OpenVPN Hackathon 2023
This year's hackathon is organized by Lev Stipakov. For the most part.
Dates
October 6-8, 2023
Venue
The venue for the hackathon is at Scandinavian School Costa Blanca, which is in Orihuela Costa, Alicante province, Valencian Community, Spain.
C. Pablo Picasso, 5 Bloque 6, 3ª Planta 03189 Orihuela, Alicante
The closest airport is Alicante Elche. From there it takes 50min by taxi to arrive at Orihuela Costa. Note that the venue located about 8km from Torrevieja center, so you probably don't want to book a hotel there.
Hotels close-by:
Who is coming?
| Name | Topics | Arrival | Departure | Hotel | T-shirt size |
|---|---|---|---|---|---|
| Lev Stipakov | DCO, new TAP driver | already there | 08.10 late evening | TBD | M |
| Gert Döring | triage open issues, Tunnelcrack | Thu. Oct. 5 16:20 at ALC | Sun Oct. 8 flight at 12:30 | Servigroup | XL |
| Arne Schwabe | things | Tur late (19:00 at ALC) | Sun afternoon (flight at 18:50) | TBD | XXL |
| Johan Draaisma | gerrit | Thu. Oct. 5. 16:30 | Sa. Oct. 14. 17:20 | una casa cerca de la escuela | XL |
| Frank Lichtenheld | gerrit | Thu. Oct. 5. 16:45 | So. Oct. 8. 18:10 | Servigroup | XL |
| Heiko Hund | future of --dhcp-options | Thu. Oct. 5. 16:25 | Sa. Oct. 14. 15:00 | una casa cerca de la escuela | XXL |
| Max Fillinger | TBD | Thu. 16:30 at ALC | Mon. 13:00 | Orihuela Costa Resort | XL |
| Antonio Quartulli | i just want a shirt kthxbye | not attending | not attending | not attending | M |
| James Yonan | unable to attend | not attending | not attending | not attending | XL |
| Samuli Seppänen | not attending | not attending | not attending |
Meeting summary
TunnelCrack vulnerabilities
- Published a statement on the community wiki regarding TunnelCrack. A security advisory on the main site is to follow a bit later.
- Planned future mitigation steps to counter these vulnerabilities. Out of necessity the mitigations will be different per platform.
- Windows: Rework
--redirect-gateway block-localto use Windows Filtering Platform - precedent for using WFP in--block-outside-dns. - macOS: Look at the VPN API and maybe PF for a solution to block the unwanted traffic paths.
- Linux: Implement a separate routing table and set up a routing policy. Add options to control this.
- BSD OSes: Provide an
--up scriptexample and documentation to block unwanted traffic paths. - Android: Has traffic isolation out of the box and is not affected by these vulnerabilities.
- iOS: Currently only implemented in OpenVPN Connect, so OpenVPN Inc. will look into a fix.
Change default for topology directive
- Change the default from net30 topology to subnet topology planned for OpenVPN 2.7.
DNS implementation on Windows
- Implement new split-DNS functionality using the new
--dnsdirective. - Deduplicate DNS and route handling code in the privileged interactive service.
- Implement new split-DNS functionality using the new
DNS implementation on Linux
- Provide a script with OpenVPN 2.7 on Linux that supports resolved and resolvconf out-of-the-box.
Windows GUI update mechanism
- Consider adding a software update mechanism, possibly using Sparkle or another existing solution.
Future of dhcp-option directive
- Evaluate all the dhcp-option directive options and see if any can be separated into its own directive.
Planned deprecation of NTLM proxy authentication methods
- NTLMv1 is already deprecated and will be removed from OpenVPN 2.7. NTLMv2 will become marked as deprecated but still work in OpenVPN 2.7.
Planned deprecation of
--secretstatic key directive- Begin deprecation in OpenVPN 2.7, and removal in OpenVPN 2.8.
Multiple authentication plugins support
- Planned for OpenVPN 2.7.
Improve OpenVPN2 and network-manager integration
- Implement changes in master intended for 2.7 and if non-disruptive backport to 2.6.
Multi-socket support
- Implement the ability for OpenVPN2 to listen on multiple sockets at the same time in OpenVPN 2.7.
Live route updates
- Support updating routes live on the client side without having to force a reconnect in OpenVPN 2.7.
Custom control channel packets
- Implement a new control channel message for arbitrary messages in OpenVPN 2.7.
mbedTLS updates
- Final stages of updating the licensing of OpenVPN2 to resolve this, allowing updates to newer mbedTLS versions.
Remove OpenSSL 1.0.2 support
- Planned for OpenVPN 2.7.
2.6 client with DCO connecting to 2.4 server silent failure
- Add a notification for this issue and advise upgrading to newer versions to solve it.
Incoming patchset for DCO-win
- Lev will help with splitting the huge patchset into manageable related pieces and work on merging it.
