Blame
| 6f02e7 | Samuli Seppänen | 2025-01-29 06:40:08 | 1 | # Basic info |
| 2 | ||||
| 3 | - **Time:** Wednesday 5 July 2023 at 13:00 CET (12:00 UTC) |
|||
| 4 | - **Place:** #openvpn-meeting channel on LiberaChat IRC network |
|||
| 5 | ||||
| 6 | # Topics |
|||
| 7 | ||||
| 8 | ## Current topics |
|||
| 9 | ||||
| 10 | - **2.6.6 release plans** |
|||
| 11 | - _tentatively last week of July_ |
|||
| 12 | ||||
| 13 | - **cmake work is done, need to decide if to merge that to 2.6 or not** |
|||
| 14 | - _djpig notes that there are some things to be ironed out before we can backport_ |
|||
| 15 | ||||
| 16 | - **Hackathon arrangements** |
|||
| 17 | - [See Hackathon2023 details](https://community.openvpn.net/openvpn/wiki/Hackathon2023) |
|||
| 18 | ||||
| 19 | - **Security assessment of OpenVPN2 codebase.** |
|||
| 20 | - _company agreed to publish. novaflash to push this to marketing for a release on site._ |
|||
| 21 | ||||
| 22 | - **Static-key mini how-to is outdated.** |
|||
| 23 | - [This page is outdated badly](https://openvpn.net/community-resources/static-key-mini-howto/) |
|||
| 24 | - _Company will send this to tech writer to redo based on [GitHub doc info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc._ |
|||
| 25 | ||||
| 26 | - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues** |
|||
| 27 | - _we have a deadline at August 1st_ |
|||
| 28 | - **update:** _2 additional people reached successfully, currently attempting 3rd hard-to-reach person_ |
|||
| 29 | ||||
| 30 | - **License amendment for OpenVPN2: keep old openssl exception or no?** |
|||
| 31 | - _someone mentioned that we should remove the old exception._ |
|||
| 32 | - _we will, eventually. while we still support openssl 1.0.2 we still need it_ |
|||
| 33 | - _if someone really wants to get rid of the exception they can fork openvpn2_ |
|||
| 34 | ||||
| 35 | - **OpenVPN 2.6 performance results.** |
|||
| 36 | - _We should work on an article to publish some performance results when 2.6 is out as stable._ |
|||
| 37 | ||||
| 38 | - **Website release process woes** |
|||
| 39 | - _website team is working on migrating community downloads content to new cms system._ |
|||
| 40 | ||||
| 41 | ## Topics on standby |
|||
| 42 | ||||
| 43 | - **Teach someone other than djpig to do releases** |
|||
| 44 | - _uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases._ |
|||
| 45 | - _likewise dazo and djpig will share knowledge about copr/fedora releases._ |
|||
| 46 | - **update:** _placed on standby for now because of holidays._ |
|||
| 47 | ||||
| 48 | - **What's going on with new taskbar icons?** |
|||
| 49 | - _matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_ |
|||
| 50 | - **update:** _will be picked up by selva when he has time_ |
|||
| 51 | ||||
| 52 | - **security@openvpn.net mailing list** |
|||
| 53 | - _company is trying to get to soc2 compliance._ |
|||
| 54 | - _probably will need a simple nda to be signed by recipients of emails to security@openvpn.net_ |
|||
| 55 | - _company guy took standard nda we use for contractors, suggests to use that._ |
|||
| 56 | - _novaflash thinks we should review that first to see if it's really suitable or not, as community members are not contractors._ |
|||
| 57 | ||||
| 58 | - **Another key signing topic** |
|||
| 59 | - _company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._ |
|||
| 60 | - _in future we could possibly switch community to that same key. saves having to maintain 2 different keys._ |
|||
| 61 | - _depends on how hard/easy it is to access company key signing thing from community infrastructure._ |
|||
| 62 | - _also no high priority at the moment, we have a working solution now._ |
|||
| 63 | ||||
| 64 | - **SBOM topic** |
|||
| 65 | - _cron2 was asked if openvpn has a software bill of materials. answer was no._ |
|||
| 66 | - _coincidentally, in openvpn inc a security requirement is to have an SBOM so this is on our list of things to do_ |
|||
| 67 | - _when we pick up this task we can coordinate on it._ |
|||
| 68 | ||||
| 69 | - **Forums machine on community infrastructure is only non-Linux system.** |
|||
| 70 | - _mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist._ |
|||
| 71 | - _ecrist has looked at it but the current state of the migration is unknown._ |
|||
| 72 | ||||
| 73 | - **Management interface documentation on main website will be updated with info from doc/management-notes.txt** |
|||
| 74 | - _novaflash will pick this up at some point_ |
|||
| 75 | ||||
| 76 | - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.** |
|||
| 77 | - _Static-key will be deprecated and contents updated with peer-fingerprint stuff._ |
|||
| 78 | - _novaflash will pick this up again as time permits and other more important topics are done._ |
