Blame
| 6f02e7 | Samuli Seppänen | 2025-01-29 06:40:08 | 1 | # IrcMeetings |
| 2 | ||||
| 3 | ## Basic info |
|||
| 4 | ||||
| 5 | - **Time:** Wednesday 13 March 2024 at 13:00 CEST (11:00 UTC) |
|||
| 6 | - **Place:** #openvpn-meeting channel on LiberaChat IRC network |
|||
| 7 | ||||
| 8 | ## Topics |
|||
| 9 | ||||
| 10 | ### Current topics |
|||
| 11 | ||||
| 12 | - **New: topic from an OpenVPN Inc contributor to community (illia)** |
|||
| 13 | - Would like to discuss the `--inactive` option that disconnects a VPN when it is not sending/receiving more than the set seconds timeout. |
|||
| 14 | - One part of it is that openvpn2 only counts outgoing packets and openvpn3 counts incoming and outgoing. Which is correct? |
|||
| 15 | - Another part is the type of packets to count - this is all not so clear. |
|||
| 16 | - For now, we are counting any packets and ICMP spam from the router resets inactive timeout very often for openvpn3 so it disconnects later than 2. |
|||
| 17 | - Current proposal: count also incoming packets for openvpn2 and do not reset inactive timeout on ICMP packets for both ovpn3 and ovpn2. |
|||
| 18 | - There was an argument made that "this is how it has been in openvpn2 forever and we had no complaints" but oddly the documentation claims incoming and outgoing is counted. |
|||
| 19 | - After looking into this a bit some screwiness was found with tracking the data in openvpn2 that could use fixing, and illia will work on it. |
|||
| 20 | - There is some voodoo happening in openvpn2 that skips inactive reset packets and similar magic is missing in ovpn3, so illia will work on that too. |
|||
| 21 | ||||
| 22 | - **New: breaking DCO changes, how to approach?** |
|||
| 23 | - During the upstreaming process to the Linux kernel, some alterations had to be made. |
|||
| 24 | - This made the updated implementation different enough from ovpn-dco-v2 that OpenVPN 2.6 won't work with it anymore. |
|||
| 25 | - The plan is to adjust OpenVPN 2.6 so it can support the ovpn-dco-v2 delivered as out-of-tree kernel module, and the in-tree new kernel module. |
|||
| 26 | - We can then update the out-of-tree kernel module to work in the new way and have a graceful transition period. |
|||
| 27 | - So when it goes upstream and is in the Linux kernel, or DCO is installed out-of-tree, it will work the same. |
|||
| 28 | - We can later decide on when to drop the support for ovpn-dco-v2 old methods. |
|||
| 29 | ||||
| 30 | - **Updated: openvpn 2.6.10 release** |
|||
| 31 | - There are some Windows related issues to be resolved in this release. |
|||
| 32 | - Was planned for this week - pushed to begin next week. |
|||
| 33 | ||||
| 34 | - **Updated: website release process** |
|||
| 35 | - Next week a website release is planned that will enable a new way for updating Community Downloads page. |
|||
| 36 | - The new way has a much faster release method separate from the rest of the website's release schedule. |
|||
| 37 | ||||
| 38 | - **Server-side testing status and next meeting** |
|||
| 39 | - Mattock has created a PoC of `--dev null` "does a client connect" check. |
|||
| 40 | - Client config has `--dev null` and `ifconfig-noexec`. |
|||
| 41 | - Uses an "up" script to stop the parent (openvpn) process gracefully soon after connection initialization. |
|||
| 42 | - The "up" script almost certainly includes some Linux-specifics. |
|||
| 43 | - Example usage: |
|||
| 44 | - `openvpn --config client.conf | grep "Initialization Sequence Completed"` |
|||
| 45 | - Integration with `make check`, buildbot, etc. is still missing. |
|||
| 46 | - Next steps: |
|||
| 47 | - Integrate the PoC with `make check`. |
|||
| 48 | - Make the script portable. |
|||
| 49 | - Buildbot integration (if required separately). |
|||
| 50 | - We want to continue on this topic once a bit more progress has been made. |
|||
| 51 | ||||
| 52 | - **Forums topics** |
|||
| 53 | - A new forum is under construction. But already spammers have found it. |
|||
| 54 | - Suggestion is to give openvpn_inc user novaflash and Pippin_ full admin rights so they can help find a solution and help maintain the forums. |
|||
| 55 | - To be discussed with ecrist. |
|||
| 56 | - Layout and categories look ok? |
|||
| 57 | - Access for Mod to delete users that put spam URL in profile and never post a message. |
|||
| 58 | - Related to above, Access for Mod to edit user profiles (asks for AdminCP password). |
|||
| 59 | - Mod guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic). |
|||
| 60 | - Access for mods to logs so one can see what others did. |
|||
| 61 | - Email confirmation on register? |
|||
