Blame

c9d9c9 Samuli Seppänen 2025-01-29 12:06:32 1
# Introduction
2
3
This page shows the high-level status of OpenVPN 2.5 release. For all the details, see the [Active Tickets by Milestone](report:3) report.
4
5
# Schedule
6
7
As we missed our original deadline (Debian Buster freeze), we don't have a schedule yet, except "in year 2020". Nevertheless, the release will proceed as follows:
8
9
- **2.5_beta1 (August 14)**
10
After this date, no new features allowed, stabilizing starts for real. Some minor "nice to have patches" might be accepted after evaluation/discussion on IRC; but should be avoided.
11
Git will be branched to release/2.5 at that point.
12
13
- **??? - 2.5_beta2 (optional)**
14
Only patches related to stabilizing and important bug-fixes are allowed after this point. No more "nice to have patches" after this point.
15
If we have no bug fixes or otherwise stabilizing code, this release can be skipped.
16
17
- **??? - 2.5_rc1**
18
Only really needed and critical bug fixes allowed.
19
20
- **??? - 2.5_rc2**
21
"If needed"
22
23
- **2.5.0 (September 17)**
24
Final release.
25
26
# Features/Fixes to Include
27
28
## Must Have
29
30
| Task Description | Assigned to | Status | Ticket |
31
|------------------|-------------|--------|--------|
32
| [MSI installers](wiki:OpenvpnMSIInstaller) | mattock | Final integration tests not done | #1122 |
33
| update auth-user-pass docs | mattock | not started, discussion [here](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12835.html) |
34
| polish auth-token / auth-gen-token corner cases | cron2, plaisthos | pending | - |
35
36
## Postponed Items (former "nice to have" items for 2.5)
37
38
| Task Description | Assigned to | Status | Ticket |
39
|------------------|-------------|--------|--------|
40
| support for multiple-protocol sockets (UDP/TCP) | ordex | wip |
41
| Support for multiple sockets (multi-port/multi-IP) | ordex | pending review | #556 |
42
| Dynamic routes ('route in ccd-file'), depends on netlink support | ??? | ??? |
43
| transport plugin (primary use case: obfuscation) | ordex | wip |
44
| [tftp/wpad patch](http://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg10511.html) | jjk | patch on list, needs review and merge |
45
| support TLS record splitting (like ovpn3) | syzzer | (started, but no patches available yet) | #554 |
46
| test server that does --auth-user-pass and/or challenge stuff | cron2 (snair) | not started |
47
| Update OpenVPN PRF (move away from SHA1/MD5) | syzzer | not started |
48
| maybe: add PRF plugin interface | ??? | ??? |
49
| maybe: add key exchange plugin interface | ??? | ??? |
50
| maybe: add data channel separation | ??? | ??? |
51
| maybe: fix radius-plugin | ??? | ??? |
52
| improve control channel performance | syzzer | ??? |
53
54
## Work Needed
55
- trac tickets (2.4.x, 2.5.x, unclassified)
56
- MSI testing and user documentation
57
58
## Items Already Done
59
- remove ENABLE_CRYPTO
60
- [ChaCha20-Poly1305 support for the data channel](https://patchwork.openvpn.net/patch/496/)
61
- tls-crypt-v2 (#1121)
62
- MSI packaging
63
- [struct argv overhaul](https://patchwork.openvpn.net/project/openvpn2/list/?series=638)
64
- [Wintun support](https://patchwork.openvpn.net/patch/824/)
65
- [Auth failure messages back to client](https://patchwork.openvpn.net/project/openvpn2/list/?series=543&submitter=&state=3&q=&archive=&delegate=)
66
- #6 - VLAN patch set
67
- #1123 - Netlink support (includes route.c / tun.c refactoring)
68
- [IPv6-only server](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg16998.html) | ordex & cron2 | most of the work is done! some details remain to be cleaned up | #208 |
69
- Implement asymmetric compression | plaisthos | v5 merged (lev/cron2) |
70
- [Allow OpenVPN to communicate to peers via a Linux VRF](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12767.html) | cron2 | patch v2 on the list & merged |
71
- man page formatting change | dazo | [merged](https://gitlab.com/openvpn/openvpn/-/commit/f500c49c8e0a77ce665b11f6adbea4029cf3b85f) |
72
- async client-connect support | plaisthos + ordex | [Merged](https://patchwork.openvpn.net/project/openvpn2/list/?series=827&state=*) |
73
74
# Missing Pieces from MSI
75
76
Bundling OpenVPN as an MSI will require changes to several projects: openvpn, openvpnserv2, openvpn-build, and tap-windows6. Here's a list of the missing pieces (hopefully) in the order in which they should be merged:
77
78
1. ~~[openvpn: the openvpnmsica and tapctl patch series](https://patchwork.openvpn.net/project/openvpn2/list/?series=662)~~
79
2. [tap-windows6: MSM packaging](https://github.com/OpenVPN/tap-windows6/pull/106)
80
3. [openvpn-build: Windows MSI packaging](https://github.com/OpenVPN/openvpn-build/pull/141)
81
4. [openvpn-vagrant: Add MSI build support](https://github.com/OpenVPN/openvpn-vagrant/pull/7)
82
- Needs to be adapted to final upstream URLs before merging
83
84
## Dropping tap-windows6 NSI Changes?
85
86
I (mattock) propose we **drop** the following tap-windows6 PRs that change the **NSIS** installer:
87
88
- [installer: Refine the WoW64 decision logic](https://github.com/OpenVPN/tap-windows6/pull/98)
89
- [installer: Select Win7/8/8.1 vs. Win10 driver at runtime](https://github.com/OpenVPN/tap-windows6/pull/99)
90
- [installer: Add code signing certificate before installing the driver](https://github.com/OpenVPN/tap-windows6/pull/100)
91
92
Current OpenVPN / tap-windows6 NSIS installers are working well across all the platforms, so I'd prefer not to "rock the boat" by introducing changes unnecessarily. Also, I believe the above PRs were originally meant for OpenVPN 2.5, not for 2.4. And OpenVPN 2.5 does not need these PRs anymore now that we have [MSM packaging](https://github.com/OpenVPN/tap-windows6/pull/106) for tap-windows6. Even if we did decide that the above PRs make sense for 2.4, our support policy says that 2.4 would move to "Old stable" in ~6 months after 2.5.0, after which we would not provide any Windows installers. So the gain for 2.4 would be rather small, maybe for one or two 2.4.x releases at most.