Blame

8cd016 uddr 2025-04-02 17:24:54 1
# Changes in 2.6.14
2
3
```
4
Arne Schwabe (1):
5
Allow tls-crypt-v2 to be setup only on initial packet of a session
6
7
Frank Lichtenheld (3):
8
GHA: Drop Ubuntu 20.04 and other maintenance (2.6)
9
crypto_backend: fix type of enc parameter
10
Fix compatibility with mbedTLS 2.28.10+ and 3.6.3+
11
12
Qingfang Deng (1):
13
dco: fix source IP selection when multihome
14
```
15
16
# Changes in 2.6.13
17
18
```
19
Arne Schwabe (2):
20
Refuse clients if username or password is longer than USER_PASS_LEN
21
Improve peer fingerprint documentation
22
23
Ben Boeckel (1):
24
console_systemd: remove the timeout when using 'systemd-ask-password'
25
26
Frank Lichtenheld (5):
27
Fix missing spaces in various messages
28
GHA: Update macOS runners
29
GHA: Simplify macOS builds
30
Various typo fixes
31
forward: Fix potential unaligned access in drop_if_recursive_routing
32
33
Gert Doering (2):
34
send uname() release as IV_PLAT_VER= on non-windows versions
35
preparing release 2.6.13
36
37
Gianmarco De Gregori (1):
38
Route: remove incorrect routes on exit
39
40
Lev Stipakov (1):
41
Use a more robust way to get dco-win version
42
43
Ralf Lici (1):
44
Fix check_addr_clash argument order
45
46
Rémi Farault (1):
47
Add calls to nvlist_destroy to avoid leaks
48
49
Selva Nair (3):
50
proxy.c: Clear sensitive data after use
51
Protect cached username, password and token on client
52
Fix more of uninitialized struct user_pass local vars
53
54
corubba (2):
55
Fix IPv6 in port-share journal
56
Fix port-share journal doc
57
```
58
9752b9 Samuli Seppänen 2025-02-11 09:49:00 59
# Changes in 2.6.12
60
61
```
62
Arne Schwabe (1):
63
Allow trailing \r and \n in control channel message
64
65
Frank Lichtenheld (1):
66
configure: Try to detect LZO with pkg-config
67
68
Gert Doering (1):
69
preparing release 2.6.12
70
71
Gianmarco De Gregori (1):
72
Http-proxy: fix bug preventing proxy credentials caching
73
```
74
75
# Changes in 2.6.11
76
77
```
78
5andr0 (1):
79
Implement server_poll_timeout for socks
80
81
Arne Schwabe (6):
82
Use snprintf instead of sprintf for get_ssl_library_version
83
Add bracket in fingerprint message and do not warn about missing verification
84
Replace macos11 with macos14 in github runners
85
Only run coverity scan in OpenVPN/OpenVPN repository
86
Workaround issue in LibreSSL crashing when enumerating digests/ciphers
87
Properly handle null bytes and invalid characters in control messages
88
89
Franco Fichtner (1):
90
Allow to set ifmode for existing DCO interfaces in FreeBSD
91
92
Frank Lichtenheld (6):
93
samples: Update sample configurations
94
documentation: make section levels consistent
95
phase2_tcp_server: fix Coverity issue 'Dereference after null check'
96
script-options.rst: Update ifconfig_* variables
97
LZO: do not use lzoutils.h macros
98
Remove "experimental" denotation for --fast-io
99
100
Gert Doering (1):
101
preparing release 2.6.11
102
103
Heiko Wundram (1):
104
Implement Windows CA template match for Crypto-API selector
105
106
Lev Stipakov (2):
107
misc.c: remove unused code
108
interactive.c: Improve access control for gui<->service pipe
109
110
Reynir Björnsson (1):
111
Only schedule_exit() once
112
```
113
114
# Changes in 2.6.10
115
116
```
117
Christoph Schug (1):
118
Update documentation references in systemd unit files
119
120
Frank Lichtenheld (6):
121
Fix typo --data-cipher-fallback
122
samples: Remove tls-*.conf
123
check_compression_settings_valid: Do not test for LZ4 in LZO check
124
t_client.sh: Allow to skip tests
125
Update Copyright statements to 2024
126
GHA: general update March 2024
127
128
Gert Doering (1):
129
preparing release 2.6.10
130
131
Lev Stipakov (4):
132
win32: Enforce loading of plugins from a trusted directory
133
interactive.c: disable remote access to the service pipe
134
interactive.c: Fix potential stack overflow issue
135
Disable DCO if proxy is set via management
136
137
Martin Rys (1):
138
openvpn-[client|server].service: Remove syslog.target
139
140
Max Fillinger (1):
141
Remove license warning from README.mbedtls
142
143
Selva Nair (1):
144
Document that auth-user-pass may be inlined
145
146
wellweek (1):
147
remove repetitive words in documentation and comments
148
```
149
150
# Changes in 2.6.9
151
152
```
153
Arne Schwabe (15):
154
Remove unused function prototype crypto_adjust_frame_parameters
155
Log SSL alerts more prominently
156
Document tls-exit option mainly as test option
157
Remove TEST_GET_DEFAULT_GATEWAY as it duplicates --show-gateway
158
Fix check_session_buf_not_used using wrong index
159
Add missing check for nl_socket_alloc failure
160
Add check for nice in cmake config
161
Remove compat versionhelpers.h and remove cmake/configure check for it
162
Extend the error message when TLS 1.0 PRF fails
163
Fix unaligned access in macOS, FreeBSD, Solaris hwaddr
164
Check PRF availability on initialisation and add --force-tls-key-material-export
165
Make it more explicit and visible when pkg-config is not found
166
Clarify that the tls-crypt-v2-verify has a very limited env set
167
Implement the --tls-export-cert feature
168
Remove conditional text for Apache2 linking exception
169
170
David Sommerseth (2):
171
Remove --tls-export-cert
172
Remove superfluous x509_write_pem()
173
174
Frank Lichtenheld (14):
175
sample-keys: renew for the next 10 years
176
GHA: clean up libressl builds with newer libressl
177
configure.ac: Remove unused AC_TYPE_SIGNAL macro
178
documentation: remove reference to removed option --show-proxy-settings
179
unit_tests: remove includes for mock_msg.h
180
documentation: improve documentation of --x509-track
181
NTLM: add length check to add_security_buffer
182
NTLM: increase size of phase 2 response we can handle
183
proxy-options.rst: Add proper documentation for --http-proxy-user-pass
184
buf_string_match_head_str: Fix Coverity issue 'Unsigned compared against 0'
185
--http-proxy-user-pass: allow to specify in either order with --http-proxy
186
README.cmake.md: Document minimum required CMake version for --preset
187
documentation: Update and fix documentation for --push-peer-info
188
documentation: Fixes for previous fixes to --push-peer-info
189
190
Gert Doering (4):
191
OpenBSD: repair --show-gateway
192
get_default_gateway() HWADDR overhaul
193
fix uncrustify complaints about previous patch
194
preparing release 2.6.9
195
196
Kristof Provost (1):
197
dco-freebsd: dynamically re-allocate buffer if it's too small
198
199
Lev Stipakov (1):
200
tun.c: don't attempt to delete DNS and WINS servers if they're not set
201
202
Marc Becker (1):
203
vcpkg-ports/pkcs11-helper: bump to version 1.30
204
205
Max Fillinger (4):
206
Add support for mbedtls 3.X.Y
207
Update README.mbedtls
208
Disable TLS 1.3 support with mbed TLS
209
Enable key export with mbed TLS 3.x.y
210
211
Reynir Bjoernsson (1):
212
protocol_dump: tls-crypt support
213
214
Steffan Karger (1):
215
Fix IPv6 route add/delete message log level
216
217
yatta (1):
218
fix(ssl): init peer_id when init tls_multi
219
```
220
221
# Changes in 2.6.8
222
223
```
224
Aquila Macedo (1):
225
doc: Correct typos in multiple documentation files
226
227
Arne Schwabe (1):
228
Do not check key_state buffers that are in S_UNDEF state
229
230
Frank Lichtenheld (1):
231
platform.c: Do not depend Windows build on HAVE_CHDIR
232
233
Gert Doering (1):
234
preparing release 2.6.8
235
236
Lev Stipakov (3):
237
config.h: fix incorrect defines for _wopen()
238
Make --dns options apply for tap-windows6 driver
239
Warn if pushed options require DHCP
240
```
241
242
# Changes in 2.6.7
243
244
```
245
Antonio Quartulli (1):
246
dco: fix crash when --multihome is used with --proto tcp
247
248
Arne Schwabe (8):
249
Mock openvpn_exece on win32 also for test_tls_crypt
250
Add warning for the --show-groups command that some groups are missing
251
Print peer temporary key details
252
Add warning if a p2p NCP client connects to a p2mp server
253
Remove openssl engine method for loading the key
254
Remove saving initial frame code
255
Double check that we do not use a freed buffer when freeing a session
256
Fix using to_link buffer after freed
257
258
Frank Lichtenheld (7):
259
GHA: do not trigger builds in openvpn-build anymore
260
GHA: new workflow to submit scan to Coverity Scan service
261
buffer: use memcpy in buf_catrunc
262
vcpkg-ports/pkcs11-helper: Backport MinGW series from master to release/2.6
263
CMake: backport CMake buildsystem from master to release/2.6
264
Remove all traces of the previous MSVC build system
265
doc: fix argument name in --route-delay documentation
266
267
Gert Doering (1):
268
preparing release 2.6.7
269
270
Heiko Hund (1):
271
dns option: remove support for exclude-domains
272
273
Lev Stipakov (3):
274
Warn user if INFO control command is too long
275
dco-win: get driver version
276
dco: warn if DATA_V1 packets are sent to userspace
277
278
Selva Nair (2):
279
Make cert_data.h and test_cryptoapi/pkcs11.c MSVC compliant
280
Log OpenSSL errors on failure to set certificate
281
282
orbea (1):
283
configure: disable engines if OPENSSL_NO_ENGINE is defined
284
```
285
286
# Changes in 2.6.6
287
288
```
289
Antonio Quartulli (1):
290
configure.ac: fix typ0 in LIBCAPNG_CFALGS
291
292
Arne Schwabe (8):
293
Avoid unused function warning/error on FreeBSD (and potientially others)
294
fix warning with gcc 12.2.0 (compiler bug?)
