Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# IrcMeetings
2
3
## Basic info
4
5
- **Time:** Wednesday 6 November 2024 at 14:00 CEST (12:00 UTC)
6
- **Place:** #openvpn-meeting channel on LiberaChat IRC network
7
8
## Topics
9
10
### Current topics
11
12
- **Updated: DCO windows multi-peer**
13
_Kernelspace looks done, now working on userspace stuff. It listens for incoming clients and attempts handshake. Still a bit of work to do._
14
15
- **Updated: multi-socket patch series**
16
_This has been rebased and comments addressed, waiting for another review._
17
18
- **Updated: data format v3 / epoch data keys**
19
_Some comments from syzzer came in and were addressed on the RFC addition for epoch keys:_
20
_See [RFC Pull Request #5](https://github.com/OpenVPN/openvpn-rfc/pull/5)._
21
_plaisthos is working to implement it in openvpn3 first._
22
23
- **Updated: push_update / live route updates**
24
_Lev added some clarifying comments to the push_update section in the RFC, as per popular demand._
25
_Implementation of push_update for OpenVPN v2 will be looked at by ordex and his team._
26
27
- **New: TLS-exporter in mbedtls**
28
_Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls._
29
_maxf reports he's making some progress on implementing this._
30
31
- **DCO and Linux upstreaming, API change**
32
_Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._
33
_ordex sent in **patchset version 11**. Awaiting feedback._
34
35
- **buildbot improvements**
36
_cron2 requests that we pretty please have a mingw build in gerrit. djpig indicates next week should be possible._
37
_mattock has a patch to split the mails for different project to different mail addresses. The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore._
38
_Instead we could create a openvpn3-builds@ ML. djpig will look into that._
39
40
- **where next community meeting**
41
_Italy or Spain have been mentioned._
42
_Beer: yes._
43
_T-shirts: yes._
44
45
- **t_server_null improvements**
46
_The tests against latest git master server against older openvpn client versions are almost done._
47
48
- **Release 2.7**
c9d9c9 Samuli Seppänen 2025-01-29 12:06:32 49
_../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup._
6f02e7 Samuli Seppänen 2025-01-29 06:40:08 50
_compare wiki:CommunityMeetup2024._
51
_Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right._
52
53
### Backlog
54
55
- **2.7 security audit**
56
_ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code._
57
58
- **--dns patch review upcoming**
59
_DNS patches were discussed during Meetup. d12fk will provide them for review real soon._
60
61
- **community.openvpn.net trac wiki**
62
_Seems mattock managed to get it into a reasonable shape ready for production._
63
_Some required changes to otterwiki have been submitted upstream._
64
_Next step is looking at migrating data from old to new._
65
_Also djpig needs to provide an EC2 instance in the community account for hosting production._
66
67
- **forums topics**
68
_novaflash has access and is working on a PoC setup combining old and new on an ubuntu server._
69
70
- **Tunnelcrack progress**
71
_Status update on TunnelCrack mitigations:_
72
_The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this._
73
_Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review._
74
_Linux, openvpn2: in progress. openvpn3: in progress._
75
_macOS: to be determined._
76
_iOS: to be determined._
77
_Android: not vulnerable._
78
79
- **run tests of 2.x against openvpn3? how?**
80
_There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes._
81
_This is in the openvpn3 repository._
82
83
- **donation collection**
84
_From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._
85
_What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on._
86
_There are some options to consider. There may be existing solutions that we want to consider._
87
_PayPal seems overly expensive with all their fees._
88
_Stripe could be worth considering for credit card processing._
89
_GitHub Sponsors was mentioned as a possible solution, this is worth investigating._
90
_Open Collective was also mentioned, that needs some investigating how that exactly would work for us._
91
92
- **Community AWS account governance**
93
_Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization_
94
_With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella._
95
_Requires further discussion whether that is something we want._
96
97
- **website release process**
98
_Waiting for faster way to update community downloads and security advisories on main site._
99
_Again postponed due to issues. Now planned for this week. We'll see._
100
101
- **Status of SBOM**
102
_There was a discussion between MaxF and djpig and others._
103
_For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
104
_The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
105
106
- **Static-key mini how-to is outdated.**
107
_This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)_
108
_company will send this to tech writer to redo based on [GitHub Info](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) and also retain a link to that github doc._
109
_having a simple guide online will help adoption._
110
111
- **OpenVPN 2.6 performance results.**
112
_tests should cover: gre, ipsec, userland, dco_
113
_linux, freebsd, windows_
114
_requires time to be dedicated to doing this, when time available will do it._
115
116
- **What's going on with new taskbar icons?**
117
_matt provided icons in [GitHub Issue #595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
118
_last update: will be picked up by selva when he has time._
119
120
- **software code signing topic**
121
_company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
122
_in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
123
_depends on how hard/easy it is to access company key signing thingee from community infrastructure._
124
_also no high priority at the moment, we have a working solution now._