Blame
| 4b7a1f | novaflash | 2025-06-27 20:32:33 | 1 | # IrcMeetings |
| 2 | ||||
| 3 | ## Basic info |
|||
| 4 | ||||
| 5 | - **Time:** Wednesday 19 February 2025 at 14:00 CEST (12:00 UTC) |
|||
| 6 | - **Place:** #openvpn-meeting channel on LiberaChat IRC network |
|||
| 7 | ||||
| 8 | ## Topics |
|||
| 9 | ||||
| 0f5a85 | novaflash | 2025-06-27 21:03:36 | 10 | - **New: community downloads hard to find on main website** |
| 11 | Three suggestions that will be passed on to company: |
|||
| 12 | 1 rename community to open source, there is a consensus in the meeting that community could be anything and open source is specific to openvpn open source software. |
|||
| 13 | 2 open source community would prefer to see open source downloads back on the 'second line' main menu. |
|||
| 14 | 3 it was suggested to add a call to action like "looking for open source downloads?" at the bottom of the page. |
|||
| 15 | ||||
| 16 | - **Updated: OpenSSL update severity high** |
|||
| 17 | We discussed internally and looks like it doesn't affect us. But since a copy of OpenSSL is shipped with the Windows installer, we'll just update that copy just to be sure. |
|||
| 18 | This will be shipped as a 2.6.13-I002 update/revision to the MSI installer only, not a full OpenVPN release. |
|||
| 19 | ||||
| 20 | - **Updated: Release 2.7** |
|||
| 21 | We want to get our release done before the next major Debian release. |
|||
| 22 | This means tentatively getting stuff for 2.7 done before March 1 or so, and release early April. |
|||
| 23 | Looking into a weird failure to deliver properly working openssl binary on amd64 on master. Looks like with old MSVC the OpenSSL ARM64 bug we observed doesn't occur. |
|||
| 24 | We need to decide on switching to newer API for DCO and making a newer out-of-tree DCO. We're already working towards an updated out-of-tree DCO copy. |
|||
| 25 | There is a party interested in doing a security audit of OpenVPN 2.7, there are some questions to be clarified about it being a code audit and/or testing. |
|||
| 26 | ||||
| 27 | - **Updated: data format v3 / epoch data keys** |
|||
| 28 | Implementation in user space in OpenVPN2 and OpenVPN3 are both done now. |
|||
| 29 | Since Linux DCO is in the process of upstreaming to Linux kernel, we're not changing the implementation to include this now, but will do it after. |
|||
| 30 | Windows DCO multipeer support is currently in review process - once that part is done we can look at adding the necessary changes for epoch data keys. |
|||
| 31 | ||||
| 32 | - **Updated: DCO Linux upstreaming** |
|||
| 33 | Upstreaming DCO to Linux is proceeding, it is in review stage at the moment. |
|||
| 34 | Patchset v19 lead to some further discussions which are believed to now be resolved, v20 should land by end of this week. |
|||
| 35 | ||||
| 36 | - **Updated: multi-socket support** |
|||
| 37 | https://gerrit.openvpn.net/q/topic:%22multisocket%22 |
|||
| 38 | Currently there's 3 patches left. A trivial one, then one that may need more discussion, and then the big one that makes it all work. |
|||
| 39 | It generally works but cron2 was able to trigger crashes after stress testing it - so that needs to be addressed. |
|||
| 40 | ||||
| 41 | - **Updated: DCO windows multi-peer** |
|||
| 42 | This is in review now - it compiles and works. |
|||
| 43 | cron2 is looking into stress testing it to see what breaks. |
|||
| 44 | ||||
| 45 | - **Updated: new --dns option support** |
|||
| 46 | https://gerrit.openvpn.net/q/topic:%22dns+option%22 |
|||
| 47 | It's going to be updated based on feedback received and discussions had on how to handle the situation of being unable to handle certain DNS options. |
|||
| 4b7a1f | novaflash | 2025-06-27 20:32:33 | 48 | Expect it to be ready for review again by end of the week. |