295
Fix CR_RESPONSE mangaement message using wrong key_id
296
Print a more user-friendly error when tls-crypt-v2 client auth fails
297
Ignore Ipv6 route delete request on Android and set ipv4 verbosity to 7
298
Revert commit 423ced962d
299
Implement using --peer-fingerprint without CA certificates
300
show extra info for OpenSSL errors
301
302
David Sommerseth (1):
303
ntlm: Clarify details on NTLM phase 3 decoding
304
305
Frank Lichtenheld (8):
306
dist: add more missing files only used in the MSVC build
307
dist: Include all documentation in distribution
308
unit_tests: Add missing cert_data.h to source list for unit tests
309
test_tls_crypt: Improve mock() usage to be more portable
310
Remove old Travis CI related files
311
options: Do not hide variables from parent scope
312
pkcs11_openssl: Disable unused code
313
route: Fix overriding return value of add_route3
314
315
George Pchelkin (1):
316
fix typo: dhcp-options to dhcp-option in vpn-network-options.rst
317
318
Gert Doering (2):
319
Make received OCC exit messages more visible in log.
320
preparing release 2.6.6
321
322
Heiko Hund (1):
323
work around false positive warning with mingw 12
324
325
Lev Stipakov (3):
326
tun.c: enclose DNS domain in single quotes in WMIC call
327
manage.c: document missing KID parameter
328
Set WINS servers via interactice service
329
330
Sergey Korolev (1):
331
dco-linux: fix counter print format
332
```
333
334
# Changes in 2.6.5
335
336
```
337
Arne Schwabe (1):
338
Fix use-after-free with EVP_CIPHER_free
339
340
Frank Lichtenheld (6):
341
dco_linux: properly close dco version file
342
DCO: fix memory leak in dco_get_peer_stats_multi for Linux
343
Fix two unused assignments
344
sample-plugins: Fix memleak in client-connect example plugin
345
options: remove --key-method from usage message
346
msvc-generate: include version.m4.in in tarball
347
348
Gert Doering (1):
349
preparing release 2.6.5
350
351
Ilya Shipitsin (1):
352
src/openvpn/dco_freebsd.c: handle malloc failure
353
354
Lev Stipakov (2):
355
dco-win: support for --dev-node
356
tapctl: generate driver-specific adapter names
357
358
Selva Nair (2):
359
Correctly handle Unicode names for exit event
360
Interactive service: do not force a target desktop for openvpn.exe
361
```
362
363
# Changes in 2.6.4
364
365
```
366
Arne Schwabe (3):
367
Remove unused variable line
368
Add Apache2 linking with for new commits
369
Fix compile error on TARGET_ANDROID
370
371
Frank Lichtenheld (2):
372
man page: Remove cruft from --topology documentation
373
tests: do not include t_client.sh in dist
374
375
Kristof Provost (1):
376
DCO: support key rotation notifications
377
378
Michael Nix (1):
379
fix typo in help text: --ignore-unknown-option
380
381
Selva Nair (2):
382
Format Windows error message in Unicode
383
Bugfix: dangling pointer passed to pkcs11-helper
384
```
385
386
# Changes in 2.6.3
387
388
```
389
Frank Lichtenheld (3):
390
GHA: remove Ubuntu 18.04 builds
391
vcpkg: request "tools" feature of openssl for MSVC build
392
doc: run rst2* with --strict to catch warnings
393
394
Lev Stipakov (1):
395
Support of DNS domain for DHCP-less drivers
396
397
Selva Nair (1):
398
Bug-fix: segfault in dco_get_peer_stats()
399
```
400
401
# Changes in 2.6.2
402
403
```
404
Antonio Quartulli (6):
405
dco: don't use NetLink to exchange control packets
406
dco: print version to log if available
407
dco-linux: remove M_ERRNO flag when printing netlink error message
408
multi: don't call DCO APIs if DCO is disabled
409
dco-freebsd: use m->instances[] instead of m->hash
410
dco-linux: implement dco_get_peer_stats{, multi} API
411
412
Arne Schwabe (12):
413
Set netlink socket to be non-blocking
414
Ensure n = 2 is set in key2 struct in tls_crypt_v2_unwrap_client_key
415
Fix memory leaks in open_tun_dco()
416
Fix memory leaks in HMAC initial packet generation
417
Use key_state instead of multi for tls_send_payload parameter
418
Make sending plain text control message session aware
419
Only update frame calculation if we have a valid link sockets
420
Improve description of compat-mode
421
Simplify --compress parsing in options.c
422
Refuse connection if server pushes an option contradicting allow-compress
423
Add 'allow-compression stub-only' internally for DCO
424
Parse compression options and bail out when compression is disabled
425
426
Frank Lichtenheld (1):
427
tests/unit_tests: Fix 'make distcheck' with subdir-objects enabled
428
429
Gert Doering (1):
430
preparing release 2.6.2
431
432
Heiko Hund (1):
433
dns option: allow up to eight addresses per server
434
435
Kristof Provost (1):
436
dco: print FreeBSD version
437
438
Lev Stipakov (4):
439
Support --inactive option for DCO
440
Fix '--inactive <time> 0' behavior for DCO
441
Print DCO client stats on SIGUSR2
442
Don't overwrite socket flags when using DCO on Windows
443
444
Michael Baentsch (1):
445
using OpenSSL3 API for EVP PKEY type name reporting
446
447
Selva Nair (8):
448
Bugfix: Convert ECDSA signature form pkcs11-helper to DER encoded form
449
Import some sample certificates into Windows store for testing
450
Add tests for finding certificates in Windows cert store
451
Refactor SSL_CTX_use_CryptoAPI_certificate()
452
Add a test for signing with certificates in Windows store
453
Unit tests: add test for SSL_CTX_use_Cryptoapi_certificate()
454
Improve error message on short read from socks proxy
455
Make error in setting metric for IPv6 interface non-fatal
456
```
457
458
# Changes in 2.6.1
459
460
```
461
Antonio Quartulli (1):
462
Avoid warning about missing braces when initialising key struct
463
464
Arne Schwabe (13):
465
Fix unaligned access in auth-token
466
Update LibreSSL to 3.7.0 in Github actions
467
Add printing USAN stack trace on github actions
468
Fix LibreSSL not building in Github Actions
469
Add missing stdint.h includes in unit tests files
470
Combine extra_tun/frame parameter of frame_calculate_payload_overhead
471
Update the last sections in the man page to a be a bit less outdated
472
Add building unit tests with mingw to github actions
473
Revise the cipher negotiation info about OpenVPN3 in the man page
474
Exit if a proper message instead of segfault on Android without management
475
Use proper print format/casting when converting msg_channel handle
476
Reduce initialisation spam from verb <= 3 and print summary instead
477
Dynamic tls-crypt for secure soft_reset/session renegotiation
478
479
Frank Lichtenheld (8):
480
Changes.rst: document removal of --keysize
481
Windows: fix unused function setenv_foreign_option
482
Windows: fix unused variables in delete_route_ipv6
483
Windows: fix wrong printf format in x_check_status
484
Windows: fix unused variable in win32_get_arch
485
configure: enable DCO by default on FreeBSD/Linux
486
Windows: fix signedness errors with recv/send
487
configure: fix formatting of --disable-lz4 and --enable-comp-stub
488
489
Gert Doering (3):
490
Get rid of unused 'bool tuntap_buffer' arguments.
