Basic info

  • Time: Wednesday 16 July 2025 at 14:00 CEST (12:00 UTC)
  • Place: #openvpn-meeting channel on !LiberaChat IRC network

Topics

  • Updated: cve.mitre.org deprecation notice
    The MITRE CVE site we are linking to for all CVE record references has a deprecation notice. Instead cve.org is being advised as the site to use from now on.
    novaflash made an internal company ticket to update links on the main site.
    novaflash search/replaced all the CVE links on community wiki to the new address.

  • ** Release 2.7**
    For macOS DNS script there is a patch up for review.
    For multisocket, a bug report came in, and a patch is up for review.
    For float and DCO, lev has an idea on how to implement it but needs some agreement with ordex on adjustments for user space.
    For the DCO related changes, DCO+TCP is improving. Epoch data keys still needs to be done, mssfix not planned yet.
    For the live route updates changes, chances are improving that it may get in to 2.7 after all.

  • minor issue on community.openvpn.net site
    While not causing critical issues, there are some cache related issues caused by cloudflare.
    This requires some finetuning of settings to solve issues like: Logging in requires to use query string parameter to defeat cache.
    Changes like enabling dark mode can linger in cache and affect other visitors.
    Sometimes pages added don't show in menu until cache is defeated in some way.
    The "are you human" screen is quite persistent and annoying, perhaps it can be fixed.
    novaflash is working with the company to look into finetuning the cloudflare settings to address these issues.

  • format code using clang formatting
    It seems prudent to do this before the real 2.7 release.
    It was discussed and there's some additional work to be paid either on reviewer or submitter side.
    Strategy will be; get all code into beta1, collect bugfixes, reformat everything, then beta2.
    Collect more bugfixes and then do release 2.7.0 and branch it off into its own release branch.

  • push_update / live route updates
    For client-side support, company did QA on it against the current only server implementation (cloudconnexa) and it works as expected.
    cron2 will put reviewing it on his to-do list.
    Server-side support patch is up and requires review and is a bit more involved, lev__ and company QA will work on it.

  • OpenVPN community meetup 2025
    https://community.openvpn.net/openvpn/wiki/CommunityMeetup2025
    When: weekend of 25 and 26 october.
    Where: Napoli, Italy.
    Meeting room: it looks like this may be it; https://www.hotelparadisonapoli.it/en/home-page.aspx we will work to get budget cleared for this.
    Hotel: probably Paradiso Napoli. Beer: yes.
    T-shirts: yes.

Backlog

  • forums situation
    The current forums are not maintained, not working well, and flooded with spam.
    We have a contributor (minx) with web development experience willing to set up something new, but migrate the old forum contents.
    To the question where the instance should be hosted, community indicates it should be under the community AWS infrastructure.
    To the question what authentication system should be used, community indicates it should just be the built-in system from the forum solution itself.

  • snapshot releases via Chocolatey software
    mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.
    Seems like the maintainer is amenable to helping us achieve that goal.

  • 2.7 security audit
    ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.

  • Tunnelcrack progress (see TunnelCrack community wiki article)
    Status update on TunnelCrack mitigations:
    The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
    Windows, openvpn2: block-local merged to master, not to 2.6.x. openvpn3: in code review.
    Linux, openvpn2: in progress. openvpn3: in progress.
    macOS: to be determined.
    iOS: to be determined.
    Android: not vulnerable.

  • donation collection
    From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
    What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
    There are some options to consider. There may be existing solutions that we want to consider.
    PayPal seems overly expensive with all their fees.
    Stripe could be worth considering for credit card processing.
    GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
    Open Collective was also mentioned, that needs some investigating how that exactly would work for us.

  • Static-key mini how-to is outdated.
    This page is outdated badly: https://openvpn.net/community-resources/static-key-mini-howto/
    company will send this to tech writer to redo based on https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst info. and also retain a link to that github doc.
    having a simple guide online will help adoption

On this page
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9