Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# Basic Info
2
3
- **Time:** Wednesday 2 August 2023 at 13:00 CET (12:00 UTC)
4
- **Place:** #openvpn-meeting channel on LiberaChat IRC network
5
6
# Topics
7
8
## Current Topics
9
10
- **An issue was brought up on security list by Mathy**
11
- This was discussed internally
12
- At the moment, it is not yet clear if this really is a CVE reportable issue
13
- We do see that there are issues here that need to be addressed, so we acknowledge it and commit to implementing mitigations
14
- We'll put together a draft here: [Cryptpad Draft](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/)
15
16
- **Security assessment topic that dazo wanted to bring up**
17
- TOB-OVPN-14, NTLM issues in some buffer length checks
18
- An audit will be done on code fixes for software assessment, and this is the most relevant one requiring code changes that is left
19
- Conclusion is that we will document that if the challenge is too short, we will fill remaining bytes with zero bytes from buf2
20
21
- **How to handle coverity scans/results by djpig**
22
- The idea was to use the company coverity code scanner but there may be licensing issues
23
- Also, it turns out there is a free version (Travis CI) that we used in the past but stopped working
24
- We should instead focus on getting that free service working again
25
26
- **2.6.6 release plans**
27
- Release date between 9 and 15 August
28
- We could do the cmake backport in this release
29
- Lev mentions a WINS patch to go into 2.6.6
30
31
- **Hackathon arrangements**
32
- See [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
33
34
- **Teach someone other than djpig to do releases**
35
- Uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases
36
- Likewise, dazo and djpig will share knowledge about copr/fedora releases
37
- **Update:** Dazo sort of back from vacation
38
39
- **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
40
- There are a total of 5 contributions that need to be reimplemented/removed to finalize the license change
41
- 1 item was reimplemented by plaisthos and merged already, so 4 remain
42
- One person asked if old exception could be kept for libressl, plaisthos asked for clarification
43
44
- **Static-key mini how-to is outdated**
45
- This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
46
- Company will send this to tech writer to redo based on [GitHub Doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info
47
- And also retain a link to that GitHub doc
48
- Having a simple guide online will help adoption
49
50
- **Website release process woes**
51
- Website team is working on migrating community downloads content to new CMS system
52
53
## Topics on Standby
54
55
- **OpenVPN 2.6 performance results**
56
- Tests should cover: GRE, IPSec, userland, DCO
57
- Linux, FreeBSD, Windows
58
- Requires time to be dedicated to doing this
59
- When time available will do it
60
61
- **What's going on with new taskbar icons?**
62
- Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
63
- **Update:** Will be picked up by Selva when he has time
64
65
[... Additional topics on standby continue ...]