# IrcMeetings ## Basic info - **Time**: Wednesday 11 December 2024 at 14:00 CEST (12:00 UTC) - **Place**: #openvpn-meeting channel on LiberaChat IRC network ## Topics ### Current topics - **Reminder: no meetings on 25th of December, 1st of January** _For obvious reasons._ - **Updated: DCO Linux upstreaming** _Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._ _Patchset v13 and v14 followed really fast and v14 is now under review._ _Interesting news article appeared on the webs: [Phoronix News](https://www.phoronix.com/news/OpenVPN-Data-Channel-DCO-Soon)_ - **Updated: OpenVPN community meetup 2025** [OpenVPN Community Meetup 2025](../../Meetups/2025-Naples) _When: September/October-ish, a poll for checking availability is here: [Poll](https://nuudel.digitalcourage.de/NROHeFlkfaYnoNGC)_ _Where: Napoli, Italy._ _Meeting room: TBD._ _Hotel: TBD._ _Beer: Yes._ _T-shirts: Yes._ - **swupdate.openvpn.net/org cleanup** _Basic idea is agreed; set up a new S3 bucket in AWS community account, keep only community stuff there, move swupdate.openvpn.net/org domains there, have only 1 caching layer (not 2 like now)._ _There will be some redirects for some of the company stuff that go to packages.openvpn.net._ - **t_server_null improvements** _ovpnlwip seems to work fine on all Linux platforms, based on buildbot tests._ _Waiting review._ - **buildbot improvements** _cron2 requests that we pretty please have a mingw build in gerrit. This has in the meantime materialized._ _mattock is looking into adding ubu24.04 clang+asan build._ - **multi-socket support** _Now in review. Patchset v8 should be going out this week._ - **new --dns option support** _Now in review. d12fk sent in patchset for new --dns option support._ - **community.openvpn.net wiki** _A more suitable production deployment schema for otterwiki has been submitted upstream. That does not block us however._ _uddr35 has arranged a node for mattock to use and the DNS record for it should be ready today._ _That means mattock will have access to a node to set things up on in the next few hours or so._ - **data format v3 / epoch data keys** _RFC is here: [GitHub RFC](https://github.com/OpenVPN/openvpn-rfc/pull/5)._ _plaisthos is working to implement it in openvpn3 first._ _MaxF reviewed the RFC and commented that it looks good._ - **DCO windows multi-peer** _Preparing patchset for the userspace implementation._ - **snapshot releases via Chocolatey software** _mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well._ _Seems like the maintainer is amenable to helping us achieve that goal._ - **push_update / live route updates** _There have been some initial tests on a server implementation in PG._ _There is a server-side bug that will be fixed in PG, and a request to support a few more options (keepalive options)._ _lev__ will add keepalive to OpenVPN3 code._ _mrbff and ordex will implement the openvpn2 server and client support for push_update._ - **TLS-exporter in mbedtls** _Needed for TLS 1.3 support with openvpn and mbedtls - TLS-exporter currently missing in mbedtls._ _maxf reports he's making some progress on implementing this - currently working to ensure all unit tests in all million billions of configurations work._ - **Release 2.7** _../../Development/StatusOfOpenvpn27 was updated with the results from Karlsruhe meetup._ _compare wiki:CommunityMeetup2024._ _Note: automatic enabling of --compression migrate was dropped from feature list since djpig discovered it is too complicated to get right._ ### Backlog - **2.7 security audit** _ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code._ - **forums topics** _novaflash has access and is working on a PoC setup combining old and new on an ubuntu server._ - **Tunnelcrack progress** _Status update on TunnelCrack mitigations:_ _The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this._ _Windows, openvpn2: merged to master, not to 2.6.x. openvpn3: in code review._ _Linux, openvpn2: in progress. openvpn3: in progress._ _macOS: to be determined._ _iOS: to be determined._ _Android: not vulnerable._ - **run tests of 2.x against openvpn3? how?** _There is a 'null client' variant of ovpncli that allows to make VPN connections but not fully, for testing purposes._ _This is in the openvpn3 repository._ - **donation collection** _From earlier exploration, it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._ _What we can do is start out with an existing company that can collect the money and puts it to good community use. Ordex volunteers to take this on._ _There are some options to consider. There may be existing solutions that we want to consider._ _PayPal seems overly expensive with all their fees._ _Stripe could be worth considering for credit card processing._ _GitHub Sponsors was mentioned as a possible solution, this is worth investigating._ _Open Collective was also mentioned, that needs some investigating how that exactly would work for us._ - **Community AWS account governance** _Currently the Community AWS account is part of the OpenVPN, Inc. AWS organization_ _With the OTF founding there would be opportunity to move to a separate AWS account that is not under the corporate umbrella._ _Requires further discussion whether that is something we want._ - **website release process** _Waiting for faster way to update community downloads and security advisories on main site._ _Again postponed due to issues. Now planned for this week. We'll see._ - **Status of SBOM** _There was a discussion between MaxF and djpig and others._ _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._ _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._ - **Static-key mini how-to is outdated.** _This page is outdated badly: [Static Key Mini How-To](https://openvpn.net/community-resources/static-key-mini-howto/)_ _Company will send this to tech writer to redo based on [GitHub Example](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that GitHub doc._ _Having a simple guide online will help adoption._ - **OpenVPN 2.6 performance results.** _Tests should cover: GRE, IPsec, userland, DCO_ _Linux, FreeBSD, Windows_ _Requires time to be dedicated to doing this, when time available will do it._ - **What's going on with new taskbar icons?** _Matt provided icons in [GitHub Issue](https://github.com/OpenVPN/openvpn-gui/issues/595)_ _Last update: will be picked up by Selva when he has time._ - **Software code signing topic** _Company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._ _In future, we could possibly switch community to that same key. Saves having to maintain 2 different keys._ _Depends on how hard/easy it is to access company key signing thing from community infrastructure._ _Also no high priority at the moment, we have a working solution now._
