# Basic info - **Time:** Wednesday 30 August 2023 at 13:00 CEST (11:00 UTC) - **Place:** #openvpn-meeting channel on LiberaChat IRC network # Topics ## Current topics ### OpenVPN release process topics - djpig explained the release process to uddr. dazo explained the copr release process to djpig. Progress on spreading release process knowledge around. - When 2.6.7 is released, it will be done by uddr under supervision from djpig, ensuring a good backup. - There was also a request in [OpenVPN GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig thinks it would be fairly doable to copy/paste that info to GitHub. ### Tunnelcrack publication - Published at [Tunnelcrack](https://tunnelcrack.mathyvanhoef.com). - Acknowledging issues and committing to implementing mitigations. - Drafting mitigations [here](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/). - Company discussions about possible mitigations will reference the community document and participate in making the mitigations happen. ### Security assessment review - Currently reviewing the fixes. ### Hackathon arrangements - Details at [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023). - Possible discussion topic: deprecation of NTLM and timing for it. ### License amendment for OpenVPN2 - To address openssl/mbedtls licensing issues. - 5 contributions need to be reimplemented/removed to finalize the license change. - One item was reimplemented by plaisthos and merged. Four remain. - Discussion about whether the old exception could be kept for libressl. - Djpig and MaxF will assist with changes. Dazo will consult with Pam. ### Handling coverity scans/results - Consider using a free version of the service, such as Travis CI. - A patch is available for GHA and just needs to be merged to master. ### Static-key mini how-to is outdated - The page at [OpenVPN Static-Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/) is outdated. - A tech writer will redo it based on the information in [GitHub](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst). - A simple guide online will help with adoption. ### Website release process woes - The website team is working on migrating community downloads content to a new CMS system. ## Topics on standby - **OpenVPN 2.6 performance results:** Testing covers various configurations. Pending dedicated time. - **New taskbar icons:** Update pending time availability. - **Security mailing list:** Company is moving towards SOC2 compliance; a simple NDA might be required. - **Key signing topic:** Transition to cloud-based key signing is under consideration but not a priority. - **SBOM topic:** No current software bill of materials; coordination will occur when task is picked up. - **Forums machine on community infrastructure:** Transition to a new system is in progress. - **Management interface documentation update:** Will be updated based on management-notes.txt when possible. - **OpenVPN Quickstart update:** Static-key will be deprecated; update will include peer-fingerprint info when possible. - **Security assessment of OpenVPN2 codebase:** Agreed to be published; pending marketing release.