491
FreeBSD 12.x workaround for IPv6 ifconfig is needed on 12.4 as well
492
preparing release 2.6.1
493
494
Kristof Provost (3):
495
options.c: enforce a minimal fragment size
496
configure: improve FreeBSD DCO check
497
dco: define OVPN_DEL_PEER_REASON_TRANSPORT_DISCONNECT on FreeBSD
498
499
Lev Stipakov (6):
500
Allow certain DHCP options to be used without DHCP server
501
dco-win: use proper calling convention on x86
502
Improve format specifier for socket handle in Windows
503
Disable DCO if proxy is set via management
504
Add logging for windows driver selection process
505
Avoid management log loop with verb >= 6
506
507
Matthias Andree (1):
508
make dist: Ship ovpn_dco_freebsd.h, too
509
510
Selva Nair (9):
511
block-dns using iservice: fix a potential double free
512
Conditionally add subdir-objects option to automake
513
Build unit tests in mingw Windows build
514
cyryptapi.c: log the selected certificate's name
515
cryptoapi.c: remove pre OpenSSL-3.01 support
516
cryptoapi.c: simplify parsing of thumbprint hex string
517
Option --cryptoapicert: support issuer name as a selector
518
Add a unit test for functions in cryptoapi.c
519
Do not save pointer to 'struct passwd' returned by getpwnam etc.
520
```
521
522
# Changes in 2.6.0
523
524
```
525
Antonio Quartulli (1):
526
dco_linux: update license for ovpn_dco_linux.h
527
528
Arne Schwabe (1):
529
Workaround: make ovpn-dco more reliable
530
531
Gert Doering (3):
532
Fix OVPN_DEL_PEER_REASON_TRANSPORT_DISCONNECT breakage on FreeBSD+DCO
533
Repair special-casing of EEXIST for Linux/SITNL route install
534
preparing release 2.6.0
535
536
Lev Stipakov (3):
537
openvpnmsica: remove dco installer custom actions
538
openvpnmsica: remove unused declarations
539
openvpnmsica: fix adapters discovery logic for DCO
540
541
Selva Nair (4):
542
Define and use macros for route addition status code
543
Warn when pkcs11-id or pkcs11-id-management options are ignored
544
Cleanup route error and debug logging on Windows
545
Fix one more 'existing route may get deleted' case
546
547
Timo Rothenpieler (1):
548
Don't clear capability bounding set on capng_change_id
549
```
550
551
# Changes in 2.6_rc2
552
553
```
554
Antonio Quartulli (4):
555
dco: properly re-initialize dco_del_peer_reason
556
dco: bail out when no peer-specific message is delivered
557
dco: improve comment about hidden debug message
558
dco: print proper message in case of transport disconnection
559
560
Arne Schwabe (3):
561
Add connect-freq-initial option to limit initial connection responses
562
Log peer-id if loglevel is D_DCO_DEBUG and dco is enabled
563
Deprecate OCC checking
564
565
Frank Lichtenheld (7):
566
options.c: fix format security error when compiling without optimization
567
options.c: update usage description of --cipher
568
Update copyright year to 2023
569
xkey_pkcs11h_sign: fix dangling pointer
570
options: Always define options->management_flags
571
check_engine_keys: make pass with OpenSSL 3
572
documentation: update 'unsupported options' section
573
574
Gert Doering (3):
575
Undo FreeBSD 12.x workaround on IPv6 ifconfig for 12.4 and up
576
Reduce logspam about 'dco_update_keys: peer_id=-1' in p2p server mode
577
preparing release 2.6_rc2
578
579
Lev Stipakov (1):
580
tun: move print_windows_driver() out of tun.h
581
582
Selva Nair (11):
583
Properly unmap ring buffer file-map in interactive service
584
Use undo_lists for saving ring-buffer handles in interactive service
585
Cleanup: Close duplicated handles in interactive service
586
Preparing for better signal handling: some code refactoring
587
Refactor signal handling in openvpn_getaddrinfo
588
Use IPAPI for setting ipv6 routes when iservice not available
589
Fix signal handling on Windows
590
Assign and honour signal priority order
591
Distinguish route addition errors from route already exists
592
Propagate route error to initialization_completed()
593
Include CE_DISABLED status of remote in "remote-entry-get" response
594
```
595
596
# Changes in 2.6_rc1
597
598
```
599
Arne Schwabe (17):
600
Ensure that argument to parse_line has always space for final sentinel
601
Improve documentation on user/password requirement and unicodize function
602
Eliminate or comment empty blocks and switch fallthrough
603
Remove unused gc_arena
604
Fix corner case that might lead to leaked file descriptor
605
Deprecate NTLMv1 proxy auth method.
606
Use include "buffer.h" instead of include <buffer.h>
607
Ensure that dco keepalive and mssfix options are also set in pure p2p mode
608
Make management password check constant time
609
Rename TM_UNTRUSTED to TM_INITIAL, always start session in TM_INITIAL rather than TM_ACTIVE or TM_INITIAL
610
Move dco_installed back to link_socket from link_socket.info.actual
611
Do not set nl socket buffer size
612
Also drop incoming dco packet content when dropping the packet
613
Improve logging when seeing a message for an unkown peer
614
Ignore OVPN_DEL_PEER_REASON_USERSPACE to avoid race conditions
615
Replace custom min macro and use more C99 style in man_remote_entry_get
616
Replace realloc with new gc_realloc function
617
618
David Sommerseth (1):
619
ssl_verify: Fix memleak if creating deferred auth control files fails
620
621
Gert Doering (2):
622
bandaid fix for TCP multipoint server crash with Linux-DCO
623
Preparing release 2.6_rc1
624
625
Lev Stipakov (2):
626
git-version.py: proper support for tags
627
msvc: upgrade to Visual Studio 2022
628
629
Selva Nair (7):
630
Reduce default restart pause to 1 second
631
Do not include auth-token in pulled option digest
632
Persist DCO client data channel traffic stats on restart
633
Add remote-count and remote-entry query via management
634
Permit unlimited connection entries and remotes
635
Use a template for 'unsupported management commands' error
636
Allow skipping multple remotes via management interface
637
```
638
639
# Changes in 2.6_beta2
640
641
```
642
Antonio Quartulli (1):
643
disable DCO if --secret is specified
644
645
Arne Schwabe (7):
646
Fix connection cookie not including address and fix endianness in test
647
Fix unit test of test_pkt on little endian Linux
648
Disable DCO when TLS mode is not used
649
Ignore connection attempts while server is shutting down
650
Improve debug logging of DCO swap key message and Linux dco_new_peer
651
Trigger a USR1 if dco_update_keys fails
652
Set DCO_NOT_INSTALLED also for keys not in the get_key_scan range
653
654
Frank Lichtenheld (1):
655
ChangeLog: Fix encoding
656
657
Gert Doering (1):
658
Preparing release 2.6_beta2
659
660
Kristof Provost (4):
661
Read DCO traffic stats from the kernel
662
dco: Update counters when a client disconnects
663
Read the peer deletion reason from the kernel
664
dco: cleanup FreeBSD dco_do_read()
665
666
Lev Stipakov (3):
667
Rename dco_get_peer_stats to dco_get_peer_stats_multi
668
management: add timer to output BYTECOUNT
669
Introduce dco_get_peer_stats API and Windows implementation
670
671
Marc Becker (4):
672
unify code path for adding PKCS#11 providers
673
use new pkcs11-helper interface to add providers
674
special handling for PKCS11 providers on win32
675
vcpkg-ports/pkcs11-helper: support loader flags
676
677
Max Fillinger (2):
