# IrcMeetings

## Basic info

- **Time:** Wednesday 24 July 2024 at 14:00 CEST (12:00 UTC)
- **Place:** #openvpn-meeting channel on LiberaChat IRC network

## Topics

### Current topics

- **Updated: release openvpn 2.6.12**  
  _This was released on July 18th._

- **New: live route updates**  
  _lev has a proposal to go through, to see if the approach is acceptable to community members._

- **OpenVPN community meetup 2024**  
  _Hotel recommendation added; Hotel Santo in Karlsruhe._  
  _Wiki coordination page: [CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)_  
  _Where: Karlsruhe, Germany. SteamWork, Karlsruhe._  
  _When: Set to 20-22 September 2024._  
  _Shirts: novaflash spoke to matt - he will get us some design in August._

- **community.openvpn.net trac wiki**  
  _novaflash tried out a few things and updated: [NewWiki](https://community.openvpn.net/openvpn/wiki/NewWiki)_  
  _the search continues._  
  _the security level on community.openvpn.net was lowered by one notch. Immediately attacks happened again._  
  _turns out trac has a reflection attack vulnerability and this was mitigated. Let's see how it runs now._  
  _We know we need to replace this but need to find a solution that fits our needs first._

- **forums topics**  
  _novaflash has access and is working on a PoC setup combining old and new on an ubuntu server._

- **Tunnelcrack progress**  
  _Status update on TunnelCrack mitigations:_  
  _The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this._  
  _Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review._  
  _Linux, openvpn2: in progress. openvpn3: in progress._  
  _macOS: to be determined._  
  _iOS: to be determined._  
  _Android: not vulnerable._

- **DCO and Linux upstreaming, API change**  
  _Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._  
  _ordex has sent in **patchset version 5**._  
  _There will be an API change that makes it incompatible with the current implementation._  
  _A graceful solution to that was already discussed and in motion. giaan will be working on this._  
  _(in a nutshell, make OpenVPN understand old and new API, DKMS and kernel versions both will then use new API, then we drop old API)_

- **fixing openvpn3-linux builds in Buildbot**  
  _Mattock has this almost working. Some platforms will have to be skipped because openvpn3-linux / gdbuspp dependencies (Meson in particular) are too old or missing._  
  _As an aside, OpenVPN3 Linux v22 dev for Ubuntu 24.04 LTS and Fedora 39 and 40 are in the release process._  
  _Next step is a 'regular' OpenVPN3 Linux v23 release again._

- **Linux arm64 buildbot workers**  
  _Mattock has done initial research._  
  _Docker seems to support (QEMU) emulated non-native containers, but Buildbot might be missing the glue to make it work._  
  _Patching Buildbot should not be *that* difficult._  
  _External (arm64) Docker host might be a more performant alternative option._

- **run tests of 2.x against openvpn3? how?**  
  _There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes._  
  _This is in the openvpn3 repository._

- **donation collection**  
  _From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._  
  _What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on._  
  _There are some options to consider. There may be existing solutions that we want to consider._  
  _PayPal seems overly expensive with all their fees._  
  _Stripe could be worth considering for credit card processing._  
  _GitHub Sponsors was mentioned as a possible solution, this is worth investigating._  
  _Open Collective was also mentioned, that needs some investigating how that exactly would work for us._

- **website release process**  
  _Waiting for faster way to update community downloads and security advisories on main site._  
  _Again postponed due to issues. Now planned for this week. We'll see._

- **Status of SBOM**  
  _There was a discussion between MaxF and djpig and others._  
  _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._  
  _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._

- **Security mailing list**

- **Static-key mini how-to is outdated.**  
  _This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)_  
  _Company will send this to tech writer to redo based on [GitHub example](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc._  
  _Having a simple guide online will help adoption._

- **OpenVPN 2.6 performance results.**  
  _Tests should cover: gre, ipsec, userland, dco_  
  _Linux, FreeBSD, Windows_  
  _Requires time to be dedicated to doing this, when time available will do it._

- **What's going on with new taskbar icons?**  
  _Matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_  
  _Last update: will be picked up by Selva when he has time._

- **software code signing topic**  
  _Company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing._  
  _In future we could possibly switch community to that same key. Saves having to maintain 2 different keys._  
  _Depends on how hard/easy it is to access company key signing thingee from community infrastructure._  
  _Also, no high priority at the moment, we have a working solution now._
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9