* [Openvpn-devel] Community meetings in December 2020
@ 2020-12-03 19:30
2020-12-03 20:09 ` [Openvpn-devel] Summary of the community meeting (3rd December 2020)
` (3 more replies)
0 siblings, 4 replies; 7+ messages in thread
From: @ 2020-12-03 19:30 UTC (permalink / raw)
To: openvpn-devel
Hi,
Our community meetings will alternate between Wed 11:30 CET and Thu
20:00 CET.
Next meetings have been scheduled to
- Thu 3rd December 20:00 CET (ongoing)
- Wed 9th December 11:30 CET
- Thu 17th December 20:00 CET
The place is #openvpn-meeting IRC channel at Freenode. Meeting agendas
and summaries are in here:
<https://community.openvpn.net/openvpn/wiki/IrcMeetings>
Samuli
^ permalink raw reply [flat|nested] 7+ messages in thread
* [Openvpn-devel] Summary of the community meeting (3rd December 2020)
2020-12-03 19:30 [Openvpn-devel] Community meetings in December 2020
@ 2020-12-03 20:09 `
2020-12-09 17:48 ` [Openvpn-devel] Summary of the community meeting (9th "
` (2 subsequent siblings)
3 siblings, 0 replies; 7+ messages in thread
From: @ 2020-12-03 20:09 UTC (permalink / raw)
To: openvpn-devel
[-- Attachment #1: Type: text/plain, Size: 1700 bytes --]
Hi,
Here's the summary of the IRC meeting.
---
COMMUNITY MEETING
Place: #openvpn-meeting on irc.freenode.net
Date: Thu 3rd December 2020
Time: 20:00 CET (19:00 UTC)
Planned meeting topics for this meeting were here:
<https://community.openvpn.net/openvpn/wiki/Topics-2020-12-03>
Your local meeting time is easy to check from services such as
<http://www.timeanddate.com/worldclock>
SUMMARY
becm, cron2, dazo, mattock, ordex, plaisthos and syzzer participated in
this meeting.
---
Agreed to release OpenVPN 2.4.10 early next week, assuming OpenSSL has
made their pre-announced (=important) release before that.
---
Agreed to bundle libpkcs11-helper 1.27 with 2.4.10. We're at 1.26 now,
and the changes between the versions look safe.
---
Noted that some of the auth-token fixed from Git "master" could and
should be backported to release/2.5. The refactorings done in "master"
could be omitted. It seems like at the moment there's no real need to
push out 2.5.1.
---
Agreed to not have meeting on Dec 23rd or 31st. The last meeting this
month will be on 17th.
--
Talked about HackerOne bounties. Agreed to go through the current
HackerOne reports and set awards (bounties) and close all reports down
(if possible) in the next meeting. Then we can close our HackerOne
project for good.
---
Noted that "IPv6 to community.openvpn.net" has not moved forward. But
OpenVPN Inc. ops team manager is aware that cron2 needs to be kept happy
and that IPv6 will have to arrive eventually.
---
Talked about the buildbot upgrade. It will need a couple of days of
concentrated effort from mattock's part. Doing the upgrade around
Christmas time sounds realistic.
---
Full chatlog attached
[-- Attachment #2: openvpn_irc_meeting_chatlog_2020-12-03.txt --]
[-- Type: text/plain, Size: 13500 bytes --]
(21:01:32) ordex: aloha!
(21:01:57) syzzer_: hi!
(21:02:10) mattock: hi
(21:02:28) becm: hi
(21:02:47) ordex: cron2: dazo: plaisthos: ?
(21:02:53) ***cron2 hides
(21:03:16) cron2 ha scelto come argomento: https://community.openvpn.net/openvpn/wiki/Topics-2020-12-03
(21:03:35) dazo: Hey!
(21:03:41) cron2: yo!
(21:04:43) plaisthos: I am only semi here
(21:04:52) ordex: which part is here exactly?
(21:05:00) cron2: which is half more than usual on thursday evenings
(21:05:05) ordex: :D
(21:05:53) cron2: whoa, 4 ACKs on the list
(21:06:20) ordex: amazzing
(21:06:33) ordex: are we aiming at doing another 2.4.x release?
