Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# Agenda
2
3
## Handling Security Vulnerabilities in the Future
4
- Always get a CVE entry?
5
- Always make a security announcement (threat, impact, etc.)
6
- Makes handling the issue much easier for downstream
7
- Compile a list of OpenVPN package maintainer (e.g. *BSD, Linux) email addresses, so that they can be notified in advance of security updates.
8
9
## OpenVPN 3.0
10
- Was released along with API documentation under AGPL v3 at FOSDEM 2013
11
- Currently used primarily/only in OpenVPN Connect clients for Android/iOS from OpenVPN Technologies, Inc.
12
- Getting the code to Git: currently only an outdated tarball is available
13
- [OpenVPN 3.0 staging site](http://staging.openvpn.net/openvpn3/)
14
15
## OpenVPN 2.4
16
- What is the goal of the 2.4 release?
17
- What patches in "master" are 2.4-only material?
18
19
### Patches
20
- Android patchsets
21
- Dual stack client patches
22
- utun on macOS
23
- Native tun, no need for extra tun.kext
24
- Supported for all OS X >= 10.6.8 (latest PPC version)
25
- Unfortunately requires root
26
- Real question: Drop tun.kext support and support only utun or "try utun first, fall back to tun.kext if it fails"
27
- svn 2.1 patchset (snappy support, push-peer-info changes, see trac#268-273)
28
- Management interface changes (status 2/3)
29
- Formatting and whitespace fixes (just before 2.4 release)
30
31
### Additional Considerations
32
- `--version` to include git commit id and branch?