OpenVPN Hackathon 2023

This year's hackathon is organized by Lev Stipakov. For the most part.

Dates

October 6-8, 2023

Venue

The venue for the hackathon is at Scandinavian School Costa Blanca, which is in Orihuela Costa, Alicante province, Valencian Community, Spain.

Address:

C. Pablo Picasso, 5
Bloque 6, 3ª Planta
03189 Orihuela, Alicante

The closest airport is Alicante Elche. From there it takes 50min by taxi to arrive at Orihuela Costa. Note that the venue located about 8km from Torrevieja center, so you probably don't want to book a hotel there.

Hotels close-by:

Who is coming?

Name Topics Arrival Departure Hotel T-shirt size
Lev Stipakov DCO, new TAP driver already there 08.10 late evening TBD M
Gert Döring triage open issues, Tunnelcrack Thu. Oct. 5 16:20 at ALC Sun Oct. 8 flight at 12:30 Servigroup XL
Arne Schwabe things Tur late (19:00 at ALC) Sun afternoon (flight at 18:50) TBD XXL
Johan Draaisma gerrit Thu. Oct. 5. 16:30 Sa. Oct. 14. 17:20 una casa cerca de la escuela XL
Frank Lichtenheld gerrit Thu. Oct. 5. 16:45 So. Oct. 8. 18:10 Servigroup XL
Heiko Hund future of --dhcp-options Thu. Oct. 5. 16:25 Sa. Oct. 14. 15:00 una casa cerca de la escuela XXL
Max Fillinger TBD Thu. 16:30 at ALC Mon. 13:00 Orihuela Costa Resort XL
Antonio Quartulli i just want a shirt kthxbye not attending not attending not attending M
James Yonan unable to attend not attending not attending not attending XL
Samuli Seppänen not attending not attending not attending

Meeting summary

  • TunnelCrack vulnerabilities

    • Published a statement on the community wiki regarding TunnelCrack. A security advisory on the main site is to follow a bit later.
    • Planned future mitigation steps to counter these vulnerabilities. Out of necessity the mitigations will be different per platform.
    • Windows: Rework --redirect-gateway block-local to use Windows Filtering Platform - precedent for using WFP in --block-outside-dns.
    • macOS: Look at the VPN API and maybe PF for a solution to block the unwanted traffic paths.
    • Linux: Implement a separate routing table and set up a routing policy. Add options to control this.
    • BSD OSes: Provide an --up script example and documentation to block unwanted traffic paths.
    • Android: Has traffic isolation out of the box and is not affected by these vulnerabilities.
    • iOS: Currently only implemented in OpenVPN Connect, so OpenVPN Inc. will look into a fix.
  • Change default for topology directive

    • Change the default from net30 topology to subnet topology planned for OpenVPN 2.7.
  • DNS implementation on Windows

    • Implement new split-DNS functionality using the new --dns directive.
    • Deduplicate DNS and route handling code in the privileged interactive service.
  • DNS implementation on Linux

    • Provide a script with OpenVPN 2.7 on Linux that supports resolved and resolvconf out-of-the-box.
  • Windows GUI update mechanism

    • Consider adding a software update mechanism, possibly using Sparkle or another existing solution.
  • Future of dhcp-option directive

    • Evaluate all the dhcp-option directive options and see if any can be separated into its own directive.
  • Planned deprecation of NTLM proxy authentication methods

    • NTLMv1 is already deprecated and will be removed from OpenVPN 2.7. NTLMv2 will become marked as deprecated but still work in OpenVPN 2.7.
  • Planned deprecation of --secret static key directive

    • Begin deprecation in OpenVPN 2.7, and removal in OpenVPN 2.8.
  • Multiple authentication plugins support

    • Planned for OpenVPN 2.7.
  • Improve OpenVPN2 and network-manager integration

    • Implement changes in master intended for 2.7 and if non-disruptive backport to 2.6.
  • Multi-socket support

    • Implement the ability for OpenVPN2 to listen on multiple sockets at the same time in OpenVPN 2.7.
  • Live route updates

    • Support updating routes live on the client side without having to force a reconnect in OpenVPN 2.7.
  • Custom control channel packets

    • Implement a new control channel message for arbitrary messages in OpenVPN 2.7.
  • mbedTLS updates

    • Final stages of updating the licensing of OpenVPN2 to resolve this, allowing updates to newer mbedTLS versions.
  • Remove OpenSSL 1.0.2 support

    • Planned for OpenVPN 2.7.
  • 2.6 client with DCO connecting to 2.4 server silent failure

    • Add a notification for this issue and advise upgrading to newer versions to solve it.
  • Incoming patchset for DCO-win

    • Lev will help with splitting the huge patchset into manageable related pieces and work on merging it.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9