(21:07:26) cron2: yes
(21:08:00) cron2: a number of bugfixes have accumulated in release/2.4, so we agreed (2-3 weeks ago) to do a 2.4.10
(21:08:04) cron2: eventually
(21:08:18) mattock: internal meeting goes on and goes on...
(21:08:36) cron2: tell them you do not care until the IPv6 crisis is solved :)
(21:08:44) mattock: :)
(21:08:57) ordex: :D
(21:09:02) ordex: cron2: ok
(21:09:12) mattock: so 2.4.10 when?
(21:09:47) cron2: I want the line number fix to be in, but have not written the second version yet... so maybe early next week? What works for you?
(21:10:31) mattock: early next week would be ok
(21:11:07) cron2: good. I'll see that I can get the patch done tomorrow-ish, so ordex can review it ("he ACKed the other one but wanted to see a variant")
(21:11:39) ordex: yup, can do
(21:12:28) becm: will the 2.4.10 for Windows ship with the brand new pkcs11-helper 1.27?
(21:12:28) cron2: 25 patches in tree since 2.4.9
(21:13:05) cron2: do we have feedback about pcks11-helper in 2.5.0?
(21:13:30) cron2: like, "works!" or "breaks :-("? I haven't seen *any* feedback on 2.5.0 yet, which is sort of... "what does that mean?"
(21:13:31) mattock: becm: it looks like we have 1.26 now in generic/build.vars
(21:13:50) mattock: cron2: I think it means it is stable and boring
(21:14:17) cron2: this is how I like my software :)
(21:14:20) mattock: which is somewhat surprising given how much stuff went to it
(21:14:31) mattock: perhaps we're doing something right :D
(21:14:37) ordex: :D
(21:14:38) ordex: it happens
(21:14:44) ***cron2 pats his test rig :)
(21:15:22) mattock: so, libpkcs11-helper 1.26 -> 1.27 in 2.4.10 and 2.5.1?
(21:15:28) mattock: any reason not to?
(21:15:35) cron2: becm: what is in there?
(21:16:08) dazo: https://github.com/OpenSC/pkcs11-helper/releases
(21:16:19) becm: looks like 2 bugfixes to me?
(21:16:59) dazo: "thanks to Tunnelblick" ... smells like it has been tested ;-)
(21:17:20) mattock: at least in tunnelblick
(21:17:37) mattock: also look like your libpkcs11-helper patch should apply ok
(21:17:46) mattock: I say "why not"
(21:17:53) cron2: yea
(21:17:54) cron2: h
(21:18:28) dazo: agreed
(21:19:17) ordex: looks good to me too
(21:20:47) cron2: anything else on 2.4?
(21:21:38) dazo: Don't think so
(21:21:44) cron2: good :-)
(21:21:48) cron2: 2.5 status, then
(21:22:05) mattock: I think we need to update all the other dependencies as well - build-complete.vars has not been updated since 2.4.9, but that's the normal procedure anyways
(21:22:23) cron2: 4 patches in tree since 2.5.0, 1 "make install" patch, 2 "client side fixup for auth-token + auth-nocache" patches
(21:22:34) dazo: oh, OpenSSL is about to do a critical release one of these days .... we should wait for that to arrive
(21:22:44) plaisthos: yeah
(21:22:47) cron2: for the windows release, yes...
(21:22:49) plaisthos: next week
(21:22:50) dazo: I have no details what it might carry, but they did a pre-announcement
(21:23:03) mattock: ok, let's not release anything before that openssl upgrade is out
(21:23:14) mattock: I don't want to do releases every other day :)
(21:23:29) cron2: anyway... we could do a 2.5.1 release, which has client side benefits, but the changes are small yet
(21:23:44) dazo: mattock: Do you know how many releases Amazone does per day? ;-)
(21:23:53) mattock: we're not Amazon
(21:24:01) syzzer_: cron2: and a couple of tls-crypt-v2 fixes, "soonish", right? :-p
(21:24:02) mattock: we have one guy doing releases
(21:24:04) mattock: :)
(21:24:15) cron2: master has a much larger fix set for auth-token in combination with plugin auth (or generally "multiple auth paths"). The patch is 3 lines, but it needs 7 pre-patches for cleanup... :-)
(21:24:50) cron2: this would be a good fix to have in 2.5.x, but I'm somewhat reluctant to pull in all the refactoring needed
(21:24:57) cron2: plaisthos: what do you think?
