OpenVPN 2.7_rc1 -- Released 31 October 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_rc1. This is the first release candidate for the feature release 2.7.0.
Feature changes since 2.7_beta3:
- add warning for unsupported combination of --push and --tls-server
- add warning for unsupported combination of
--reneg-bytesor--reneg-pktswith DCO - remove perf_push()/perf_pop() infrastructure (because it did not work anymore, and compiler profiling will give better results today)
- ensure compatibility with OpenSSL 3.6.0 - specifically, do not crash in t_lpback.sh trying to use new encrypt-then-mac (ETM) ciphers
- improved PUSH_UPDATE server side support, which now handles changes of pushed ifconfig/ifconfig-ipv6 addresses correctly (send packets to new IP addresses to this client, stop sending packets to the old addresses).
- freshen URLs all over the tree, and change to HTTPS where possible
- on DCO Linux/FreeBSD, add support for clients receiving an IPv4/IPv6 address that is not part of the --server/--server-ipv6 subnet (= install extra on-interface host routes).
- Windows programs use a new API for path name canonicalization now (PathCchCanonicalizeEx()) which will break building with MinGW on Ubuntu 22.04 -> Upgrade to 24.04 to make builds work again.
- on Windows, when setting up WINS servers using netsh, use interface index instead of adapter name now ("as for all other netsh calls")
- remove undocumented and unused --memstats feature
Important bug fixes since 2.7_beta3:
- even more type conversion related warnings have been fixed
- more bugfixes related to BYTECOUNT display on the management interface and byte counters on DCO platforms in general
- numerous minibugs reported by ZeroPath AI have been fixed (small memleaks, possible file descriptor leaks, improved sanity checks, add ASSERT() on function contracts, etc.)
For a list of all changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
- Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
- "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
- COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
For details see Changes.rst
Windows MSI changes since 2.7_beta3:
- Built against OpenSSL 3.6.0
- Included openvpn-gui updated to 11.57.0.0
- Encrypt username saved in registry
- Avoid blocking calls during WM_OVPN_ECHOMSG processing
- Fixes segfault when echo msg-notify happens with no message to display (Github: OpenVPN/openvpn-gui#771)
- Check the path of the process listening on management port
- Error out if imported profile file name is too long
- Disallow Windows special filenames for imported profile
- Replace % characters in param->id as it's used in format template
- Excplicitly check that urls start with http:// or https://
- Included win-dco driver updated to 2.8.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc1-I008-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_rc1-I008-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc1-I008-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_rc1.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.6.15 -- Released 22 September 2025
The OpenVPN community project team is proud to release OpenVPN 2.6.15. This is a bugfix release.
For details see Changes.rst
Bug fixes:
- On Windows, do not use "wmic.exe" any longer to set DNS search domain (discontinued by Microsoft), use "powershell" fragment instead.
- On Windows, logging to the windows event log has been improved (and logging of GetLastError() strings repaired). To make this work, a new "openvpnmsgserv.dll" library is now installed and registered.
- DNS domain names are now strictly validated with a positive-list of allowed characters (including UTF-8 high-bit-set bytes) before being handed to powershell.
- Apply more checks to incoming TLS handshake packets before creating new state - namely, verify message ID / acked ID for "valid range for an initial packet". This fixes a problem with clients that float very early but send control channel packet from the pre-float IP (Github: OpenVPN/openvpn#704, backported from 2.7_beta1).
- Backport handling of client float notifications on FreeBSD 14/STABLE DCO (see https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=289303)
- Update GPL license text to latest version from FSF
- On Linux, on interfaces where applicable, OpenVPN explicitly configures the broadcast address again. This was dropped for 2.6.0 "because computers are smart and can do it themselves", but the kernel netlink interface isn't, and will install "0.0.0.0". This does not normally matter, but for broadcast-based applications that get the address to use from "ifconfig", this change repairs functionality.
Windows MSI changes since 2.6.14-I004:
- Built against OpenSSL 3.5.3
- Included openvpn-gui updated to 11.56.0.0
- Fix "Cannot open the System Tray Menu with Keyboard" (Github: OpenVPN/openvpn-gui#763)
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.15-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.15-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.15-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.15.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.5.9 -- Released 15 February 2023
The OpenVPN community project team is proud to release OpenVPN 2.5.9. This is a small bugfix release.
For details see Changes.rst
Windows MSI changes since 2.5.8:
- Build against OpenSSL 1.1.1t which contains several security fixes.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.5.9-I601-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.5.9-I601-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.5.9-I601-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.5.9.tar.gz |
