Blame

9ad98e Samuli Seppänen 2025-01-29 12:45:51 1
# Deprecated Options in OpenVPN
2
92a954 Samuli Seppänen 2025-02-24 13:57:19 3
[OpenVPN](https://openvpn.net/) is a software VPN product which has been around since [May 2001](https://en.wikipedia.org/wiki/OpenVPN). And it has mostly been backwards compatible on the most important features through all these years. But the world moves forward, security issues are discovered, and expectations of how a secure VPN should be configured have changed over the years.
9ad98e Samuli Seppänen 2025-01-29 12:45:51 4
92a954 Samuli Seppänen 2025-02-24 13:57:19 5
As OpenVPN carries a lot of options (over 230), we need to do a clean-up here from time to time. The main goal is to be as backwards compatible in regards to the *configuration files* as possible. We do not recommend running any older OpenVPN releases than the supported versions. Whenever possible you should always upgrade to the latest available OpenVPN release. But some times we unfortunately need to remove old options as they impose a security risk to VPN configurations.
9ad98e Samuli Seppänen 2025-01-29 12:45:51 6
92a954 Samuli Seppänen 2025-02-24 13:57:19 7
In this wiki page, we will try to keep an up-to-date list of all options we have deprecated, when they will be removed, the new alternative approach and the reasoning behind removing the option. This wiki page summarizes the "Deprecated features" section in the [Changes.rst](https://github.com/OpenVPN/openvpn/blob/master/Changes.rst#deprecated-features) file which is distributed with the source code.
9ad98e Samuli Seppänen 2025-01-29 12:45:51 8
92a954 Samuli Seppänen 2025-02-24 13:57:19 9
## Remove clear-text VPN mode | **Status: Under consideration**
9ad98e Samuli Seppänen 2025-01-29 12:45:51 10
92a954 Samuli Seppänen 2025-02-24 13:57:19 11
| | |
12
|-|-|
13
| **Status ** | Under consideration |
14
| **Deprecated in: ** | **Not currently deprecated** |
15
| **To be removed in: ** | N/A |
16
| **Affects: ** | Client and server |
17
| **Result if used: ** | N/A |
18
| **Replaced by: ** | Not replaced |
19
| **Examples: ** |(N/A)|
20
This is a place-holder for the **possible** deprecation of clear-text mode.
9ad98e Samuli Seppänen 2025-01-29 12:45:51 21
22
**Important**: OpenVPN DCO does **not** support clear-text mode.
23
92a954 Samuli Seppänen 2025-02-24 13:57:19 24
## Change default `--topology net30` to `subnet` | **Status: Pending**
25
| | |
26
|-|-|
27
| **Status ** | Pending |
28
| **Deprecated in: ** | OpenVPN v2.5 |
29
| **To be removed in: ** | TBD |
30
| **Affects: ** | Client and server |
31
| **Result if used: ** | N/A |
32
| **Replaced by: ** | Not replaced |
33
| **Examples: ** |(N/A)|
34
https://community.openvpn.net/openvpn/ticket/1288
35
Changing from `--topology net30` to `subnet`, for most simple servers, only requires the addition of `topology subnet` to the server configuration file. However, for more complex setups there is potentially a lot more that requires changing. E.g. CCD files etc.
36
**OpenVPN recommends using `topology subnet` now, so that when the default is changed, you will not be affected.**
37
38
## Option: `--key-method` | Status: Removed in OpenVPN v2.5
39
40
| | |
41
|-|-|
42
| **Status ** |**Removed in OpenVPN v2.5** |
43
| **Deprecated in: ** |OpenVPN v2.4 |
44
| **Affects: ** |Client and server |
45
| **Result if used: ** |OpenVPN will not start due to unknown option|
46
| **Replaced by: ** |Not replaced |
47
| **Examples: ** |(N/A)|
48
OpenVPN has used `--key-method 2` since OpenVPN v2.0 if it was not provided. Using the older `--key-method 1` was primarily present to allow OpenVPN clients running older releases than v2.0 to connect to a v2.0 server. This older key-method is not recommended as the key negotiation method is not as strong as the current default.
