Basic info

  • Time: Wednesday 6 August 2025 at 14:00 CEST (12:00 UTC)
  • Place: #openvpn-meeting channel on !LiberaChat IRC network

Topics

  • Release 2.7
    A 2.7 alpha3 release went out last week.
    This includes a fix for a couple of rare crashes on Windows DCO driver. This was backported to the installer for 2.6.14.
    Another further small fix (driver fix for recursive routing issue) will be included in 2.6.14 Windows installer version i004 later today.
    The FreeBSD patch for float is now in review.
    The tentative plan for release is now:
    August 20: beta1
    September 3: release candidate 1
    September 17: stable release
    These are some known remaining tasks:
    Epoch data keys for Linux DCO and Windows DCO - can be done in a minor release after 2.7.0.
    Small fix to check message id/acked ids too when doing sessionid cookie checks - should go into 2.7.0.
    PUSH_UPDATE review and server-side support - cron2 wants to discuss changes.
    mi prefix handling, int/uint fixes, and the new 'real route' gateway handling

  • Updated: OpenVPN community meetup 2025
    https://community.openvpn.net/openvpn/wiki/CommunityMeetup2025
    When: 25 and 26 october (saturday and sunday), with travel days on the friday before and monday after.
    Where: Napoli, Italy.
    Meeting room: https://www.hotelparadisonapoli.it/en/home-page.aspx sponsored by company.
    Hotel: Paradiso Napoli Hotel.
    Beer: yes.
    T-shirts: yes.

  • Github repo for open sourced MCP project
    MCP is a protocol that AI agents can speak, like a universal API, so that if other programs also speak MCP, then AI can work with it.
    Company is going to do some MCP project to work with CloudConnexa, maybe in the future Access Server.
    They want to open source this and ask for a repo to publish it in.
    This is a bit similar to this project; https://github.com/OpenVPN/terraform-provider-cloudconnexa which was started elsewhere but got published to open source.

  • push_update / live route updates
    Client-side support for push_update is now merged.
    For server-side support, company did QA on it with openvpn2 but found some missing features that are being added now.
    Client-side support made it into alpha3.

  • format code using clang formatting
    It seems prudent to do this before the real 2.7 release.
    It was discussed and there's some additional work to be paid either on reviewer or submitter side.
    Strategy will be; get all code into beta1, collect bugfixes, reformat everything, then beta2.
    Collect more bugfixes and then do release 2.7.0 and branch it off into its own release branch.

  • cve.mitre.org deprecation notice
    The MITRE CVE site we are linking to for all CVE record references has a deprecation notice. Instead cve.org is being advised as the site to use from now on.
    novaflash made an internal company ticket to update links on the main site.
    novaflash search/replaced all the CVE links on community wiki to the new address.

Backlog

  • build failures
    Changes in Gerrit do not automatically pick up fixes from master, so sometimes we see a lot of build failures even though those are fixed in master.
    Some options were discussed, seems like the one preferred is to reject pushes that are behind. djpig will look into it.

  • Reference manuals OpenVPN 2.x
    There was a mistake made on the main website which for a few hours? or days? made the reference manual 404.
    This has been restored. However the URL will slightly change in the future, but a redirect on the old URL will be in place.
    mattock raised the question where the latest OpenVPN man page should be hosted.
    When discussing this we agreed that djpig will contact the technical writer for openvpn.net and see if the ingestion/updating process can be smoother.
    Independently we can also investigate getting the manuals on the wiki somewhere, perhaps automated.

  • forums situation
    The current forums are not maintained, not working well, and flooded with spam.
    We have a contributor (minx) with web development experience willing to set up something new, but migrate the old forum contents.
    To the question where the instance should be hosted, community indicates it should be under the community AWS infrastructure.
    To the question what authentication system should be used, community indicates it should just be the built-in system from the forum solution itself.

  • snapshot releases via Chocolatey software
    mattock contacted the Chocolate package maintainer for OpenVPN and asked if he would be okay with publishing Windows MSI snapshots as well.
    Seems like the maintainer is amenable to helping us achieve that goal.

  • 2.7 security audit
    ordex mentioned that OTF offers the possibility to get a 3rd-party security audit for supported projects. So we will apply for that around or after the 2.7 release to review the latest code.

  • Tunnelcrack progress (see TunnelCrack community wiki article)
    Status update on TunnelCrack mitigations:
    The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
    Windows, openvpn2: block-local merged to master, not to 2.6.x. openvpn3: in code review.
    Linux, openvpn2: in progress. openvpn3: in progress.
    macOS: to be determined.
    iOS: to be determined.
    Android: not vulnerable.

  • donation collection
    From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
    What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
    There are some options to consider. There may be existing solutions that we want to consider.
    PayPal seems overly expensive with all their fees.
    Stripe could be worth considering for credit card processing.
    GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
    Open Collective was also mentioned, that needs some investigating how that exactly would work for us.

On this page
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9