Blame
| 6f02e7 | Samuli Seppänen | 2025-01-29 06:40:08 | 1 | # Basic info |
| 2 | ||||
| 3 | - **Time:** Wednesday 6 September 2023 at 13:00 CEST (11:00 UTC) |
|||
| 4 | - **Place:** #openvpn-meeting channel on LiberaChat IRC network |
|||
| 5 | ||||
| 6 | # Topics |
|||
| 7 | ||||
| 8 | ## Current topics |
|||
| 9 | ||||
| 10 | ### OpenVPN Release Process Topics |
|||
| 11 | - djpig explained the release process to uddr. |
|||
| 12 | - dazo explained the copr release process to djpig. |
|||
| 13 | - When 2.6.7 goes out, it will be done by uddr under the supervision of djpig to ensure we have a good backup. |
|||
| 14 | - There was also a request in [OpenVPN Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig thinks it would be fairly doable to copy/paste that info to GitHub as well. |
|||
| 15 | ||||
| 16 | ### Tunnelcrack Publication |
|||
| 17 | - Published at [Tunnelcrack](https://tunnelcrack.mathyvanhoef.com). |
|||
| 18 | - Acknowledged issues and committed to implementing mitigations. |
|||
| 19 | - A draft is being put together [here](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/). |
|||
| 20 | - The company will discuss possible mitigations, add them to the draft, and publish it on the community side. |
|||
| 21 | - The main website will reference this document and contribute to making the mitigations happen. |
|||
| 22 | ||||
| 23 | ### Security Assessment Review |
|||
| 24 | - Currently, the fixes are being reviewed. |
|||
| 25 | ||||
| 26 | ### Hackathon Arrangements |
|||
| 27 | - See [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023). |
|||
| 28 | - Topics include deprecation of NTLM and discussion about merchandise like t-shirts. |
|||
| 29 | ||||
| 30 | ### License Amendment for OpenVPN2 |
|||
| 31 | - To solve openssl/mbedtls licensing issues, there are 5 contributions that need to be reimplemented/removed. |
|||
| 32 | - One contribution was reimplemented by plaisthos and merged already, so 4 remain. |
|||
| 33 | - Discussion about keeping old exceptions for libressl and mbedtls related changes. |
|||
| 34 | ||||
| 35 | ### Handling Coverity Scans/Results |
|||
| 36 | - The idea was to use the company's coverity code scanner, but there are licensing issues. |
|||
| 37 | - There is a free version (Travis CI) that we used in the past but stopped working. |
|||
| 38 | - Focus on getting the free service working again. |
|||
| 39 | - A patch is available for GHA and just needs to be merged to master. |
|||
| 40 | ||||
| 41 | ### Static-Key Mini How-To is Outdated |
|||
| 42 | - The page is badly outdated: [Static-Key Mini HowTo](https://openvpn.net/community-resources/static-key-mini-howto/). |
|||
| 43 | - The company will send this to a tech writer to redo based on the information from [GitHub](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst). |
|||
| 44 | - A simple guide online will help adoption. |
|||
| 45 | ||||
| 46 | ### Website Release Process Woes |
|||
| 47 | - The website team is working on migrating community downloads content to a new CMS system. |
|||
| 48 | ||||
| 49 | ## Topics on Standby |
|||
| 50 | ||||
| 51 | ### OpenVPN 2.6 Performance Results |
|||
| 52 | - Tests should cover various configurations and operating systems. |
|||
| 53 | - Requires time to be dedicated to doing this. |
|||
| 54 | ||||
| 55 | ### New Taskbar Icons |
|||
| 56 | - Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595). |
|||
| 57 | - Update: will be picked up by Selva when he has time. |
|||
| 58 | ||||
| 59 | ### Security Mailing List |
|||
| 60 | - Company is trying to get to SOC2 compliance. |
|||
| 61 | - Might need a simple NDA to be signed by recipients of emails to security@openvpn.net. |
|||
| 62 | - The community needs to review if the standard NDA used for contractors is suitable. |
|||
| 63 | ||||
| 64 | ### Another Key Signing Topic |
|||
| 65 | - Company switched EV code signing to CloudHSM. |
|||
| 66 | - Possible future switch for community to the same key. |
|||
| 67 | - Depends on access ease from community infrastructure. |
|||
| 68 | ||||
| 69 | ### SBOM Topic |
|||
| 70 | - OpenVPN has no SBOM currently. |
|||
| 71 | - OpenVPN Inc. needs an SBOM for security requirements. |
|||
| 72 | ||||
| 73 | ### Forums Machine on Community Infrastructure |
|||
| 74 | - New forums system runs on Rocky Linux 8. |
|||
| 75 | - Current state of migration is unknown. |
|||
| 76 | ||||
| 77 | ### Management Interface Documentation |
|||
| 78 | - Documentation on the main website will be updated with info from `doc/management-notes.txt`. |
|||
| 79 | - Novaflash will pick this up eventually. |
|||
| 80 | ||||
| 81 | ### OpenVPN Quickstart Update |
|||
| 82 | - Static-key will be deprecated and contents updated with peer-fingerprint stuff. |
|||
| 83 | - Novaflash will manage updates as time permits. |
|||
| 84 | ||||
| 85 | ### Security Assessment of OpenVPN2 Codebase |
|||
| 86 | - Company agreed to publish. |
|||
| 87 | - Novaflash to push this to marketing for release on site. |