678
Correct tls-crypt-v2 metadata length in man page
679
Fix message for too long tls-crypt-v2 metadata
680
```
681
682
# Changes in 2.6_beta1
683
684
```
685
Adrian (1):
686
Fix error in example firewall.sh script
687
688
Antonio Quartulli (99):
689
tun.c: remove unused variable
690
openssl: fix EVP_PKEY_CTX memory leak
691
openssl: avoid NULL pointer dereference
692
ssl: remove unneeded if block
693
options: check for blanks in fingerprints and reject string if found
694
crypto: respect ECB argument type from prototype
695
Add documentation on EVENT_READ/EVENT_WRITE constants
696
windows: use appropriate and portable format specifier for 64bit pointer
697
windows: define variable only where used
698
windows: list all enum values in switch block
699
forward: get rid of useless declarations for actually static functions
700
mbedtls: do not define mbedtls_ctr_drbg_update_ret when not needed
701
route.c: pass the right parameter to IN6_IS_ADDR_UNSPECIFIED
702
man/protocol-options: add missing ending metachar
703
compat-mode: allow user to specify version to be compatible with
704
reject compression by default
705
Remove support for PF (Packet Filter)
706
configure: search also for rst2{man, html}.py
707
multi: remove extra brackets in multi_process_incoming_link()
708
do not include --cipher value in data-ciphers
709
compat-mode: add --data-cipher-fallback auomatically if requested
710
Set TLS 1.2 as minimum by default
711
doc: fix indentation in protocol-options.rst
712
networking: add and implement net_addr_ll_set() API
713
networking: add missing brackets
714
set_lladdr: use networking API net_addr_ll_set() on Linux
715
configure: remove useless -Wno-* from default CFLAGS
716
options.c: fix version reported in --cipher warning message
717
doc/cipher-negotiation.rst: avoid warning by fixing indentation
718
doc: remove PF leftovers from documentation
719
sig.c: define signal_handler on non-windows only
720
GitHub Actions: ensure Ubuntu builds are made with the chosen SSL library
721
ssl.c: use arrow operator to access object member
722
use 'static inline' instead of 'inline static'
723
GitHub Actions: add other config flavours
724
unit-test: fix test_crypto when USE_COMP is not defined
725
update copyright year to 2022
726
keyingmaterialexporter.c: include strings.h
727
crypto: move validation logic from cipher_get to cipher_valid
728
crypto: move OpenSSL specific FIPS check to its backend
729
Get rid of README.IPv6 and TODO.IPv6
730
auth_token/tls_crypt: fix usage of md_valid()
731
crypto: unify key_type creation code
732
remove unused sitnl.h file
733
options: drop useless netmask variable
734
networking: use OPENVPN_ETH_ALEN instead of ETH_ALEN
735
networking: silence warnings about unused arguments
736
networking_iproute2: don't pass M_WARN to openvpn_execve_check()
737
networking: implement net_iface_new and net_iface_del APIs
738
t_net.sh: delete dummy iface using iproute command
739
auth-pam.c: add missing include limits.h
740
dco: introduce low-level code for handling ovpn-dco in the Linux kernel
741
dco: add helper function to detect if DCO is enabled or not
742
dco: create DCO interface using SITNL
743
tls-crypt-v2: bail out if the client key is too small
744
dco: use specific metric when installing routes
745
networking: fix doc for net_iface_new() API
746
options: don't export local function pre_connect_save()
747
networking_sitnl: always return negative error code in case of failure
748
networking: add net_iface_type API
749
tun: create tun_name_is_fixed helper
750
dco: add option check - disable DCO if conflict is detected
751
dco: allow user to disable it at runtime
752
GitHub Actions: add Linux DCO build (on Ubuntu 20.04)
753
dco: introduce open_tun_dco_generic() to open dynamic or fixed-name DCO devices
754
dco: initialize context and save pointer in TLS object
755
dco: configure keys in DCO right after generating them
756
disable DCO if no --dev was specified
757
dco: periodically check and possibly rotate/delete keys
758
dco: split option parsing routines
759
push: fix compilation with --disable-management and --enable-werror
760
dco: check that pulled options are compatible
761
dco: implement dco support for p2p/client code path
762
dco: add documentation for ovpn-dco-linux
763
dco: implement dco support for p2mp/server code path
764
dco: perform pull options check only if we pulled any option
765
dco: disable DCO if --allow-compress yes/asym was specified
766
dco: turn supported ciphers list into a function
767
do_open_tun: restyle 'can preserve TUN' check
768
do_close_tun: get rid of one level of indentation
769
ovpn-dco: print some netlink messages to debug level
770
dco: move message to DCO debug level and reword a bit
771
dco: properly name variables
772
dco: don't pass VPN IPs to NEW_PEER API in P2P mode
773
dco-win: ensure the DCO API is not used when running on Windows
774
ssl_util: fix prototype style
775
dco: move availability check to the end of check_option_conflict() function
776
dco-win: introduce low-level code for handling ovpn-dco-win in Windows
777
dco-win: check for incompatible options
778
dco-win: implement ovpn-dco support in P2P Windows code path
779
dco-win: add documentation to README.dco.md
780
dco-win: update GH Actions config file
781
dco: trigger ping timeout event only if the peer expired
782
delete_routes(_ipv6): avoid memleak if RT_DEFINED is not set
783
solaris/open_tun: prevent crash when dev is empty string
784
do not push route-ipv6 entries that are also in the iroute-ipv6 list
785
auth-user-pass: add support for inline credentials
786
get_user_pass_cr: get password from stdin if missing inline
787
close_tun: print interface type consistently in message
788
789
Arne Schwabe (289):
790
Fix client's poor man NCP fallback
791
Refactor key_state_export_keying_material functions
792
Fix compilation with older mbed TLS versions (mbedtls_tls_prf_types undefined)
793
Fix client NCP OCC fallback when server and client cipher are identical
794
Move openvpn specific key expansion into its own function
795
Allow 'none' cipher being specified in --data-ciphers
796
Implement generating data channel keys via EKM/RFC 5705
797
Ignore deprecation warning for daemon on macOS
798
Add function for common env setting of verify user/pass calls
799
Inline function tls_get_peer_info
800
Align reliable_free with other free methods to accept NULL
801
Remove NULL checks before calling free
802
Remove explicit setting of peer_id to false
803
Remove --disable-def-auth configure argument
804
Replace key_scan array of static pointers with inline function
805
Add more documentation about our internal TLS functions
806
Improve keys out of sync message
807
Clean up tls_authentication_status and document it
808
Rename DECRYPT_KEY_ENABLED to TLS_AUTHENTICATED
809
Send AUTH_FAILED message to clients on renegotiation failures
810
Make any auth failure tls_authentication_status return auth failed
811
Fix auth-token not being updated if auth-nocache is set
812
Remove auth_user_pass.wait_for_push variable
813
Fix port-share option with TLS-Crypt v2
814
Zero initialise msghdr prior to calling sendmesg
815
Fix tls-auth mismatch OCC message when tls-cryptv2 is used.
