script for --crl-verify dir mode |
|||
| 1489 | ||||
| 1490 | ``` |
