Agenda

Handling Security Vulnerabilities in the Future

  • Always get a CVE entry?
  • Always make a security announcement (threat, impact, etc.)
  • Makes handling the issue much easier for downstream
  • Compile a list of OpenVPN package maintainer (e.g. *BSD, Linux) email addresses, so that they can be notified in advance of security updates.

OpenVPN 3.0

  • Was released along with API documentation under AGPL v3 at FOSDEM 2013
  • Currently used primarily/only in OpenVPN Connect clients for Android/iOS from OpenVPN Technologies, Inc.
  • Getting the code to Git: currently only an outdated tarball is available
  • OpenVPN 3.0 staging site

OpenVPN 2.4

  • What is the goal of the 2.4 release?
  • What patches in "master" are 2.4-only material?

Patches

  • Android patchsets
  • Dual stack client patches
  • utun on macOS
    • Native tun, no need for extra tun.kext
    • Supported for all OS X >= 10.6.8 (latest PPC version)
    • Unfortunately requires root
    • Real question: Drop tun.kext support and support only utun or "try utun first, fall back to tun.kext if it fails"
  • svn 2.1 patchset (snappy support, push-peer-info changes, see trac#268-273)
  • Management interface changes (status 2/3)
  • Formatting and whitespace fixes (just before 2.4 release)

Additional Considerations

  • --version to include git commit id and branch?
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9