# Introduction

This page shows the high-level status of the OpenVPN 2.4 release. For all the details, see the [Active Tickets by Milestone](report:3) report.

# Schedule

- **November 16** - 2.4_beta1
  After this date, no new features are allowed; stabilizing starts for real. Some minor "nice to have" patches might be accepted after evaluation/discussion on IRC.

- **(optional) November 24th/25th** - 2.4_beta2
  Only patches related to stabilizing and important bug-fixes are allowed after this point. No more "nice to have" patches after this point. This release can be skipped if there are no bug fixes or otherwise stabilizing code.

- **December 1st** - 2.4_rc1
  Only really needed and critical bug fixes allowed. This is also the time where we change to a unified coding style across the whole source code.

- **December 15th** - 2.4_rc2
  Branching out release/2.4 happens here.

- **December 28th** - 2.4.0
  Final release.

## Deadline: Debian 9 freeze

Mattock asked the Debian package maintainer about getting 2.4_something into Debian 9 before the freeze. Here's the response: *"I'll consider uploading 2.4_something in early December, so we have a month to fix possible issues. After December 29, it won't be doable."*

# Features/Fixes to Include

## Must Have

All done.

## Minor, but "We Should Try to Make It Happen"

| **Task Description** | **Assigned to** | **Status** |
| --- | --- | --- |
| [struct argv overhaul](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12818.html) | d12fk | Patch review completed (dazo), patches 1-4 applied, patches 5-7 need v2 |
| [auth-gen-token: Inform client why auth-token was rejected](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12848.html) | dazo | Patch review in progress (syzzer) |
| [tftp/wpad patch](http://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg10511.html) | jjk | Patch on list, needs review and merge |
| Support TLS record splitting (like ovpn3) | syzzer | #554 (started, but no patches available yet) |
| [Allow OpenVPN to communicate to peers via a Linux VRF](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12767.html) | - | [Updated patches](https://github.com/OpenVPN/openvpn/pull/65/commits/1baa7e6782b39ed664eedb9b006728d31e22c07e) need review + ML submission |
| Test server that does --auth-user-pass and/or challenge stuff | cron2 (snair) | Not started |
| Update auth-user-pass docs | mattock | Not started, discussion [here](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12835.html) |
| Update OpenVPN PRF (move away from SHA1/MD5) | syzzer | Not started |

## Work Needed

- Trac tickets (2.3.x, 2.4.x, unclassified)

## (Major) Items Already Done

- Poor man's NCP (v6)
- Make openvpnserv2 use exit-events
- Combined 32/64-bit Windows installers
- Semi-automated testing of OpenVPN/OpenVPN-GUI/openvpnserv2 on Windows using [openvpn-windows-test](https://github.com/OpenVPN/openvpn-windows-test)
- dhcp-option DNS6 (stub, windows netsh+service, android)
- Bundle OpenSSL 1.0.2 on Windows
- [Refactor CRL handling](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12809.html)
- [--tls-crypt control channel encryption](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12974.html) #633
- ifconfig-before-open reversal patch for Windows fixed (argv_printf) and merged
- openvpnserv2 integration
- Pushable ciphers, and cipher negotiation
- True dual-stack operation (2.3 has "dual single-stack")
- Interactive service + openvpn-gui integration
- IPv6 route-gateway redirection
- AEAD cipher
- Cipher negotiation (for all but a few corner cases)
- Peer-id (server and client, 2.3 has only client)
- Compression v2 = more efficient alignment
- Unified TCP timeout handling (Arne v3)
- New buildbots for FreeBSD 10.3, NetBSD 7.0.1, OpenBSD 6.0, MacOS X, various recent Linux versions
- --multihome fixed on BSD/amd64 architectures, tested by buildbots
- Recursive routing fixup (Lev v4)
- Block-outside-dns on multiple tunnels (v2, Selva)
- Re-indent formatting (dazo, syzzer). More details on CodeStyle
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9