Basic Info
- Time: Wednesday 7 December 2022 at 13:00 CET (12:00 UTC)
- Place: #openvpn-meeting channel on LiberaChat IRC network
Topics
How do we tag issues received on Github in our commit messages?
- djpig indicated the GitHub parses this format: "Github: OpenVPN/openvpn#123"
We will no doubt get bug reports about OpenVPN Connect software on GitHub issues. They do not belong there. How to deal with them?
- novaflash will discuss with the team lead of OpenVPN Connect team and discuss options.
Collect and discuss feedback on 2.6_beta1 release.
- Windows I601 missing legacy.dll OpenSSL provider is fixed (lev)
- eduvpn node crashed machine with 2.6_beta1 ouch, berniv6 should open an issue (berniv6) (cron2)
- FreeBSD openvpn-devel port updated (cron2/m-a)
- maxf has found a junior victim to test openvpn 2.6_beta1 (maxf)
- Anything else?
Should we do a 2.6_beta1 I602 windows release?
- Only change is the legacy fix. Let's just do a release next week on December 15.
2.6_beta2 release date
- We aim to do this on December 15. Website release to be planned in accordance.
Patchset that makes pkcs11 code even worse but will make users happy (becm)
- This patch makes it possible to tell pkcs11 thingee where to look for libraries and then things will just work.
License amendment for OpenVPN2 to accommodate mbedtls.
- plaisthos made a first draft. plaisthos asked to get novaflash to ask francis and james to sign off on it.
- In the meantime, we need to compile a list of contributors and get ready to ask them to accept the changes.
The reference manual for OpenVPN 2.6 will be posted on the main website this week.
- This will be included in this week's website updates. Note: if there are updates to the documentation in the future kindly advise novaflash so he can update it on the main website too.
OpenVPN2 build environment and improving it.
- djpig is currently working on this. The company has decided to prioritize this task.
- In light of the recent security incident, we also want to move the code signing key to an HSM type solution. Working on it.
Management interface documentation on the main website will be updated with info from doc/management-notes.txt
Automated windows testing status. (lev)
What is this page https://community.openvpn.net/openvpn/wiki/CodeRepositories, can we delete it?
- No, we need to keep it, just has some outdated items that we can update.
Peer-to-peer DCO handling status. (ordex, plaisthos)
- For Windows, it works if both peers have --remote, because it is client-only on Windows and therefore expected to work this way.
- On Linux/FreeBSD all previously found nastiness is now resolved and in beta1 already.
Initial handshake rate limiting status (cron2, plaisthos)
- plaisthos brought up the idea to do a particular filter method.
NM integration / CAP_NET_ADMIN status. (dazo)
- Dazo currently unavailable.
Build failure with private-install openssl 3 & DCO ticket #1469. (cron2)
- djpig's environment does not show the bug, but cron2's does. Not sure what's going on yet.
- Will need to investigate further before deciding to make a bug report or not.
SRV support, testers, and OpenBSD decision needed. (cron2)
- djpig tested and nacked it - themiron promised to test and did not deliver anything, so it missed the boat.
- Unless a fix comes in early next week and makes it into beta2, then it's likely going to miss the 2.6.0 boat.
Management interface improvement patches. (selva)
- 2 parts are now merged, the rest is in the review/merge process.
As discussed in Hackathon, we want to do a PoC with using Gerrit for code review.
- This requires an environment to be set up and tuned. This is postponed until after the 2.6 stable release.
Forums machine on community infrastructure is only non-Linux system.
- mattock agreed to convert it to rocky linux 8 with ecrist's blessing.
- Was blocked from creating a VM, am now unblocked, will work on it now.
Forums issues, permissions, layout.
- Over the weekend things were broken on the forums, they're working again now. For some reason, novaflash and openvpn_inc are being denied permissions, why?
novaflash needs some input on https://www-dev.openvpn.in/community-resources/openvpn-quickstart/
- Static-key will be deprecated, there's already a warning about that in OpenVPN if you use it.
- plaisthos has a tutorial for peer fingerprint that will be much easier to use. It is at https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst
- novaflash will update this outdated page.
IPv6 to community.
- No new information to report.
