Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# IrcMeetings
2
3
## Basic info
4
5
- **Time**: Wednesday 9th October 2024 at 14:00 CEST (12:00 UTC)
6
- **Place**: #openvpn-meeting channel on LiberaChat IRC network
7
8
## Topics
9
10
### Current topics
11
12
- **Updated: DCO and Linux upstreaming, API change**
13
_Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._
14
_ordex is collecting feedback on **patchset version 8**. Plan is to send v9 after collecting feedback._
15
_During meetup it was discussed that if the patchset does not make it into the kernel before 2.7 we should update the out-of-tree module to match the new API anyway. So that 2.7 supports the new API and we need no or minimal further changes to work with the eventual in-tree version._
16
17
- **Updated: buildbot improvements**
18
_djpig reports that the first arm64 architecture buildbot agent now works. We can add more workers as required._
19
_mattock has a patch to split the mails for different project to different mail addresses._
20
_The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore._
21
_Instead we could create a openvpn3-builds@ ML. djpig will look into that._
22
23
- **Updated: t_server_null improvements**
24
_The tests against latest git master server against older openvpn client versions are almost done._
25
26
- **Release 2.7**
c9d9c9 Samuli Seppänen 2025-01-29 12:06:32 27
_[StatusOfOpenvpn27](../../Development/StatusOfOpenvpn27) was updated with the results from Karlsruhe meetup._
6f02e7 Samuli Seppänen 2025-01-29 06:40:08 28
_compare [CommunityMeetup2024](wiki:CommunityMeetup2024)._
29
_Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right._
30
31
- **multi-socket patch series**
32
_New version of the patch series is posted. Reviews welcome :)_
33
34
- **DATA_V3 patch**
35
_plaisthos has written a new draft for new key handling for the data channel based on discussions in Karlsruhe._
36
_See [https://github.com/OpenVPN/openvpn-rfc/pull/5](https://github.com/OpenVPN/openvpn-rfc/pull/5). Feedback welcome :)_
37
38
- **2.7 security audit**
39
_ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code._
40
41
### Backlog
42
43
- **--dns patch review upcoming**
44
_DNS patches were discussed during Meetup. d12fk will provide them for review real soon._
45
46
- **live route updates**
47
_PR to RFC was merged. ([https://github.com/OpenVPN/openvpn-rfc/pull/4](https://github.com/OpenVPN/openvpn-rfc/pull/4))_
48
_Now we need to complete the actual implementations._
49
_Implementation for OpenVPN v2 will be looked at by ordex and his team._
50
_lev is working on (client-side) implementation in OpenVPN 3._
51
52
- **community.openvpn.net trac wiki**
53
_Seems mattock managed to get it into a reasonable shape ready for production._
54
_Some required changes to otterwiki have been submitted upstream._
55
_Next step is looking at migrating data from old to new._
56
_Also djpig needs to provide an EC2 instance in the community account for hosting production._
57
58
- **forums topics**
59
_novaflash has access and is working on a PoC setup combining old and new on an ubuntu server._
60
61
- **Tunnelcrack progress**
62
_Status update on TunnelCrack mitigations:_
63
_The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this._
64
_Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review._
65
_Linux, openvpn2: in progress. openvpn3: in progress._
66
_macOS: to be determined._
67
_iOS: to be determined._
68
_Android: not vulnerable._
69
70
- **run tests of 2.x against openvpn3? how?**
71
_There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes._
72
_This is in the openvpn3 repository._
73
74
- **donation collection**
75
_From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._
76
_What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on._
77
_There are some options to consider. There may be existing solutions that we want to consider._
78
_PayPal seems overly expensive with all their fees._
79
_Stripe could be worth considering for credit card processing._
80
_GitHub Sponsors was mentioned as a possible solution, this is worth investigating._
81
_Open Collective was also mentioned, that needs some investigating how that exactly would work for us._
82
83
- **Community AWS account governance**
84
_Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization_
85
_With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella._
86
_Requires further discussion whether that is something we want._
87
88
- **website release process**
89
_Waiting for faster way to update community downloads and security advisories on main site._
90
_Again postponed due to issues. Now planned for this week. We'll see._
91
92
- **Status of SBOM**
93
_There was a discussion between MaxF and djpig and others._
94
_For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
95
_The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
96
97
- **Security mailing list**
98
99
- **Static-key mini how-to is outdated.**
100
_This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)_
101
_company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc._
102
_having a simple guide online will help adoption_
103
104
- **OpenVPN 2.6 performance results.**
105
_tests should cover: gre, ipsec, userland, dco_
106
_linux, freebsd, windows_
107
_requires time to be dedicated to doing this, when time available will do it_
108
109
- **What's going on with new taskbar icons?**
110
_matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
111
_last update: will be picked up by selva when he has time_
112
113
- **software code signing topic**
114
_company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
115
_in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
116
_depends on how hard/easy it is to access company key signing thingee from community infrastructure._
117
_also no high priority at the moment, we have a working solution now._