# OpenVPN Hackathon 2023 This year's hackathon is organized by Lev Stipakov. For the most part. ## Dates October 6-8, 2023 ## Venue The venue for the hackathon is at [Scandinavian School Costa Blanca](https://skandinaviskaskolan.com/), which is in Orihuela Costa, Alicante province, Valencian Community, Spain. [Address](https://goo.gl/maps/UGVHcnQyWAN2cUfNA?coh=178572&entry=tt): ``` C. Pablo Picasso, 5 Bloque 6, 3ª Planta 03189 Orihuela, Alicante ``` The closest airport is [Alicante Elche](https://www.aena.es/en/alicante-elche-miguel-hernandez.html). From there it takes 50min by taxi to arrive at Orihuela Costa. Note that the venue located about 8km from Torrevieja center, so you probably don't want to book a hotel there. Hotels close-by: - [Hotel Servigroup La Zenia - Orihuela](https://www.servigroup.com/en/la-zenia-hotel-orihuela-costa/) ## Who is coming? | **Name** | **Topics** | **Arrival** | **Departure** | **Hotel** | **T-shirt size** | |-------------------|----------------------------------------|------------------------------|-----------------------------|----------------|------------------| | Lev Stipakov | DCO, new TAP driver | already there | 08.10 late evening | TBD | M | | Gert Döring | triage open issues, Tunnelcrack | Thu. Oct. 5 16:20 at ALC | Sun Oct. 8 flight at 12:30 | Servigroup | XL | | Arne Schwabe | things | Tur late (19:00 at ALC) | Sun afternoon (flight at 18:50) | TBD | XXL | | Johan Draaisma | gerrit | Thu. Oct. 5. 16:30 | Sa. Oct. 14. 17:20 | una casa cerca de la escuela | XL | | Frank Lichtenheld | gerrit | Thu. Oct. 5. 16:45 | So. Oct. 8. 18:10 | Servigroup | XL | | Heiko Hund | future of --dhcp-options | Thu. Oct. 5. 16:25 | Sa. Oct. 14. 15:00 | una casa cerca de la escuela | XXL | | Max Fillinger | TBD | Thu. 16:30 at ALC | Mon. 13:00 | Orihuela Costa Resort | XL | | Antonio Quartulli | i just want a shirt kthxbye | not attending | not attending | not attending | M | | James Yonan | unable to attend | not attending | not attending | not attending | XL | | Samuli Seppänen | | not attending | not attending | not attending | | ## Meeting summary - **TunnelCrack vulnerabilities** - Published a statement on the community wiki regarding TunnelCrack. A security advisory on the main site is to follow a bit later. - Planned future mitigation steps to counter these vulnerabilities. Out of necessity the mitigations will be different per platform. - **Windows:** Rework `--redirect-gateway block-local` to use Windows Filtering Platform - precedent for using WFP in `--block-outside-dns`. - **macOS:** Look at the VPN API and maybe PF for a solution to block the unwanted traffic paths. - **Linux:** Implement a separate routing table and set up a routing policy. Add options to control this. - **BSD OSes:** Provide an `--up script` example and documentation to block unwanted traffic paths. - **Android:** Has traffic isolation out of the box and is not affected by these vulnerabilities. - **iOS:** Currently only implemented in OpenVPN Connect, so OpenVPN Inc. will look into a fix. - **Change default for topology directive** - Change the default from net30 topology to subnet topology planned for OpenVPN 2.7. - **DNS implementation on Windows** - Implement new split-DNS functionality using the new `--dns` directive. - Deduplicate DNS and route handling code in the privileged interactive service. - **DNS implementation on Linux** - Provide a script with OpenVPN 2.7 on Linux that supports resolved and resolvconf out-of-the-box. - **Windows GUI update mechanism** - Consider adding a software update mechanism, possibly using Sparkle or another existing solution. - **Future of dhcp-option directive** - Evaluate all the dhcp-option directive options and see if any can be separated into its own directive. - **Planned deprecation of NTLM proxy authentication methods** - NTLMv1 is already deprecated and will be removed from OpenVPN 2.7. NTLMv2 will become marked as deprecated but still work in OpenVPN 2.7. - **Planned deprecation of `--secret` static key directive** - Begin deprecation in OpenVPN 2.7, and removal in OpenVPN 2.8. - **Multiple authentication plugins support** - Planned for OpenVPN 2.7. - **Improve OpenVPN2 and network-manager integration** - Implement changes in master intended for 2.7 and if non-disruptive backport to 2.6. - **Multi-socket support** - Implement the ability for OpenVPN2 to listen on multiple sockets at the same time in OpenVPN 2.7. - **Live route updates** - Support updating routes live on the client side without having to force a reconnect in OpenVPN 2.7. - **Custom control channel packets** - Implement a new control channel message for arbitrary messages in OpenVPN 2.7. - **mbedTLS updates** - Final stages of updating the licensing of OpenVPN2 to resolve this, allowing updates to newer mbedTLS versions. - **Remove OpenSSL 1.0.2 support** - Planned for OpenVPN 2.7. - **2.6 client with DCO connecting to 2.4 server silent failure** - Add a notification for this issue and advise upgrading to newer versions to solve it. - **Incoming patchset for DCO-win** - Lev will help with splitting the huge patchset into manageable related pieces and work on merging it.
