Blame
| c9d9c9 | Samuli Seppänen | 2025-01-29 12:06:32 | 1 | # Introduction |
| 2 | ||||
| 3 | This page shows the high-level status of OpenVPN 2.5 release. For all the details, see the [Active Tickets by Milestone](report:3) report. |
|||
| 4 | ||||
| 5 | # Schedule |
|||
| 6 | ||||
| 7 | As we missed our original deadline (Debian Buster freeze), we don't have a schedule yet, except "in year 2020". Nevertheless, the release will proceed as follows: |
|||
| 8 | ||||
| 9 | - **2.5_beta1 (August 14)** |
|||
| 10 | After this date, no new features allowed, stabilizing starts for real. Some minor "nice to have patches" might be accepted after evaluation/discussion on IRC; but should be avoided. |
|||
| 11 | Git will be branched to release/2.5 at that point. |
|||
| 12 | ||||
| 13 | - **??? - 2.5_beta2 (optional)** |
|||
| 14 | Only patches related to stabilizing and important bug-fixes are allowed after this point. No more "nice to have patches" after this point. |
|||
| 15 | If we have no bug fixes or otherwise stabilizing code, this release can be skipped. |
|||
| 16 | ||||
| 17 | - **??? - 2.5_rc1** |
|||
| 18 | Only really needed and critical bug fixes allowed. |
|||
| 19 | ||||
| 20 | - **??? - 2.5_rc2** |
|||
| 21 | "If needed" |
|||
| 22 | ||||
| 23 | - **2.5.0 (September 17)** |
|||
| 24 | Final release. |
|||
| 25 | ||||
| 26 | # Features/Fixes to Include |
|||
| 27 | ||||
| 28 | ## Must Have |
|||
| 29 | ||||
| 30 | | Task Description | Assigned to | Status | Ticket | |
|||
| 31 | |------------------|-------------|--------|--------| |
|||
| 32 | | [MSI installers](wiki:OpenvpnMSIInstaller) | mattock | Final integration tests not done | #1122 | |
|||
| 33 | | update auth-user-pass docs | mattock | not started, discussion [here](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12835.html) | |
|||
| 34 | | polish auth-token / auth-gen-token corner cases | cron2, plaisthos | pending | - | |
|||
| 35 | ||||
| 36 | ## Postponed Items (former "nice to have" items for 2.5) |
|||
| 37 | ||||
| 38 | | Task Description | Assigned to | Status | Ticket | |
|||
| 39 | |------------------|-------------|--------|--------| |
|||
| 40 | | support for multiple-protocol sockets (UDP/TCP) | ordex | wip | |
|||
| 41 | | Support for multiple sockets (multi-port/multi-IP) | ordex | pending review | #556 | |
|||
| 42 | | Dynamic routes ('route in ccd-file'), depends on netlink support | ??? | ??? | |
|||
| 43 | | transport plugin (primary use case: obfuscation) | ordex | wip | |
|||
| 44 | | [tftp/wpad patch](http://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg10511.html) | jjk | patch on list, needs review and merge | |
|||
| 45 | | support TLS record splitting (like ovpn3) | syzzer | (started, but no patches available yet) | #554 | |
|||
| 46 | | test server that does --auth-user-pass and/or challenge stuff | cron2 (snair) | not started | |
|||
| 47 | | Update OpenVPN PRF (move away from SHA1/MD5) | syzzer | not started | |
|||
| 48 | | maybe: add PRF plugin interface | ??? | ??? | |
|||
| 49 | | maybe: add key exchange plugin interface | ??? | ??? | |
|||
| 50 | | maybe: add data channel separation | ??? | ??? | |
|||
| 51 | | maybe: fix radius-plugin | ??? | ??? | |
|||
| 52 | | improve control channel performance | syzzer | ??? | |
|||
| 53 | ||||
| 54 | ## Work Needed |
|||
| 55 | - trac tickets (2.4.x, 2.5.x, unclassified) |
|||
| 56 | - MSI testing and user documentation |
|||
| 57 | ||||
| 58 | ## Items Already Done |
|||
