Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# IrcMeetings
2
3
## Basic info
4
5
- **Time:** Wednesday 13 March 2024 at 13:00 CEST (11:00 UTC)
6
- **Place:** #openvpn-meeting channel on LiberaChat IRC network
7
8
## Topics
9
10
### Current topics
11
12
- **New: topic from an OpenVPN Inc contributor to community (illia)**
13
- Would like to discuss the `--inactive` option that disconnects a VPN when it is not sending/receiving more than the set seconds timeout.
14
- One part of it is that openvpn2 only counts outgoing packets and openvpn3 counts incoming and outgoing. Which is correct?
15
- Another part is the type of packets to count - this is all not so clear.
16
- For now, we are counting any packets and ICMP spam from the router resets inactive timeout very often for openvpn3 so it disconnects later than 2.
17
- Current proposal: count also incoming packets for openvpn2 and do not reset inactive timeout on ICMP packets for both ovpn3 and ovpn2.
18
- There was an argument made that "this is how it has been in openvpn2 forever and we had no complaints" but oddly the documentation claims incoming and outgoing is counted.
19
- After looking into this a bit some screwiness was found with tracking the data in openvpn2 that could use fixing, and illia will work on it.
20
- There is some voodoo happening in openvpn2 that skips inactive reset packets and similar magic is missing in ovpn3, so illia will work on that too.
21
22
- **New: breaking DCO changes, how to approach?**
23
- During the upstreaming process to the Linux kernel, some alterations had to be made.
24
- This made the updated implementation different enough from ovpn-dco-v2 that OpenVPN 2.6 won't work with it anymore.
25
- The plan is to adjust OpenVPN 2.6 so it can support the ovpn-dco-v2 delivered as out-of-tree kernel module, and the in-tree new kernel module.
26
- We can then update the out-of-tree kernel module to work in the new way and have a graceful transition period.
27
- So when it goes upstream and is in the Linux kernel, or DCO is installed out-of-tree, it will work the same.
28
- We can later decide on when to drop the support for ovpn-dco-v2 old methods.
29
30
- **Updated: openvpn 2.6.10 release**
31
- There are some Windows related issues to be resolved in this release.
32
- Was planned for this week - pushed to begin next week.
33
34
- **Updated: website release process**
35
- Next week a website release is planned that will enable a new way for updating Community Downloads page.
36
- The new way has a much faster release method separate from the rest of the website's release schedule.
37
38
- **Server-side testing status and next meeting**
39
- Mattock has created a PoC of `--dev null` "does a client connect" check.
40
- Client config has `--dev null` and `ifconfig-noexec`.
41
- Uses an "up" script to stop the parent (openvpn) process gracefully soon after connection initialization.
42
- The "up" script almost certainly includes some Linux-specifics.
43
- Example usage:
44
- `openvpn --config client.conf | grep "Initialization Sequence Completed"`
45
- Integration with `make check`, buildbot, etc. is still missing.
46
- Next steps:
47
- Integrate the PoC with `make check`.
48
- Make the script portable.
49
- Buildbot integration (if required separately).
50
- We want to continue on this topic once a bit more progress has been made.
51
52
- **Forums topics**
53
- A new forum is under construction. But already spammers have found it.
54
- Suggestion is to give openvpn_inc user novaflash and Pippin_ full admin rights so they can help find a solution and help maintain the forums.
55
- To be discussed with ecrist.
56
- Layout and categories look ok?
57
- Access for Mod to delete users that put spam URL in profile and never post a message.
58
- Related to above, Access for Mod to edit user profiles (asks for AdminCP password).
59
- Mod guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic).
60
- Access for mods to logs so one can see what others did.
61
- Email confirmation on register?
62
- [Forgot password or user name?](https://forums-new.openvpn.net/lostpw) and [Contact](https://forums-new.openvpn.net/contact-us).
63
- Considering some existing platform to do discussions next to the forum.
64
65
- **Status of SBOM**
66
- There was a discussion between MaxF and djpig and others.
67
- For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
68
- The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
69
70
- **Debian and Ubuntu snapshot packages and buildbot**
71
- Cloudfront + S3 + aptly PoC is complete and seems to work fine.
72
- Cloudfront caches need to be invalidated when new packages are added or removed, or the apt repository will end up in an inconsistent state almost immediately.
73
- If we use swupdate.openvpn.net to publish the snapshots, we will have to deal with cloudfront + cloudflare.
74
- We can choose to just publish snapshots on build.openvpn.net. This seems the preferred option.
75
- Alternatively, a new S3 bucket + cloudfront can be done. Whatever people like best.
76
- Buildbot integration is missing, but should be fairly straightforward.
77
- This will probably have to wait until `--dev null` is done.
78
79
- **Status of trac/wiki**
80
- No progress since the last meeting.
81
- This will probably have to wait until `--dev null` is done.
82
- Should have access controls so only approved members can edit.
83
84
- **Security mailing list procedure can stand improvement**
85
- To be discussed in more detail later.
86
87
- **Community funding**
88
- Ordex has an initiative he wants to bring up regarding dev resources to be added to the community.
89
- This may tie into the donations topic.
90
- In short, ordex convinced OTF (Open Tech Fund) to provide a "test FOSS funding scheme" to OpenVPN.
91
- This would, for example, allow paying for allocated hours for mattock and cron2 to work on OpenVPN community tasks.
92
- This is to be worked out more and in collaboration between OpenVPN Community, OpenVPN Inc., and OTF.
93
94
- **Donation collection**
95
- What are the options?
96
97
- **Tunnelcrack progress [TunnelCrack community wiki article](wiki:TunnelCrack)**
98
- Current status: when mitigations start appearing, we will mention them in meeting notes.
99
100
- **OpenVPN community meetup 2024**
101
- Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome.
102
- Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged.
103
- When: At the moment tentatively set to 20-22 September 2024.
104
- Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest.
105
- Shirts: There is plenty of time still to prepare a shirt design.
106
107
- **Static-key mini how-to is outdated.**
108
- This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)
109
- The company will send this to a tech writer to redo based on [GitHub doc info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc.
110
- Having a simple guide online will help adoption.
111
112
- **OpenVPN 2.6 performance results.**
113
- Tests should cover: gre, ipsec, userland, dco.
114
- Linux, FreeBSD, Windows.
115
- Requires time to be dedicated to doing this, when time available will do it.
116
117
- **What's going on with new taskbar icons?**
118
- Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)
119
- Last update: will be picked up by selva when he has time.
120
121
- **Software code signing topic**
122
- The company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing.
123
- In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys.
124
- Depends on how hard/easy it is to access the company key signing thing from community infrastructure.
125
- Also, no high priority at the moment, we have a working solution now.
126
127
- **Management interface documentation on the main website will be updated with info from doc/management-notes.txt**
128
- Novaflash will pick this up at some point.