Blame
| 6f02e7 | Samuli Seppänen | 2025-01-29 06:40:08 | 1 | # Basic info |
| 2 | ||||
| 3 | - **Time:** Wednesday 29 November 2023 at 13:00 CEST (11:00 UTC) |
|||
| 4 | - **Place:** #openvpn-meeting channel on LiberaChat IRC network |
|||
| 5 | ||||
| 6 | # Topics |
|||
| 7 | ||||
| 8 | ## Current topics |
|||
| 9 | ||||
| 10 | - **Meeting today cancelled due to lack of attendance** |
|||
| 11 | ||||
| 12 | - **Publish security assessment of OpenVPN2 on main website.** |
|||
| 13 | _Trail of Bits security audit of OpenVPN2 published:_ [https://openvpn.net/blog/trail-of-bits/](https://openvpn.net/blog/trail-of-bits/) |
|||
| 14 | ||||
| 15 | - **Website release process woes** |
|||
| 16 | _Website team reports they are going to publish the new CMS for community downloads and security advisories next week._ |
|||
| 17 | ||||
| 18 | - **TLS 1.0 PRF problem** |
|||
| 19 | _OpenVPN has used a scheme based on the TLS 1.0 PRF with MD5+SHA1 in the past. Since OpenVPN 2.6.0+ and 3.6.0+ using Keying Material Exporters (RFC 5705) is preferred as modern alternative to that._ |
|||
| 20 | _If one or both sides are older versions of OpenVPN like 2.5 and use the older method of making key material, there can be a problem._ |
|||
| 21 | _For example, on platforms like RHEL9 with FIPS enabled, you cannot use TLS 1.0 PRF with MD5+SHA1. So even for these special cases MD5 has become impossible in this particular situation._ |
|||
| 22 | _As a practical example, this means OpenVPN 2.5 on RHEL9 with FIPS enabled cannot work at all. But 2.6 does work because it uses TLS export, but only if the other side supports TLS export too._ |
|||
| 23 | _We should first of all document this. But second, having a self-test in OpenVPN that warns of this situation can be beneficial._ |
|||
| 24 | ||||
| 25 | - **License amendment for OpenVPN2 to solve openssl/mbedtls licensing issues** |
|||
| 26 | _For new contributions the new license already applies._ |
|||
| 27 | _The --tls-export-cert option needs to be removed, and reimplemented. dazo sent in the patch to remove it, plaisthos will reimplement it._ |
|||
| 28 | _Then it is up to dazo to review things so we can work on finalizing this._ |
|||
| 29 | _One of the last tasks is reviewing if remaining items are trivial patches, and maybe get legal advice on those if necessary._ |
|||
| 30 | ||||
| 31 | - **Donations for OpenVPN community** |
|||
| 32 | _There is currently no place to donate money to the community._ |
|||
| 33 | _The question is, do we want to allow donations? The answer is yes._ |
|||
| 34 | _We need to figure out how to deal with that legally, and what payment methods to accept and how._ |
|||
| 35 | _Probably credit card is a must. Maybe PayPal as well. Bitcoin seems to encounter some resistance in the discussions._ |
|||
| 36 | _We definitely do not want the donation thing to be forced - have a mechanism to do it, but keep it out of the way._ |
|||
| 37 | _Random things yelled out (to investigate): legal entity? stripe? PayPal? credit card? open collective? GitHub sponsors? Linux foundation? sf conservancy?_ |
|||
| 38 | ||||
| 39 | - **Tunnelcrack progress** [TunnelCrack community wiki article](/wiki/TunnelCrack) |
|||
| 40 | _Current status: when mitigations start appearing we will mention them in meeting notes._ |
|||
| 41 | ||||
| 42 | - **OpenVPN community meetup 2024** |
|||
| 43 | _Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome._ |
|||
| 44 | _Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged._ |
|||
| 45 | _When: At the moment tentatively set to 20-22 September 2024._ |
|||
| 46 | _Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest._ |
|||
| 47 | _Shirts: There is plenty of time still to prepare a shirt design._ |
|||
| 48 | ||||
| 49 | - **Static-key mini how-to is outdated.** |
|||
| 50 | _This page is outdated badly:_ [Static Key Mini How-to](https://openvpn.net/community-resources/static-key-mini-howto/) |
|||
| 51 | _Company will send this to tech writer to redo based on [GitHub Example Fingerprint](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc._ |
|||
| 52 | _Having a simple guide online will help adoption._ |
|||
| 53 | ||||
| 54 | - **OpenVPN release process topics** |
|||
| 55 | _There was a request in [GitHub Issue #397](https://github.com/OpenVPN/openvpn/issues/397) to have releases on GitHub as well. djpig seems to think it would be fairly doable to copy/paste that info to GitHub as well. We could do this during a next release._ |
|||
| 56 | ||||
| 57 | - **OpenVPN 2.6 performance results.** |
|||
| 58 | _Tests should cover: GRE, IPSec, userland, DCO |
|||
| 59 | Linux, FreeBSD, Windows |
|||
| 60 | Requires time to be dedicated to doing this |
|||
| 61 | When time available will do it._ |
|||
| 62 | ||||
| 63 | - **What's going on with new taskbar icons?** |
|||
| 64 | _Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_ |
|||
| 65 | _**Update:** will be picked up by Selva when he has time._ |
|||
| 66 | ||||
| 67 | - **security@openvpn.net mailing list** |
|||
| 68 | _Company is trying to get to SOC2 compliance._ |
|||
| 69 | _Probably will need a simple NDA to be signed by recipients of emails to security@openvpn.net._ |
|||
| 70 | _Company guy took standard NDA we use for contractors, suggests to use that._ |
|||
| 71 | _Novaflash thinks we should review that first to see if it's really suitable or not, community members are not contractors after all._ |
|||
| 72 | ||||
| 73 | - **Another key signing topic** |
|||
| 74 | _Company switched EV code signing to CloudHSM, this is the same cert type we use for driver signing, is also suitable for binary signing._ |
|||
| 75 | _In future, we could possibly switch community to that same key. Saves having to maintain 2 different keys._ |
|||
| 76 | _Depends on how hard/easy it is to access company key signing thing from community infrastructure._ |
|||
| 77 | _Also no high priority at the moment, we have a working solution now._ |
|||
| 78 | ||||
| 79 | - **SBOM topic** |
|||
| 80 | _Cron2 was asked if OpenVPN has a software bill of materials. Answer was no._ |
|||
| 81 | _Coincidentally, in OpenVPN Inc a security requirement is to have an SBOM so this is on our list of things to do._ |
|||
| 82 | _When we pick up this task we can coordinate on it._ |
|||
| 83 | ||||
| 84 | - **Forums machine on community infrastructure is only non-Linux system.** |
|||
| 85 | _Mattock made a new forums system that runs on Rocky Linux 8 as agreed with ecrist._ |
|||
| 86 | _Ecrist has looked at it but the current state of the migration is unknown._ |
|||
| 87 | ||||
| 88 | - **Management interface documentation on main website will be updated with info from doc/management-notes.txt** |
|||
| 89 | _Novaflash will pick this up at some point._ |