| 59 | - remove ENABLE_CRYPTO |
|||
| 60 | - [ChaCha20-Poly1305 support for the data channel](https://patchwork.openvpn.net/patch/496/) |
|||
| 61 | - tls-crypt-v2 (#1121) |
|||
| 62 | - MSI packaging |
|||
| 63 | - [struct argv overhaul](https://patchwork.openvpn.net/project/openvpn2/list/?series=638) |
|||
| 64 | - [Wintun support](https://patchwork.openvpn.net/patch/824/) |
|||
| 65 | - [Auth failure messages back to client](https://patchwork.openvpn.net/project/openvpn2/list/?series=543&submitter=&state=3&q=&archive=&delegate=) |
|||
| 66 | - #6 - VLAN patch set |
|||
| 67 | - #1123 - Netlink support (includes route.c / tun.c refactoring) |
|||
| 68 | - [IPv6-only server](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg16998.html) | ordex & cron2 | most of the work is done! some details remain to be cleaned up | #208 | |
|||
| 69 | - Implement asymmetric compression | plaisthos | v5 merged (lev/cron2) | |
|||
| 70 | - [Allow OpenVPN to communicate to peers via a Linux VRF](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12767.html) | cron2 | patch v2 on the list & merged | |
|||
| 71 | - man page formatting change | dazo | [merged](https://gitlab.com/openvpn/openvpn/-/commit/f500c49c8e0a77ce665b11f6adbea4029cf3b85f) | |
|||
| 72 | - async client-connect support | plaisthos + ordex | [Merged](https://patchwork.openvpn.net/project/openvpn2/list/?series=827&state=*) | |
|||
| 73 | ||||
| 74 | # Missing Pieces from MSI |
|||
| 75 | ||||
| 76 | Bundling OpenVPN as an MSI will require changes to several projects: openvpn, openvpnserv2, openvpn-build, and tap-windows6. Here's a list of the missing pieces (hopefully) in the order in which they should be merged: |
|||
| 77 | ||||
| 78 | 1. ~~[openvpn: the openvpnmsica and tapctl patch series](https://patchwork.openvpn.net/project/openvpn2/list/?series=662)~~ |
|||
| 79 | 2. [tap-windows6: MSM packaging](https://github.com/OpenVPN/tap-windows6/pull/106) |
|||
| 80 | 3. [openvpn-build: Windows MSI packaging](https://github.com/OpenVPN/openvpn-build/pull/141) |
|||
| 81 | 4. [openvpn-vagrant: Add MSI build support](https://github.com/OpenVPN/openvpn-vagrant/pull/7) |
|||
| 82 | - Needs to be adapted to final upstream URLs before merging |
|||
| 83 | ||||
| 84 | ## Dropping tap-windows6 NSI Changes? |
|||
| 85 | ||||
| 86 | I (mattock) propose we **drop** the following tap-windows6 PRs that change the **NSIS** installer: |
|||
| 87 | ||||
| 88 | - [installer: Refine the WoW64 decision logic](https://github.com/OpenVPN/tap-windows6/pull/98) |
|||
| 89 | - [installer: Select Win7/8/8.1 vs. Win10 driver at runtime](https://github.com/OpenVPN/tap-windows6/pull/99) |
|||
| 90 | - [installer: Add code signing certificate before installing the driver](https://github.com/OpenVPN/tap-windows6/pull/100) |
|||
| 91 | ||||
| 92 | Current OpenVPN / tap-windows6 NSIS installers are working well across all the platforms, so I'd prefer not to "rock the boat" by introducing changes unnecessarily. Also, I believe the above PRs were originally meant for OpenVPN 2.5, not for 2.4. And OpenVPN 2.5 does not need these PRs anymore now that we have [MSM packaging](https://github.com/OpenVPN/tap-windows6/pull/106) for tap-windows6. Even if we did decide that the above PRs make sense for 2.4, our support policy says that 2.4 would move to "Old stable" in ~6 months after 2.5.0, after which we would not provide any Windows installers. So the gain for 2.4 would be rather small, maybe for one or two 2.4.x releases at most. |