816
Remove inetd support from OpenVPN
817
Change pull request timeout use a timeout rather than a number
818
Check return values in md_ctx_init and hmac_ctx_init
819
Implement client side handling of AUTH_PENDING message
820
Introduce management client state for AUTH_PENDING notifications
821
Add S_EXITCODE flag for openvpn_run_script to report exit code
822
Prefer TLS libraries TLS PRF function, fix OpenVPN in FIPS mode
823
Implement server side of AUTH_PENDING with extending timeout
824
Refactor extract_var_peer_info into standalone function and add ssl_util.c
825
Change parameter of send_auth_pending_messages from context to tls_multi
826
Allow pending auth to be send from a auth plugin
827
Avoid generating unecessary mbed debug messages
828
Add README.wolfssl documentating the state of WolfSSL in OpenVPN
829
Fix multiple problems when compiling with LLVM/Windows (clang-cl)
830
Move extract_iv_proto to ssl_util.c/h
831
Extend verify-hash to allow multiple hashes
832
Implement peer-fingerprint to check fingerprint of peer certificate
833
Document the simple self-signed certificate setup in examples
834
Deprecate the --verify-hash option
835
Remove empty dummy functions
836
Move restoring pre pull options to initialising of c2 context
837
Move NCP saving and restore to the prepush restore code
838
Restore also ping related options on a reconnect
839
Make buffer related function conversion explicit when narrowing
840
Fix socket related functions using int instead of socket_descriptor_t
841
Use correct types for OpenSSL and Windows APIs
842
Cleanup print_details and add signature/ED certificate print
843
Remove flexible array member autoconf check
844
Remove support for non ISO C99 vararg support
845
Fix #elif TARGET_LINUX missing defined() call
846
Remove superflous ifdefs around enum like defines
847
Rename tunnel_server_udp_single_threaded to tunnel_server_udp
848
Remove code for aligning non-swapped compression
849
Remove pointless tun_adjust_frame_parameters function
850
Remove unused field txqueuelen from struct tuntap
851
Remove unused function tls_test_auth_deferred_interval
852
Remove unused variable pass_config_info
853
Move is_proto function to the socket.h header
854
Implement '--compress migrate' to migrate to non-compression setup
855
Remove thread_mode field of multi_context
856
Extract multi_assign_peer_id into its own function
857
Remove do_init_socket_2 and do_init_socket_1 wrapper function
858
Always disable TLS renegotiations
859
Allow running a default configuration with TLS libraries without BF-CBC
860
Deprecate non TLS mode in OpenVPN
861
Remove deprecated option '--keysize'
862
Move auth deferred related members into its own struct
863
log file descriptor in more socket related error messages
864
Fix async push broken after auth deferred refactor
865
Remove conditionals compilation for P2MP, ENABLE_SHAPER and TIME_BACKTRACK_PROTECTION
866
Remove check for socket functions and Win XP compatbility code
867
Remove checks for uint* types that are part of C99
868
Remove a number of checks for functions/headers that are always present
869
Use EVP_CTRL_AEAD_* instead EVP_CTRL_GCM_*
870
Remove OpenSSL configure checks
871
Always save/restore pull options
872
Also restore/save compress related options in reconnects
873
Also restore/save route-gateway options on SIGUSR1 reconnects
874
Remove LibreSSL specific defines not needed for modern LibreSSL
875
Add parsing of dhcp-option PROXY_HTTP
876
Ensure using const variables with EVP_PKEY_get0_*
877
Move context_auth from context_2 to tls_multi and name it multi_state
878
Fix condition to generate session keys
879
Remove always enabled USE_64_BIT_COUNTERS define
880
Fix a number of mingw warnings
881
Move tls_select_primary_key into its own function
882
Allow all GCM ciphers
883
Change options->data_channel_use_ekm to flags
884
Implement deferred auth for scripts
885
Use functions to access key_state instead direct member access
886
Avoid failing_test unused warning in example_test
887
Move direct.h header where it is used
888
Replace OS_SPECIFIC_DIRSEP with PATH_SEPARATOR
889
Remove a number of platform specific checks in configure.ac
890
Remove --disable-multihome option
891
Remove support for blocking connect()
892
Fix memory leak in misc unit test
893
Fix binary and (&) used in auth-token check instead of logical and (&&)
894
Add missing free_key_ctx for auth_token
895
Remove explicit struct iovec check (HAVE_IOVEC)
896
Remove getpeername, getpid check
897
Inline do_init_auth_token_key
898
Add noreturn attribute for MSVC to assert_failed method.
899
Move utility function from win32.c to win32-util.c
900
Document stub-v2 being basically an alias for no compression at all
901
Return cached result in tls_authentication_status
902
Use exponential backoff for caching in tls_authentication_status
903
Add github actions
904
Silence warning about format string in check_ca_required
905
Implement auth-token-user
906
Move auth_token_state from multi to key_state
907
Add connection_established as state in tls_multi->context_auth
908
Make waiting on auth an explicit state in the context state machine
909
Ensure tls session is authenticated before sending push reply
910
Extracting key_state deferred auth status update into function
911
Move examples into openvpn-examples(5) man page
912
Introduce S_GENERATED_KEYS state and generate keys only when authenticated
913
Fix tls-cert-profile broken on OpenSSL 1.1+
914
Cleanup handling of initial auth token
915
Remove --ncp-disable option
916
Add detailed man page section to setup a OpenVPN setup with peer-fingerprint
917
Support NCP in pure P2P VPN setups
918
Remove unistd.h from unit test
919
Introduce webauth auth pending method and deprecate openurl
920
Include Chacha20-Poly1305 into default --data-ciphers when available
921
Detect unusable ciphers on patched OpenSSL of RHEL/Centos
922
Fix Ubuntu spelling and duplicate run in Github Actions
923
Add message when decoding PKCS12 file fails.
924
Add small unit test for testing HMAC
925
Deprecate --ecdh-curve with OpenSSL 3.0 and adjust mbed TLS message
926
Use EVP_PKEY based API for loading DH keys
927
Remove DES check with OpenSSL 3.0
928
Remove DES key fixup code
929
Do not allow CTS ciphers
930
Use new EVP_MAC API for HMAC implementation
931
Add --with-openssl-engine autoconf option (auto|yes|no)
932
Use EVP_PKEY_get_group_name to query group name
933
Replace EVP_get_cipherbyname with EVP_CIPHER_fetch
934
Use EVP_MD_get0_name instead EV_MD_name
935
Remove dependency on BF-CBC existance from test_ncp
936
Implement DES ECB encrypt via EVP_CIPHER api
937
Fix error when BF-CBC is not available
938
Fix function name in DH error message
939
Add insecure tls-cert-profile options
940
Remove custom PRNG function
941
Completely remove DES checks
942
Refactor early initialisation and uninitialisation into methods
943
Use TYPE_do_all_provided function for listing cipher/digest
944
Add macos OpenSSL 3.0 and ASAN builds
945
Allow loading of non default providers
946
Move IV_TCPNL from comp_generate_peer_info_string to push_peer_info
947
Implement optional cipher in --data-ciphers prefixed with ?
948
Directly use hardcoed OPENVPN_AEAD_TAG_LENGTH instead lookup
949
Remove cipher_kt_var_key_size and remaining --keysize documentation
950
Remove cipher_ctx_get_cipher_kt and replace with direct context calls
951
Remove key_type->cipher_length field
952
Remove key_type->hmac_length
953
Fix handling an optional invalid cipher at the end of data-ciphers
954
Make --nobind default for --pull
955
Remove ENABLE_CRYPTO_OPENSSL ifdef inside ENABLE_CRYPTO_OPENSSL ifdef
956
Remove max_size from buffer_list_new
957
Add argv_insert_head__empty_argv__head_only to argv tests
958
Remove cipher_kt_t and change type to const char* in API
959
Move deprecation of SWEET32/64bit block size ciphers to 2.7
960
Adjust cipher-negotiation.rst with compat-mode changes
961
Remove md_kt_t and change crypto API to use const char*
962
Initialise kt_cipher even when no crypto is enabled
963
Remove align_adjust frame code
964
Fix triggering assertion of ks->authenticated after tls_deauthenticate
965
Document frame related function and variables a bit more
966
Remove post_open_mtu code
967
Make github actions names nicer, include Ubuntu18+OpenSSL 1.0.2
968
Add helper functions to calculate header/payload sizes
969
Decouple MSS fix calculation from frame calculation
970
Rework occ link-mtu calculation
971
Remove pointless do_init_frame_tls function
972
Remove BUFFER_LIST_AGGREGATE_TEST test code
973
Deprecate link-mtu
974
Fix mssfix and frame calculation in CBC mode
975
Change buffer allocation calculation and checks to be more static
976
Fix datagram_overhead and assorted functions
977
Implement optional mtu parameter for mssfix
978
Remove link_mtu parameter when running up/down scripts
979
Replace TUN_MTU_SIZE with frame->tun_mtu
980
Change the default for mssfix to mssfix 1492 mtu
981
Add mtu paramter to --fragment and change fragment calculation
982
Update fragment and mssfix related warnings
983
Use new frame header methods to calculate OCC_MTU_LOAD payload size
984
Remove extra_link from frame
985
Remove frame->link_mtu
986
Remove frame.extra_frame and frame.extra_buffer
987
Default to --cipher BF-CBC if not set and compat-mode < 2.4.0
988
Fix 'defined but not used' warnings with enable-small/disable-management
989
Add Werror to github action ubuntu build
990
Add better documentation for CAS_* states
991
Add unit test for mssfix with compression involved
992
Remove FRAME_HEADROOM, PAYLOAD_SIZE, EXTRA_FRAME and TUN_LINK_DELTA macros
993
Fix mbed TLS compile if OpenSSL headers are not available
994
Remove unused function cipher_var_key_size
995
Implement fixed MSS value for mssfix and use it for non default MTUs
996
networking: remove duplicate methods from networking_sitnl.c
997
Remove dead PID_TEST code
998
Remove inc_pid argument from reliable_mark_deleted that is always true
999
Remove EXPONENTIAL_BACKOFF define
1000
Remove tls_init_control_channel_frame_parameters wrapper function
1001
Add documentation for swap_hmac function
1002
Make buf_write_u8/16/32 take the type they pretend to take
1003
Move pre decrypt lite check to its own function
1004
Extend tls_pre_decrypt_lite to return type of packet and keep state
1005
Move ssl function related to control channel wrap/unwrap to ssl_pkt.c/h
1006
Add unit tests for test_tls_decrypt_lite
1007
Split out reliable_ack_parse from reliable_ack_read
1008
Refactor tls-auth/tls-crypt wrapping into into own function
1009
Extract session_move_pre_start as own function, use local buffer variable
1010
Change FULL_SYNC macro to no_pending_reliable_packets function
1011
Extract session_move_active into its own function
1012
Move tls_process_state into its own function
1013
Remove pointless indentation from tls_process.
