Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# Basic info
2
3
- Time: Wednesday 23 August 2023 at 13:00 CEST (11:00 UTC)
4
- Place: #openvpn-meeting channel on LiberaChat IRC network
5
6
# Topics
7
8
## Current topics
9
10
- **openvpn release process topics**
11
- djpig explained release process to uddr. dazo explained copr release process to djpig. So progress on spreading release process knowledge around.
12
- when 2.6.7 goes out it will be done by uddr under supervision from djpig. that way we'll be sure we have a good backup.
13
- there was also the request in [https://github.com/OpenVPN/openvpn/issues/397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
14
15
- **Tunnelcrack published now [https://tunnelcrack.mathyvanhoef.com](https://tunnelcrack.mathyvanhoef.com)**
16
- we do see that there are issues here that need to be addressed so we acknowledge it and commit to implementing mitigations
17
- we'll put together a draft here [https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/)
18
- in the company there will also be discussions about possible mitigations. any mitigation plans we can put into the draft and publish it on community side.
19
- company will then reference that document on the main website and contribute/participate in making the mitigations happen.
20
21
- **security assessment review**
22
- currently the fixes are being reviewed.
23
24
- **Hackathon arrangements**
25
- See [https://community.openvpn.net/openvpn/wiki/Hackathon2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
26
- a possible topic for discussion is deprecation of NTLM and when to deprecate
27
28
- **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
29
- there are a total of 5 contributions that need to be reimplemented/removed to finalize the license change.
30
- 1 item was reimplemented by plaisthos and merged already, so 4 remain
31
- one of them wanted
32
- one person asked if old exception could be kept, for libressl, plaisthos asked for clarification. djpig volunteered to look at the original changes to describe them for people interested in reimplementing them. MaxF has volunteered to help with any mbedtls related required changes. dazo will speak to Pam to get her opinions on the contributions. plaisthos has volunteered to reimplement tls-export-cert.
33
34
- **how to handle coverity scans/results by djpig**
35
- the idea was to use the company coverity code scanner but there may be licensing issues
36
- also, it turns out there is a free version (Travis CI) that we used in the past but stopped working
37
- we should instead focus on getting that free service working again.
38
- patch is available for GHA. Just needs to be merged to master.
39
40
- **Static-key mini how-to is outdated.**
41
- This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
42
- company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info
43
- and also retain a link to that GitHub doc.
44
- having a simple guide online will help adoption
45
46
- **Website release process woes**
47
- website team is working on migrating community downloads content to new CMS system.
48
49
## Topics on standby
50
51
- **OpenVPN 2.6 performance results.**
52
- tests should cover: gre, ipsec, userland, dco
53
- linux, freebsd, windows
54
- requires time to be dedicated to doing this
55
- when time available will do it
56
57
- **What's going on with new taskbar icons?**
58
- matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)
59
- **update:** will be picked up by selva when he has time
60
61
- **security@openvpn.net mailing list**
62
- company is trying to get to soc2 compliance.
63
- probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net
64
- company guy took standard NDA we use for contractors, suggests to use that.
65
- novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.
66
67
- **Another key signing topic**
68
- company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
69
- in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
70
- depends on how hard/easy it is to access company key signing thingee from community infrastructure.
71
- also no high priority at the moment, we have a working solution now.
72
73
- **SBOM topic**
74
- cron2 was asked if openvpn has a software bill of materials. answer was no.
75
- coincidentally, in openvpn inc a security requirement is to have an SBOM so this is on our list of things to do
76
- when we pick up this task we can coordinate on it.
77
78
- **Forums machine on community infrastructure is only non-Linux system.**
79
- mattock made a new forums system that runs on rocky linux 8 as agreed with ecrist.
80
- ecrist has looked at it but the current state of the migration is unknown.
81
82
- **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
83
- novaflash will pick this up at some point
84
85
- **[https://openvpn.net/community-resources/openvpn-quickstart/](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
86
- Static-key will be deprecated and contents updated with peer-fingerprint stuff.
87
- novaflash will pick this up again as time permits and other more important topics are done.
88
89
- **Security assessment of OpenVPN2 codebase.**
90
- company agreed to publish. novaflash to push this to marketing for a release on site.