49
50
## Option: `--tls-remote` | Status: Removed in OpenVPN v2.4
51
52
| | |
53
|-|-|
54
| **Status ** | **Removed in OpenVPN v2.4** |
55
| **Deprecated in: ** |OpenVPN v2.3 |
56
| **Affects: ** |Client and server |
57
| **Result if used: ** |OpenVPN will not start due to unknown option |
58
| **Replaced by: ** |`--verify-x509-name` |
59
| **Examples: ** |`--verify-x509-name 'C=KG, ST=NA, L=Bishkek, CN=Server-1'`|
60
| |`--verify-x509-name Server-1 name` |
61
| |`--verify-x509-name Server name-prefix` |
62
63
## Option: `--compat-names` | Status: Removed in OpenVPN v2.5
64
65
| | |
66
|-|-|
67
| **Status ** |**Removed in OpenVPN v2.5** |
68
| **Deprecated in: ** |OpenVPN v2.3 |
69
| **Affects: ** |Client and server |
70
| **Result if used: ** |OpenVPN will print an error message and **terminate** |
71
| **Replaced by: ** |Not replaced |
72
| **Examples: ** |(N/A)|
73
|Ref:| https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg17804.html |
74
OpenVPN used the former OpenSSL formatting of X.509 Subject fields. They could look like this:
9ad98e Samuli Seppänen 2025-01-29 12:45:51 75
```
76
/C=US/L=Somewhere/CN=John Doe/emailAddress=john@example.com
77
```
92a954 Samuli Seppänen 2025-02-24 13:57:19 78
As of OPenVPN v2.3, this format was changed to the more widely used X.509 formatting:
9ad98e Samuli Seppänen 2025-01-29 12:45:51 79
```
80
C=US, L=Somewhere, CN=John Doe, emailAddress=john@example.com
81
```
92a954 Samuli Seppänen 2025-02-24 13:57:19 82
This option would in addition add remapping of characters and rendering most characters outside the typical a-z/A-Z/0-9 range to be replaced by an underscore (_) - unless the `no-remapping` flag was added. This behaviour would in many cases be required by older authentication plug-ins or scripts which was not able to process the newer format. As this behaviour is now considered bad, it is expected that authentication plug-ins and scripts will have had enough time to get an update to handle the new X.509 Subject formatting.
83
84
## Option: `--no-name-remapping` | Status: Removed in OpenVPN v2.5
85
86
| | |
87
|-|-|
88
| **Status ** |**Removed in OpenVPN v2.5** |
89
| **Deprecated in: ** |OpenVPN v2.3 |
90
| **Affects: ** |Client and server |
91
| **Result if used: ** |OpenVPN will print an error message and **terminate** |
92
| **Replaced by: ** |Not replaced |
93
| **Examples: ** |(N/A) |
94
|Ref:| https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg17804.html |
95
This is essentially just an alias for `--compat-names no-remapping`. This option would avoid the character remapping of characters being outside the typical a-z/A-Z/0-9 range in the X.509 Subject identifiers.
96
97
## Option: `--no-iv` | Status: Removed in OpenVPN v2.5
98
99
| | |
100
|-|-|
101
| **Status ** | **Removed in OpenVPN v2.5** |
102
| **Deprecated in: ** |OpenVPN v2.4 |
103
| **Affects: ** |Client and server |
104
| **Result if used: ** |OpenVPN will not start due to unknown option|
105
| **Replaced by: ** |Not replaced |
106
| **Examples: ** |(N/A) |
107
This option will disable OpenVPN's use of the cipher initialization vector (IV). This is considered very harmful on today's ciphers and will severely reduce the security of VPN tunnels. As the use cases for `--no-iv` are few and mostly obscure, it was decided to remove this option to ensure the tunnels security can not be deliberately reduced.
108
109
110
## Option: `--no-replay` | Status: Removed in OpenVPN v2.7
111
112
| | |
113
|-|-|
114
| **Status ** | **Removed in OpenVPN v2.7** |
115
| **Deprecated in: ** |OpenVPN v2.4 |
116
| **Affects: ** |Client and server |
117
| **Result if used: ** |OpenVPN will refuse the option and provide an error message that the option is no longer supported |
118
| **Replaced by: ** |Not replaced |
119
| **Examples: ** |(N/A) |
120
121
This option will disable OpenVPN's use of replay protection. This slightly reduces the overhead (8 bytes per packet for static keyed setups, 4 bytes for TLS with CBC mode, 0 bytes for TLS with GCM/OFB/CFB mode). The overhead reduction in CBC mode can better be achieved by switching to GCM mode. The remaining benefit for static key mode does not warrant keeping this option around. The added code complexity adds attack surface and increases the chance of users reducing their security more than they realize.
