OpenVPN 2.7_rc6 -- Released 28 January 2026

The OpenVPN community project team is proud to release OpenVPN 2.7_rc6. This is the sixth release candidate for the feature release 2.7.0.

Important changes since 2.7_rc5:

  • bugfix on restarting a p2mp server instance with SIGUSR1 (inadvertedly closing fd 0, causing a crash on the next restart - GH OpenVPN/openvpn#966)
  • prevent NULL pointer crash on suitable combination of --dns-updown statements in openvpn config file (not pushable)
  • prevent inappropriate management interface activity if a password is set and --management-forget-disconnect or --management-signal are active
  • add mbedTLS 4 support

For a list of all changes see the git log.

Highlights of 2.7 include:

  • Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
  • Improved Client support for DNS options
    • Client implementations for Linux/BSD/macOS, included with the default install
    • New client implementation for Windows, adding support for features like split DNS and DNSSEC
  • Architectural improvements on Windows
    • The block-local flag is now enforced with WFP filters
    • Windows network adapters are now generated on demand
    • Windows automatic service now runs as an unpriviledged user
    • Support for server mode in win-dco driver
    • Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
  • Improved data channel
    • Enforcement of AES-GCM usage limit
    • Epoch data keys and packet format
  • Support for new upstream DCO Linux kernel module
    • This release supports the new ovpn DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
  • Client-side support for new PUSH_UPDATE control-channel message
    • This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
  • PUSH_UPDATE server support (minimal)
    • New management interface commands push-update-broad and push-update-cid to send PUSH_UPDATE option updates.
  • TLS 1.3 support with bleeding-edge mbedTLS versions
  • Support for mbedTLS version 4
  • Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
  • Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
  • "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
  • COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo

For details see Changes.rst

Windows 64-bit MSI installer GnuPG Signature OpenVPN-2.7_rc6-I014-amd64.msi
Windows ARM64 MSI installer GnuPG Signature OpenVPN-2.7_rc6-I014-arm64.msi
Windows 32-bit MSI installer GnuPG Signature OpenVPN-2.7_rc6-I014-x86.msi
Source archive file GnuPG Signature openvpn-2.7_rc6.tar.gz

For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.

OpenVPN 2.6.18 -- Released 4 February 2026

The OpenVPN community project team is proud to release OpenVPN 2.6.18. This is a bugfix release.

For details see Changes.rst

User visible changes:

  • disable DCO if --bind-dev option is given (no support for this in the old out-of-kernel Linux DCO implementation)
  • on Windows, if using --ip-win32 netsh and not using the interactive service, IPv4 addresses would be installed as "permanent", possibly causing problems later on with using that IPv4 address on a different interface. Change to "store=active". (GH: #915)
  • improve pull-filter documentation, emphasizing possible problems if used as a naive security measure (reported by SRLabs)

Bugfixes:

  • p2mp server: fix incorrect file descriptor handling on "inotify" FD during a SIGUSR1 restart (GH: #966)
  • management interface: fix bug where --management-forget-disconnect and --management-signal could be executed even if password authentication to managment interface was still pending (ZeroPath finding)
  • repair client-side interaction on reconnect between DCO event handling and --persist-tun - after a ping timeout and reconnect, the DCO event handler would not be armed, and the next ping timeout would not be received by userland, causing non-working connections with nothing in the openvpn log (Linux and FreeBSD only, GH: #947)
  • prevent crash on invalid server-ipv6 argument, calling freeaddrinfo() with a NULL pointer. This only affects OpenBSD. (Klemens Nanni).

Windows MSI changes since 2.6.17-I001:

  • Built against OpenSSL 3.6.1
  • Included openvpn-gui updated to 11.61.0.0
    • translation updates
Windows 64-bit MSI installer GnuPG Signature OpenVPN-2.6.18-I001-amd64.msi
Windows ARM64 MSI installer GnuPG Signature OpenVPN-2.6.18-I001-arm64.msi
Windows 32-bit MSI installer GnuPG Signature OpenVPN-2.6.18-I001-x86.msi
Source archive file GnuPG Signature openvpn-2.6.18.tar.gz

For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.

OpenVPN 2.5.9 -- Released 15 February 2023

The OpenVPN community project team is proud to release OpenVPN 2.5.9. This is a small bugfix release.

For details see Changes.rst

Windows MSI changes since 2.5.8:

  • Build against OpenSSL 1.1.1t which contains several security fixes.
Windows 64-bit MSI installer GnuPG Signature OpenVPN-2.5.9-I601-amd64.msi
Windows ARM64 MSI installer GnuPG Signature OpenVPN-2.5.9-I601-arm64.msi
Windows 32-bit MSI installer GnuPG Signature OpenVPN-2.5.9-I601-x86.msi
Source archive file GnuPG Signature openvpn-2.5.9.tar.gz

Full Release History

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9