OpenVPN 2.7.3 -- Released 27 April 2026
The OpenVPN community project team is proud to release OpenVPN 2.7.3. This is a small bugfix release.
For details see Changes.rst
Bugfixes:
- in combination with
--management-query-passwords, setups using--auth-user-pass fileor inlineauth-user-passwould no longer use the configured passwords and prompt on the management interface instead (OpenVPN GUI would then provide an empty user/password prompt) (Github: openpvn#1021).
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7.3-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7.3-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7.3-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7.3.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.7.2 -- Released 22 April 2026
The OpenVPN community project team is proud to release OpenVPN 2.7.2. This is a bugfix release containing security fixes.
For details see Changes.rst
Security fixes:
- CVE-2026-40215: fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances
- CVE-2026-35058: fix server ASSERT() on receiving a suitably malformed packet with a valid tls-crypt-v2 key
New features:
- management interface: permit input of very long passwords in base64-encoded multiline format. Signal support to management clients via "management version 6".
User-visible Changes:
- improve error messages on
--verify-x509-namefailures - improve error logging when overlong username or passwords can not be written to TLS buffer
Bugfixes:
- when using a config file with inlined username and no password, fix prompting for the password from management interface.
- Windows: fix DNSSEC flag handling - this got never applied due to a bad comparison being always false.
- Windows: fix deinstallation progress bar on adapter deletion.
Windows MSI changes since 2.7.1:
- Built against OpenSSL 3.6.2
- Included openvpn-gui updated to 11.63.0.0
- Translation cleanup. Remove obsolete strings related to support for OpenVPN < 2.0
- Translation updates.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7.2-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7.2-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7.2-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7.2.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.6.20 -- Released 22 April 2026
The OpenVPN community project team is proud to release OpenVPN 2.6.20. This is a bugfix release containing security fixes.
For details see Changes.rst
Security fixes:
- CVE-2026-40215: fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances
- CVE-2026-35058: fix server ASSERT() on receiving a suitably malformed packet with a valid tls-crypt-v2 key
Bugfixes:
- management: stop periodic bytecount output on mgmt client disconnection
- FreeBSD: make DCO work on systems with no IPv4 support
- FreeBSD: fix compilation with --enable-async-push on FreeBSD 15
- Linux: make DCO work on big endian architectures (MIPS, PowerPC)
- Windows: fix deinstallation progress bar on adapter deletion.
- Linux: fix problem with DCO kernel notifications getting lost, leading to overcounting of number of connected clients and general confusion between kernel and userland regarding peer status (Github #900, #918, #931, #919, #945) - this is a backport of the fixes in 2.7 plus the infrastructural changes around DCO needed to support it.
Windows MSI changes since 2.6.19-I001:
- Built against OpenSSL 3.6.2
- Included openvpn-gui updated to 11.63.0.0
- Translation cleanup. Remove obsolete strings related to support for OpenVPN < 2.0
- Translation updates.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.20-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.20-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.20-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.20.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.7.1 -- Released 31 March 2026
The OpenVPN community project team is proud to release OpenVPN 2.7.1. This is a bug fix release.
For details see Changes.rst
New features:
- Add a new
username-onlyflag argument to--auth-user-passwhich will now make OpenVPN only query for username and send a dummy password to the server. This is only useful if auth schemes are used on the server side that will do some sort of external challenge base on username, and not password authentication. See discussion in GH OpenVPN/openvpn#501 (starting Jan 30, 2024). - Increase default sizing of internal hash maps to
4 * --max-clients. The default used to be256with a--max-clientsdefault of 1024 - this is bad for performance, while the memory savings are minimal. On a very memory constrained system, reduce--max-clients.
User-visible Changes:
- When compiled with the AWS-LC SSL library, using
--tls-cert-profilewill now print a run-time warning - the library does not support it, so it would silently do nothing. - Systemd unit files: change LimitNPROC to TasksMax and increase limit (GH: OpenVPN/openvpn#929)
- Documentation improvements.
- port-share: log incoming connections at
verb 3, not onerrorlevel anymore (GH: OpenVPN/openvpn#976).
Bugfixes:
- Fix usage of
--lportinside a<connection>block - this got broken with the multi-socket patchset (GH: OpenVPN/openvpn#995) - Do not try to run auto-pam unit test when cross-compiling.
- Do not break private-key passphrases of length >= 64 (GH: OpenVPN/openvpn#993)
- Fix obscure ASSERT() crash on TCP connects with TAP and no ip config.
- Make DCO work on FreeBSD systems that have no IPv4 support in kernel (FreeBSD PR 286263)
- Make DCO work on Linux on big endian systems (namely, MIPS and PowerPC) (GH: OpenVPN/ovpn-dco#96)
- Fixup responses to management interface
versioncommand (for >= 4) - Make
--enable-async-pushwork on FreeBSD 15 (which has native inotify support, and consequently no libinotify.pc anymore) - Adjust some code parts to new "const" handling on string function returns (ISO C23, as implemented by glibc 2.43 and newer).
Windows MSI changes since 2.7.1:
- Make sure that included openvpnserv2.exe is signed (GH: OpenVPN/openvpn-build#1293)
- Included openvpn-gui updated to 11.62.0.0
- Translation updates
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7.1-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7.1-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7.1-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7.1.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.7.0 -- Released 11 February 2026
The OpenVPN community project team is proud to release OpenVPN 2.7.0. This is the new stable version of OpenVPN with some major new features.
This release has only minor changes relative to the last release candidate release 2.7_rc6. For a list of these changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Support for mbedTLS version 4
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
- Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
- "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
- COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
For details see Changes.rst
Note: Windows MSI was updated to I017 on February 19th. Changes in I017:
- msi: use Wix Util:EventSource to register OpenVPNService event source instead of PowerShell. GH: openvpn-build #1230
- Included dco-win driver updated to 2.8.2
- CVE-2026-2738: Fix TX buffer overflow in epoch AEAD encryption. GH: ovpn-dco-win #130
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7.0-I017-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7.0-I017-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7.0-I017-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7.0.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.6.19 -- Released 4 February 2026
The OpenVPN community project team is proud to release OpenVPN 2.6.19. This is a bugfix release. 2.6.19 only fixes one small issue in the creation of the 2.6.18 release tarball. It was released on the same day as 2.6.18.
For details see Changes.rst
Bugfixes:
make distwould fail to packunit_tests/openvpn/test_common.h, breakingmake checkon the tarball if cmocka is installed. Fix.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.19-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.19-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.19-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.19.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.6.18 -- Released 4 February 2026
The OpenVPN community project team is proud to release OpenVPN 2.6.18. This is a bugfix release.
For details see Changes.rst
User visible changes:
- disable DCO if
--bind-devoption is given (no support for this in the old out-of-kernel Linux DCO implementation) - on Windows, if using
--ip-win32 netshand not using the interactive service, IPv4 addresses would be installed as "permanent", possibly causing problems later on with using that IPv4 address on a different interface. Change to "store=active". (GH: #915) - improve pull-filter documentation, emphasizing possible problems if used as a naive security measure (reported by SRLabs)
Bugfixes:
- p2mp server: fix incorrect file descriptor handling on "inotify" FD during a SIGUSR1 restart (GH: #966)
- management interface: fix bug where
--management-forget-disconnectand--management-signalcould be executed even if password authentication to managment interface was still pending (ZeroPath finding) - repair client-side interaction on reconnect between DCO event handling
and
--persist-tun- after a ping timeout and reconnect, the DCO event handler would not be armed, and the next ping timeout would not be received by userland, causing non-working connections with nothing in the openvpn log (Linux and FreeBSD only, GH: #947)
- prevent crash on invalid server-ipv6 argument, calling
freeaddrinfo()with a NULL pointer. This only affects OpenBSD. (Klemens Nanni).
