Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# Basic info
2
3
- **Time:** Wednesday 5 July 2023 at 13:00 CET (12:00 UTC)
4
- **Place:** #openvpn-meeting channel on LiberaChat IRC network
5
6
# Topics
7
8
## Current topics
9
10
- **2.6.6 release plans**
11
- _tentatively last week of July_
12
13
- **cmake work is done, need to decide if to merge that to 2.6 or not**
14
- _djpig notes that there are some things to be ironed out before we can backport_
15
16
- **Hackathon arrangements**
17
- [See Hackathon2023 details](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
18
19
- **Security assessment of OpenVPN2 codebase.**
20
- _company agreed to publish. novaflash to push this to marketing for a release on site._
21
22
- **Static-key mini how-to is outdated.**
23
- [This page is outdated badly](https://openvpn.net/community-resources/static-key-mini-howto/)
24
- _Company will send this to tech writer to redo based on [GitHub doc info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc._
25
26
- **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
27
- _we have a deadline at August 1st_
28
- **update:** _2 additional people reached successfully, currently attempting 3rd hard-to-reach person_
29
30
- **License amendment for OpenVPN2: keep old openssl exception or no?**
31
- _someone mentioned that we should remove the old exception._
32
- _we will, eventually. while we still support openssl 1.0.2 we still need it_
33
- _if someone really wants to get rid of the exception they can fork openvpn2_
34
35
- **OpenVPN 2.6 performance results.**
36
- _We should work on an article to publish some performance results when 2.6 is out as stable._
37
38
- **Website release process woes**
39
- _website team is working on migrating community downloads content to new cms system._
40
41
## Topics on standby
42
43
- **Teach someone other than djpig to do releases**
44
- _uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases._
45
- _likewise dazo and djpig will share knowledge about copr/fedora releases._
46
- **update:** _placed on standby for now because of holidays._
47
48
- **What's going on with new taskbar icons?**
49
- _matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
50
- **update:** _will be picked up by selva when he has time_
51
52
- **security@openvpn.net mailing list**
53
- _company is trying to get to soc2 compliance._
54
- _probably will need a simple nda to be signed by recipients of emails to security@openvpn.net_
55
- _company guy took standard nda we use for contractors, suggests to use that._
56
- _novaflash thinks we should review that first to see if it's really suitable or not, as community members are not contractors._
57
58
- **Another key signing topic**
59
- _company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
60
- _in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
61
- _depends on how hard/easy it is to access company key signing thing from community infrastructure._
62
- _also no high priority at the moment, we have a working solution now._
63
64
- **SBOM topic**
65
- _cron2 was asked if openvpn has a software bill of materials. answer was no._
66
- _coincidentally, in openvpn inc a security requirement is to have an SBOM so this is on our list of things to do_
67
- _when we pick up this task we can coordinate on it._
68
69
- **Forums machine on community infrastructure is only non-Linux system.**
70
- _mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist._
71
- _ecrist has looked at it but the current state of the migration is unknown._
72
73
- **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
74
- _novaflash will pick this up at some point_
75
76
- **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
77
- _Static-key will be deprecated and contents updated with peer-fingerprint stuff._
78
- _novaflash will pick this up again as time permits and other more important topics are done._