= Agenda = * Handling security vulnerabilities in the future * Always get a CVE entry? * Always make a security announcement (threat, impact, etc.) * Makes handling the issue much easier for downstream * OpenVPN 3.0 * Was released along API documentation under AGPL (v3?) in FOSDEM 2013 * Currently used primarily/only in OpenVPN Connect clients for Android/iOS from OpenVPN Technologies, Inc. * Getting the code to Git: currently only a tarball is available * OpenVPN 2.4 * What is the goal of the 2.4 release? * What patches in "master" are 2.4-only material?