Windows MSI changes since 2.6.17-I001:
- Built against OpenSSL 3.6.1
- Included openvpn-gui updated to 11.61.0.0
- translation updates
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.18-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.18-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.18-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.18.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.7_rc6 -- Released 28 January 2026
The OpenVPN community project team is proud to release OpenVPN 2.7_rc6. This is the sixth release candidate for the feature release 2.7.0.
Important changes since 2.7_rc5:
- bugfix on restarting a p2mp server instance with SIGUSR1 (inadvertedly closing fd 0, causing a crash on the next restart - GH OpenVPN/openvpn#966)
- prevent NULL pointer crash on suitable combination of --dns-updown statements in openvpn config file (not pushable)
- prevent inappropriate management interface activity if a password is set and --management-forget-disconnect or --management-signal are active
- add mbedTLS 4 support
For a list of all changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Support for mbedTLS version 4
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
- Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
- "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
- COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
For details see Changes.rst
Windows MSI was updated on Feb 4th to 2.7_rc6-I015 to rebuild with updated OpenSSL 3.6.1.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc6-I014-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_rc6-I014-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc6-I014-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_rc6.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.7_rc5 -- Released 15 January 2026
The OpenVPN community project team is proud to release OpenVPN 2.7_rc5. This is the fifth release candidate for the feature release 2.7.0.
Security fixes:
- CVE-2025-15497: in epoch key handling (an authenticated remote system can send a valid OpenVPN data packet that triggers an edge case where a too-strict check would trigger an ASSERT(), exiting OpenVPN)
Important bug fixes since 2.7_rc4:
- remove "resolve --remote on incoming TCP connects on --tcp-server" code base, because that did not work in a long time (since 2.4) and is seen as too obscure and too complicated to rescue.
- repair interaction between DCO and persist-tun after reconnection (in this case the client side would fail to set up the DCO event handler, and not notice further --ping timeouts - GH: #947)
- remove ENABLE_X509ALTUSERNAME conditional, always enabling "configure --enable-x509-alt-username". Effectively no change in code size, and one less build variant to maintain and test (GH: OpenVPN/openvpn#917).
- require "script-security 2" when using
--dev unix:<program> - socks client: fix and improve various code parts
- configure etc: drop support for systemd 216 and older, adapt other checks to reflect modern systemd setups
- fix unit test building with libcmocka 2.0+
- fix Android build warnings about unused variables/methods
- allow --test-crypto to run without --secret (prepare for removal of --secret after 2.7)
- improve WolfSSL build compatibility
For a list of all changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
- Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
- "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
- COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
For details see Changes.rst
Windows MSI changes since 2.7_rc4:
- Built against OpenSSL 3.6.0
- Included openvpn-gui updated to 11.61.0.0
- Included win-dco driver updated to 2.8.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc5-I013-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_rc5-I013-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc5-I013-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_rc5.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.7_rc4 -- Released 17 December 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_rc4. This is the fourth release candidate for the feature release 2.7.0.
Important bug fixes since 2.7_rc3:
- Windows interactive service: do not configure adapter DNS if there are no search-domains but there are resolve-domains (which get resolved via NRPT rules) - GH: OpenVPN/openvpn#473
- improve documentation and error messages for a number of deprecated options
- improve documentation for not-really-deprecated-yet
--ns-cert-type - Windows IPv4 configuration with netsh.exe: ensure addresses are added with "store=active" (ensure proper cleanup) - GH: OpenVPN/openvpn#915
- Windows: set UTF8 code page in openvpn.exe manifest, to make cert/key loading work again for files with non-ASCII characters in their file name (GH: OpenVPN/openvpn#920)
- tun.c: unify read_tun()/write_tun() functions for all BSD platforms
- more type conversion related cleanups
- add NULL check before freeaddrinfo() call, which might lead to a crash on OpenBSD (GH: OpenVPN/openvpn#930)
- add NULL check to mbedtls handling of external and inline certificates
- add check for auth none / cipher none on FreeBSD DCO
- add CAP_SYS_NICE to positive list in Linux systemd unit files (GH: OpenVPN/openvpn#834)
- drop mbedtls 2.x support (which is end of life, and work on mbedtls 4 is much simplified by not having to take care of 2.x compat as well)
- PUSH_UPDATE: bugfix for the client side where split/continued messages (due to large number of "route" statements) would not correctly handle the full set of routes. Add unit test. (GH: OpenVPN/openvpn#925)
- new unit test module for mbuf handling
- deprecate --fast-io option (it got partially broken by the multisocket implementation, and the benefits of the existing implementation did not outweigh the extra code complexity to make it work again)
- change the ssl_ctx in struct tls_options to be a pointer - this is a shared data structure between various contexts, but previously it was shallow-copied, leading to needless CRL reloading - and when working on implementing the new OpenSSL CRL API, to segfaults (the existing code works, as these new APIs are not used yet).
For a list of all changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
- Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
- "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
- COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
For details see Changes.rst
Windows MSI changes since 2.7_rc3:
- Built against OpenSSL 3.6.0
- Included openvpn-gui updated to 11.60.0.0
- Update copyright year in About dialog
- Included win-dco driver updated to 2.8.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc4-I012-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_rc4-I012-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc4-I012-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_rc4.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.7_rc3 -- Released 28 November 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_rc3. This is the third release candidate for the feature release 2.7.0.
Security fixes:
- CVE-2025-13751: Windows/interactive service: fix bug where the interactive service would error-exit in certain error conditions instead of just logging the fact and continuing. After the error-exit, OpenVPN connections will no longer work until the service is restarted (or the system rebooted). This can be triggered by any authenticated local user, and has thus been classified as a "local denial of service" attack.
Important bug fixes since 2.7_rc2:
- Windows/Interactive Service bugfixes: many small bugfixes to registry-related DNS domain handling
- Windows/Interactive Service: harden service pipe handling close a small race condition, and add restrictive ACLs
- more type conversion related warnings have been fixed
- --multihome behaviour regarding egress interface selection has been changed. See Changes.rst and manpage for details.
- cleanup dead code in event handling code (leftover of the multisocket patch set)
- add new feature, --tls-crypt-v2-max-age n. See Changes.rst and manpage for details.
- improve documentation to point out the pitfalls of case-insensitive filesystems and --client-config-dir
- split default gateway query logic in two:
- for --redirect-gateway functionality, query for the gateway towards the actual IP address of the VPN server connecting to
- for the "net_gateway" special destination for --route, and the corresponding environment variable, always query for 0.0.0.0 / ::
- upgrade embedded pkcs11-helper vcpkg + pkcs11-uri patch to 1.31
- CMake / autoconf cleanup wrt unused checks, outdated old-Linux checks, Windows oddities
- DCO (primarily Linux): improve handling of bulk notifications from kernel (do not lose notifications, do not crash) (github#900)
For a list of all changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
- Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
- "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
- COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
For details see Changes.rst
Windows MSI changes since 2.7_rc2:
- Built against OpenSSL 3.6.0
- Included openvpn-gui updated to 11.59.0.0
- Authorize config before opening the service pipe
- Remove dependence on pathcch.dll not in Windows 7
- Included win-dco driver updated to 2.8.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc3-I010-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_rc3-I010-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc3-I010-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_rc3.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.6.17 -- Released 28 November 2025
The OpenVPN community project team is proud to release OpenVPN 2.6.17. This is a bugfix release containing one security fix.
For details see Changes.rst
Security fixes:
- CVE-2025-13751: Windows/interactive service: fix erroneous exit on error that could be used by a local Windows users to achieve a local denial-of-service
Bug fixes:
- Windows/interactive service: improve service pipe robustness against file access races (uuid) and access by unauthorized processes (ACL).