122
123
124
## Policy: Removal of insecure ciphers | **Status: To be decided**
125
Ciphers with cipher block-size less than 128 bits; Most commonly `BF`, `DES`, `CAST5`, `IDEA` and `RC2`.
126
127
| | |
128
|-|-|
129
| **Status ** |Pending removal |
130
| **Deprecated in: ** |OpenVPN v2.4 |
131
| **To be removed in: ** | TBD |
132
| **Affects: ** |Client and server |
133
| **Result if used: ** |OpenVPN will not start due to incorrect cipher being used|
134
| **Replaced by: ** |Replaced by stronger ciphers, most commonly AES-256-GCM |
135
| **Examples: ** |(N/A) |
136
After the discovery of the [SWEET32 Birthday attacks on 64-bit block ciphers](https://sweet32.info) any cipher using a cipher block length smaller than 128 bits is considered insecure and prone to be successfully attacked. The cipher block length is ***not*** an indication of the cipher *key* length.
137
138
For now we will not officially remove them and focus on educating users. Maybe at some point the SSL libraries will start dropping them.
139
140
## Policy: Migrate away from deprecated ciphers. **Status: In progress**
141
With the OpenVPN v2.4 release a new feature was introduced, Negotiated Cipher Protocol (NCP). This allows users to seamlessly migrate away from deprecated ciphers without much extra work. If both client and server runs OpenVPN v2.4, the tunnel will automatically be upgraded to `AES-256-GCM`. If the environment also uses clients older than OpenVPN v2.4, the server can deploy:
9ad98e Samuli Seppänen 2025-01-29 12:45:51 142
```
143
--data-ciphers AES-256-GCM:AES-256-CBC:BF-CBC
144
```
92a954 Samuli Seppänen 2025-02-24 13:57:19 145
This will allow older clients to add or change `--cipher` to use `AES-256-CBC` instead of the default `BF-CBC` or any other cipher enlisted. This can be done on client configuration files on a one-by-one approach. Unmodified clients will be able to connect as before. Once all clients have been updated to OpenVPN v2.4 or later (preferred) or have their configuration altered, the `--data-ciphers` list can be modified to remove `BF-CBC`.
146
147
**WARNING:** This migration approach **will not** work after the release of OpenVPN v2.7. As of that release, `BF-CBC`, `CAST` or `RC2` ciphers **will not** be accepted any more.
148
149
## Option: `--keysize` | Status: Removed in OpenVPN v2.6
150
151
| | |
152
|-|-|
153
| **Status ** | **Removed in OpenVPN v2.6** |
154
| **Deprecated in: ** |OpenVPN v2.4 |
155
| **Affects: ** |Client and server |
156
| **Result if used: ** |OpenVPN will not start due to unknown option|
157
| **Replaced by: ** |Not replaced |
158
| **Examples: ** |(N/A) |
159
160
The `--keysize` option was only useful to change the key length when using the `BF`, `CAST6` or `RC2` ciphers. For all other ciphers the key-size is fixed with the chosen cipher. As OpenVPN v2.6 will no longer support any of these variable length ciphers, this option will be removed as well to avoid confusion.
161
162
## Option: `--comp-lzo` | **Status: Pending removal**
163
164
| | |
165
|-|-|
166
| **Status ** |Currently not planned for removal, see description for details |
167
| **Deprecated in: ** |OpenVPN v2.4 |
168
| **To be removed in: ** |(not decided) |
169
| **Affects: ** |Client and server |
170
| **Result if used: ** |OpenVPN will ignore the option and provide a warning|
171
| **Replaced by: ** | Not replaced |
172
| **Examples: ** |(N/A) |
173
Compression is not recommended and is a feature users should avoid using. See `--compress` for more details.
