Basic Info

  • Time: Wednesday 2 August 2023 at 13:00 CET (12:00 UTC)
  • Place: #openvpn-meeting channel on LiberaChat IRC network

Topics

Current Topics

  • An issue was brought up on security list by Mathy

    • This was discussed internally
    • At the moment, it is not yet clear if this really is a CVE reportable issue
    • We do see that there are issues here that need to be addressed, so we acknowledge it and commit to implementing mitigations
    • We'll put together a draft here: Cryptpad Draft
  • Security assessment topic that dazo wanted to bring up

    • TOB-OVPN-14, NTLM issues in some buffer length checks
    • An audit will be done on code fixes for software assessment, and this is the most relevant one requiring code changes that is left
    • Conclusion is that we will document that if the challenge is too short, we will fill remaining bytes with zero bytes from buf2
  • How to handle coverity scans/results by djpig

    • The idea was to use the company coverity code scanner but there may be licensing issues
    • Also, it turns out there is a free version (Travis CI) that we used in the past but stopped working
    • We should instead focus on getting that free service working again
  • 2.6.6 release plans

    • Release date between 9 and 15 August
    • We could do the cmake backport in this release
    • Lev mentions a WINS patch to go into 2.6.6
  • Hackathon arrangements

  • Teach someone other than djpig to do releases

    • Uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases
    • Likewise, dazo and djpig will share knowledge about copr/fedora releases
    • Update: Dazo sort of back from vacation
  • License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues

    • There are a total of 5 contributions that need to be reimplemented/removed to finalize the license change
    • 1 item was reimplemented by plaisthos and merged already, so 4 remain
    • One person asked if old exception could be kept for libressl, plaisthos asked for clarification
  • Static-key mini how-to is outdated

    • This page is outdated badly: Static Key Mini How-To
    • Company will send this to tech writer to redo based on GitHub Doc info
    • And also retain a link to that GitHub doc
    • Having a simple guide online will help adoption
  • Website release process woes

    • Website team is working on migrating community downloads content to new CMS system

Topics on Standby

  • OpenVPN 2.6 performance results

    • Tests should cover: GRE, IPSec, userland, DCO
    • Linux, FreeBSD, Windows
    • Requires time to be dedicated to doing this
    • When time available will do it
  • What's going on with new taskbar icons?

    • Matt provided icons in GitHub Issue
    • Update: Will be picked up by Selva when he has time

[... Additional topics on standby continue ...]

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9