OpenVPN 2.4/3.x

Contributor License Agreement (CLA)

  • This is required to distribute OpenVPN on Apple's AppStore and possibly other stores (e.g., Windows Marketplace) due to their incompatibility with the AGPLv3 license.
  • It's important to minimize the scope of the agreement:
    • Android contributor license agreements appear well-crafted and we can assume they are backed by substantial legal expertise and resources.

Permissive Licensing

  • It’s currently unclear if adopting a permissive license would completely eliminate the need for a CLA.
  • Potential licenses include BSD, MIT, Apache.
  • Releasing OpenVPN 3.0 under a permissive license may lead to (big) companies forking it, potentially resulting in numerous incompatible forks.
    • To combat potential fragmentation, standardizing the OpenVPN protocol might be necessary, though this comes with substantial overhead.

Minimizing the Scope of the CLA

  • This approach reduces risks related to fragmentation, forks, and loss of contributions.
  • Aim to maximize the potential to extend OpenVPN through isolated APIs:
    • Plugins and similar extensions would not require a CLA.
  • Extension mechanisms in OpenVPN:
    • 2.x:
      • Plugin API
      • Management interface
      • SSL library abstraction
      • Platform support (isolated by #ifdefs)
    • 3.x:
      • SSL library abstraction
      • Other mechanisms
  • Potential separation of server-side and client-side code, where only the client-side would need a CLA.

Public Release Date for OpenVPN 3.x Codebase

  • Source packages are currently available in old tar.gz formats.
  • James aims to release this in the coming weeks.

Future of OpenVPN 2.x and 3.x

  • Transitioning to the AGPLv3-licensed OpenVPN 3.x codebase is favorable, provided that the negative impact of the CLA is minimized.
  • OpenVPN 2.x will remain maintained until 3.x can effectively replace it:
    • This may include releasing versions up to 2.5.