174
175
## Option: `--comp-noadapt` | **Status: Pending removal**
176
177
| | |
178
|-|-|
179
| **Status ** |Currently not planned for removal, see description for details |
180
| **Deprecated in: ** |OpenVPN v2.4 |
181
| **To be removed in: ** |(not decided) |
182
| **Affects: ** |Client and server |
183
| **Result if used: ** |OpenVPN will ignore the option and provide a warning|
184
| **Replaced by: ** | Not replaced |
185
| **Examples: ** |(N/A) |
186
Compression is not recommended and is a feature users should avoid using. See `--compress` for more details.
187
188
## Option: `--compress` | **Status: Pending removal**
189
190
| | |
191
|-|-|
192
| **Status ** |Currently not planned for removal, see description for details |
193
| **Deprecated in: ** |OpenVPN v2.5 |
194
| **To be removed in: ** |(not decided) |
195
| **Affects: ** |Client and server |
196
| **Result if used: ** |OpenVPN will ignore the option and provide a warning|
197
| **Replaced by: ** | Not replaced |
198
| **Examples: ** |(N/A) |
199
Compression is not recommended and is a feature users should avoid using. To signal this clearly, `--comp-lzo` and `--compress` are discouraged and considered deprecated features. Beginning with 2.5, these options will no longer enable compression, just enable the compression framing to be able to receive compressed packets.
200
201
## Option: `--ifconfig-pool-linear` | Status: Removed in OpenVPN v2.5
202
203
| | |
204
|-|-|
205
| **Status ** |**Removed in OpenVPN v2.5** |
206
| **Deprecated in: ** |OpenVPN v2.1 |
207
| **Affects: ** |Client and server |
208
| **Result if used: ** |OpenVPN will not start due to unknown option|
209
| **Replaced by: ** |`--topology` |
210
| **Examples: ** |`--topology p2p` |
211
This option will not work with Windows based clients. Since the `--topology p2p` mode is equivalent to `--ifconfig-pool-linear` and works with Windows, this option will be removed.
212
213
## Option: `--client-cert-not-required` | Status: Removed in OpenVPN v2.5
214
215
| | |
216
|-|-|
217
| **Status ** | **Removed in OpenVPN v2.5** |
218
| **Deprecated in: ** |OpenVPN v2.4 |
219
| **Affects: ** |Client and server |
220
| **Result if used: ** |OpenVPN will print an error message and **terminate**|
221
| **Replaced by: ** |`--verify-client-cert` |
222
| **Examples: ** |`--verify-client-cert none` |
223
| | `--verify-client-cert optional` |
224
| | `--verify-client-cert require` |
225
The replacement option allows a far more fine grained control of authentication methods, and can allow a combination of only username/password authentication, only certificate based authentication or a combination. This would not be possible with the old `--client-cert-not-required` option.
226
227
## Option: `--ns-cert-type` | **Status: Pending removal
228
229
| | |
230
|-|-|
231
| **Status ** |Pending removal |
232
| **Deprecated in: ** |OpenVPN v2.4 and v2.3.18 |
233
| **To be removed in: ** | TBD |
234
| **Affects: ** |Client and server |
235
| **Result if used: ** |OpenVPN will complain and remap to replacement option|
236
| **Replaced by: ** |`--remote-cert-tls` |
237
| **Examples: ** |`--remote-cert-tls server` |
238
| |`--remote-cert-tls client` |
239
As of OpenSSL v1.1, the nsCertType extension in X.509 certificates are no longer supported. This extension is old and has been deprecated for a long time. The replacement option, `--remote-cert-tls` is a macro which sets the `--remote-cert-ku` and `--remote-cert-eku` to appropriate values, depending on whether you to check if the remote provided certificate is a server certificate or client certificate. As the extended key usage extension is far more commonly used today, this is effectively the equivalent of `--ns-cert-type`. For the time being, if `--ns-cert-type` is used in OpenVPN v2.5 or later, it will currently be re-mapped to `--remote-cert-tls` and complain about a deprecated option being used. (FIXME: the remapping doesn't actually seem to be implemented?)
9ad98e Samuli Seppänen 2025-01-29 12:45:51 240
241
This cannot be turned into a "hard error" due to compatibility issues with OpenVPN AS and commercial upgrade cycles.