- upgrade bundled build instruction (vcpkg and patch) for pkcs11-helper to 1.31, fixing a parser bug
Windows MSI changes since 2.6.16-I001:
- Built against OpenSSL 3.6.0
- Included openvpn-gui updated to 11.59.0.0
- Authorize config before opening the service pipe
- Remove dependence on pathcch.dll not in Windows 7
- Included win-dco driver updated to 2.8.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.17-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.17-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.17-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.17.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.7_rc2 -- Released 17 November 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_rc2. This is the second release candidate for the feature release 2.7.0.
Security fixes:
- CVE-2025-12106: IPv6 address parsing: fix buffer overread on invalid input
- CVE-2025-13086: HMAC verification check: fix incorrect memcmp() call
Important bug fixes since 2.7_rc1:
- even more type conversion related warnings have been fixed
- DCO FreeBSD improvements:
- improving debug messages (verb 6)
- implement client-side counter handling
- repair --inactive (and document shortcomings)
- repair handling of DCO disconnection notifications in --client mode
- Windows/Service improvements, hardening, bugfixes
- fix DNS address list generation (if 3 or more --dns addresses in use)
- fix DNS server undo_list
- disallow "stdin" as config name unless user has OpenVPN admin privs
- fix compilation errors with MSVC v19
- iservice: improve validation of config path (pathcc lib)
- [NOTE: this breaks OpenVPN compatibility with Windows 7]
- tapctl: refactor, improve output, change driver default to ovpn-dco
- iservice: when restoring iface metrics, enforce correct ifindex
- improve cmocka unit test assert() handling
- PUSH_UPDATE server: fix reporting of client IPs in
statusoutput after pushing a new IPv4/IPv6 address to client - AEAD cipher safety margins: fix calculation of AEAD blocks in use (old code would undercount blocks)
- fix invalid pointer creation / memory overread in tls_pre_decrypt
- deprecate
--opt-verify(change into no-op + warning)
For a list of all changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
- Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
- "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
- COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
For details see Changes.rst
Windows MSI changes since 2.7_rc1:
- Built against OpenSSL 3.6.0
- Included openvpn-gui updated to 11.58.0.0
- Check the return value of GetProp()
- Make config path check similar to that in interactive service
- Escape the type id of password message received from openvpn
- Add a message source for event logging
- Check correct management daemon path when OpenVPN3 is enabled
- Fix OpenVPN3 radio button label size when OVPN3 is enabled
- Use GetTempPath() for debug file in plap as well
- Migrate all saved plain usernames to encrypted format
- Included win-dco driver updated to 2.8.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc2-I009-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_rc2-I009-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc2-I009-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_rc2.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.6.16 -- Released 17 November 2025
The OpenVPN community project team is proud to release OpenVPN 2.6.16. This is a bugfix release containing one security fix.
For details see Changes.rst
Security fixes:
- CVE-2025-13086: Fix memcmp check for the hmac verification in the 3way handshake. This bug renders the HMAC based protection against state exhaustion on receiving spoofed TLS handshake packets in the OpenVPN server inefficient.
Bug fixes:
- fix invalid pointer creation in tls_pre_decrypt() - technically this is a memory over-read issue, in practice, the compilers optimize it away so no negative effects could be observed.
- Windows: in the interactive service, fix the "undo DNS config" handling.
- Windows: in the interactive service, disallow using of "stdin" for the config file, unless the caller is authorized OpenVPN Administrator
- Windows: in the interactive service, change all netsh calls to use interface index and not interface name - sidesteps all possible attack avenues with special characters in interface names.
- Windows: in the interactive service, improve error handling in some "unlikely to happen" paths.
- auth plugin/script handling: properly check for errors in creation on $auth_failed_reason_file (arf).
- for incoming TCP connections, close-on-exec option was applied to the wrong socket fd, leaking socket FDs to child processes.
- sitnl: set close-on-exec flag on netlink socket
- ssl_mbedtls: fix missing perf_pop() call (optional performance profiling)
Windows MSI changes since 2.6.15-I001:
- Built against OpenSSL 3.6.0
- Included openvpn-gui updated to 11.58.0.0
- Check the return value of GetProp()
- Make config path check similar to that in interactive service
- Escape the type id of password message received from openvpn
- Add a message source for event logging
- Check correct management daemon path when OpenVPN3 is enabled
- Fix OpenVPN3 radio button label size when OVPN3 is enabled
- Use GetTempPath() for debug file in plap as well
- Migrate all saved plain usernames to encrypted format
- Included win-dco driver updated to 2.8.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.16-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.16-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.16-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.16.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.7_rc1 -- Released 31 October 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_rc1. This is the first release candidate for the feature release 2.7.0.
Feature changes since 2.7_beta3:
- add warning for unsupported combination of --push and --tls-server
- add warning for unsupported combination of
--reneg-bytesor--reneg-pktswith DCO - remove perf_push()/perf_pop() infrastructure (because it did not work anymore, and compiler profiling will give better results today)
- ensure compatibility with OpenSSL 3.6.0 - specifically, do not crash in t_lpback.sh trying to use new encrypt-then-mac (ETM) ciphers
- improved PUSH_UPDATE server side support, which now handles changes of pushed ifconfig/ifconfig-ipv6 addresses correctly (send packets to new IP addresses to this client, stop sending packets to the old addresses).
- freshen URLs all over the tree, and change to HTTPS where possible
- on DCO Linux/FreeBSD, add support for clients receiving an IPv4/IPv6 address that is not part of the --server/--server-ipv6 subnet (= install extra on-interface host routes).
- Windows programs use a new API for path name canonicalization now (PathCchCanonicalizeEx()) which will break building with MinGW on Ubuntu 22.04 -> Upgrade to 24.04 to make builds work again.
- on Windows, when setting up WINS servers using netsh, use interface index instead of adapter name now ("as for all other netsh calls")
- remove undocumented and unused --memstats feature
Important bug fixes since 2.7_beta3:
- even more type conversion related warnings have been fixed
- more bugfixes related to BYTECOUNT display on the management interface and byte counters on DCO platforms in general
- numerous minibugs reported by ZeroPath AI have been fixed (small memleaks, possible file descriptor leaks, improved sanity checks, add ASSERT() on function contracts, etc.)
For a list of all changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
- Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
- "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
- COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
For details see Changes.rst
Windows MSI changes since 2.7_beta3:
- Built against OpenSSL 3.6.0
- Included openvpn-gui updated to 11.57.0.0
- Encrypt username saved in registry
- Avoid blocking calls during WM_OVPN_ECHOMSG processing
- Fixes segfault when echo msg-notify happens with no message to display (Github: OpenVPN/openvpn-gui#771)
- Check the path of the process listening on management port
- Error out if imported profile file name is too long
- Disallow Windows special filenames for imported profile
- Replace % characters in param->id as it's used in format template
- Excplicitly check that urls start with http:// or https://
- Included win-dco driver updated to 2.8.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc1-I008-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_rc1-I008-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc1-I008-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_rc1.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.7_beta3 -- Released 13 October 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_beta3. This is the third Beta release for the feature release 2.7.0. As the Beta name implies this is an early release build, it is not intended for production use.
