Blame
| 6f02e7 | Samuli Seppänen | 2025-01-29 06:40:08 | 1 | # Basic Info |
| 2 | ||||
| 3 | - **Time**: Wednesday 17 May 2023 at 13:00 CET (12:00 UTC) |
|||
| 4 | - **Place**: #openvpn-meeting channel on [LiberaChat](https://libera.chat/) IRC network |
|||
| 5 | ||||
| 6 | # Topics |
|||
| 7 | ||||
| 8 | ## Current Topics |
|||
| 9 | ||||
| 10 | - **2.6.5 Release Plans** |
|||
| 11 | - "in about 4 to 8 weeks from now so anywhere between half June and half July" |
|||
| 12 | ||||
| 13 | - **Hackathon Arrangements** |
|||
| 14 | - When: [Schedule](https://nuudel.digitalcourage.de/t1hjepaHGhdpiV2P) |
|||
| 15 | - Location: Torrevieja. |
|||
| 16 | - Topics: Yes. |
|||
| 17 | ||||
| 18 | - **2.7 Plans, if Any?** |
|||
| 19 | - [Status of OpenVPN 2.7](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn27) |
|||
| 20 | ||||
| 21 | - **PGP Signing Key for OpenVPN Releases** |
|||
| 22 | - djpig noticed an issue with the GPG signing key. |
|||
| 23 | - Accidentally used a recently revoked key instead of the new key from a recent key rotation. |
|||
| 24 | - Also, the latest Debian release's GPG does not like SHA-1 anymore. |
|||
| 25 | ||||
| 26 | - **Status of PoC Using Gerrit for Code Review** |
|||
| 27 | - cron2 took a look, hopefully it will be working now. |
|||
| 28 | ||||
| 29 | - **Security Assessment of OpenVPN2 Codebase** |
|||
| 30 | - What was the result of last week's meeting? |
|||
| 31 | ||||
| 32 | - **security@openvpn.net Mailing List** |
|||
| 33 | - The company is trying to get to SOC2 compliance. |
|||
| 34 | - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net. |
|||
| 35 | - Company guy took the standard NDA we use for contractors, suggests using that. |
|||
| 36 | - novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all. |
|||
| 37 | ||||
| 38 | - **License Amendment for OpenVPN2 to Solve OpenSSL/mbedTLS Licensing Issues** |
|||
| 39 | - Current status: [GitHub License Change](https://github.com/OpenVPN/openvpn-license-change) |
|||
| 40 | - The next step for us is to put in extra effort to try and reach those people that didn't respond or we couldn't reach yet. |
|||
| 41 | ||||
| 42 | - **Website Release Process Woes** |
|||
| 43 | - The website team claims their solution is 95% done. We'll see. |
|||
| 44 | ||||
| 45 | ## Topics on Standby |
|||
| 46 | ||||
| 47 | - **Another Key Signing Topic** |
|||
| 48 | - The company switched EV code signing to CloudHSM, which is the same cert type used for driver signing and is also suitable for binary signing. |
|||
| 49 | - In the future, we could possibly switch the community to that same key to save having to maintain two different keys. |
|||
| 50 | - Depends on how hard/easy it is to access the company key signing thing from community infrastructure. |
|||
| 51 | - Also, no high priority at the moment, we have a working solution now. |
|||
| 52 | ||||
| 53 | - **Can We Have Someone at OpenVPN Create Nicer Windows Traybar Logos?** |
|||
| 54 | - Matt is currently working on it in [GitHub Issue 595](https://github.com/OpenVPN/openvpn-gui/issues/595). |
|||
| 55 | ||||
| 56 | - **SBOM Topic** |
|||
| 57 | - cron2 was asked if OpenVPN has a software bill of materials. The answer was no. |
|||
| 58 | - Coincidentally, at OpenVPN Inc., a security requirement is to have an SBOM so this is on our list of things to do. |
|||
| 59 | - When we pick up this task, we can coordinate on it. |
|||
| 60 | ||||
| 61 | - **Forums Machine on Community Infrastructure is Only Non-Linux System** |
|||
| 62 | - mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist. |
|||
| 63 | - ecrist has looked at it but the current state of the migration is unknown. |
|||
| 64 | ||||
| 65 | - **OpenVPN 2.6 Performance Results** |
|||
| 66 | - We should work on an article to publish some performance results when 2.6 is out as stable, but first press release. |
|||
| 67 | ||||
| 68 | - **Management Interface Documentation on Main Website Will Be Updated** |
|||
| 69 | - Information from doc/management-notes.txt will be updated. |
|||
| 70 | - novaflash will pick this up at some point. |
|||
| 71 | ||||
| 72 | - **OpenVPN Quickstart on Community Resources Will Be Updated** |
|||
| 73 | - From `/doc/man-sections/example-fingerprint.rst` information. |
|||
| 74 | - Static-key will be deprecated and contents updated with peer-fingerprint stuff. |
|||
| 75 | - novaflash will pick this up again as time permits and other more important topics are done. |
