OpenVPN 2.7.1 -- Released 31 March 2026
The OpenVPN community project team is proud to release OpenVPN 2.7.1. This is a bug fix release.
For details see Changes.rst
New features:
- Add a new
username-onlyflag argument to--auth-user-passwhich will now make OpenVPN only query for username and send a dummy password to the server. This is only useful if auth schemes are used on the server side that will do some sort of external challenge base on username, and not password authentication. See discussion in GH OpenVPN/openvpn#501 (starting Jan 30, 2024). - Increase default sizing of internal hash maps to
4 * --max-clients. The default used to be256with a--max-clientsdefault of 1024 - this is bad for performance, while the memory savings are minimal. On a very memory constrained system, reduce--max-clients.
User-visible Changes:
- When compiled with the AWS-LC SSL library, using
--tls-cert-profilewill now print a run-time warning - the library does not support it, so it would silently do nothing. - Systemd unit files: change LimitNPROC to TasksMax and increase limit (GH: OpenVPN/openvpn#929)
- Documentation improvements.
- port-share: log incoming connections at
verb 3, not onerrorlevel anymore (GH: OpenVPN/openvpn#976).
Bugfixes:
- Fix usage of
--lportinside a<connection>block - this got broken with the multi-socket patchset (GH: OpenVPN/openvpn#995) - Do not try to run auto-pam unit test when cross-compiling.
- Do not break private-key passphrases of length >= 64 (GH: OpenVPN/openvpn#993)
- Fix obscure ASSERT() crash on TCP connects with TAP and no ip config.
- Make DCO work on FreeBSD systems that have no IPv4 support in kernel (FreeBSD PR 286263)
- Make DCO work on Linux on big endian systems (namely, MIPS and PowerPC) (GH: OpenVPN/ovpn-dco#96)
- Fixup responses to management interface
versioncommand (for >= 4) - Make
--enable-async-pushwork on FreeBSD 15 (which has native inotify support, and consequently no libinotify.pc anymore) - Adjust some code parts to new "const" handling on string function returns (ISO C23, as implemented by glibc 2.43 and newer).
Windows MSI changes since 2.7.1:
- Make sure that included openvpnserv2.exe is signed (GH: OpenVPN/openvpn-build#1293)
- Included openvpn-gui updated to 11.62.0.0
- Translation updates
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7.1-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7.1-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7.1-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7.1.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.6.19 -- Released 4 February 2026
The OpenVPN community project team is proud to release OpenVPN 2.6.19. This is a bugfix release. 2.6.19 only fixes one small issue in the creation of the 2.6.18 release tarball. It was released on the same day as 2.6.18.
All the following mentioned changes are from 2.6.18.
For details see Changes.rst
User visible changes:
- disable DCO if
--bind-devoption is given (no support for this in the old out-of-kernel Linux DCO implementation) - on Windows, if using
--ip-win32 netshand not using the interactive service, IPv4 addresses would be installed as "permanent", possibly causing problems later on with using that IPv4 address on a different interface. Change to "store=active". (GH: #915) - improve pull-filter documentation, emphasizing possible problems if used as a naive security measure (reported by SRLabs)
Bugfixes:
- p2mp server: fix incorrect file descriptor handling on "inotify" FD during a SIGUSR1 restart (GH: #966)
- management interface: fix bug where
--management-forget-disconnectand--management-signalcould be executed even if password authentication to managment interface was still pending (ZeroPath finding) - repair client-side interaction on reconnect between DCO event handling
and
--persist-tun- after a ping timeout and reconnect, the DCO event handler would not be armed, and the next ping timeout would not be received by userland, causing non-working connections with nothing in the openvpn log (Linux and FreeBSD only, GH: #947) - prevent crash on invalid server-ipv6 argument, calling
freeaddrinfo()with a NULL pointer. This only affects OpenBSD. (Klemens Nanni).
Windows MSI changes since 2.6.17-I001:
- Built against OpenSSL 3.6.1
- Included openvpn-gui updated to 11.61.0.0
- translation updates
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.19-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.19-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.19-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.19.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