| 62 | - [Forgot password or user name?](https://forums-new.openvpn.net/lostpw) and [Contact](https://forums-new.openvpn.net/contact-us). |
|||
| 63 | - Considering some existing platform to do discussions next to the forum. |
|||
| 64 | ||||
| 65 | - **Status of SBOM** |
|||
| 66 | - There was a discussion between MaxF and djpig and others. |
|||
| 67 | - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does. |
|||
| 68 | - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client. |
|||
| 69 | ||||
| 70 | - **Debian and Ubuntu snapshot packages and buildbot** |
|||
| 71 | - Cloudfront + S3 + aptly PoC is complete and seems to work fine. |
|||
| 72 | - Cloudfront caches need to be invalidated when new packages are added or removed, or the apt repository will end up in an inconsistent state almost immediately. |
|||
| 73 | - If we use swupdate.openvpn.net to publish the snapshots, we will have to deal with cloudfront + cloudflare. |
|||
| 74 | - We can choose to just publish snapshots on build.openvpn.net. This seems the preferred option. |
|||
| 75 | - Alternatively, a new S3 bucket + cloudfront can be done. Whatever people like best. |
|||
| 76 | - Buildbot integration is missing, but should be fairly straightforward. |
|||
| 77 | - This will probably have to wait until `--dev null` is done. |
|||
| 78 | ||||
| 79 | - **Status of trac/wiki** |
|||
| 80 | - No progress since the last meeting. |
|||
| 81 | - This will probably have to wait until `--dev null` is done. |
|||
| 82 | - Should have access controls so only approved members can edit. |
|||
| 83 | ||||
| 84 | - **Security mailing list procedure can stand improvement** |
|||
| 85 | - To be discussed in more detail later. |
|||
| 86 | ||||
| 87 | - **Community funding** |
|||
| 88 | - Ordex has an initiative he wants to bring up regarding dev resources to be added to the community. |
|||
| 89 | - This may tie into the donations topic. |
|||
| 90 | - In short, ordex convinced OTF (Open Tech Fund) to provide a "test FOSS funding scheme" to OpenVPN. |
|||
| 91 | - This would, for example, allow paying for allocated hours for mattock and cron2 to work on OpenVPN community tasks. |
|||
| 92 | - This is to be worked out more and in collaboration between OpenVPN Community, OpenVPN Inc., and OTF. |
|||
| 93 | ||||
| 94 | - **Donation collection** |
|||
| 95 | - What are the options? |
|||
| 96 | ||||
| 97 | - **Tunnelcrack progress [TunnelCrack community wiki article](wiki:TunnelCrack)** |
|||
| 98 | - Current status: when mitigations start appearing, we will mention them in meeting notes. |
|||
| 99 | ||||
| 100 | - **OpenVPN community meetup 2024** |
|||
| 101 | - Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it, as we want to encourage developers and those interested in contributing to feel welcome. |
|||
| 102 | - Where: Karlsruhe, Germany. It is a relatively central location in Europe and is fairly easily reachable by train. A meeting location is yet to be arranged. |
|||
| 103 | - When: At the moment tentatively set to 20-22 September 2024. |
|||
| 104 | - Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest. |
|||
| 105 | - Shirts: There is plenty of time still to prepare a shirt design. |
|||
| 106 | ||||
| 107 | - **Static-key mini how-to is outdated.** |
|||
| 108 | - This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/) |
|||
| 109 | - The company will send this to a tech writer to redo based on [GitHub doc info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that GitHub doc. |
|||
| 110 | - Having a simple guide online will help adoption. |
|||
| 111 | ||||
| 112 | - **OpenVPN 2.6 performance results.** |
|||
| 113 | - Tests should cover: gre, ipsec, userland, dco. |
|||
| 114 | - Linux, FreeBSD, Windows. |
|||
| 115 | - Requires time to be dedicated to doing this, when time available will do it. |
|||
| 116 | ||||
| 117 | - **What's going on with new taskbar icons?** |
|||
| 118 | - Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595) |
|||
| 119 | - Last update: will be picked up by selva when he has time. |
|||
| 120 | ||||
| 121 | - **Software code signing topic** |
|||
| 122 | - The company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing. |
|||
| 123 | - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys. |
|||
| 124 | - Depends on how hard/easy it is to access the company key signing thing from community infrastructure. |
|||
| 125 | - Also, no high priority at the moment, we have a working solution now. |
|||
| 126 | ||||
| 127 | - **Management interface documentation on the main website will be updated with info from doc/management-notes.txt** |
|||
| 128 | - Novaflash will pick this up at some point. |