Feature changes since 2.7_beta2:
- improvements on PUSH_UPDATE handling on the server side
- improve "recursive routing checks", prepare the way for a policy-based setup where "packets to VPN server" could end up in the tunnel without interfering with OpenVPN operations
- add support for "eoch" data format to DCO on Windows (needs dco-win driver 2.8.0+)
- clean up and remove outdated stuff from COPYING
Important bug fixes since 2.7_beta2:
- bugfixes reconnect and PUSH_UPDATE handling on the client side (notably handling of ifconfig/ifconfig-ipv6/redirect-gateway ipv6 if the server is not always pushing the same address families)
For a list of all changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
- Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
- "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
- COPYING: license details only relevant to our Windows installers havebeen updated and moved to the openvpn-build repo
For details see Changes.rst
Windows MSI changes since 2.7_beta2:
- Built against OpenSSL 3.6.0
- Included openvpn-gui updated to 11.56.0.0
- Included win-dco driver updated to 2.8.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_beta3-I007-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_beta3-I007-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_beta3-I007-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_beta3.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.7_beta2 -- Released 25 September 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_beta2. This is the second Beta release for the feature release 2.7.0. As the Beta name implies this is an early release build, it is not intended for production use.
Feature changes since 2.7_beta1:
- greatly improved event log handling for the Windows interactive service - this brings build system changes and a new openvpnservmsg.dll
Important bug fixes since 2.7_beta1:
- add proper input sanitation to DNS strings to prevent an attack coming from a trusted-but-malicous OpenVPN server (CVE-2025-10680, affects unixoid systems with
--dns-updownscripts and windows using the built-in powershell call) - bugfixes when using multi-socket on windows (properly recognize that TCP server mode does not work with DCO, properly handle TCP multi-socket server setups without DCO)
- bring back configuring of IPv4 broadcast addresses on Linux
- repair "--dhcp-option DNS" setting in combination with DHCP (TAP) or "--up" scripts (Github: OpenVPN/openvpn#839, OpenVPN/openvpn#840)
For a list of all changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
For details see Changes.rst
Windows MSI changes since 2.7_beta1:
- Built against OpenSSL 3.5.3
- Included openvpn-gui updated to 11.56.0.0
- Fix "Cannot open the System Tray Menu with Keyboard" (Github: OpenVPN/openvpn-gui#763)
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_beta2-I006-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_beta2-I006-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_beta2-I006-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_beta2.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.6.15 -- Released 22 September 2025
The OpenVPN community project team is proud to release OpenVPN 2.6.15. This is a bugfix release.
For details see Changes.rst
Bug fixes:
- on Windows, do not use "wmic.exe" any longer to set DNS search domain (discontinued by Microsoft), use "powershell" fragment instead.
- on Windows, logging to the windows event log has been improved (and logging of GetLastError() strings repaired). To make this work, a new "openvpnmsgserv.dll" library is now installed and registered.
- DNS domain names are now strictly validated with a positive-list of allowed characters (including UTF-8 high-bit-set bytes) before being handed to powershell.
- Apply more checks to incoming TLS handshake packets before creating new state - namely, verify message ID / acked ID for "valid range for an initial packet". This fixes a problem with clients that float very early but send control channel packet from the pre-float IP (Github: OpenVPN/openvpn#704, backported from 2.7_beta1.
- backport handling of client float notifications on FreeBSD 14/STABLE DCO (see https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=289303)
- update GPL license text to latest version from FSF
- on Linux, on interfaces where applicable, OpenVPN explicitly configures the broadcast address again. This was dropped for 2.6.0 "because computers are smart and can do it themselves", but the kernel netlink interface isn't, and will install "0.0.0.0". This does not normally matter, but for broadcast-based applications that get the address to use from "ifconfig", this change repairs functionality.
Windows MSI changes since 2.6.14-I004:
- Built against OpenSSL 3.5.3
- Included openvpn-gui updated to 11.56.0.0
- Fix "Cannot open the System Tray Menu with Keyboard" (Github: OpenVPN/openvpn-gui#763)
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.15-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.15-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.15-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.15.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.7_beta1 -- Released 04 September 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_beta1. This is the first Beta release for the feature release 2.7.0. As the Beta name implies this is an early release build, it is not intended for production use.
Feature changes since 2.7_alpha3:
- Introduction of
route_redirect_gateway_ipv4and_ipv6env variables - PUSH_UPDATE server support (via management interface)
- Rewrite of the management interface "bytecount" infastructure to better interact with DCO
Important bug fixes since 2.7_alpha3:
- Bugfixes in
--dns-updownscript for linux systems using resolvconf - A large number of signed/unsigned related warnings have been fixed
For a list of all changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
For details see Changes.rst
Windows MSI changes since 2.7_alpha3:
- Included dco-win driver updated to 2.7.1
- add support for multipeer stats
- Built against OpenSSL 3.5.1
- Included openvpn-gui 11.55.0.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_beta1-I005-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_beta1-I005-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_beta1-I005-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_beta1.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.7_alpha3 -- Released 31 July 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_alpha3. This is the third Alpha release for the feature release 2.7.0. As the Alpha name implies this is an early release build, it is not intended for production use.
Feature changes since 2.7_alpha2:
--dns-updownscript for macOS- Client-side support for PUSH_UPDATE handling
- Support for floating TLS clients when DCO is active (requires latest versions of DCO drivers)
- Use of user-defined routing tables on Linux
- PQE support for WolfSSL
Important bug fixes since 2.7_alpha2:
- Fix issue in handling DCO messages on Linux that could lead to various problems due to unhandled messages
- Fix issues with DHCP on Windows with tap driver
For a list of all changes in Alpha 3 changes see the git log.
For details about 2.7 features see Changes.rst
Windows MSI changes since 2.7_alpha3:
- win-dco driver updated from 2.5.9 to 2.6.2
- Adds float support
- Built against OpenSSL 3.5.1
- Included openvpn-gui updated to 11.55.0.0
- Fix Chinese localization for OpenVPN GUI
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_alpha3-I004-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_alpha3-I004-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_alpha3-I004-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_alpha3.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.7_alpha2 -- Released 19 June 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_alpha2. This is the second Alpha release containing bugfixes and one security fix for the feature release 2.7.0. As the Alpha name implies this is an early release build, this is not intended for production use.
New feature since 2.7_alpha1:
- TLS 1.3 support with bleeding-edge mbedTLS versions
For a list of all changes in Alpha 2 changes see the git log.
For details about 2.7 features see Changes.rst
Windows MSI changes since 2.7_alpha1:
- Includes fix for CVE-2025-50054
- Built against OpenSSL 3.5.0
- Included openvpn-gui updated to 11.54.0.0
- Improve French (fr) and Turkish (tr) localization for OpenVPN GUI
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_alpha2-I003-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_alpha2-I003-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_alpha2-I003-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_alpha2.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.7_alpha1 -- Released 28 May 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_alpha1. This is the first Alpha release for the feature release 2.7.0. As the Alpha name implies this is an early release build, this is not intended for production use.
Highlights of this release include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
For details see Changes.rst
Windows MSI changes since 2.6.14:
- Built against OpenSSL 3.5.0
- Included openvpn-gui updated to 11.53.0.0
- Support for webauth in PLAP (Pre-Logon Access Provider) via QR code (github openvpn-gui#687)
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_alpha1-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_alpha1-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_alpha1-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_alpha1.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.6.14 -- Released 02 April 2025
The OpenVPN community project team is proud to release OpenVPN 2.6.14. This is a bugfix release containing one security fix.
