Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# IrcMeetings
2
3
## Basic info
4
5
- **Time:** Wednesday 20 November 2024 at 14:00 CEST (12:00 UTC)
6
- **Place:** #openvpn-meeting channel on LiberaChat IRC network
7
8
## Topics
9
10
### Current topics
11
12
- **Updated: DCO Linux upstreaming**
13
Upstreaming DCO to Linux is proceeding, it is in review stage at the moment.
14
ordex intended to send out patchset v12 but was delayed due to illness. Now expected this week.
15
16
- **Updated: data format v3 / epoch data keys**
17
RFC is here: [https://github.com/OpenVPN/openvpn-rfc/pull/5](https://github.com/OpenVPN/openvpn-rfc/pull/5).
18
plaisthos is working to implement it in openvpn3 first.
19
MaxF reviewed the RFC and commented that it looks good.
20
21
- **Updated: DCO windows multi-peer**
22
Preparing patchset for the userspace implementation.
23
24
- **Updated: t_server_null improvements**
25
The LWIP ping testing in t_server_null.sh is somewhat working.
26
It is a bit tricky to get it right but then it seems to be working.
27
mattock will prepare a patch.
28
29
- **Updated: community.openvpn.net wiki**
30
A more suitable production deployment schema for otterwiki has been submitted upstream. That does not block us however.
31
mattock is ready to proceed and needs an EC2 instance in the community account for hosting production.
32
This instance can have some new address so we can start setting it up and migrating content.
33
After migrating data we can then remove the old wiki and put the new wiki on the address of the old one.
34
djpig or uddr35 can help to provide the instance and give mattock full access to it so he can then deploy the necessary otterwiki deployment on it.
35
36
- **New: snapshot releases via Chocolatey software**
37
mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.
38
Seems like the maintainer is amenable to helping us achieve that goal.
39
40
- **Updated: --dns patch review upcoming**
41
d12fk patches are being made ready for gerrit review now - should arrive before next meeting.
42
43
- **multi-socket patch series**
44
Now in review.
45
46
- **push_update / live route updates**
47
There have been some initial tests on a server implementation in PG.
48
There is a server-side bug that will be fixed in PG, and a request to support a few more options (keepalive options).
49
lev__ will add keepalive to OpenVPN3 code.
50
mrbff and ordex will implement the openvpn2 server and client support for push_update.
51
52
- **TLS-exporter in mbedtls**
53
Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls.
54
maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work.
55
56
- **buildbot improvements**
57
cron2 requests that we pretty please have a mingw build in gerrit. djpig indicates next week should be possible.
58
mattock has a patch to split the mails for different project to different mail addresses. The idea is to split openvpn3 and openvpn3-linux out so it doesn't go to openvpn-builds@ ML anymore.
59
Instead we could create a openvpn3-builds@ ML. djpig will look into that.
60
61
- **where next community meeting**
62
Italy or Spain have been mentioned.
63
Beer: yes.
64
T-shirts: yes.
65
66
- **Release 2.7**
c9d9c9 Samuli Seppänen 2025-01-29 12:06:32 67
../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup.
6f02e7 Samuli Seppänen 2025-01-29 06:40:08 68
compare wiki:CommunityMeetup2024.
69
Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right.
70
71
---
72
73
### Backlog
74
75
- **2.7 security audit**
76
ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.
77
78
- **forums topics**
79
novaflash has access and is working on a PoC setup combining old and new on an ubuntu server.
80
81
- **Tunnelcrack progress [TunnelCrack community wiki article](https://openvpn.net/community-resources/tunnelcrack)**
82
Status update on TunnelCrack mitigations:
83
The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
84
Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review.
85
Linux, openvpn2: in progress. openvpn3: in progress.
86
macOS: to be determined.
87
iOS: to be determined.
88
Android: not vulnerable.
89
90
- **run tests of 2.x against openvpn3? how?**
91
There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes.
92
This is in the openvpn3 repository.
93
94
- **donation collection**
95
From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
96
What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
97
There are some options to consider. There may be existing solutions that we want to consider.
98
PayPal seems overly expensive with all their fees.
99
Stripe could be worth considering for credit card processing.
100
GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
101
Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
102
103
- **Community AWS account governance**
104
Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization.
105
With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella.
106
Requires further discussion whether that is something we want.
107
108
- **website release process**
109
Waiting for faster way to update community downloads and security advisories on main site.
110
Again postponed due to issues. Now planned for this week. We'll see.
111
112
- **Status of SBOM**
113
There was a discussion between MaxF and djpig and others.
114
For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does.
115
The interesting use-case for an SBOM is really the OpenVPN Windows GUI client.
116
117
- **Static-key mini how-to is outdated.**
118
This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)
119
company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc.
120
having a simple guide online will help adoption
121
122
- **OpenVPN 2.6 performance results.**
123
tests should cover: gre, ipsec, userland, dco
124
linux, freebsd, windows
125
requires time to be dedicated to doing this, when time available will do it
126
127
- **What's going on with new taskbar icons?**
128
matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)
129
last update: will be picked up by selva when he has time
130
131
- **software code signing topic**
132
company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing.
133
in future we could possibly switch community to that same key. saves having to maintain 2 different keys.
134
depends on how hard/easy it is to access company key signing thingee from community infrastructure.
135
also no high priority at the moment, we have a working solution now.