Basic info
- Time: Wednesday 5 November 2025 at 14:00 CEST (12:00 UTC)
- Place: #openvpn-meeting channel on !LiberaChat IRC network
Topics
Updated: 2.7 security audit
ordex arranged mostly through STF funding to get a security audit of OpenVPN 2.7 (currently in release candidate phase).
Recently this has kicked off and 2.7 is being put through the meat grinder now by SRLabs.Updated: Release 2.7
Currently we're working on 2.7rc2.
There are some security reports coming in and being triaged at the moment.Updated: Release 2.6.16
Some of the issues for 2.7 also affect 2.6 code.
So a 2.6.16 release seems prudent, to coincide with similar/same fixes done in 2.7rc2.community meetup 2026
Tentatively in Paderborn, Germany.forums situation
minx from OpenVPN Inc. originally set up flarum and started migration process, but he left the company before completion.
Now we have eduardo at OpenVPN Inc. who is taking a look and he managed to get migration working.
He suggests some further migration testing, and to then plan a hard cutover date.
Backlog
t_server and t_client testing framework
mattock reports that he's started publishing his work for t_server in this location:
https://github.com/mattock/openvpn-tests/tree/t_server_template/t_serverformat code using clang formatting
It seems prudent to do this before the real 2.7 release.
It was discussed and there's some additional work to be paid either on reviewer or submitter side.
Strategy will be; get all code into beta1, collect bugfixes, reformat everything, then beta2.
Collect more bugfixes and then do release 2.7.0 and branch it off into its own release branch.push_update / live route updates
Client-side support for push_update is now merged.
For server-side support, company did QA on it with openvpn2 but found some missing features that are being added now.
Client-side support made it into alpha3.Tunnelcrack progress (see TunnelCrack community wiki article)
Status update on TunnelCrack mitigations:
The tunnelcrack mitigation for Windows has gone in master, which will go to 2.7 release. There is the possibility for it to go to 2.6.x if we can find testers for this.
Windows, openvpn2: block-local merged to master, not to 2.6.x. openvpn3: in code review.
Linux, openvpn2: in progress. openvpn3: in progress.
macOS: to be determined.
iOS: to be determined.
Android: not vulnerable.donation collection
From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations.
What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on.
There are some options to consider. There may be existing solutions that we want to consider.
PayPal seems overly expensive with all their fees.
Stripe could be worth considering for credit card processing.
GitHub Sponsors was mentioned as a possible solution, this is worth investigating.
Open Collective was also mentioned, that needs some investigating how that exactly would work for us.