For details see Changes.rst
Security fixes:
- CVE-2025-2704: fix possible
ASSERT()on OpenVPN servers using--tls-crypt-v2Security scope: OpenVPN servers between 2.6.1 and 2.6.13 using--tls-crypt-v2can be made to abort with anASSERT()message by sending a particular combination of authenticated and malformed packets. To trigger the bug, a valid tls-crypt-v2 client key is needed, or network observation of a handshake with a valid tls-crypt-v2 client key. No crypto integrity is violated, no data is leaked, and no remote code execution is possible. This bug does not affect OpenVPN clients. (Bug found by internal QA at OpenVPN Inc)
Bug fixes:
- Linux DCO: repair source IP selection for
--multihome(Qingfang Deng)
Windows MSI changes since 2.6.13:
- Built against OpenSSL 3.4.1
- Included openvpn-gui updated to 11.52.0.0
- Use correct
%TEMP%directory for debug log file. - Disable config in menu listing if its ovpn file becomes inaccessible (github openvpn-gui#729)
- Use correct
Note: Windows MSI was updated to I002 on June 19th. Changes in I002:
- Includes fix for CVE-2025-50054
- Built against OpenSSL 3.5.0
- Included openvpn-gui updated to 11.54.0.0
- Support for webauth in PLAP (Pre-Logon Access Provider) via QR code (github openvpn-gui#687)
- Improve French (fr) and Turkish (tr) localization for OpenVPN GUI
- Included dco-win driver updated to 1.3.1
Note: Windows MSI was update to I003 on August 4th. Changes in I003:
- Built against OpenSSL 3.5.1
- Included openvpn-gui updated to 11.55.0.0
- Fix Chinese localization for OpenVPN GUI
- Included dco-win driver updated to 1.3.2
Note: Windows MSI was updated to I004 on August 6th. Changes in I004:
- Included dco-win driver updated to 1.3.3
- Fix for recursive routing behavior
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.14-I004-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.14-I004-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.14-I003-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.14.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.6.13 -- Released 15 January 2025
The OpenVPN community project team is proud to release OpenVPN 2.6.13. This is a bugfix release.
For details see Changes.rst
Feature changes:
- on non-windows clients (MacOS, Linux, Unix) send "release" string from
uname()call asIV_PLAT_VERto server - while highly OS specific this is still helpful to keep track of OS versions used on the client side (github #637) - Windows: protect cached username, password and token in client memory
(using the
CryptProtectMemory()windows API) - Windows: use new API to get dco-win driver version from driver (newly introduced non-exclusive control device) (github ovpn-dco-win#76)
- Linux: pass
--timeout=0 argumenttosystemd-ask-password, to avoid default timeout of 90 seconds ("console prompting also has no timeout") (github #649)
Security fixes:
- improve server-side handling of clients sending usernames or passwords
longer than
USER_PASS_LEN- this would not result in a crash, buffer overflow or other security issues, but the server would then misparse incoming IV variables and produce misleading error messages.
Notable bug fixes:
- FreeBSD DCO: fix memory leaks in nvlist handling (github #636)
- purge proxy authentication credentials from memory after use
(if
--auth-nocacheis in use)
Windows MSI changes since 2.6.12:
- Built against OpenSSL 3.4.0
- Included openvpn-gui updated to 11.51.0.0
- Higher resolution eye icons (github openvpn-gui#697)
- Support for concatenating OTP with password
- Optionally always prompt for OTP
- Fix tooltip positioning when the taskbar is at top (github openvpn-gui#710)
Debian/Ubuntu packages in OpenVPN Software Repositories are now available for Ubuntu 24.10 (oracular).
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.13-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.13-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.13-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.13.tar.gz |
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
OpenVPN 2.5.11 -- Released 18 July 2024
The OpenVPN community project team is proud to release OpenVPN 2.5.11. This is a security fix release.
For details see Changes.rst
Security fixes:
CVE-2024-5594: control channel: refuse control channel messages with nonprintable characters in them. Security scope: a malicious openvpn peer can send garbage to openvpn log, or cause high CPU load. (Reynir Björnsson)
(Backport of the security fix in 2.6.11 and the fix for the bugfix in 2.6.12)
In accordance with our support policy packages and installers are not provided for 2.5 anymore.
| Source archive file | GnuPG Signature | openvpn-2.5.11.tar.gz |
OpenVPN 2.6.12 -- Released 18 July 2024
The OpenVPN community project team is proud to release OpenVPN 2.6.12. This is a bugfix release.
For details see Changes.rst
Bug fixes:
- the fix for CVE-2024-5594 (refuse control channel messages with nonprintable characters) was too strict, breaking user configurations with AUTH_FAIL messages having trailing CR/NL characters. This often happens if the AUTH_FAIL reason is set by a script. Strip those before testing the command buffer (github #568). Also, add unit test.
- Http-proxy: fix bug preventing proxy credentials caching (trac #1187)
Windows MSI changes since 2.6.11:
- Built against OpenSSL 3.3.1
- Included openvpn-gui updated to 11.50.0.0
- Update Italian language (github #696)
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.12-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.12-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.12-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.12.tar.gz |
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
OpenVPN 2.6.11 -- Released 20 June 2024
The OpenVPN community project team is proud to release OpenVPN 2.6.11. This is a bugfix release containing several security fixes.
For details see Changes.rst
Security fixes:
- CVE-2024-4877: Windows: harden interactive service pipe. Security scope: a malicious process with "some" elevated privileges (!SeImpersonatePrivilege) could open the pipe a second time, tricking openvn GUI into providing user credentials (tokens), getting full access to the account openvpn-gui.exe runs as. (Zeze with TeamT5)
- CVE-2024-5594: control channel: refuse control channel messages with nonprintable characters in them. Security scope: a malicious openvpn peer can send garbage to openvpn log, or cause high CPU load. (Reynir Björnsson)
- CVE-2024-28882: only call schedule_exit() once (on a given peer). Security scope: an authenticated client can make the server "keep the session" even when the server has been told to disconnect this client (Reynir Björnsson)
New features:
- Windows Crypto-API: Implement Windows CA template match for searching certificates in windows crypto store.
- Support pre-created DCO interface on FreeBSD (OpenVPN would fail to set ifmode p2p/subnet otherwise)
Bug fixes:
- Fix connect timeout when using SOCKS proxies (trac #328, github #267)
- Work around LibreSSL crashing on OpenBSD 7.5 when enumerating ciphers (LibreSSL bug, already fixed upstream, but not backported to OpenBSD 7.5, see also LibreSSL/OpenBSD#150)
- Add bracket in fingerprint message and do not warn about missing verification (github #516)
Documentation:
- Remove "experimental" denotation for --fast-io
- Correctly document ifconfig_* variables passed to scripts
- Documentation: make section levels consistent
- Samples: Update sample configurations (remove compression & old cipher settings, add more informative comments)
Windows MSI changes since 2.6.10:
- For the Windows-specific security fixes see above
- Built against OpenSSL 3.3.1
- Included openvpn-gui updated to 11.49.0.0
- Contains part of the fix for CVE-2024-4877
Note: Windows MSI was updated to I002 on June 26th. Changes in I002:
- Group names are localized in some localizations, so we have to use SIDs. (Github: #671)
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.11-I002-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.11-I002-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.11-I002-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.11.tar.gz |
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
OpenVPN 2.5.10 -- Released 21 March 2024
The OpenVPN community project team is proud to release OpenVPN 2.5.10. This is a bugfix release containing several security fixes specific to the Windows platform.
For details see Changes.rst
Note that OpenVPN 2.5.x is in "Old Stable Support" status (see SupportedVersions). This usually means that we do not provide updated Windows Installers anymore, even for security fixes. Since this release fixes several issues specific to the Windows platform we decided to provide installers anyway. This does not change the support status of 2.5.x branch. We might not provide security updates for issues found in the future. We recommend that everyone switch to the 2.6.x versions of installers as soon as possible.