1014
Move CRL reload to key_state_init from S_START transition
1015
Change reliable_get_buf_sequenced to reliable_get_entry_sequenced
1016
Implement constructing a control channel reset client as standalone function
1017
Implement stateless HMAC-based sesssion-id three-way-handshake
1018
Extract read_incoming_tls_ciphertext into function
1019
Fix format specifier for printing size_t on 32bit size_t platforms
1020
Remove workaround for Android 4.4
1021
Implement HMAC based session id for tls-crypt v2
1022
Optimise three-way handshake condition for S_PRE_START to S_START
1023
Extract read_incoming_tls_plaintext into its own function
1024
Add uncrustify check to github actions
1025
Add ubuntu 22.04 to Github Actions
1026
Implement ED448 and ED25519 support in xkey_provider
1027
Translate OpenSSL 3.0 digest names to OpenSSL 1.1 digest names
1028
Fix client-pending-auth error message to say ERROR instead of SUCCESS
1029
Remove useless empty line from CR_RESPONSE message
1030
Remove leftover frame_set_mtu_dynamic definitions in mtu.h
1031
Inline frame_add_to_extra_tun function and remove frame_defined
1032
tun: extract close_tun_handle into its own fucntion and print correct type
1033
Error out if both remap-usr1 SIGHUP and config stdin are used
1034
Fix segfault when no --config argument is given
1035
Extract check_session_cipher into standalone function
1036
Cleanup receive_auth_failed and simplify method
1037
Fix IV_PLAT_VER and UV_ variables sent without push-peer-info
1038
Rename OPT_P_IPWIN32 to OPT_P_DHCPDNS and include --dns in it
1039
Include DCO status in GLOBAL_STATS status v2 output
1040
Github Actions: Add libreSSL actions
1041
Include libressl and macOS 12 to macOS github actions
1042
Fix declaration of pubkeys in test_provider.c in MSVC builds
1043
Change command help to match man page and implementation
1044
Implement --client-crresponse script options and plugin interface
1045
Add example script demonstrating TOTP via auth-pending
1046
Add OpenSSL 3.0 to mingw build
1047
Update android.txt to reflect more recent changes.
1048
Allow scripts and plugins to set a custom AUTH_FAILED message
1049
Implement exit notification via control channel
1050
Implement AUTH_FAIL, TEMP message support
1051
Document/cleanup event_timeout functions
1052
Fix OpenVPN querying user/password if auth-token with user expires
1053
Enable -Werror on macOS builds
1054
Ensure only CBC, CFB, OFB and AEAD ciphers are considered valid data ciphers
1055
Change exit signal in P2P to be a SIGUSR1 and delayed CC exit in P2MP
1056
Allow Authtoken lifetime to be short than renegotiation time
1057
Allows renegotiation only to start if session is fully established
1058
Fix renewal spelling and actually allow external-auth with renewal time
1059
Fix regression of ignoring --user
1060
Refactor/optimise code sending TLS control channel messages
1061
Add unit test for reliable_get_num_output_sequenced_available
1062
Allow setting control channel packet size with max-packet-size
1063
Always include ACKs for the last seen control packets
1064
Add workaround for Softether server dropping P_ACK_V1 with >= 5 acks
1065
Improve data key id not found error message
1066
Add packet type in accept/reject messages for HMAC packet
1067
Fix md_kt_size in mbed TLS when queried for size of "none"
1068
Add algorithm and bits used in key_print2 method and refactor method
1069
Remove unused addr_inet4or6, addr_guess_family and inline addr_copy_sa
1070
Allow tun-mtu to be pushed
1071
Push server mtu to client when supported and support occ mtu
1072
Fix logic error in checking early negotiation support check
1073
Move dco_installed from sock->info to sock->info.lsa.actual
1074
Use dedicated multi->dco_peer_id for DCO instead of multi->peer_id
1075
Add section about common error with OpenVPN 2.6 and OpenSSL 3.0
1076
Introduce connection state for reconnecting peer in p2p
1077
Signal USR1 when connection initialising fails
1078
Allow reconnecting in p2p mode work under FreeBSD
1079
1080
Camille Guérin (1):
1081
Removed error message for an option flag not supported with --server-ipv6
1082
1083
David Korczynski (1):
1084
Fix argv leaks in add_route() and add_route_ipv6()
1085
1086
David Sommerseth (18):
1087
man: Add missing --server-ipv6
1088
man: Improve --remote entry
1089
sample-plugins: Partially autotoolize the sample-plugins build
1090
build: Fix make distclean/distcheck
1091
compat/lz4: Update to v1.9.2
1092
build: Fix missing install of man page in certain environments
1093
build: Remove compat-lz4
1094
Update copyrights
1095
doc: Use generic rules for man/html generation
1096
man: Clarify IV_HWADDR
1097
crypto: Fix OPENSSL_FIPS enabled builds
1098
sample-plugin: New plugin for testing multiple auth plugins
1099
plugins: Remove defer/simple.c sample plugin
1100
plug-ins: Disallow multiple deferred authentication plug-ins
1101
dev-tools: Remove no longer needed openvpn-plugin.h.in patching
1102
dev-tools: Remove uncrustify -p
1103
dev-tools: Avoid uncrustify mangling MAC_FMT macro
1104
The Great Reformatting of 2022
1105
1106
Dmitry Zelenkovsky (1):
1107
implement --session-timeout
1108
1109
Domagoj Pensa (3):
1110
Fix too early argv freeing when registering DNS
1111
Remove 1 second delay before running netsh
1112
Skip DHCP renew with Wintun adapter
1113
1114
Eric Thorpe (1):
1115
Fixes a bug in management_callback_send_cc_message, should be strlen instead of sizeof
1116
1117
Frank Lichtenheld (18):
1118
doc/Makefile: rebuild rst docs if input files change
1119
doc: fix misc documentation issues
1120
doc/options: clean up documentation for --proto and related options
1121
Reformat for sp_after_comma=add
1122
uncrustify: add sp_after_comma=add
1123
uncrustify: have exactly one newline at the end of files
1124
t_client: Allow to force FAIL on prerequisite fails
1125
systemd: remove generated service files on clean
1126
Reduce usage of __DATE__
1127
config-version.h: remove unused includes
1128
t_client.sh: do not require fping6
1129
doc: cleanup for --data-ciphers and related
1130
test_crypto: fix test_occ_mtu_calculation with --disable-fragment
1131
msvc: always call git-version.py
1132
GitHub Issues: add note to Changes as well
1133
GitHub Issues: add new links to INSTALL and README
1134
GitHub Issues: Create first issue template (Bug)
1135
documentation: avoid recommending --user nobody
1136
1137
Gert Doering (67):
1138
Change version.m4 to 2.6_git
1139
Fix stack overflow in OpenSolaris NEXTADDR()
1140
Workaround FreeBSD 12+ race condition on tun/tap open with IPv6.
1141
Document that --push-remove is generally more suitable than --push-reset
1142
Fix error detection / abort in --inetd corner case.
1143
Fix TUNSETGROUP compatibility with very old Linux systems.
1144
Fix handling of 'route remote_host' for IPv6 transport case.
1145
Replace 'echo -n' with 'printf' in tests/t_lpback.sh
1146
Fix description of --client-disconnect calling convention in manpage.
1147
Handle NULL returns from calloc() in sample plugins.
1148
Fix --show-gateway for IPv6 on NetBSD/i386.
1149
socks.c: fix alen for DOMAIN type addresses, bump up buffer sizes
1150
Fix netbits setting (in TAP mode) for IPv6 on Windows.
1151
If IPv6 pool specification sets pool start to ::0 address, increment.
1152
Add demo plugin that excercises "CLIENT_CONNECT" and "CLIENT_CONNECT_V2" paths
1153
Fix combination of --dev tap and --topology subnet across multiple platforms.
1154
Fix redirecting of IPv4 default gateway if connecting over IPv6.