(21:25:03) plaisthos: yeah I think the main fix can be backported
(21:25:14) plaisthos: without the refactoring
(21:25:32) plaisthos: the refactoring was also due to better understanding of the code etc
(21:26:32) mattock: btw. do we want to have a meeting on 23rd Dec?
(21:26:38) cron2: agree. I'm not sure which of the interesting bits it needs
(21:26:40) mattock: I'm sending the invite I forgot to send :)
(21:26:45) mattock: 31st is probably out of the question
(21:26:47) mattock: at least for me
(21:26:57) dazo: 23rd is also not an ideal date
(21:27:13) cron2: mattock: no 31st for me, and 23 is also interfering with family business :)
(21:27:34) dazo: I'd suggest 17th as the last meeting this year and we all go and have a nice holiday time until January
(21:27:57) cron2: syzzer_: yes, 3 tls-crypt related fixes coming in
(21:28:14) cron2: dazo: someone wanted to do a 2.6 release in January or so :-)
(21:28:27) cron2: "to meet debian cutoff"
(21:28:32) mattock: dazo: agreed
(21:28:34) ordex: :D
(21:28:36) mattock: 17th it shall be
(21:28:41) ordex: +1
(21:28:44) cron2: aye aye sir!
(21:29:21) dazo: cron2: I say a lot of crazy stuff :-P ... but! it's also depending on a lot of other factors, as the dco work and such
(21:29:44) cron2: ok, sounds like "2.5.1 when there is enough interesting bits in"
(21:30:19) cron2: dazo: haha :-) - I hear voices that tell me DCO is all done, it just needs a bit of polish
(21:30:49) dazo: but we all know the polishing is where all the hard work appears :-P
(21:30:55) cron2: well said :)
(21:32:03) cron2: that said... 2.6? anything interesting?
(21:32:17) plaisthos: I broke ordex frist idea how to implement multiple peer mode
(21:32:28) ordex: well, we're getting there :D
(21:32:32) cron2: that was the wrong sort of polish :)
(21:32:41) plaisthos: and now I passed to token back to ordex
(21:35:12) cron2: sooo...
(21:35:45) mattock: more on?
(21:35:49) mattock: move on
(21:35:55) mattock: auth-nocache?
(21:36:05) cron2: auth-nocache went on the agenda because I felt it was a bit unclear what it was supposed to do... but since we managed to not change what it does while fixing the token stuff, it is somewhat "not that impotrant"
(21:36:18) mattock: ok
(21:36:23) mattock: next topic?
(21:36:29) mattock: that is, "HackerOne bounties"
(21:36:37) mattock: anyone remember how they're supposed to work?
(21:36:39) cron2: (so what it does: it cleans username *and* password after TLS connect, and still does, just now it does so "after PUSH_REPLY, if pull")
(21:36:46) cron2: mattock: i hoped that you could answer that
(21:37:13) cron2: we actually received a useful submission - one of our travis scripts was doing http downloads with no checksumming, while it could have done https.
(21:37:23) mattock: I have a vague recollection that we have to close the report down and then we can do something to tag the report as worth a bounty
(21:37:25) cron2: So I changed that (it's in tree)
(21:37:36) mattock: emphasis on "vague" :)
(21:37:40) cron2: but I have no idea what the rules, and the sums, and the process is
(21:37:48) mattock: we've never done it I believe
(21:37:55) syzzer_: I share a vague recollection that matches mattock's
(21:37:59) cron2: it's no critical bug, but worth some sort of thank you in any case
(21:38:03) mattock: yeah
(21:38:14) mattock: if two people have the same recollection that recollection may be correct :D
(21:38:15) cron2: mattock: can you find out?
(21:38:28) mattock: probably, I can try closing the report down now
(21:38:36) cron2: commit d3dd620b13a21c3ed73fd466390f471915937309
(21:38:38) cron2: Reported by "jub0bs" on hackerone.com (#1039504)
(21:40:00) mattock: ah
(21:40:03) mattock: we can "Set award"
(21:40:07) mattock: in dollars
(21:40:08) cron2: ah!