Security fixes:
- CVE-2024-27459: Windows: fix a possible stack overflow in the interactive service component which might lead to a local privilege escalation. Reported-by: Vladimir Tokarev vtokarev@microsoft.com
- CVE-2024-24974: Windows: disallow access to the interactive service pipe from remote computers. Reported-by: Vladimir Tokarev vtokarev@microsoft.com
- CVE-2024-27903: Windows: disallow loading of plugins from untrusted
installation paths, which could be used to attack
openvpn.exevia a malicious plugin. Plugins can now only be loaded from the OpenVPN install directory, the Windows system directory, and possibly from a directory specified byHKLM\SOFTWARE\OpenVPN\plugin_dir. Reported-by: Vladimir Tokarev vtokarev@microsoft.com - CVE-2024-1305: Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket. Reported-by: Vladimir Tokarev vtokarev@microsoft.com
Windows MSI changes since 2.5.10:
- For the Windows-specific security fixes see above
- Built against OpenSSL 1.1.1w
- Note that OpenSSL 1.1.1 is not supported anymore, so this might not address all known issues in OpenSSL 1.1.1. If that concerns you, please switch to OpenVPN 2.6.x
- Included tap6-windows driver updated to 9.27.0
- Security fix, see above
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.5.10-I601-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.5.10-I601-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.5.10-I601-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.5.10.tar.gz |
OpenVPN 2.6.10 -- Released 20 March 2024
The OpenVPN community project team is proud to release OpenVPN 2.6.10. This is a bugfix release containing several security fixes specific to the Windows platform.
For details see Changes.rst
Security fixes:
- CVE-2024-27459: Windows: fix a possible stack overflow in the interactive service component which might lead to a local privilege escalation. Reported-by: Vladimir Tokarev vtokarev@microsoft.com
- CVE-2024-24974: Windows: disallow access to the interactive service pipe from remote computers. Reported-by: Vladimir Tokarev vtokarev@microsoft.com
- CVE-2024-27903: Windows: disallow loading of plugins from untrusted
installation paths, which could be used to attack
openvpn.exevia a malicious plugin. Plugins can now only be loaded from the OpenVPN install directory, the Windows system directory, and possibly from a directory specified byHKLM\SOFTWARE\OpenVPN\plugin_dir. Reported-by: Vladimir Tokarev vtokarev@microsoft.com - CVE-2024-1305: Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket. Reported-by: Vladimir Tokarev vtokarev@microsoft.com
New features:
t_client.shcan now run pre-tests and skip a test block if needed (e.g. skip NTLM proxy tests if SSL library does not support MD4)
User visible changes:
- Update copyright notices to 2024
Bug fixes:
- Windows: if the win-dco driver is used (default) and the GUI requests use of a proxy server, the connection would fail. Disable DCO in this case. (Github: #522)
- Compression: minor bugfix in checking option consistency vs. compiled-in algorithm support
- systemd unit files: remove obsolete syslog.target
Documentation:
- remove license warnings about mbedTLS linking (README.mbedtls)
- update documentation references in systemd unit files
- sample config files: remove obsolete tls-*.conf files
- document that auth-user-pass may be inlined
Windows MSI changes since 2.6.9:
- For the Windows-specific security fixes see above
- Built against OpenSSL 3.2.1
- Included tap6-windows driver updated to 9.27.0
- Security fix, see above
- Included ovpn-dco-win driver updated to 1.0.1
- Ensure we don't pass too large key size to CryptoNG. We do not consider this a security issue since the CryptoNG API handles this gracefully either way.
- Included openvpn-gui updated to 11.48.0.0
- Position tray tooltip above the taskbar
- Combine title and message in tray icon tip text
- Use a custom tooltip window for the tray icon
Note: Windows MSI was updated to I002 on April 15th. Changes in I002:
- Update include ovpn-dco-win to v1.1.1
- Improves reconnect behavior after hibernate/standby. (Github: #64)
Note: Windows MSI was updated to I003 on May 23rd. Changes in I003:
- Update include ovpn-dco-win to v1.2.1
- Fix bug check in timer management routines. (Github: #70)
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.10-I003-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.10-I003-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.10-I003-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.10.tar.gz |
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
OpenVPN 2.6.9 -- Released 12 February 2024
The OpenVPN community project team is proud to release OpenVPN 2.6.9. This is a bugfix release containing one security fix for the Windows installer.
For details see Changes.rst
Security fixes:
- Windows Installer: fix CVE-2023-7235 where installing to a non-default directory could lead to a local privilege escalation. Reported by Will Dormann.
New features:
- Add support for building with mbedTLS 3.x.x
- New option
--force-tls-key-material-exportto only accept clients that can do TLS keying material export to generate session keys (mostly an internal option to better deal with TLS 1.0 PRF failures). - Windows: bump vcpkg-ports/pkcs11-helper to 1.30
- Log incoming SSL alerts in easier to understand form and move logging
from
--verb 8to--verb 3. - protocol_dump(): add support for printing
--tls-cryptpackets
User visible changes:
License change is now complete, and all code has been re-licensed under the new license (still GPLv2, but with new linking exception for Apache2 licensed code). See COPYING for details.
Code that could not be re-licensed has been removed or rewritten.
The original code for the
--tls-export-certfeature has been removed (due to the re-licensing effort) and rewritten without looking at the original code. Feature-compatibility has been tested by other developers, looking at both old and new code and documentation, so there should not be a user-visible change here.IPv6 route addition/deletion are now logged on the same level (3) as for IPv4. Previously IPv6 was always logged at
--verb 1.Better handling of TLS 1.0 PRF failures in the underlying SSL library (e.g. on some FIPS builds) - this is now reported on startup, and clients before 2.6.0 that can not use TLS EKM to generate key material are rejected by the server. Also, error messages are improved to see what exactly failed.
Notable bug fixes:
- FreeBSD: for servers with multiple clients, reporting of peer traffic statistics would fail due to insufficient buffer space (Github: #487)
Windows MSI changes since 2.6.8:
- Security fix, see above
- Built against OpenSSL 3.2.0
- Included openvpn-gui updated to 11.47.0.0
- Windows GUI: always update tray icon on state change (Github: #669) (for persistent connection profiles, "connecting" state would not show)
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.9-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.9-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.9-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.9.tar.gz |
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
OpenVPN 2.6.8 -- Released 17 November 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.8. This is a small bugfix release fixing a few regressions in 2.6.7 release.
For details see Changes.rst
User visible changes:
- Windows: print warning if pushed options require DHCP (e.g. DOMAIN-SEARCH) and driver in use does not use DHCP (wintun, dco).
Bug fixes:
- SIGSEGV crash: Do not check key_state buffers that are in S_UNDEF state (Github #449) - the new sanity check function introduced in 2.6.7 sometimes tried to use a NULL pointer after an unsuccessful TLS handshake
- Windows:
--dnsoption did not work when tap-windows6 driver was used, because internal flag for "apply DNS option to DHCP server" wasn't set (Github #447) - Windows: fix status/log file permissions, caused by regression after changing to CMake build system (Github: #454, Trac: #1430)
- Windows: fix
--chdirfailures, also caused by error in CMake build system (Github #448)
Windows MSI changes since 2.6.7:
- Included openvpn-gui updated to 11.46.0.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.8-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.8-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.8-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.8.tar.gz |
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
OpenVPN 2.6.7 -- Released 09 November 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.7. This is a bugfix release containing security fixes.
For details see Changes.rst
Security Fixes:
- CVE-2023-46850 OpenVPN versions between 2.6.0 and 2.6.6 incorrectly use a send buffer after it has been free()d in some circumstances, causing some free()d memory to be sent to the peer. All configurations using TLS (e.g. not using --secret) are affected by this issue. (found while tracking down CVE-2023-46849 / Github #400, #417)
- CVE-2023-46849 OpenVPN versions between 2.6.0 and 2.6.6 incorrectly restore
--fragmentconfiguration in some circumstances, leading to a division by zero when--fragmentis used. On platforms where division by zero is fatal, this will cause an OpenVPN crash. (Github #400, #417).
