Blame
| 6f02e7 | Samuli Seppänen | 2025-01-29 06:40:08 | 1 | # Basic Info |
| 2 | ||||
| 3 | - **Time:** Wed 14th April 2021 14:00 CET (12:30 UTC) |
|||
| 4 | - **Place:** #openvpn-meeting channel on Freenode IRC network + [Jitsi Meet](https://demo.vct.spacenet.de/openvpn) |
|||
| 5 | ||||
| 6 | # Topics |
|||
| 7 | ||||
| 8 | ## 1. Sync up on OpenVPN 2.5 and 2.6 |
|||
| 9 | - **2.5:** next Tuesday. |
|||
| 10 | - patches pending: |
|||
| 11 | - route lookup |
|||
| 12 | - compress-restore-on-SIGUSR1 |
|||
| 13 | - 1666+1667 (fix client with --bind) |
|||
| 14 | - **2.6:** |
|||
| 15 | - please get ACKed patches in! |
|||
| 16 | - configure.ac coming |
|||
| 17 | - DCOoooooh :-) |
|||
| 18 | ||||
| 19 | ## 2. --key and --chroot (with and without --persist-key) |
|||
| 20 | - (Ordex, MaxF21, patches on the list) |
|||
| 21 | - Key reloading on SIGUSR1 fails in chroot (it works with persist-key) |
|||
| 22 | - **Consensus:** we remove the "no-persist-key" path, make the feature always-on and the option a no-op |
|||
| 23 | ||||
| 24 | ## 3. Option to set http-proxy on Android |
|||
| 25 | - Suggestion: "dhcp-option HTTP-PROXY IP PORT" |
|||
| 26 | - This is for programs using the VPN, and they should use this proxy. Configured via the VPN API. Not "for OpenVPN" but "for everyone else". Check with 3 clients on iOS what that one uses. |
|||
| 27 | ||||
| 28 | ## 4. Lev: dco-win Driver in Windows installer |
|||
| 29 | - How do we want to do this? |
|||
| 30 | - msm package inside msi? (like for tap+wintun) |
|||
| 31 | - Wintun created msm approach but uses different approach now |
|||
| 32 | - Connect client brings tap binary + tapinstall.exe, no msm for tap-windows6 |
|||
| 33 | - Cron2 and mattock seem to recall "msm works better for driver upgrades than the old NSIS approach" but nobody knew for sure |
|||
| 34 | - Mattock is talking to MS about arm64 support, we can ask the experts |
|||
| 35 | - Ask Simon :-) |
|||
| 36 | ||||
| 37 | ## 5. --cipher in 2.6 |
|||
| 38 | - Currently, this always adds that likely non-AEAD cipher to the data-ciphers list. This is bad for DCO. |
|||
| 39 | - We have to pick one: |
|||
| 40 | - Make DCO work without having user to reconfigure --cipher/--data-ciphers |
|||
| 41 | - Requires modifying config if you still want to connect to a 2.3 server, allow 2.3 clients |
|||
| 42 | - Keep configuration compatibility with non-NCP server/clients |
|||
| 43 | - Requires configuration changes to allow DCO |
|||
| 44 | - Windows OpenVPN 2.x with ovpn-dco-win will refuse to start with most configs |
|||
| 45 | - The complex interaction between data-ciphers, cipher and data-ciphers-fallback is still there. |
|||
| 46 | - Need to add an option like 'occ-cipher' to avoid OCC warnings with 2.4/2.5 clients/server. |
|||
| 47 | - Make behaviour of OpenVPN dependent on selected driver |
|||
| 48 | - Only interims solution. With 2.7 we still have to decide if we want to go one of the other options |
|||
| 49 | - Will create a lot of confusion. |
|||
| 50 | - Breaks opportunistic approach of allowing OpenVPN to automatically enable DCO if the config is DCO compatible |
|||
| 51 | - Introduce "--compat-mode" |
|||
| 52 | - OpenVPN will behave like first option without option |
|||
| 53 | - Also increase TLS min version to 1.2 by default |
|||
| 54 | - Default to --nobind when --pull is active |
