Blame
| 6f02e7 | Samuli Seppänen | 2025-01-29 06:40:08 | 1 | # Basic info |
| 2 | ||||
| 3 | - Time: Wednesday 18 January 2023 at 13:00 CET (12:00 UTC) |
|||
| 4 | - Place: #openvpn-meeting channel on LiberaChat IRC network |
|||
| 5 | ||||
| 6 | # Topics |
|||
| 7 | ||||
| 8 | ## Current topics |
|||
| 9 | ||||
| 10 | - **Can we have someone at OpenVPN create nicer windows traybar logos (#1276)?** |
|||
| 11 | "yes, novaflash will check with a designer to see if he can be motivated to generate something." |
|||
| 12 | ||||
| 13 | - **Press release of 2.6 to go out with stable release** |
|||
| 14 | "novaflash will work with openvpn inc folks to prepare something." |
|||
| 15 | ||||
| 16 | - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues** |
|||
| 17 | "plaisthos and novaflash brought this to francis and james. they consent. |
|||
| 18 | plaisthos sent proposal to the developer mailing list. response was mostly not seeing the need. |
|||
| 19 | but debian obviously does see a problem. we need a lawyer to advise us if there is a problem and if how, how to solve. |
|||
| 20 | so it's back to plaisthos and novaflash to contact the specific lawyer and figure this out. |
|||
| 21 | main issue is convincing the developers that there is an issue, they currently do not see/understand it." |
|||
| 22 | ||||
| 23 | - **As discussed in Hackathon we want to do a PoC with using Gerrit for code review.** |
|||
| 24 | "openvpn inc is working on setting up a poc for this." |
|||
| 25 | ||||
| 26 | - **2.6 release plans** |
|||
| 27 | "2.6 rc2 went out on January 12th. Intend to do another release on 25th. |
|||
| 28 | lev_'s config folder patches made it in. |
|||
| 29 | plaisthos' dynamic tls-crypt patches did not. pushed to 2.6.1. |
|||
| 30 | what about `SRV`? pushed to 2.6.1 |
|||
| 31 | Looks like we're going to do a stable 2.6.0 release on January 25th. |
|||
| 32 | lev_ wants to slip in some minor changes to driver installation on windows. |
|||
| 33 | script-security behavior is different from 2.5 to 2.6 - permissions are less. need to decide on approach to fix. affects only linux." |
|||
| 34 | ||||
| 35 | ## OpenVPN 2.6.0 stable release open issues |
|||
| 36 | ||||
| 37 | - **blockers (must be fixed before 2.6.0)** |
|||
| 38 | ||||
| 39 | - **nice to have** |
|||
| 40 | "P2P --tls-server still gets confused sometimes when 'client just disappears' and no `--keepalive` is configured |
|||
| 41 | duplicate route addition / EEXIST with SITNL is not handled correctly (will lead to duplicate route removal) |
|||
| 42 | route_add() status code uses 0/1/2 magic numbers, should use MAGIC_CONSTANTS |
|||
| 43 | dco.dco_del_peer_reason etc. should be initialized 'upfront' not 'after the fact' (see commit aaccf8843)" |
|||
| 44 | ||||
| 45 | - **additional features** |
|||
| 46 | "---?" |
|||
| 47 | ||||
| 48 | - **DCO showstoppers (not holding up 2.6.0 release, but a reason to not use DCO in production)** |
|||
| 49 | "OOM in netlink on busy servers [Issue #16](https://github.com/OpenVPN/ovpn-dco/issues/16) |
|||
| 50 | openvpn hang on 'close tun, before restarting' [Issue #18](https://github.com/OpenVPN/ovpn-dco/issues/18) |
|||
| 51 | more... [See issues](https://github.com/OpenVPN/ovpn-dco/issues)" |
|||
| 52 | ||||
| 53 | - **OpenVPN2 build environment and improving it.** |
|||
| 54 | "djpig is currently working on this. The company has decided to prioritize this task. |
|||
| 55 | Code signing key was moved to an HSM system for increased security. |
|||
| 56 | djpig overhauled openvpn-build, it now uses submodules for openvpn and openvpn-gui, and contains debian packaging scripts. |
|||
| 57 | Further improvements to the build process are underway." |
|||
| 58 | ||||
| 59 | - **OpenVPN 2.6 performance results.** |
|||
| 60 | "We should work on an article to publish some performance results when 2.6 is out as stable." |
|||
| 61 | ||||
| 62 | - **Forums machine on community infrastructure is only non-Linux system.** |
|||
| 63 | "mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist. |
|||
| 64 | Currently waiting for ecrist to test if he has access and all is well before we're able to make the switch. |
|||
| 65 | ecrist indicated that he is missing some information, mattock will provide." |
|||
| 66 | ||||
| 67 | ## Topics on standby |
|||
| 68 | ||||
| 69 | - **Management interface documentation on main website will be updated with info from doc/management-notes.txt** |
|||
| 70 | "novaflash will pick this up again now that he is back." |
|||
| 71 | ||||
| 72 | - **[OpenVPN Quickstart](https://www-dev.openvpn.in/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.** |
|||
| 73 | "Static-key will be deprecated and contents updated with peer-fingerprint stuff. |
|||
| 74 | novaflash will pick this up again now that he is back." |
|||
| 75 | ||||
| 76 | - **IPv6 to community.** |
|||
| 77 | "No new information to report." |
