Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# Basic info
2
3
- **Time:** Wednesday 30 August 2023 at 13:00 CEST (11:00 UTC)
4
- **Place:** #openvpn-meeting channel on LiberaChat IRC network
5
6
# Topics
7
8
## Current topics
9
10
### OpenVPN release process topics
11
- djpig explained the release process to uddr. dazo explained the copr release process to djpig. Progress on spreading release process knowledge around.
12
- When 2.6.7 is released, it will be done by uddr under supervision from djpig, ensuring a good backup.
13
- There was also a request in [OpenVPN GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig thinks it would be fairly doable to copy/paste that info to GitHub.
14
15
### Tunnelcrack publication
16
- Published at [Tunnelcrack](https://tunnelcrack.mathyvanhoef.com).
17
- Acknowledging issues and committing to implementing mitigations.
18
- Drafting mitigations [here](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/).
19
- Company discussions about possible mitigations will reference the community document and participate in making the mitigations happen.
20
21
### Security assessment review
22
- Currently reviewing the fixes.
23
24
### Hackathon arrangements
25
- Details at [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023).
26
- Possible discussion topic: deprecation of NTLM and timing for it.
27
28
### License amendment for OpenVPN2
29
- To address openssl/mbedtls licensing issues.
30
- 5 contributions need to be reimplemented/removed to finalize the license change.
31
- One item was reimplemented by plaisthos and merged. Four remain.
32
- Discussion about whether the old exception could be kept for libressl.
33
- Djpig and MaxF will assist with changes. Dazo will consult with Pam.
34
35
### Handling coverity scans/results
36
- Consider using a free version of the service, such as Travis CI.
37
- A patch is available for GHA and just needs to be merged to master.
38
39
### Static-key mini how-to is outdated
40
- The page at [OpenVPN Static-Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/) is outdated.
41
- A tech writer will redo it based on the information in [GitHub](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst).
42
- A simple guide online will help with adoption.
43
44
### Website release process woes
45
- The website team is working on migrating community downloads content to a new CMS system.
46
47
## Topics on standby
48
49
- **OpenVPN 2.6 performance results:** Testing covers various configurations. Pending dedicated time.
50
- **New taskbar icons:** Update pending time availability.
51
- **Security mailing list:** Company is moving towards SOC2 compliance; a simple NDA might be required.
52
- **Key signing topic:** Transition to cloud-based key signing is under consideration but not a priority.
53
- **SBOM topic:** No current software bill of materials; coordination will occur when task is picked up.
54
- **Forums machine on community infrastructure:** Transition to a new system is in progress.
55
- **Management interface documentation update:** Will be updated based on management-notes.txt when possible.
56
- **OpenVPN Quickstart update:** Static-key will be deprecated; update will include peer-fingerprint info when possible.
57
- **Security assessment of OpenVPN2 codebase:** Agreed to be published; pending marketing release.