Basic info

  • Time: Wednesday 9 August 2023 at 13:00 CET (12:00 UTC)
  • Place: #openvpn-meeting channel on LiberaChat IRC network

Topics

Current topics

  • An issue was brought up on security list by Mathy

    • This was discussed internally.
    • At the moment it is not yet clear if this really is a CVE reportable issue.
    • We do see that there are issues here that need to be addressed so we acknowledge it and commit to implementing mitigations.
    • We'll put together a draft here: Draft Link
  • Security assessment topic that dazo wanted to bring up

    • TOB-OVPN-14, NTLM issues in some buffer length checks.
    • An audit will be done on code fixes for software assessment and this is the most relevant one requiring code changes that is left.
    • Conclusion is that we will document that if challenge is too short we will fill remaining bytes with zero bytes from buf2.
  • How to handle coverity scans/results by djpig

    • The idea was to use the company coverity code scanner but there may be licensing issues.
    • Also it turns out there is a free version (Travis CI) that we used in the past but stopped working.
    • We should instead focus on getting that free service working again.
  • 2.6.6 release plans

    • Release date between 9 and 15 August.
    • We could do the cmake backport in this release.
    • Lev mentions a WINS patch to go into 2.6.6.
  • Hackathon arrangements

  • Teach someone other than djpig to do releases

    • Uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases.
    • Likewise, dazo and djpig will share knowledge about copr/fedora releases.
    • Update: Dazo sort of back from vacation.
  • License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues

    • There are a total of 5 contributions that need to be reimplemented/removed to finalize the license change.
    • 1 item was reimplemented by plaisthos and merged already, so 4 remain.
    • One person asked if the old exception could be kept for libressl, plaisthos asked for clarification.
  • Static-key mini how-to is outdated.

    • This page is outdated badly: Static Key Mini How-to
    • Company will send this to tech writer to redo based on GitHub Doc info and also retain a link to that GitHub doc.
    • Having a simple guide online will help adoption.
  • Website release process woes

    • Website team is working on migrating community downloads content to new CMS system.

Topics on standby

  • OpenVPN 2.6 performance results.

    • Tests should cover: GRE, IPsec, userland, DCO, Linux, FreeBSD, Windows.
    • Requires time to be dedicated to doing this.
    • When time available will do it.
  • What's going on with new taskbar icons?

    • Matt provided icons in GitHub Issue
    • Update: Will be picked up by Selva when he has time.
  • security@openvpn.net mailing list

    • Company is trying to get to SOC2 compliance.
    • Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net.
    • Company guy took standard NDA we use for contractors, suggests to use that.
    • Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
  • Another key signing topic

    • Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
    • In future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
    • Depends on how hard/easy it is to access company key signing thing from community infrastructure.
    • Also no high priority at the moment, we have a working solution now.
  • SBOM topic

    • Cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
    • Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
    • When we pick up this task we can coordinate on it.
  • Forums machine on community infrastructure is only non-Linux system.

    • Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
    • Ecrist has looked at it but the current state of the migration is unknown.
  • Management interface documentation on main website will be updated with info from doc/management-notes.txt

    • Novaflash will pick this up at some point.
  • OpenVPN Quickstart will be updated from /doc/man-sections/example-fingerprint.rst information.

    • Static-key will be deprecated and contents updated with peer-fingerprint stuff.
    • Novaflash will pick this up again as time permits and other more important topics are done.
  • Security assessment of OpenVPN2 codebase.

    • Company agreed to publish. Novaflash to push this to marketing for a release on site.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9