Blame
| 6f02e7 | Samuli Seppänen | 2025-01-29 06:40:08 | 1 | # Basic info |
| 2 | ||||
| 3 | - **Time:** Wednesday 9 August 2023 at 13:00 CET (12:00 UTC) |
|||
| 4 | - **Place:** #openvpn-meeting channel on LiberaChat IRC network |
|||
| 5 | ||||
| 6 | # Topics |
|||
| 7 | ||||
| 8 | ## Current topics |
|||
| 9 | ||||
| 10 | - **An issue was brought up on security list by Mathy** |
|||
| 11 | - This was discussed internally. |
|||
| 12 | - At the moment it is not yet clear if this really is a CVE reportable issue. |
|||
| 13 | - We do see that there are issues here that need to be addressed so we acknowledge it and commit to implementing mitigations. |
|||
| 14 | - We'll put together a draft here: [Draft Link](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/) |
|||
| 15 | ||||
| 16 | - **Security assessment topic that dazo wanted to bring up** |
|||
| 17 | - TOB-OVPN-14, NTLM issues in some buffer length checks. |
|||
| 18 | - An audit will be done on code fixes for software assessment and this is the most relevant one requiring code changes that is left. |
|||
| 19 | - Conclusion is that we will document that if challenge is too short we will fill remaining bytes with zero bytes from buf2. |
|||
| 20 | ||||
| 21 | - **How to handle coverity scans/results by djpig** |
|||
| 22 | - The idea was to use the company coverity code scanner but there may be licensing issues. |
|||
| 23 | - Also it turns out there is a free version (Travis CI) that we used in the past but stopped working. |
|||
| 24 | - We should instead focus on getting that free service working again. |
|||
| 25 | ||||
| 26 | - **2.6.6 release plans** |
|||
| 27 | - Release date between 9 and 15 August. |
|||
| 28 | - We could do the cmake backport in this release. |
|||
| 29 | - Lev mentions a WINS patch to go into 2.6.6. |
|||
| 30 | ||||
| 31 | - **Hackathon arrangements** |
|||
| 32 | - See [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023) |
|||
| 33 | ||||
| 34 | - **Teach someone other than djpig to do releases** |
|||
| 35 | - Uddr and djpig will work together so they can share the responsibility/knowledge of openvpn2 releases. |
|||
| 36 | - Likewise, dazo and djpig will share knowledge about copr/fedora releases. |
|||
| 37 | - **Update:** Dazo sort of back from vacation. |
|||
| 38 | ||||
| 39 | - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues** |
|||
| 40 | - There are a total of 5 contributions that need to be reimplemented/removed to finalize the license change. |
|||
| 41 | - 1 item was reimplemented by plaisthos and merged already, so 4 remain. |
|||
| 42 | - One person asked if the old exception could be kept for libressl, plaisthos asked for clarification. |
|||
| 43 | ||||
| 44 | - **Static-key mini how-to is outdated.** |
|||
| 45 | - This page is outdated badly: [Static Key Mini How-to](https://openvpn.net/community-resources/static-key-mini-howto/) |
|||
| 46 | - Company will send this to tech writer to redo based on [GitHub Doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc. |
|||
| 47 | - Having a simple guide online will help adoption. |
|||
| 48 | ||||
| 49 | - **Website release process woes** |
|||
| 50 | - Website team is working on migrating community downloads content to new CMS system. |
|||
| 51 | ||||
| 52 | ## Topics on standby |
|||
| 53 | ||||
| 54 | - **OpenVPN 2.6 performance results.** |
|||
| 55 | - Tests should cover: GRE, IPsec, userland, DCO, Linux, FreeBSD, Windows. |
|||
| 56 | - Requires time to be dedicated to doing this. |
|||
| 57 | - When time available will do it. |
|||
| 58 | ||||
| 59 | - **What's going on with new taskbar icons?** |
|||
| 60 | - Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595) |
|||
| 61 | - **Update:** Will be picked up by Selva when he has time. |
|||
| 62 | ||||
| 63 | - **security@openvpn.net mailing list** |
|||
| 64 | - Company is trying to get to SOC2 compliance. |
|||
| 65 | - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net. |
|||
| 66 | - Company guy took standard NDA we use for contractors, suggests to use that. |
|||
| 67 | - Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all. |
|||
| 68 | ||||
| 69 | - **Another key signing topic** |
|||
| 70 | - Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing. |
|||
| 71 | - In future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys. |
|||
| 72 | - Depends on how hard/easy it is to access company key signing thing from community infrastructure. |
|||
| 73 | - Also no high priority at the moment, we have a working solution now. |
|||
| 74 | ||||
| 75 | - **SBOM topic** |
|||
| 76 | - Cron2 was asked if OpenVPN has a software bill of materials. Answer was no. |
|||
| 77 | - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do. |
|||
| 78 | - When we pick up this task we can coordinate on it. |
|||
| 79 | ||||
| 80 | - **Forums machine on community infrastructure is only non-Linux system.** |
|||
| 81 | - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist. |
|||
| 82 | - Ecrist has looked at it but the current state of the migration is unknown. |
|||
| 83 | ||||
| 84 | - **Management interface documentation on main website will be updated with info from doc/management-notes.txt** |
|||
| 85 | - Novaflash will pick this up at some point. |
|||
| 86 | ||||
| 87 | - **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.** |
|||
| 88 | - Static-key will be deprecated and contents updated with peer-fingerprint stuff. |
|||
| 89 | - Novaflash will pick this up again as time permits and other more important topics are done. |
|||
| 90 | ||||
| 91 | - **Security assessment of OpenVPN2 codebase.** |
|||
| 92 | - Company agreed to publish. Novaflash to push this to marketing for a release on site. |