1155
Fix compilation on pre-EKM mbedTLS libraries.
1156
Avoid passing NULL to argv_printf_cat() in temp_file error case.
1157
Change travis build scripts to use https when fetching prerequisites.
1158
Fix line number reporting on config file errors after <inline> segments
1159
Clarify --block-ipv6 intent and direction.
1160
Document common uses of 'echo' directive, re-enable logging for 'echo'.
1161
Make OPENVPN_PLUGIN_ENABLE_PF failures FATAL
1162
clean up / rewrite sample-plugins/defer/simple.c
1163
Fix EVP_PKEY_CTX_... compilation with LibreSSL
1164
Require at least 100MB of mlock()-able memory if --mlock is used.
1165
Get rid of last PLUGIN_DEF_AUTH #ifdef
1166
Fix 'compress migrate' for 2.2 clients.
1167
Fix potential NULL ptr crash if compiled with DMALLOC
1168
Repair --secret deprecation warning.
1169
rewrite parse_hash_fingerprint()
1170
Ignore leading whitespace and comment lines for peer-fingerprint.
1171
Add error reporting to get_console_input_win32().
1172
Ignore --explicit-exit-notify in TCP mode.
1173
Use more C99 initialization in add_route/add_route_ipv6().
1174
Include --push-remove in the output of --help.
1175
Move '--push-peer-info' documentation from 'server' to 'client options'
1176
add test case(s) to notice 'openvpn --show-cipher' crashing
1177
Repair --inactive with 'bytes' argument larger 2Gbytes.
1178
Fix --mtu-disc maybe|yes on Linux.
1179
Fix trailing-whitespace errors in last patch.
1180
Exclude the last two whitespace-only uncrustify fixes from git blame output.
1181
Implement --mtu-disc for IPv6 UDP sockets.
1182
Fix non-compliant whitespace introduced by commit 54800aa975418fe35.
1183
Pass proper sockaddr_* structure for IPv6 socket errors.
1184
Fix error message about extended errors for IPv4-only sockets.
1185
Break 'try 256 dco devices' loop on EPERM
1186
Cleanup: get rid of 'dynamic' argument of open_tun_generic()
1187
Remove outdated information from ChangeLog, point at release branches.
1188
Apply uncrustify changes that were forgotten in the last patch.
1189
Apply uncrustify changes that were forgotten in the FreeBSD DCO 1/2 patch.
1190
FreeBSD-DCO: repair device iteration to find first free interface.
1191
DCO: require valid netbits setting for non-primary iroutes.
1192
Adjust Linux+FreeBSD DCO device name handling to 'non DCO linux style'
1193
cleanup open_tun() for TARGET_NETBSD
1194
t_client: add per-instance arguments to fping
1195
introduce V= level to manage t_client.sh output verbosity
1196
un-break undo_ifconfig_ipv4()/_ipv6() on all non-linux/non-win32 platforms
1197
use boolean '||' to join two bools, not bitwise '|'
1198
denoise tests/t_lpback.sh
1199
FreeBSD: for topology subnet, put tun interface into IFF_BROADCAST mode
1200
FreeBSD DCO: introduce real subnet mode
1201
Improve documentation for --dev and --dev-node.
1202
Update PORTS
1203
rework INSTALL and README to prepare for 2.6 release
1204
Preparing release 2.6_beta1
1205
1206
Greg Cox (5):
1207
Fix naming error in sample-plugins/defer/simple.c
1208
Documentation fixes around openvpn_plugin_func_v3 in openvpn-plugin.h.in
1209
Update openvpn_plugin_func_v2 to _v3 in sample-plugins/defer/simple.c
1210
More explicit versioning compatibility in sample-plugins/defer/simple.c
1211
Explain structver usage in sample defer plugin.
1212
1213
Heiko Hund (10):
1214
add support for --dns option
1215
Add git pre-commit hook script to uncrustify
1216
pre-commit: uncrustify based on staged changes
1217
remove foreign_option() call for IPv6 DNS servers
1218
remove dead foreign-option parsing code
1219
rename foreign_option() and move it up
1220
doc: fix literal block in tls-options.rst
1221
dns: also (re)place foreign dhcp options in env
1222
signal --dns support in peer info
1223
make %x destination unsigned
1224
1225
Ilya Ponetayev (1):
1226
fix compilation issues with small and w/o debug
1227
1228
Ilya Shipitsin (2):
1229
CI: github actions: keep "pdb" in artifacts
1230
BUILD: enable CFG and Spectre mitigation for MSVC
1231
1232
Jan Mikkelsen (1):
1233
cipher-negotiation.rst missing from doc/Makefile.am
1234
1235
Jan Seeger (1):
1236
Added 'route_ipv6_metric_NN' environment variable for IPv6 route metric.
1237
1238
Jason A. Donenfeld (1):
1239
Support fingerprint authentication without CA certificate
1240
1241
Jeff (1):
1242
duplicate function declaration.
1243
1244
Juliusz Sosinowicz (4):
1245
EVP_DigestSignFinal siglen parameter correction
1246
Support for wolfSSL in OpenVPN
1247
build: Add support for pkg-config < 0.28 for old autoconf versions
1248
README.wolfssl Update
1249
1250
Kristof Provost (6):
1251
Handle exceeding 'max-clients'
1252
ovpn-dco: introduce FreeBSD data-channel offload support
1253
Support creating iroute route entries on FreeBSD
1254
FreeBSD networking cleanup
1255
FreeBSD DCO: support AES-192-GCM
1256
dco: pass control packets through the socket on FreeBSD
1257
1258
Lev Stipakov (68):
1259
tun.c: enable using wintun driver under SYSTEM
1260
openvpnmsica: make adapter renaming non-fatal
1261
msvc: better support for 32bit architecture
1262
Alias ADAPTER_DOMAIN_SUFFIX to DOMAIN
1263
ssl_common.h: fix 'not all control paths return a value' msvc warning
1264
Remove compat-lz4 references from VS project files
1265
tapctl: support for ovpn-dco Windows driver
1266
msvc: add ARM64 configuration
1267
win32: add missing include header
1268
openvpnmsica: properly schedule reboot in the end of installation
1269
options.c: fix msvc build error
1270
msvc: standalone building
1271
contrib/vcpkg-ports: add pkcs11-helper port
1272
vcpkg-ports: restore trailing whitespaces in .patch files
1273
GitHub actions: add MSVC build
1274
crypto_openssl.c: disable explicit initialization on Windows (CVE-2121-3606)
1275
contrib/vcpkg-ports: add openssl port with --no-autoload-config option set (CVE-2121-3606)
1276
Fix console prompts with redirected log
1277
GitHub Actions: fix MSVC builds
1278
contrib/vcpkg-ports: remove openssl port
1279
Add building man page on Windows
1280
GitHub Actions: remove Ubuntu 16.04 environment
1281
Fix loading PKCS12 files on Windows
1282
msvc: fix product version display
1283
config-msvc.h: fix OpenSSL-related defines
1284
GitHub Actions: use latest working lukka/run-vcpkg
1285
Use network address for emulated DHCP server as a default
1286
Load OpenSSL config on Windows from trusted location
1287
ring_buffer.h: fix GCC warning about unused function
1288
ssh_openssl.h: remove unused declaration
1289
vcpkg/pkcs11-helper: compatibility with latest vcpkg
1290
config-msvc.h: indicate key material export support
1291
auth_token.c: add NULL initialization
1292
tun: remove tun_finalize()
1293
vcpkg-ports/pkcs11-helper: bump to release 1.28
1294
vcpkg-ports/pkcs11-helper: indicate OpenSSL EC support
1295
xkey: fix msvc build
1296
msvc: switch to openssl3
1297
msvc: cleanup
1298
vcpkg: link lzo statically
1299
openvpnmsica: add ovpn-dco custom actions
1300
vcpkg-ports/pkcs11-helper: adapt to new upstream URL
1301
vcpkg-ports\pkcs11-helper: shorten patch filename
1302
vcpkg-ports\openssl3: update to 3.0.2
1303
Fix incorrect default mssfix value in server mode
1304
msvc: adjust build options to harden binaries
1305
vcpkg: switch to manifest
1306
Fix M_ERRNO behavior on Windows
1307
GitHub Actions: trigger openvpn-build GHA on success
1308
Set o->use_peer_id flag for p2p mode
1309
openvpnmsica: remove OpenVPNService state check code
1310
tun.c: remove unused gc_arena from init_tun()
1311
error.c: remove unused crash() function
1312
tun: properly handle device interface list
1313
dco.h: fix return type when DCO is not enabled
1314
dco-win: use run-time dynamic linking for GetOverlappedResultEx
1315
vcpkg: bump baseline version
1316
do_persist_tuntap: remove indentation level
1317
msvc: remove .filters files
1318
dco.c: check certain options only on startup
1319
