Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# Basic Info
2
3
- **Time:** Wed 14th April 2021 14:00 CET (12:30 UTC)
4
- **Place:** #openvpn-meeting channel on Freenode IRC network + [Jitsi Meet](https://demo.vct.spacenet.de/openvpn)
5
6
# Topics
7
8
## 1. Sync up on OpenVPN 2.5 and 2.6
9
- **2.5:** next Tuesday.
10
- patches pending:
11
- route lookup
12
- compress-restore-on-SIGUSR1
13
- 1666+1667 (fix client with --bind)
14
- **2.6:**
15
- please get ACKed patches in!
16
- configure.ac coming
17
- DCOoooooh :-)
18
19
## 2. --key and --chroot (with and without --persist-key)
20
- (Ordex, MaxF21, patches on the list)
21
- Key reloading on SIGUSR1 fails in chroot (it works with persist-key)
22
- **Consensus:** we remove the "no-persist-key" path, make the feature always-on and the option a no-op
23
24
## 3. Option to set http-proxy on Android
25
- Suggestion: "dhcp-option HTTP-PROXY IP PORT"
26
- This is for programs using the VPN, and they should use this proxy. Configured via the VPN API. Not "for OpenVPN" but "for everyone else". Check with 3 clients on iOS what that one uses.
27
28
## 4. Lev: dco-win Driver in Windows installer
29
- How do we want to do this?
30
- msm package inside msi? (like for tap+wintun)
31
- Wintun created msm approach but uses different approach now
32
- Connect client brings tap binary + tapinstall.exe, no msm for tap-windows6
33
- Cron2 and mattock seem to recall "msm works better for driver upgrades than the old NSIS approach" but nobody knew for sure
34
- Mattock is talking to MS about arm64 support, we can ask the experts
35
- Ask Simon :-)
36
37
## 5. --cipher in 2.6
38
- Currently, this always adds that likely non-AEAD cipher to the data-ciphers list. This is bad for DCO.
39
- We have to pick one:
40
- Make DCO work without having user to reconfigure --cipher/--data-ciphers
41
- Requires modifying config if you still want to connect to a 2.3 server, allow 2.3 clients
42
- Keep configuration compatibility with non-NCP server/clients
43
- Requires configuration changes to allow DCO
44
- Windows OpenVPN 2.x with ovpn-dco-win will refuse to start with most configs
45
- The complex interaction between data-ciphers, cipher and data-ciphers-fallback is still there.
46
- Need to add an option like 'occ-cipher' to avoid OCC warnings with 2.4/2.5 clients/server.
47
- Make behaviour of OpenVPN dependent on selected driver
48
- Only interims solution. With 2.7 we still have to decide if we want to go one of the other options
49
- Will create a lot of confusion.
50
- Breaks opportunistic approach of allowing OpenVPN to automatically enable DCO if the config is DCO compatible
51
- Introduce "--compat-mode"
52
- OpenVPN will behave like first option without option
53
- Also increase TLS min version to 1.2 by default
54
- Default to --nobind when --pull is active