# Basic info

- **Time:** Wednesday 27 September 2023 at 13:00 CEST (11:00 UTC)
- **Place:** #openvpn-meeting channel on LiberaChat IRC network

**Note:** Next week's meeting cancelled because of hackathon meeting next week.

# Topics

## Current topics

- **Security assessment of OpenVPN2 codebase.**
  - *Update:* Publishing this is currently being handled, it requires some preparation and internal reviews that is ongoing.

- **Hackathon t-shirts**
  - *Update:* Shirts arrived. [View Shirt](https://crashed.computer/shirt2023.jpg)
  - Back of shirt will be as usual with all previous locations.

- **Hackathon arrangements**
  - See [Hackathon 2023 Wiki](https://community.openvpn.net/openvpn/wiki/Hackathon2023)
  - Topics collected and placed in wiki page.

- **Tunnelcrack published now** [Tunnelcrack](https://tunnelcrack.mathyvanhoef.com)
  - We acknowledge issues and commit to implementing mitigations.
  - We'll put together a draft [here](https://cryptpad.fr/pad/#/2/pad/edit/TWa9QJYxSQLjllhUfstlb13T/)
  - Discussions about possible mitigations are ongoing within the company. Any mitigation plans will be added to the draft and published on the community side. The company will then reference that document on the main website and contribute/participate in making the mitigations happen.

- **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues**
  - *Update:* Dazo is working to make a full overview of the 'considered trivial' patches, and will then reach out to a legal expert.
  - There are some contributors that didn't respond; need to reimplement those items.
  - MaxF has volunteered to help with any mbedtls related required changes.
  - Plaisthos has volunteered to reimplement tls-export-cert.
  - James Bottomley's contribution will be removed as he does not agree to the license change.

- **How to handle coverity scans/results**
  - Free coverity open source code scanner now working on OpenVPN2 codebase again.

- **Static-key mini how-to is outdated.**
  - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
  - Company will send this to tech writer to redo based on [GitHub Doc](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc.
  - Having a simple guide online will help adoption.

- **Website release process woes**
  - Website team is working on migrating community downloads content to new CMS system.
  - Novaflash pushed them on coming up with a firm date, getting tired of this.

## Topics on standby

- **OpenVPN release process topics**
  - There was a request in [GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well.
  - Djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well.
  - We could do this during the next release.

- **OpenVPN 2.6 performance results.**
  - Tests should cover: GRE, IPSec, userland, DCO, Linux, FreeBSD, Windows.
  - Requires time to be dedicated to doing this.
  - When time available will do it.

- **What's going on with new taskbar icons?**
  - Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)
  - **Update:** Will be picked up by Selva when he has time.

- **security@openvpn.net mailing list**
  - Company is trying to get to SOC2 compliance.
  - Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net.
  - Company guy took standard NDA we use for contractors, suggests to use that.
  - Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all.

- **Another key signing topic**
  - Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing.
  - In future we could possibly switch community to that same key. Saves having to maintain 2 different keys.
  - Depends on how hard/easy it is to access company key signing thing from community infrastructure.
  - Also, no high priority at the moment, we have a working solution now.

- **SBOM topic**
  - Cron2 was asked if OpenVPN has a software bill of materials. Answer was no.
  - Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do.
  - When we pick up this task we can coordinate on it.

- **Forums machine on community infrastructure is only non-Linux system.**
  - Mattock made a new forums system that runs on Rocky Linux 8 as agreed with Ecrist.
  - Ecrist has looked at it but the current state of the migration is unknown.

- **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
  - Novaflash will pick this up at some point.

- **[OpenVPN Quickstart](https://openvpn.net/community-resources/openvpn-quickstart/) will be updated from /doc/man-sections/example-fingerprint.rst information.**
  - Static-key will be deprecated and contents updated with peer-fingerprint stuff.
  - Novaflash will pick this up again as time permits and other more important topics are done.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9