Use DCO on Windows by default
1320
doc: add "ovpn-dco" to usage and man page
1321
dco-win: support for --persist-tun
1322
msvc: add branch name and commit hash to version output
1323
vcpkg: use the latest versions of dependency ports
1324
win32: detect arm64 architecture and emulations
1325
INSTALL: update Windows notes
1326
dco: disable dco on Windows if --remote is not defined
1327
1328
Magnus Kroken (2):
1329
doc: fix typos in cipher-negotiation.rst
1330
Changes.rst: fix mistyped option names
1331
1332
Marc Becker (2):
1333
vcpkg-ports/pkcs11-helper: bump to release 1.29
1334
fix GitHub workflow working directories in MinGW builds
1335
1336
Martin Janů (1):
1337
Update the replay-window backtrack log message
1338
1339
Matthias Andree (1):
1340
Fix SIGSEGV (NULL deref) receiving push "echo"
1341
1342
Max Fillinger (15):
1343
Wipe Socks5 credentials after use
1344
Fix build with mbedtls w/o SSL renegotiation support
1345
In init_ssl, open the correct CRL path pre-chroot
1346
Abort if CRL file can't be stat-ed in ssl_init
1347
Update Fox e-mail address in copyright notices
1348
Replace deprecated mbedtls DRBG update function
1349
Fix build with compression disabled
1350
Don't manually free DH params in OpenSSL 3
1351
Remove unused havege.h header
1352
Don't use BF-CBC in unit tests if we don't have it
1353
Add warning about mbed TLS licensing problem
1354
Don't "undo" ifconfig on exit if it wasn't done
1355
Update openssl_compat.h for newer LibreSSL
1356
Handle EVP_MD_CTX as an opaque struct
1357
Check if pkcs11_cert is NULL before freeing it
1358
1359
Michael Baentsch (1):
1360
Enable usage of TLS groups not identified by a NID in OpenSSL 3
1361
1362
Paolo Cerrito (1):
1363
Insert client connection data into PAM environment
1364
1365
Richard Bonhomme (6):
1366
Improve error msg when all TAP adapters are in use 'or disabled'
1367
Man page sections corrections
1368
Do not print Diffie Hellman parameters file to log file
1369
Log messages: Replace NCP with --data-ciphers (NFC)
1370
doc link-options.rst: Use free open-source dynamic-DNS provider URL
1371
doc/protocol-options.rst: Correct default for --allow-compression
1372
1373
Saifur Rahman Mohsin (1):
1374
Ignore deprecation warning for daemon() on macOS (plugin/auth-pam)
1375
1376
Selva Nair (64):
1377
Improve the documentation for --dhcp-option
1378
In tap.c use DiInstallDevice to install the driver on a new adapter
1379
Add a remark on dropping privileges when --mlock is used
1380
Allow --dhcp-option in config file when windows-driver is wintun
1381
Set DNS Domain using iservice
1382
Improve documentation of --username-as-common-name
1383
Quote the domain name argument passed to the wmic command
1384
Remove automatic service
1385
tun.c on WIN32: remove more unused variables
1386
Make it explicit that WIndows build requires UNICODE support
1387
Use C standard compliant format specs in wprintf functions
1388
Print format spec changes for tapctl and openvpnmscia
1389
Replace TEXT(__FUNCTION__) by __FUNCTION__ in openvpnmscia.c
1390
Fix parsing of IV_SSO string
1391
Do not require CA when peer-fingerprint is used
1392
Improve documentation of AUTH_PENDING related directives
1393
Apply the connect-retry backoff to only one side of a connection
1394
Fix client-pending-auth help message in management interface
1395
Minor doc correction: tls-crypt-v2 key generation
1396
Fix the "default" tls-version-min setting
1397
Fix some more wrong defines in config-msvc.h
1398
Require Windows CNG keys for cryptoapicert
1399
Remove error injection into OpenSSL from cryptoapi.c
1400
Require EC key support in Windows builds
1401
Ensure the current common_name is in the environment for scripts
1402
Avoid memory leak in hmac_ctx_new (OpenSSL 3.0 only)
1403
Fix tls-version-min default once again
1404
A built-in provider for using external key with OpenSSL 3.0
1405
Implement KEYMGMT in the xkey provider
1406
Implement SIGNATURE operations in xkey provider
1407
Implement import of custom external keys
1408
Initialize the xkey provider and use it in SSL context
1409
A helper function to import private key for management-external-key
1410
Add xkey_provider sources and includes to MSVC project
1411
Enable signing via provider for management-external-key
1412
Add a function to encode digests with PKCS1 DigestInfo wrapper
1413
Allow management client to announce pss padding support
1414
Respect algorithm support announced by management client
1415
Support sending DigestSign request to management client
1416
Increase ERR_BUF_SIZE when management interface support is enabled
1417
Add a generic key loading helper function for xkey provider
1418
pkcs11: Interface the xkey provider with pkcs11-helper
1419
Enable signing using CNG through xkey provider
1420
Add a unit test for external key provider
1421
xkey: Use a custom error level for debug messages
1422
Fix max saltlen calculation in cryptoapi.c
1423
Support PSS signing using pkcs11-helper >= 1.28
1424
Do not error when md_kt_size() is called with mdname="none"
1425
Fix a potential memory leak in tls_ctx_use_management_external_key
1426
pkcs11_openssl.c: check EVP_get_digestbyname() != NULL
1427
Fix crash in xkey-provider in msvc builds
1428
Remove management_write_peer_info_file and related code
1429
Log the actual management interface port in use
1430
Log address of management client on accept
1431
In x_check_status() read errno early
1432
xkey_provider: fix building with --disable-management
1433
Do not skip ERROR:/SUCCESS: response from management interface
1434
Allow a few levels of recursion in virtual_output_callback()
1435
Fix auth-token usage with management-def-auth
1436
Ensure --auth-nocache is handled during renegotiation
1437
Purge auth-token as well while purging passwords
1438
Do not copy auth_token username to itself
1439
Do not add leading space to pushed options
1440
pull-filter: ignore leading "spaces" in option names
1441
1442
Sergio E. Nemirowski (1):
1443
resolvconf fails with -p
1444
1445
Simon Rozman (9):
1446
iservice: Resolve MSVC C4996 warnings
1447
openvpnserv: Cache last error before it is overridden
1448
netsh: Specify interfaces by index rather than name
1449
netsh: Clear existing IPv6 DNS servers before configuring new ones
1450
netsh: Delete WINS servers on TUN close
1451
openvpnmsica: Simplify find_adapters() to void return
1452
tun.c: Remove dead code
1453
interactive.c: Resolve MSVC C4996 warning
1454
tapctl: Resolve MSVC C4996 warnings
1455
1456
Steffan Karger (5):
1457
networking_iproute2: fix memory leak in net_iface_mtu_set()
1458
Simplify key material exporter backend API
1459
tls-crypt-v2: fix server memory leak
1460
tls-crypt-v2: also preload tls-crypt-v2 keys (if --persist-key)
1461
reliable: retransmit if 3 follow-up ACKs are received
1462
1463
Timo Rothenpieler (5):
1464
Linux: Retain CAP_NET_ADMIN when dropping privileges
1465
GitHub Actions: Add new libcap-ng-dev dependency
1466
Github Actions: update used actions
1467
dco: disable DCO if --user specified but unable to retain capabilities
1468
dco: turn platform config checks into separate function
1469
1470
Todd Zullinger (2):
1471
Update IRC information in CONTRIBUTING.rst
1472
doc/man (vpn-network-options): fix foreign_option_{n} typo
1473
1474
Tõivo Leedjärv (1):
1475
Stop using deprecated getpass()
1476
1477
Ville Skyttä (1):
1478
README.down-root: Fix plugin module name
1479
1480
Vladislav Grishenko (8):
1481
Fix best gateway selection over netlink
1482
Fix fatal error at switching remotes (#629)
1483
Fix update_time() and openvpn_gettimeofday() coexistence
1484
Selectively reformat too long lines
1485
Speedup TCP remote hosts connections
1486
Support X509 field list to be username
1487
Fix IPv4 default gateway with multiple route tables
1488
Add CRL extractor script for --crl-verify dir mode
1489
1490
```