User visible changes:
- DCO: warn if DATA_V1 packets are sent by the other side - this a hard
incompatibility between a 2.6.x client connecting to a 2.4.0-2.4.4 server,
and the only fix is to use
--disable-dco. - Remove OpenSSL Engine method for loading a key. This had to be removed because the original author did not agree to relicensing the code with the new linking exception added. This was a somewhat obsolete feature anyway as it only worked with OpenSSL 1.x, which is end-of-support.
- add warning if p2p NCP client connects to a p2mp server - this is a combination that used to work without cipher negotiation (pre 2.6 on both ends), but would fail in non-obvious ways with 2.6 to 2.6.
- add warning to
--show-groupsthat not all supported groups are listed (this is due the internal enumeration in OpenSSL being a bit weird, omitting X448 and X25519 curves). --dns: remove support forexclude-domainsargument (this was a new 2.6 option, with no backend support implemented yet on any platform, and it turns out that no platform supported it at all - so remove option again)- warn user if INFO control message too long, do not forward to management client (safeguard against protocol-violating server implementations)
New features:
- DCO-WIN: get and log driver version (for easier debugging).
- print "peer temporary key details" in TLS handshake
- log OpenSSL errors on failure to set certificate, for example if the algorithms used are in acceptable to OpenSSL (misleading message would be printed in cryptoapi / pkcs11 scenarios)
- add CMake build system for MinGW and MSVC builds
- remove old MSVC build system
- improve cmocka unit test building for Windows
Windows MSI changes since 2.6.6:
- Included openvpn-gui updated to 11.45.0.0
- MSIs now use OpenSSL 3.1.4
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.7-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.7-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.7-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.7.tar.gz |
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
OpenVPN 2.6.6 -- Released 15 August 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.6. This is a small bugfix release.
For details see Changes.rst
User visible changes:
- OCC exit messages are now logged more visibly See GH #391.
- OpenSSL error messages are now logged with more details (for example, when loading a provider fails, which .so was tried, and why did it fail) See GH #361.
- print a more user-friendly message when tls-crypt-v2 client auth fails
- packaging now includes all documentation in the source tarball
New features:
- set WINS server via interactive service - this adds support for "dhcp-option WINS 192.0.2.1" for DCO + wintun interfaces where no DHCP server is used. See GH #373.
Windows MSI changes since 2.6.5:
- Included openvpn-gui updated to 11.44.0.0
- MSIs now use OpenSSL 3.1.2
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.6-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.6-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.6-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.6.tar.gz |
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
OpenVPN 2.6.5 -- Released 13 June 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.5. This is a small bugfix release.
For details see Changes.rst
User visible changes:
- tapctl (windows): generate driver-specific names (if using tapctl to create additional tap/wintun/dco devices, and not using --name). See GH #337.
- interactive service (windows): do not force target desktop for openvpn.exe - this has no impact for normal use, but enables running of OpenVPN in a scripted way when no user is logged on (for example, via task scheduler). See GH openvpn-gui#626
Windows MSI changes since 2.6.4:
- MSIs now use OpenSSL 3.1.1
Debian/Ubuntu packages in OpenvpnSoftwareRepos are now available for arm64.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.5-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.5-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.5-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.5.tar.gz |
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
OpenVPN 2.6.4 -- Released 11 May 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.4. This is a small bugfix release.
For details see Changes.rst
Note:
- License amendment: all new commits fall under a modified license that explicitly permits linking with Apache2 libraries (mbedTLS, OpenSSL) - see COPYING for details. Existing code will fall under the new license as soon as all contributors have agreed to the change - work ongoing.
Feature changes:
- DCO: support kernel-triggered key rotation (avoid IV reuse after 2^32^ packets). This is the userland side, accepting a message from kernel, and initiating a TLS renegotiation. As of 2.6.4 release, only implemented in FreeBSD kernel.
Windows MSI changes since 2.6.3:
- Rebuilt included tap-windows driver with the correct version of the old Windows 7 driver, removing a warning about unsigned driver on Windows 7 installation. See GH openvpn-build#365.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.4-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.4-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.4-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.4.tar.gz |
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
OpenVPN 2.6.3 -- Released 13 April 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.3. This is a small bugfix release.
For details see Changes.rst
Feature changes:
- Windows: support setting DNS domain in configurations without GUI and DHCP (typically wintun or windco drivers), see GH openvpn#306.
Windows MSI changes since 2.6.2:
- Several Windows-specific issues fixed:
- ensure interactive service stays enabled after silent reinstall, see GH openvpn-build#348, openvpn-build#349 and openvpn-build#351
- repair querying install path info for easyrsa-start.bat on some Windows language versions, see GH openvpn-build#352.
- MSIs are now built against OpenSSL 3.1.0.
- Update included openvpn-gui to 11.41.0.0
- This update removes the ability to change the password of a private key from the GUI. This was a niche feature which caused a direct dependency of GUI on OpenSSL. Use openssl.exe directly if you need to edit a private key.
Note: Windows MSI was updated to I002 on April 26th. Changes in I002:
- The GPG subkey for creating the .asc files for the downloads has been updated. You might need to re-download or update the GPG key if verifying the signatures.
- Fix the encoding of some documentation/sample files included in the installer. See GH openvpn-build#358
- Update include tap-windows6 driver to 9.25.0
- Fixes a problem with sending small non-IP packets (e.g. PPPoE) over the VPN connection. See GH tap-windows6#158
- Fixes occasional TCP performance degradation on Windows Server 2022 See GH tap-windows6#147
- Note: The new driver is only used on Windows 10 and newer. We can't rebuild drivers for Windows 7/8 since Microsoft doesn't support the signing mechanism anymore. We include the previous driver version to still allow installation on Windows 7/8.
- Update included openvpn-gui to 11.42.0.0
- Fixes a problem with passphrase prompt was sometimes not displayed. See GH openvpn-gui#619
- Adds "Password Reveal" feature which allows you to see passwords while entering them.
Note: Windows MSI was updated to I003 on April 27th. Changes in I003:
- Update include tap-windows6 driver to 9.26.0
- Revert fix for occasional TCP performance degradation on Windows Server 2022 (GH tap-windows6#147) since users reported BSODs in some (undetermined) scenarios.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.3-I003-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.3-I003-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.3-I003-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.3.tar.gz |
OpenVPN 2.6.2 -- Released 24 March 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.2. This is mostly a bugfix release with some improvements.
For details see Changes.rst
Feature changes:
- implement byte counter statistics for DCO Linux (p2mp server and client)
- implement byte counter statistics for DCO Windows (client only)
--dns server <n> address ...now permits up to 8 v4 or v6 addresses
Important note for Linux DCO users:
- New control packets flow for data channel offloading on Linux: 2.6.2+ changes the way OpenVPN control packets are handled on Linux when DCO is active, fixing the lockups observed with 2.6.0/2.6.1 under high client connect/disconnect activity. This is an INCOMPATIBLE change and therefore an ovpn-dco kernel module older than v0.2.20230323 (commit ID 726fdfe0fa21) will not work anymore and must be upgraded. The kernel module was renamed to "ovpn-dco-v2.ko" in order to highlight this change and ensure that users and userspace software could easily understand which version is loaded. Attempting to use the old ovpn-dco with 2.6.2+ will lead to disabling DCO at runtime.
Windows MSI changes since 2.6.1:
- Update included openvpn-gui to 11.39.0.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.2-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.2-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.2-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.2.tar.gz |
OpenVPN 2.6.1 -- Released 8 March 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.1. This is mostly a bugfix release with some improvements.
