Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# Basic Info
2
3
- **Time:** Wednesday 19 July 2023 at 13:00 CET (12:00 UTC)
4
- **Place:** #openvpn-meeting channel on LiberaChat IRC network
5
6
# Topics
7
8
## Current Topics
9
10
- **Topics Regarding Gerrit Reviewing**
11
- Solved the issue of Gerrit not being able to send emails.
12
- When the OpenVPN2 master is updated, Gerrit should be updated too. Requested cron2 to take care of this.
13
14
- **An Issue Was Brought Up on Security List by Mathy Vanhoef**
15
- 9:30 AM 20 July we'll discuss internally. The location will be disclosed on the security list.
16
17
- **2.6.6 Release Plans**
18
- Moved from the last week of July to tentatively the first week of August.
19
20
- **CMake Work is Done, Need to Decide if to Merge That to 2.6 or Not**
21
- All the work for this appears to be done. A backport will be made to 2.6.
22
23
- **Hackathon Arrangements**
24
- See [Hackathon2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
25
26
- **Security Assessment of OpenVPN2 Codebase**
27
- The company agreed to publish. Novaflash to push this to marketing for a release on the site.
28
29
- **Static-Key Mini How-to is Outdated**
30
- This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
31
- The company will send this to a tech writer to redo based on [GitHub Doc Information](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst)
32
- Also, retain a link to that GitHub doc.
33
34
- **License Amendment for OpenVPN2 to Solve OpenSSL/mbedTLS Licensing Issues**
35
- We have a deadline at August 1st.
36
- **Update:** 2 additional people reached successfully, currently attempting 3rd hard-to-reach person.
37
38
- **OpenVPN 2.6 Performance Results**
39
- Tests should cover: GRE, IPSec, userland, DCO on Linux, FreeBSD, Windows.
40
41
- **Website Release Process Woes**
42
- The website team is working on migrating community downloads content to a new CMS system.
43
44
## Topics on Standby
45
46
- **Teach Someone Other Than Djpig to Do Releases**
47
- Uddr and Djpig will work together so they can share the responsibility/knowledge of OpenVPN2 releases.
48
- Likewise, Dazo and Djpig will share knowledge about COPR/Fedora releases.
49
- **Update:** Placed on standby for now because of holidays.
50
51
- **What's Going on with New Taskbar Icons?**
52
- Matt provided icons in [Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
53
- **Update:** Will be picked up by Selva when he has time.
54
55
- **Security@openvpn.net Mailing List**
56
- The company is trying to get to SOC2 compliance.
57
- Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
58
- The company guy took the standard NDA we use for contractors, suggests to use that.
59
- Novaflash thinks we should review that first to see if it's really suitable or not, as community members are not contractors after all.
60
61
- **Another Key Signing Topic**
62
- The company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
63
- In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
64
- Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
65
- Also, no high priority at the moment, we have a working solution now.
66
67
- **SBOM Topic**
68
- Cron2 was asked if OpenVPN has a software bill of materials. The answer was no.
69
- Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do
70
- When we pick up this task we can coordinate on it.
71
72
- **Forums Machine on Community Infrastructure is Only Non-Linux System**
73
- Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
74
- Ecrist has looked at it but the current state of the migration is unknown.
75
76
- **Management Interface Documentation on Main Website Will Be Updated with Info From doc/management-notes.txt**
77
- Novaflash will pick this up at some point.
78
79
- **OpenVPN Quickstart Will Be Updated from /doc/man-sections/example-fingerprint.rst Information**
80
- Static-key will be deprecated and contents updated with peer-fingerprint stuff.
81
- Novaflash will pick this up again as time permits and other more important topics are done.