Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# Basic Info
2
3
- **Time**: Wednesday 17 May 2023 at 13:00 CET (12:00 UTC)
4
- **Place**: #openvpn-meeting channel on [LiberaChat](https://libera.chat/) IRC network
5
6
# Topics
7
8
## Current Topics
9
10
- **2.6.5 Release Plans**
11
- "in about 4 to 8 weeks from now so anywhere between half June and half July"
12
13
- **Hackathon Arrangements**
14
- When: [Schedule](https://nuudel.digitalcourage.de/t1hjepaHGhdpiV2P)
15
- Location: Torrevieja.
16
- Topics: Yes.
17
18
- **2.7 Plans, if Any?**
19
- [Status of OpenVPN 2.7](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn27)
20
21
- **PGP Signing Key for OpenVPN Releases**
22
- djpig noticed an issue with the GPG signing key.
23
- Accidentally used a recently revoked key instead of the new key from a recent key rotation.
24
- Also, the latest Debian release's GPG does not like SHA-1 anymore.
25
26
- **Status of PoC Using Gerrit for Code Review**
27
- cron2 took a look, hopefully it will be working now.
28
29
- **Security Assessment of OpenVPN2 Codebase**
30
- What was the result of last week's meeting?
31
32
- **security@openvpn.net Mailing List**
33
- The company is trying to get to SOC2 compliance.
34
- Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net.
35
- Company guy took the standard NDA we use for contractors, suggests using that.
36
- novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
37
38
- **License Amendment for OpenVPN2 to Solve OpenSSL/mbedTLS Licensing Issues**
39
- Current status: [GitHub License Change](https://github.com/OpenVPN/openvpn-license-change)
40
- The next step for us is to put in extra effort to try and reach those people that didn't respond or we couldn't reach yet.
41
42
- **Website Release Process Woes**
43
- The website team claims their solution is 95% done. We'll see.
44
45
## Topics on Standby
46
47
- **Another Key Signing Topic**
48
- The company switched EV code signing to CloudHSM, which is the same cert type used for driver signing and is also suitable for binary signing.
49
- In the future, we could possibly switch the community to that same key to save having to maintain two different keys.
50
- Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
51
- Also, no high priority at the moment, we have a working solution now.
52
53
- **Can We Have Someone at OpenVPN Create Nicer Windows Traybar Logos?**
54
- Matt is currently working on it in [GitHub Issue 595](https://github.com/OpenVPN/openvpn-gui/issues/595).
55
56
- **SBOM Topic**
57
- cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
58
- Coincidentally, at OpenVPN Inc., a security requirement is to have an SBOM so this is on our list of things to do.
59
- When we pick up this task, we can coordinate on it.
60
61
- **Forums Machine on Community Infrastructure is Only Non-Linux System**
62
- mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist.
63
- ecrist has looked at it but the current state of the migration is unknown.
64
65
- **OpenVPN 2.6 Performance Results**
66
- We should work on an article to publish some performance results when 2.6 is out as stable, but first press release.
67
68
- **Management Interface Documentation on Main Website Will Be Updated**
69
- Information from doc/management-notes.txt will be updated.
70
- novaflash will pick this up at some point.
71
72
- **OpenVPN Quickstart on Community Resources Will Be Updated**
73
- From `/doc/man-sections/example-fingerprint.rst` information.
74
- Static-key will be deprecated and contents updated with peer-fingerprint stuff.
75
- novaflash will pick this up again as time permits and other more important topics are done.