242
92a954 Samuli Seppänen 2025-02-24 13:57:19 243
In OpenVPN v2.7 support for this option was dropped when compiling OpenVPN with mbedTLS.
244
245
## Option: `--tun-ipv6` | **Status: Ignored, pending removal**
246
247
| | |
248
|-|-|
249
| **Status ** |Ignored since in OpenVPN 2.4l |
250
| **Deprecated in: ** |OpenVPN v2.4 |
251
| **To be removed in: ** |*OpenVPN v2.7* |
252
| **Affects: ** |Client and server |
253
| **Result if used: ** |OpenVPN will complain and ignore the option|
254
| **Replaced by: ** |Not replaced |
255
| **Examples: ** | |
256
257
This option was useful when IPv6 tun support was non standard and was an internal/user specified flag that tracked the Ipv6 capability of the tun device.
258
259
Today, all supported OS support IPv6 and indicating explicit support is not needed any more. Also tun-ipv6 is pushable by the remote so
260
not putting tun-ipv6 does not forbid ipv6 addresses.
261
262
263
## Policy: Automatic Up-casing of X509 Certificate field names | Status: Completed in OpenVPN 2.5
264
265
| | |
266
|-|-|
267
| **Status ** |Planned for removal |
268
| **Deprecated in: ** |OpenVPN v2.3 |
269
| **To be removed in: ** | |
270
| **Affects: ** |Server |
271
| **Result if used: ** |n/a (Always used)|
272
| **Replaced by: ** |Not replaced |
273
| **Examples: ** |This feature converts an all-lowercase field name to uppercase characters, e.g., ou -> OU |
274
275
See --x509-username-field in https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage for a detailed explanation.
276
277
## Option: `--max-routes` | **Status: Ignored, pending removal**
278
279
| | |
280
|-|-|
281
| **Status ** |Planned for removal |
282
| **Deprecated in: ** |OpenVPN v2.4 |
283
| **To be removed in: ** | |
284
| **Affects: ** | |
285
| **Result if used: ** |OpenVPN warns and ignores the option|
286
| **Replaced by: ** | N/A |
287
| **Examples: ** | |
288
289
## Option: `--dhcp-release` | **Status: Ignored, pending removal**
290
291
| | |
292
|-|-|
293
| **Status ** |Enabled by default |
294
| **Deprecated in: ** |OpenVPN v2.4 |
295
| **To be removed in: ** | |
296
| **Affects: ** | |
297
| **Result if used: ** |OpenVPN warns and ignores the option|
298
| **Replaced by: ** | N/A |
299
| **Examples: ** | |
300
| **Notes: ** | Windows only |
301
302
## Option: `--route-nopull` | **Status: To be decided**
303
304
| | |
305
|-|-|
306
| **Status ** |Disabled by default |
307
| **Deprecated in: ** | Deprecation is under discussion |
308
| **To be removed in: ** | |
309
| **Affects: ** | Client routing, dhcp-options and Windows firewall |
310
| **Result if used: ** | See the manual |
311
| **Replaced by: ** | `--pull-filter` |
312
| **Examples: ** | |
313
| **Notes: ** | Openvpn devs would like to know if you use this option |
9ad98e Samuli Seppänen 2025-01-29 12:45:51 314
315
To emulate `--route-nopull` with `--pull-filter`:
92a954 Samuli Seppänen 2025-02-24 13:57:19 316
317
- `--pull-filter ignore redirect-private redirect-gateway block-ipv6 client-nat route route-ipv6 route-metric ip-win32 dhcp-option dhcp-renew register-dns tap-sleep block-outside-dns`
318
319
- Optionally, also `ignore`: `route-gateway` `route-delay`
320
321
## Option: `--genkey --secret` | **Status: Deprecated, pending removal**
322
323
| | |
324
|-|-|
325
| **Status ** | Warning |
326
| **Deprecated in: ** | OpenVPN v2.4 |
327
| **To be removed in: ** | **OpenVPN v2.8**|
328
| **Affects: ** | `--genkey` |
329
| **Result if used: ** | User Warning printed |
330
| **Replaced by: ** | `secret` (No leading double dash) |
331
| **Examples: ** | Use `--genkey secret filename` |
332
| **Notes: ** | |
333
334
## Option: `--secret` | **Status: Deprecated, pending removal**
335
336
| | |
337
|-|-|
338
| **Status ** | Warning in OpenVPN 2.6, error in OpenVPN 2.7 (can be overridden with `--allow-deprecated-insecure-static-crypto`) |
339
| **Deprecated in: ** | OpenVPN v2.6 |
340
| **To be removed in: ** | **OpenVPN v2.8** |
341
| **Affects: ** | `--secret` |
342
| **Result if used: ** | User Warning printed |
343
| **Replaced by: ** | `--peer-fingerprint` |
344
| **Examples: ** | See `man 5 openvpn-examples` |
345
| **Notes: ** | |
346
347
static key mode (non-TLS) is no longer considered "good and secure enough" for today's requirements. Use TLS mode instead. If deploying a PKI CA
348
is considered "too complicated", using `--peer-fingerprint` makes TLS mode about as easy as using `--secret`.
