Blame
| 6f02e7 | Samuli Seppänen | 2025-01-29 06:40:08 | 1 | # Basic info |
| 2 | ||||
| 3 | - **Time:** Wednesday 30 August 2023 at 13:00 CEST (11:00 UTC) |
|||
| 4 | - **Place:** #openvpn-meeting channel on LiberaChat IRC network |
|||
| 5 | ||||
| 6 | # Topics |
|||
| 7 | ||||
| 8 | ## Current topics |
|||
| 9 | ||||
| 10 | ### OpenVPN release process topics |
|||
| 11 | - djpig explained the release process to uddr. dazo explained the copr release process to djpig. Progress on spreading release process knowledge around. |
|||
| 12 | - When 2.6.7 is released, it will be done by uddr under supervision from djpig, ensuring a good backup. |
|||
| 13 | - There was also a request in [OpenVPN GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig thinks it would be fairly doable to copy/paste that info to GitHub. |
|||
| 14 | ||||
| 15 | ### Tunnelcrack publication |
|||
| 16 | - Published at [Tunnelcrack](https://tunnelcrack.mathyvanhoef.com). |
|||
| 17 | - Acknowledging issues and committing to implementing mitigations. |
|||
| 18 | - Drafting mitigations [here](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/). |
|||
| 19 | - Company discussions about possible mitigations will reference the community document and participate in making the mitigations happen. |
|||
| 20 | ||||
| 21 | ### Security assessment review |
|||
| 22 | - Currently reviewing the fixes. |
|||
| 23 | ||||
| 24 | ### Hackathon arrangements |
|||
| 25 | - Details at [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023). |
|||
| 26 | - Possible discussion topic: deprecation of NTLM and timing for it. |
|||
| 27 | ||||
| 28 | ### License amendment for OpenVPN2 |
|||
| 29 | - To address openssl/mbedtls licensing issues. |
|||
| 30 | - 5 contributions need to be reimplemented/removed to finalize the license change. |
|||
| 31 | - One item was reimplemented by plaisthos and merged. Four remain. |
|||
| 32 | - Discussion about whether the old exception could be kept for libressl. |
|||
| 33 | - Djpig and MaxF will assist with changes. Dazo will consult with Pam. |
|||
| 34 | ||||
| 35 | ### Handling coverity scans/results |
|||
| 36 | - Consider using a free version of the service, such as Travis CI. |
|||
| 37 | - A patch is available for GHA and just needs to be merged to master. |
|||
| 38 | ||||
| 39 | ### Static-key mini how-to is outdated |
|||
| 40 | - The page at [OpenVPN Static-Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/) is outdated. |
|||
| 41 | - A tech writer will redo it based on the information in [GitHub](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst). |
|||
| 42 | - A simple guide online will help with adoption. |
|||
| 43 | ||||
| 44 | ### Website release process woes |
|||
| 45 | - The website team is working on migrating community downloads content to a new CMS system. |
|||
| 46 | ||||
| 47 | ## Topics on standby |
|||
| 48 | ||||
| 49 | - **OpenVPN 2.6 performance results:** Testing covers various configurations. Pending dedicated time. |
|||
| 50 | - **New taskbar icons:** Update pending time availability. |
|||
| 51 | - **Security mailing list:** Company is moving towards SOC2 compliance; a simple NDA might be required. |
|||
| 52 | - **Key signing topic:** Transition to cloud-based key signing is under consideration but not a priority. |
|||
| 53 | - **SBOM topic:** No current software bill of materials; coordination will occur when task is picked up. |
|||
| 54 | - **Forums machine on community infrastructure:** Transition to a new system is in progress. |
|||
| 55 | - **Management interface documentation update:** Will be updated based on management-notes.txt when possible. |
|||
| 56 | - **OpenVPN Quickstart update:** Static-key will be deprecated; update will include peer-fingerprint info when possible. |
|||
| 57 | - **Security assessment of OpenVPN2 codebase:** Agreed to be published; pending marketing release. |
