Blame
| 6f02e7 | Samuli Seppänen | 2025-01-29 06:40:08 | 1 | # Basic Info |
| 2 | ||||
| 3 | - **Time:** Wednesday 21 December 2022 at 13:00 CET (12:00 UTC) |
|||
| 4 | - **Place:** #openvpn-meeting channel on LiberaChat IRC network |
|||
| 5 | ||||
| 6 | # Topics |
|||
| 7 | ||||
| 8 | ## Current Topics |
|||
| 9 | ||||
| 10 | - **novaflash is back to resume meeting duties.** |
|||
| 11 | ||||
| 12 | - **Do we even do a meeting on the 28th?** |
|||
| 13 | "Yes, but we won't have full attendance. Would be good to sync up about a new 2.6 beta3/rc1 release." |
|||
| 14 | ||||
| 15 | - **2.6 release plans** |
|||
| 16 | "We haven't decided if we want to do beta3 or rc1, but definitely not a stable release yet. |
|||
| 17 | We have decided that we should do a release on the 28th of December." |
|||
| 18 | ||||
| 19 | - **How do we judge remaining known bugs?** |
|||
| 20 | - **Must solve:** crashbug with TCP ([#190 on GitHub](https://github.com/OpenVPN/openvpn/issues/190)) is something plaisthos will take a look at. |
|||
| 21 | - **Not critical:** keepalive not working in DCO p2p mode (#1476) [fixed in 7c66a6dab54d8] |
|||
| 22 | - **Not critical as long as keep-alive is used:** p2p TLS renegotiations getting all confused if client reconnects after server failed renegotiation, but *before* server-connect-timeout expires. |
|||
| 23 | - **Not critical:** UDP gremlin uncovers "sometimes p2mp server on linux-dco is not notified / is ignoring if client expires" (8 clients out of about 5000 connects), keeps sending TLS renegotiation packets. |
|||
| 24 | - **Must solve:** Seems DCO is not sending a signal to user space when a tcp client disconnects or gets connection reset. Will check if ordex has availability to fix. |
|||
| 25 | ||||
| 26 | - **2.6 MSVC toolchain, update to VS 2022? Windows Server 2022?** |
|||
| 27 | "Not for beta2. But might try to do before 2.6.0 stable release. lev has sent patches that need review." |
|||
| 28 | ||||
| 29 | - **Forums machine on community infrastructure is only non-Linux system.** |
|||
| 30 | "mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist. |
|||
| 31 | Currently waiting for ecrist to test if he has access and all is well before we're able to make the switch." |
|||
| 32 | ||||
| 33 | - **License amendment for OpenVPN2 to accommodate mbedtls.** |
|||
| 34 | "plaisthos made a first draft. plaisthos asked to get novaflash to ask francis and james to sign off on it. |
|||
| 35 | In the meantime we need to compile a list of contributors and get ready to ask them to accept the changes. |
|||
| 36 | novaflash will pick this up again now that he is back." |
|||
| 37 | ||||
| 38 | - **pkcs11-helper dynamic loader flags: yes/no(/cancel), add patch to openvpn/contrib to get support/exposure in 2.6(.0/beta2)?** |
|||
| 39 | "These changes were merged." |
|||
| 40 | ||||
| 41 | ## Topics on Standby |
|||
| 42 | ||||
| 43 | - **OpenVPN2 build environment and improving it.** |
|||
| 44 | "djpig is currently working on this. The company has decided to prioritize this task. |
|||
| 45 | Code signing key was moved to an HSM system for increased security. |
|||
| 46 | Further improvements to the build process are underway." |
|||
| 47 | ||||
| 48 | - **Management interface documentation on main website will be updated with info from doc/management-notes.txt** |
|||
| 49 | "novaflash will pick this up again now that he is back." |
|||
| 50 | ||||
| 51 | - **<https://www-dev.openvpn.in/community-resources/openvpn-quickstart/> will be updated from /doc/man-sections/example-fingerprint.rst information.** |
|||
| 52 | "Static-key will be deprecated and contents updated with peer-fingerprint stuff. |
|||
| 53 | novaflash will pick this up again now that he is back." |
|||
| 54 | ||||
| 55 | - **As discussed in Hackathon we want to do a PoC with using Gerrit for code review.** |
|||
| 56 | "This requires an environment to be setup and tuned. This is postponed until after 2.6 stable release." |
|||
| 57 | ||||
| 58 | - **IPv6 to community.** |
|||
| 59 | "No new information to report." |