349
350
This mode can still be enabled by using `--allow-deprecated-insecure-static-crypto` but will be removed in OpenVPN 2.8.
351
352
## Option: `--ncp-disable` | Status: Removed in OpenVPN v2.6
353
354
| | |
355
|-|-|
356
| **Status ** |**Removed in OpenVPN v2.6** |
357
| **Deprecated in: ** | OpenVPN v2.5 |
358
| **Affects: ** | |
359
| **Result if used: ** | OpenVPN will not start due to unknown option |
360
| **Replaced by: ** | |
361
| **Examples: ** | |
362
| **Notes: ** | `ncp-disable` was mainly a debug option that allowed disabling ncp if there were problem with dynamic cipher negotiation. With the current status of NCP, this option is no longer necessary. |
363
364
## plugin: `_v1 and _v2 functions for open and func call` | **Status: Pending removal**
365
366
| | |
367
|-|-|
368
| **Status ** |Planned for removal |
369
| **Deprecated in: ** | OpenVPN v2.5 (**to be done**) |
370
| **To be removed in: ** |OpenVPN v2.7 |
371
| **Affects: ** | plugins still use the old API |
372
| **Result if used: ** | User Warning printed, later: refuse to load plugin |
373
| **Replaced by: ** | _v3 functions |
374
| **Examples: ** | |
375
| **Notes: ** | the _v3 API functions can do everything _v1 and _v2 can do, and the existence of the old functions mostly confuses everyone |
376
377
## Option: `--inetd` | Status: Removed in OpenVPN v2.6
378
379
| | |
380
|-|-|
381
| **Status ** | **Removed in OpenVPN v2.6** |
382
| **Deprecated in: ** | OpenVPN v2.5 |
383
| **Affects: ** | `--inetd` |
384
| **Result if used: ** | OpenVPN will not start due to unknown option |
385
| **Replaced by: ** | |
386
| **Examples: ** | |
387
| **Notes: ** | This is a very limited and not-well-tested way to run OpenVPN, on TCP and TAP mode only, which complicates the code quite a bit for little gain. |
388
389
## Windows: `openvpn-legacy-service` | Status: Removed
390
391
| | |
392
|-|-|
393
| **Status ** | Gone |
394
| **Deprecated in: ** | A Galaxy a long time ago .. |
395
| **To be removed in: ** | It's Gone MacREADY! |
396
| **Affects: ** | Windows only |
397
| **Result if used: ** | Service is not configured and cannot be used: See #1344 |
398
| **Replaced by: ** | `openvpnserv2.exe` Windows Service: `OpenVPNService` |
399
| **Examples: ** | n/a |
400
| **Notes: ** | To use `openvpnserv2.exe` see `C:\Program Files\Openvpn\config-auto\readme.txt` |
401
402
## Option: `--persist-key` | **Status: To be decided**
403
404
| | |
405
|-|-|
406
| **Status ** | TBD |
407
| **Deprecated in: ** | TBD |
408
| **To be removed in: ** | TBD |
409
| **Affects: ** | ALL |
410
| **Result if used: ** | Nothing, always enabled: See #1405 |
411
| **Replaced by: ** | Nothing |
412
| **Examples: ** | n/a |
413
| **Notes: ** | `--persist-key` will be always enabled |
414
415
## Option: `--verify-hash` | **Status: Pending removal**
416
417
| | |
418
|-|-|
419
| **Status ** | Deprecated |
420
| **Deprecated in: ** | OpenVPN v2.6 |
421
| **To be removed in: ** | TBD |
422
| **Affects: ** | Client and Server |
423
| **Result if used: ** | Warns about deprecation |
424
