# Basic Info - **Time:** Wednesday 2 August 2023 at 13:00 CET (12:00 UTC) - **Place:** #openvpn-meeting channel on LiberaChat IRC network # Topics ## Current Topics - **An issue was brought up on security list by Mathy** - This was discussed internally - At the moment, it is not yet clear if this really is a CVE reportable issue - We do see that there are issues here that need to be addressed, so we acknowledge it and commit to implementing mitigations - We'll put together a draft here: [Cryptpad Draft](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/) - **Security assessment topic that dazo wanted to bring up** - TOB-OVPN-14, NTLM issues in some buffer length checks - An audit will be done on code fixes for software assessment, and this is the most relevant one requiring code changes that is left - Conclusion is that we will document that if the challenge is too short, we will fill remaining bytes with zero bytes from buf2 - **How to handle coverity scans/results by djpig** - The idea was to use the company coverity code scanner but there may be licensing issues - Also, it turns out there is a free version (Travis CI) that we used in the past but stopped working - We should instead focus on getting that free service working again - **2.6.6 release plans** - Release date between 9 and 15 August - We could do the cmake backport in this release - Lev mentions a WINS patch to go into 2.6.6 - **Hackathon arrangements** - See [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023) - **Teach someone other than djpig to do releases** - Uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases - Likewise, dazo and djpig will share knowledge about copr/fedora releases - **Update:** Dazo sort of back from vacation - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues** - There are a total of 5 contributions that need to be reimplemented/removed to finalize the license change - 1 item was reimplemented by plaisthos and merged already, so 4 remain - One person asked if old exception could be kept for libressl, plaisthos asked for clarification - **Static-key mini how-to is outdated** - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/) - Company will send this to tech writer to redo based on [GitHub Doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info - And also retain a link to that GitHub doc - Having a simple guide online will help adoption - **Website release process woes** - Website team is working on migrating community downloads content to new CMS system ## Topics on Standby - **OpenVPN 2.6 performance results** - Tests should cover: GRE, IPSec, userland, DCO - Linux, FreeBSD, Windows - Requires time to be dedicated to doing this - When time available will do it - **What's going on with new taskbar icons?** - Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595) - **Update:** Will be picked up by Selva when he has time [... Additional topics on standby continue ...]