For details see Changes.rst
Feature changes:
- Dynamic TLS Crypt: When both peers are OpenVPN 2.6.1+, OpenVPN will dynamically create a tls-crypt key that is used for renegotiation. This ensure that only the previously authenticated peer can do trigger renegotiation and complete renegotiations.
- CryptoAPI (Windows): support issuer name as a selector.
Certificate selection string can now specify a partial
issuer name string as "--cryptoapicert ISSUER:
" where is matched as a substring of the issuer (CA) name in the certificate.
Note: configure now enables DCO build by default on FreeBSD and Linux. On Linux this brings in a new default dependency for libnl-genl (for Linux distributions that are too old to have a suitable version of the library, use "configure --disable-dco")
Windows MSI changes since 2.6.0:
- Update included ovpn-dco-win driver to 0.9.2
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.1-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.1-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.1-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.1.tar.gz |
OpenVPN 2.5.9 -- Released 15 February 2023
The OpenVPN community project team is proud to release OpenVPN 2.5.9. This is a small bugfix release.
For details see Changes.rst
Windows MSI changes since 2.5.8:
- Build against OpenSSL 1.1.1t which contains several security fixes.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.5.9-I601-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.5.9-I601-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.5.9-I601-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.5.9.tar.gz |
OpenVPN 2.6.0 -- Released 25 January 2023
The OpenVPN community project team is proud to release OpenVPN 2.6.0. This is a release with some major new features.
For details see Changes.rst
Changes since RC2:
- Various bugfixes, see Changes.rst
Windows MSI changes since RC2:
- Included openvpn-gui updated to 11.37.0.0. See CHANGES.rst.
- DCO driver is now included as a installer module (msm) so that other products (like OpenVPN Connect) can share the DCO installation.
Note: Windows MSI was updated to I003 on January 26th. Changes in I003:
- Fix installation on Windows 7
- Fix broken tray icon menu with single profile (regression in openvpn-gui 11.36.0)
Note: Windows MSI was updated to I004 on February 6th. Changes in I004:
- Update included ovpn-dco-win driver to 0.9.0. Fixes an issue that breaks Windows boot on some machines. See OpenVPN/ovpn-dco-win#24.
- Update included easy-rsa to 3.1.2
Note: Windows MSI was updated to I005 on February 15th. Changes in I005:
- Update included ovpn-dco-win driver to 0.9.1.
- Fixes an potential crash on machines that use "legacy standby" (S3). See OpenVPN/ovpn-dco-win#36.
- Fixes an incompatibility of DCO driver with Citrix DNE Lightweight Filter. See OpenVPN/ovpn-dco-win#31.
- Built against OpenSSL 3.0.8 which includes several security fixes.
New features and improvements in 2.6.0 compared to 2.5.8:
- Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
- OpenSSL 3 support, which is now the default on Windows.
- Improved handling of tunnel MTU, including support for pushable MTU.
- Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
- Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
- Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
- Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
- Improved protocol negotiation, leading to faster connection setup.
- Updated easy-rsa3 bundled with the installer on Windows.
On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.0-I005-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.0-I005-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.0-I005-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.0.tar.gz |
OpenVPN 2.6_rc2 -- Released 12 January 2023
The OpenVPN community project team is proud to release OpenVPN 2.6_rc2. This is a release with some major new features and currently in beta (you can also download the stable release should you require it).
For details see Changes.rst
Changes since RC1:
- add rate limiter for incoming "initial handshake packets", enabled by default with a limit of 100 packets per 10 seconds. This change makes OpenVPN servers uninteresting as an UDP reflection DDoS engine.
- report
CONNECTED,ROUTE_ERRORto management GUI if connection to server succeeds but not all routes can be installed (Windows and !Linux/Netlink only, so far) - Various bugfixes, see Changes.rst
Windows MSI changes since RC1:
- Included openvpn-gui updated to 11.35.0.0. See CHANGES.rst.
- New feature: Support the
CONNECTED,ROUTE_ERRORmanagement message (see above)
- New feature: Support the
- Fix some issues related to upgrading:
- "Run on logon" option not preserved when updating from 2.5 to 2.6
- Fix check for running service when upgrading from old NSIS installations
Debian packages changes since RC1:
- Packages for Debian bookworm are now available.
New features and improvements in 2.6.0 compared to 2.5.8:
- Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
- OpenSSL 3 support, which is now the default on Windows.
- Improved handling of tunnel MTU, including support for pushable MTU.
- Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
- Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
- Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
- Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
- Improved protocol negotiation, leading to faster connection setup.
- Updated easy-rsa3 bundled with the installer on Windows.
On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6_rc2-I002-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6_rc2-I002-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6_rc2-I002-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6_rc2.tar.gz |
OpenVPN 2.6_rc1 -- Released 28 December 2022
The OpenVPN community project team is proud to release OpenVPN 2.6_rc1. This is a release with some major new features and currently in beta (you can also download the stable release should you require it).
For details see Changes.rst
Changes since Beta 2:
- Officially deprecate NTLMv1 proxy auth method in 2.6. Will be removed in 2.7.
- Support unlimited number of connection entries and remote entries.
- New management commands to enumerate and list remote entries.
- Various bugfixes, see Changes.rst
Windows MSI changes since Beta 2:
- Included openvpn-gui updated to 11.34.0.0. See CHANGES.rst.
- New feature: Connections active on exit/logout are now automatically restarted in the next session of the GUI
- Windows installers are now built with Visual Studio 17 2022 (previously built with VS 16 2019)
New features and improvements in 2.6.0 compared to 2.5.8:
- Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
- OpenSSL 3 support, which is now the default on Windows.
- Improved handling of tunnel MTU, including support for pushable MTU.
- Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
- Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
- Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
- Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
- Improved protocol negotiation, leading to faster connection setup.
- Updated easy-rsa3 bundled with the installer on Windows.
On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6_rc1-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6_rc1-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6_rc1-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6_rc1.tar.gz |
OpenVPN 2.6_beta2 -- Released 15 December 2022
The OpenVPN community project team is proud to release OpenVPN 2.6_beta2. This is a release with some major new features and currently in beta (you can also download the stable release should you require it).
For details see Changes.rst
Changes since Beta 1:
- Transport statistics (bytes in/out) for DCO environments. Currently only for Windows clients and FreeBSD servers. Other platforms will be fixed in next release.
- Various bugfixes, see Changes.rst
Windows MSI changes since Beta 1:
- Included openvpn-gui updated to 11.33.0.0. See CHANGES.rst.
- Update included pkcs11-helper so it can load pkcs11 providers from outside of its own install directory.
- Add legacy provider for included OpenSSL so that the workarounds documented for old ciphers work on Windows.
New features and improvements in 2.6.0 compared to 2.5.8:
- Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
- OpenSSL 3 support, which is now the default on Windows.
- Improved handling of tunnel MTU, including support for pushable MTU.
- Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
- Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
- Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
- Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
- Improved protocol negotiation, leading to faster connection setup.
- Updated easy-rsa3 bundled with the installer on Windows.
On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6_beta2-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6_beta2-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6_beta2-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6_beta2.tar.gz |
OpenVPN 2.6_beta1 -- Released 2 December 2022
The OpenVPN community project team is proud to release OpenVPN 2.6_beta1. This is a release with some major new features and currently in beta (you may find stable release should you require it).
For details see Changes.rst
There were a number of new features and improvements:
- Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
- OpenSSL 3 support, which is now the default on Windows.
- Improved handling of tunnel MTU, including support for pushable MTU.
- Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
- Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
- Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
- Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
- Improved protocol negotiation, leading to faster connection setup.
- Updated easy-rsa3 bundled with the installer on Windows.
On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6_beta1-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6_beta1-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6_beta1-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6_beta1.tar.gz |
