# Introduction This page shows the high-level status of OpenVPN 2.5 release. For all the details, see the [Active Tickets by Milestone](report:3) report. # Schedule As we missed our original deadline (Debian Buster freeze), we don't have a schedule yet, except "in year 2020". Nevertheless, the release will proceed as follows: - **2.5_beta1 (August 14)** After this date, no new features allowed, stabilizing starts for real. Some minor "nice to have patches" might be accepted after evaluation/discussion on IRC; but should be avoided. Git will be branched to release/2.5 at that point. - **??? - 2.5_beta2 (optional)** Only patches related to stabilizing and important bug-fixes are allowed after this point. No more "nice to have patches" after this point. If we have no bug fixes or otherwise stabilizing code, this release can be skipped. - **??? - 2.5_rc1** Only really needed and critical bug fixes allowed. - **??? - 2.5_rc2** "If needed" - **2.5.0 (September 17)** Final release. # Features/Fixes to Include ## Must Have | Task Description | Assigned to | Status | Ticket | |------------------|-------------|--------|--------| | [MSI installers](wiki:OpenvpnMSIInstaller) | mattock | Final integration tests not done | #1122 | | update auth-user-pass docs | mattock | not started, discussion [here](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12835.html) | | polish auth-token / auth-gen-token corner cases | cron2, plaisthos | pending | - | ## Postponed Items (former "nice to have" items for 2.5) | Task Description | Assigned to | Status | Ticket | |------------------|-------------|--------|--------| | support for multiple-protocol sockets (UDP/TCP) | ordex | wip | | Support for multiple sockets (multi-port/multi-IP) | ordex | pending review | #556 | | Dynamic routes ('route in ccd-file'), depends on netlink support | ??? | ??? | | transport plugin (primary use case: obfuscation) | ordex | wip | | [tftp/wpad patch](http://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg10511.html) | jjk | patch on list, needs review and merge | | support TLS record splitting (like ovpn3) | syzzer | (started, but no patches available yet) | #554 | | test server that does --auth-user-pass and/or challenge stuff | cron2 (snair) | not started | | Update OpenVPN PRF (move away from SHA1/MD5) | syzzer | not started | | maybe: add PRF plugin interface | ??? | ??? | | maybe: add key exchange plugin interface | ??? | ??? | | maybe: add data channel separation | ??? | ??? | | maybe: fix radius-plugin | ??? | ??? | | improve control channel performance | syzzer | ??? | ## Work Needed - trac tickets (2.4.x, 2.5.x, unclassified) - MSI testing and user documentation ## Items Already Done - remove ENABLE_CRYPTO - [ChaCha20-Poly1305 support for the data channel](https://patchwork.openvpn.net/patch/496/) - tls-crypt-v2 (#1121) - MSI packaging - [struct argv overhaul](https://patchwork.openvpn.net/project/openvpn2/list/?series=638) - [Wintun support](https://patchwork.openvpn.net/patch/824/) - [Auth failure messages back to client](https://patchwork.openvpn.net/project/openvpn2/list/?series=543&submitter=&state=3&q=&archive=&delegate=) - #6 - VLAN patch set - #1123 - Netlink support (includes route.c / tun.c refactoring) - [IPv6-only server](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg16998.html) | ordex & cron2 | most of the work is done! some details remain to be cleaned up | #208 | - Implement asymmetric compression | plaisthos | v5 merged (lev/cron2) | - [Allow OpenVPN to communicate to peers via a Linux VRF](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12767.html) | cron2 | patch v2 on the list & merged | - man page formatting change | dazo | [merged](https://gitlab.com/openvpn/openvpn/-/commit/f500c49c8e0a77ce665b11f6adbea4029cf3b85f) | - async client-connect support | plaisthos + ordex | [Merged](https://patchwork.openvpn.net/project/openvpn2/list/?series=827&state=*) | # Missing Pieces from MSI Bundling OpenVPN as an MSI will require changes to several projects: openvpn, openvpnserv2, openvpn-build, and tap-windows6. Here's a list of the missing pieces (hopefully) in the order in which they should be merged: 1. ~~[openvpn: the openvpnmsica and tapctl patch series](https://patchwork.openvpn.net/project/openvpn2/list/?series=662)~~ 2. [tap-windows6: MSM packaging](https://github.com/OpenVPN/tap-windows6/pull/106) 3. [openvpn-build: Windows MSI packaging](https://github.com/OpenVPN/openvpn-build/pull/141) 4. [openvpn-vagrant: Add MSI build support](https://github.com/OpenVPN/openvpn-vagrant/pull/7) - Needs to be adapted to final upstream URLs before merging ## Dropping tap-windows6 NSI Changes? I (mattock) propose we **drop** the following tap-windows6 PRs that change the **NSIS** installer: - [installer: Refine the WoW64 decision logic](https://github.com/OpenVPN/tap-windows6/pull/98) - [installer: Select Win7/8/8.1 vs. Win10 driver at runtime](https://github.com/OpenVPN/tap-windows6/pull/99) - [installer: Add code signing certificate before installing the driver](https://github.com/OpenVPN/tap-windows6/pull/100) Current OpenVPN / tap-windows6 NSIS installers are working well across all the platforms, so I'd prefer not to "rock the boat" by introducing changes unnecessarily. Also, I believe the above PRs were originally meant for OpenVPN 2.5, not for 2.4. And OpenVPN 2.5 does not need these PRs anymore now that we have [MSM packaging](https://github.com/OpenVPN/tap-windows6/pull/106) for tap-windows6. Even if we did decide that the above PRs make sense for 2.4, our support policy says that 2.4 would move to "Old stable" in ~6 months after 2.5.0, after which we would not provide any Windows installers. So the gain for 2.4 would be rather small, maybe for one or two 2.4.x releases at most.
