# IrcMeetings ## Basic info - Time: Wednesday 18 September 2024 at 14:00 CEST (12:00 UTC) - Place: #openvpn-meeting channel on LiberaChat IRC network ## Topics ### Current topics - **Updated: OpenVPN community meetup 2024** - Hotel recommendation added; Hotel Santo in Karlsruhe. - Wiki coordination page: [https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024) - Where: Karlsruhe, Germany. SteamWork, Karlsruhe. - When: 20-22 September 2024. - Shirts: T-shirts are in d12fk's possession in Karlsruhe now. - **Updated: DCO and Linux upstreaming, API change** - Upstreaming DCO to Linux is proceeding, it is in review stage at the moment. - ordex has sent in **patchset version 7**. Awaiting review again. - **Updated: community.openvpn.net trac wiki** - Seems mattock managed to get it into a reasonable shape ready for production. - Next step is looking at migrating data from old to new. - **Updated: live route updates** - There's a PR up on GitHub openvpn-rfc for the live route updates proposal. - So far it seems we are good with optional/mandatory options concept, and by default all options are mandatory. - Optional are prefixed with a question mark (?). The idea here is that if a client does not support updating that parameter live it can ignore it. - Whereas without such a prefix, it is mandatory, so if a client cannot update it live, it will do a normal reconnect to ensure changes are implemented. - **forums topics** - novaflash has access and is working on a PoC setup combining old and new on an ubuntu server. - **Tunnelcrack progress** - Status update on TunnelCrack mitigations: - The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this. - Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review. - Linux, openvpn2: in progress. openvpn3: in progress. - macOS: to be determined. - iOS: to be determined. - Android: not vulnerable. - **run tests of 2.x against openvpn3? how?** - There is a 'null client' variant of ovpncli that allows making VPN connections but not fully, for testing purposes. - This is in the openvpn3 repository. - **donation collection** - From earlier exploration, it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations. - What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on. - There are some options to consider. There may be existing solutions that we want to consider. - PayPal seems overly expensive with all their fees. - Stripe could be worth considering for credit card processing. - GitHub Sponsors was mentioned as a possible solution, this is worth investigating. - Open Collective was also mentioned, that needs some investigating how that exactly would work for us. - **website release process** - Waiting for a faster way to update community downloads and security advisories on the main site. - Again postponed due to issues. Now planned for this week. We'll see. - **Status of SBOM** - There was a discussion between MaxF and djpig and others. - For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does. - The interesting use-case for an SBOM is really the OpenVPN Windows GUI client. - **Security mailing list** - **Static-key mini how-to is outdated.** - This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/) - The company will send this to a tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc. Having a simple guide online will help adoption. - **OpenVPN 2.6 performance results.** - Tests should cover: gre, ipsec, userland, dco - Linux, FreeBSD, Windows - Requires time to be dedicated to doing this, when time available will do it. - **What's going on with new taskbar icons?** - Matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595) - Last update: will be picked up by selva when he has time. - **software code signing topic** - The company switched EV code signing to cloudhsm, this is the same cert type we use for driver signing, is also suitable for binary signing. - In the future, we could possibly switch the community to that same key. Saves having to maintain 2 different keys. - Depends on how hard/easy it is to access company key signing thingee from community infrastructure. - Also, no high priority at the moment, we have a working solution now.