| **Replaced by: ** | Nothing, potential alternatives are specifying an intermediate CA as `--ca`, using a `--tls-verify` script, or `--peer-fingerprint` |
425
| **Examples: ** | |
426
| **Notes: ** | |
427
428
## Option: `--link-mtu` | **Status: Pending Deprecation**
429
430
| | |
431
|-|-|
432
| **Status ** | TBD |
433
| **Deprecated in: ** | TBD |
434
| **To be removed in: ** | TBD |
435
| **Affects: ** | ALL |
436
| **Result if used: ** | n/a |
437
| **Replaced by: ** | Nothing |
438
| **Examples: ** | n/a |
439
| **Notes: ** | n/a |
440
441
## Option: `--management-client-pf` | Status: Removed in OpenVPN v2.6
442
443
| | |
444
|-|-|
445
| **Status ** | **Removed in OpenVPN v2.6** |
446
| **Deprecated in: ** | OpenVPN v2.5 |
447
| **Affects: ** | Server and Client |
448
| **Result if used: ** | OpenVPN will not start due to unknown option |
449
| **Replaced by: ** | Nothing |
450
| **Examples: ** | n/a |
451
| **Notes: ** | n/a |
452
453
## Option: `--prng` | **Status: Ignored, pending removal**
454
455
| | |
456
|-|-|
457
| **Status ** | Ignored in OpenVPN 2.6 |
458
| **Deprecated in: ** | OpenVPN v2.5 |
459
| **Affects: ** | ALL |
460
| **Result if used: ** | OpenVPN warns and ignores the option |
461
| **Replaced by: ** | SSL library |
462
| **Examples: ** | n/a |
463
| **Notes: ** | n/a |
464
465
OpenVPN used to implement its own PRNG based on a hash. However implementing a PRNG is better left to a crypto library. So we use the PRNG
466
of the used SSL library now.
467
468
## Option: `--opt-verify` | **Status: Deprecated, pending removal**
469
470
| | |
471
|-|-|
472
| **Status ** | Warns about deprecation |
473
| **Deprecated in: ** | OpenVPN v2.6 |
474
| **Affects: ** | ALL |
475
| **Result if used: ** | OpenVPN warns |
476
| **Replaced by: ** | n/a |
477
| **Examples: ** | n/a |
478
| **Notes: ** | n/a |
479
480
## Option: `--disable-occ` | **Status: Deprecated, pending removal**
481
482
| | |
483
|-|-|
484
| **Status ** | Warns about deprecation |
485
| **Deprecated in: ** | OpenVPN v2.6 |
486
| **Affects: ** | ALL |
487
| **Result if used: ** | OpenVPN warns |
488
| **Replaced by: ** | n/a |
489
| **Examples: ** | n/a |
490
| **Notes: ** | n/a |
491
492
## NTLM v1 authentication support in `--http-proxy` | **Status: Deprecated, pending removal**
493
494
| | |
495
|-|-|
496
| **Status ** | Deprecated in 2.6. To be removed in 2.7 |
497
| **Deprecated in: ** | OpenVPN v2.6 |
498
| **Affects: ** | `--http-proxy` |
499
| **Result if used: ** | Currently warns about deprecation. In 2.7 will try NTLM v2 instead. |
500
| **Replaced by: ** | basic auth |
501
| **Examples: ** | n/a |
502
| **Notes: ** | Generally considered insecure. If you don't care about that, just use basic auth. |
503
504
## NTLM v2 authentication support in `--http-proxy` | Status: To be deprecated in 2.7
505
506
| | |
507
|-|-|
508
| **Status ** | Considered to be declared deprecated in 2.7 |
509
| **Deprecated in: ** | TBD |
510
| **Affects: ** | `--http-proxy` |
511
| **Result if used: ** | TBD |
512
| **Replaced by: ** | basic auth |
513
| **Examples: ** | n/a |
514
| **Notes: ** | Weak crypto. If you don't care about that, just use basic auth. |