Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# Basic info
2
3
- **Time:** Wednesday 14 June 2023 at 13:00 CET (12:00 UTC)
4
- **Place:** #openvpn-meeting channel on LiberaChat IRC network
5
6
# Topics
7
8
## Current topics
9
10
- **2.6.5 release plans**
11
*released 13 June*
12
13
- **2.6.6 release plans**
14
*tentatively last week of July*
15
16
- **Hackathon arrangements**
17
*See [Hackathon2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023)*
18
19
- **Status of PoC using Gerrit for code review.**
20
*Buildbot builds from Gerrit should work now for all workers. Please use!*
21
22
- **Security assessment of OpenVPN2 codebase.**
23
*this is now done.
24
novaflash will take to company to discuss publishing it.
25
ultimately francis makes the call on that.*
26
27
- **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
28
*novaflash assisting plaisthos to reach the last 6 or so relevant people.
29
we set a deadline at august 1st*
30
31
- **Website release process woes**
32
*website team launched a new CMS system to be used with a headless system.
33
they're copying community downloads stuff in there.
34
once done we can test it and then updates there can be done independently of main website releases.*
35
36
- **Teach someone other than djpig to do releases**
37
*uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases.
38
likewise dazo and djpig will share knowledge about copr/fedora releases.*
39
40
## Topics on standby
41
42
- **security@openvpn.net mailing list**
43
*company is trying to get to soc2 compliance.
44
probably will need a simple nda to be signed by recipients of emails to security@openvpn.net
45
company guy took standard nda we use for contractors, suggests to use that.
46
novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.*
47
48
- **Another key signing topic**
49
*company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
50
in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
51
depends on how hard or easy it is to access company key signing thingee from community infrastructure.
52
also no high priority at the moment, we have a working solution now.*
53
54
- **Can we have someone at OpenVPN create nicer windows traybar logos (#1276)?**
55
*matt is currently working on it in [OpenVPN-gui#595](https://github.com/OpenVPN/openvpn-gui/issues/595)*
56
57
- **SBOM topic**
58
*cron2 was asked if openvpn has a software bill of materials. answer was no.
59
coincidentally, in openvpn inc a security requirement is to have an SBOM so this is on our list of things to do
60
when we pick up this task we can coordinate on it.*
61
62
- **Forums machine on community infrastructure is only non-Linux system.**
63
*mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
64
ecrist has looked at it but the current state of the migration is unknown.*
65
66
- **OpenVPN 2.6 performance results.**
67
*We should work on an article to publish some performance results when 2.6 is out as stable.*
68
69
- **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
70
*novaflash will pick this up at some point*
71
72
- **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
73
*Static-key will be deprecated and contents updated with peer-fingerprint stuff.
74
novaflash will pick this up again as time permits and other more important topics are done.*