# Basic info

- **Time:** Wednesday 26 July 2023 at 13:00 CET (12:00 UTC)
- **Place:** #openvpn-meeting channel on LiberaChat IRC network

# Topics

## Current topics

- **An issue brought up by Mathy on the security list**
  - "This was discussed internally; at the moment it is not yet clear if this really is a CVE reportable issue. We do see that there are issues here that need to be addressed, so we acknowledge it and commit to implementing mitigations."

- **Security assessment topic raised by dazo**
  - "TOB-OVPN-14, NTLM issues in some buffer length checks. An audit will be done on code fixes for software assessment, and this is the most relevant one requiring code changes that is left. Conclusion is that we will document that if challenge is too short, we will fill remaining bytes with zero bytes from buf2."

- **How to handle coverity scans/results discussed by djpig**
  - "The idea was to use the company Coverity code scanner, but there may be licensing issues. Also, it turns out there is a free version (Travis CI) that we used in the past but stopped working. We should instead focus on getting that free service working again."

- **2.6.6 release plans**
  - "Moved from last week of July to tentatively first week of August. There's not all that much new to release yet, but we could do the cmake backport in this release."

- **Hackathon arrangements**
  - [Hackathon 2023 Information](https://community.openvpn.net/openvpn/wiki/Hackathon2023)

- **Teach someone other than djpig to do releases**
  - "uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases. Likewise, dazo and djpig will share knowledge about copr/fedora releases. **Update:** dazo sort of back from vacation."

- **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
  - "We have a deadline at August 1st. **Update:** 2 additional people reached successfully; others could not be reached."

- **Static-key mini how-to is outdated**
  - "This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/). The company will send this to a tech writer to redo based on [GitHub documentation](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc."

- **Website release process woes**
  - "The website team is working on migrating community downloads content to a new CMS system."

## Topics on standby

- **OpenVPN 2.6 performance results**
  - "Tests should cover: gre, ipsec, userland, dco; Linux, FreeBSD, Windows. Requires time to be dedicated to doing this. When time is available, we will do it."

- **What's going on with new taskbar icons?**
  - "Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595). **Update:** will be picked up by selva when he has time."

- **security@openvpn.net mailing list**
  - "The company is trying to get to SOC2 compliance. Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net. The company guy took the standard NDA we use for contractors, suggests to use that. Novaflash thinks we should review that first to see if it's really suitable or not, as community members are not contractors after all."

- **Another key signing topic**
  - "The company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing. In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys. Depends on how hard/easy it is to access company key signing thing from community infrastructure. Also, no high priority at the moment, we have a working solution now."

- **SBOM topic**
  - "Cron2 was asked if OpenVPN has a software bill of materials. Answer was no. Coincidentally, in OpenVPN Inc, a security requirement is to have an SBOM so this is on our list of things to do. When we pick up this task, we can coordinate on it."

- **Forums machine on community infrastructure is the only non-Linux system**
  - "Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist. Ecrist has looked at it but the current state of the migration is unknown."

- **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
  - "Novaflash will pick this up at some point."

- **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information**
  - "Static-key will be deprecated and contents updated with peer-fingerprint stuff. Novaflash will pick this up again as time permits and other more important topics are done."

- **Security assessment of OpenVPN2 codebase**
  - "Company agreed to publish. Novaflash to push this to marketing for a release on site."
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9