Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# Basic info
2
3
- **Time:** Wednesday 6 September 2023 at 13:00 CEST (11:00 UTC)
4
- **Place:** #openvpn-meeting channel on LiberaChat IRC network
5
6
# Topics
7
8
## Current topics
9
10
### OpenVPN Release Process Topics
11
- djpig explained the release process to uddr.
12
- dazo explained the copr release process to djpig.
13
- When 2.6.7 goes out, it will be done by uddr under the supervision of djpig to ensure we have a good backup.
14
- There was also a request in [OpenVPN Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig thinks it would be fairly doable to copy/paste that info to GitHub as well.
15
16
### Tunnelcrack Publication
17
- Published at [Tunnelcrack](https://tunnelcrack.mathyvanhoef.com).
18
- Acknowledged issues and committed to implementing mitigations.
19
- A draft is being put together [here](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/).
20
- The company will discuss possible mitigations, add them to the draft, and publish it on the community side.
21
- The main website will reference this document and contribute to making the mitigations happen.
22
23
### Security Assessment Review
24
- Currently, the fixes are being reviewed.
25
26
### Hackathon Arrangements
27
- See [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023).
28
- Topics include deprecation of NTLM and discussion about merchandise like t-shirts.
29
30
### License Amendment for OpenVPN2
31
- To solve openssl/mbedtls licensing issues, there are 5 contributions that need to be reimplemented/removed.
32
- One contribution was reimplemented by plaisthos and merged already, so 4 remain.
33
- Discussion about keeping old exceptions for libressl and mbedtls related changes.
34
35
### Handling Coverity Scans/Results
36
- The idea was to use the company's coverity code scanner, but there are licensing issues.
37
- There is a free version (Travis CI) that we used in the past but stopped working.
38
- Focus on getting the free service working again.
39
- A patch is available for GHA and just needs to be merged to master.
40
41
### Static-Key Mini How-To is Outdated
42
- The page is badly outdated: [Static-Key Mini HowTo](https://openvpn.net/community-resources/static-key-mini-howto/).
43
- The company will send this to a tech writer to redo based on the information from [GitHub](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst).
44
- A simple guide online will help adoption.
45
46
### Website Release Process Woes
47
- The website team is working on migrating community downloads content to a new CMS system.
48
49
## Topics on Standby
50
51
### OpenVPN 2.6 Performance Results
52
- Tests should cover various configurations and operating systems.
53
- Requires time to be dedicated to doing this.
54
55
### New Taskbar Icons
56
- Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595).
57
- Update: will be picked up by Selva when he has time.
58
59
### Security Mailing List
60
- Company is trying to get to SOC2 compliance.
61
- Might need a simple NDA to be signed by recipients of emails to security@openvpn.net.
62
- The community needs to review if the standard NDA used for contractors is suitable.
63
64
### Another Key Signing Topic
65
- Company switched EV code signing to CloudHSM.
66
- Possible future switch for community to the same key.
67
- Depends on access ease from community infrastructure.
68
69
### SBOM Topic
70
- OpenVPN has no SBOM currently.
71
- OpenVPN Inc. needs an SBOM for security requirements.
72
73
### Forums Machine on Community Infrastructure
74
- New forums system runs on Rocky Linux 8.
75
- Current state of migration is unknown.
76
77
### Management Interface Documentation
78
- Documentation on the main website will be updated with info from `doc/management-notes.txt`.
79
- Novaflash will pick this up eventually.
80
81
### OpenVPN Quickstart Update
82
- Static-key will be deprecated and contents updated with peer-fingerprint stuff.
83
- Novaflash will manage updates as time permits.
84
85
### Security Assessment of OpenVPN2 Codebase
86
- Company agreed to publish.
87
- Novaflash to push this to marketing for release on site.