# Basic info - **Time:** Wednesday 6 September 2023 at 13:00 CEST (11:00 UTC) - **Place:** #openvpn-meeting channel on LiberaChat IRC network # Topics ## Current topics ### OpenVPN Release Process Topics - djpig explained the release process to uddr. - dazo explained the copr release process to djpig. - When 2.6.7 goes out, it will be done by uddr under the supervision of djpig to ensure we have a good backup. - There was also a request in [OpenVPN Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig thinks it would be fairly doable to copy/paste that info to GitHub as well. ### Tunnelcrack Publication - Published at [Tunnelcrack](https://tunnelcrack.mathyvanhoef.com). - Acknowledged issues and committed to implementing mitigations. - A draft is being put together [here](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/). - The company will discuss possible mitigations, add them to the draft, and publish it on the community side. - The main website will reference this document and contribute to making the mitigations happen. ### Security Assessment Review - Currently, the fixes are being reviewed. ### Hackathon Arrangements - See [Hackathon 2023](https://community.openvpn.net/openvpn/wiki/Hackathon2023). - Topics include deprecation of NTLM and discussion about merchandise like t-shirts. ### License Amendment for OpenVPN2 - To solve openssl/mbedtls licensing issues, there are 5 contributions that need to be reimplemented/removed. - One contribution was reimplemented by plaisthos and merged already, so 4 remain. - Discussion about keeping old exceptions for libressl and mbedtls related changes. ### Handling Coverity Scans/Results - The idea was to use the company's coverity code scanner, but there are licensing issues. - There is a free version (Travis CI) that we used in the past but stopped working. - Focus on getting the free service working again. - A patch is available for GHA and just needs to be merged to master. ### Static-Key Mini How-To is Outdated - The page is badly outdated: [Static-Key Mini HowTo](https://openvpn.net/community-resources/static-key-mini-howto/). - The company will send this to a tech writer to redo based on the information from [GitHub](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst). - A simple guide online will help adoption. ### Website Release Process Woes - The website team is working on migrating community downloads content to a new CMS system. ## Topics on Standby ### OpenVPN 2.6 Performance Results - Tests should cover various configurations and operating systems. - Requires time to be dedicated to doing this. ### New Taskbar Icons - Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595). - Update: will be picked up by Selva when he has time. ### Security Mailing List - Company is trying to get to SOC2 compliance. - Might need a simple NDA to be signed by recipients of emails to security@openvpn.net. - The community needs to review if the standard NDA used for contractors is suitable. ### Another Key Signing Topic - Company switched EV code signing to CloudHSM. - Possible future switch for community to the same key. - Depends on access ease from community infrastructure. ### SBOM Topic - OpenVPN has no SBOM currently. - OpenVPN Inc. needs an SBOM for security requirements. ### Forums Machine on Community Infrastructure - New forums system runs on Rocky Linux 8. - Current state of migration is unknown. ### Management Interface Documentation - Documentation on the main website will be updated with info from `doc/management-notes.txt`. - Novaflash will pick this up eventually. ### OpenVPN Quickstart Update - Static-key will be deprecated and contents updated with peer-fingerprint stuff. - Novaflash will manage updates as time permits. ### Security Assessment of OpenVPN2 Codebase - Company agreed to publish. - Novaflash to push this to marketing for release on site.