(21:40:20) mattock: what is the report worth?
(21:40:23) cron2: so, what are the sums we are talking about, and who pays?
(21:40:39) mattock: I believe the money comes from IBB and/or OSTIF
(21:40:47) mattock: I'm not sure what kind of deal they did
(21:41:15) mattock: I'll check if OSTIF has some guidelines on this
(21:41:17) cron2: I have no idea what "someone could mess with your build scripts" is worth. Less than "someone could crash your program", and much less than "someone can break into your software". But in absolute numbers?
(21:41:22) cron2: yes, that would be good
(21:41:49) cron2: thanks :)
(21:42:06) mattock: Guido Vranken who reported several issues in OpenVPN got $5000
(21:42:09) mattock: https://ostif.org/congratulations-to-guido-vranken-for-earning-our-first-bug-bounty/
(21:42:11) vpnHelper: Title: Congratulations to Guido Vranken for earning our first bug bounty! Open Source Technology Improvement Fund (at ostif.org)
(21:42:32) cron2: that's quite a bit of money, but I seem to remember that he had at least one "crash our software" in them
(21:42:32) mattock: but he spend _way_ more time on it than jub0bs
(21:42:41) mattock: I'd say this is something like $50-$100
(21:42:50) cron2: definitely... so $50-ish sound okay-ish
(21:43:03) mattock: let's do $50, this kind of stuff is trivial to find by anyone
(21:43:16) cron2: okay
(21:43:18) mattock: nice that it was found, but not rocket science nor required much effort
(21:44:08) syzzer_: and without any user impact :)
(21:44:22) syzzer_: so yeah, sounds like the right order of magnitude
(21:45:50) mattock: hackerone suggested $100 minimum so I chose that one
(21:46:05) cron2: so this is what it is :)
(21:46:39) mattock: awarded and closed the report
(21:46:53) mattock: next topic?
(21:46:56) cron2: purrfect
(21:47:00) cron2: yes :)
(21:47:04) cron2: dear to my heart!
(21:47:34) mattock: the response ("no progress whatsover") is probably not what you'd like to hear
(21:48:04) mattock: I will periodically bug the ops team manager about it
(21:48:22) cron2: it is time for more interesting threats... has someone's dog died yet?
(21:48:28) mattock: no, not yet
(21:48:49) mattock: maybe you could hire a bunch of people to complain about lack of IPv6 support?
(21:48:53) mattock: to build some pressure
(21:48:58) mattock: :D
(21:49:04) becm: mattock: mayba bargain, "drop the cookie-requirement or enable IPv6" :)
(21:49:17) cron2: corp policy is "these are not serious customers, they are just complainers"
(21:49:38) mattock: believe it or not, they'd like to keep _you_ happy
(21:49:39) ordex: :D
(21:49:45) mattock: they know your role in OpenVPN 2
(21:50:27) mattock: I remind them that we need to keep you happy
(21:50:32) cron2: good to be appreciated :-)
(21:50:32) mattock: happy enough, at least :)
(21:50:37) cron2: totally so!
(21:50:50) mattock: I've _been reminding_ them
(21:50:55) mattock: and will keep doing so
(21:51:02) cron2: thanks.
(21:51:05) mattock: np
(21:51:07) cron2: sooo... buildbot...
(21:51:10) becm: so if cron to "likes" to complain... the keep IPv6 from him? :)
(21:51:28) cron2: becm: you could open a few sales inquiry tickets!
(21:51:30) dazo: mattock: can you complete all the bounties there ... so we can shut it down finally?
(21:51:46) mattock: dazo: just let me know which reports deserve a bounty
(21:51:52) mattock: and what size
(21:51:56) mattock: then it is no problem for me
(21:52:31) cron2: if we close down hackerone, we should agree on a different way to receive reports that might be bounty-worthy...
(21:52:55) cron2: (but I am too tired today to have good suggestions)
(21:53:14) mattock: what if we go through the remaining hackerone tickets in the next meeting, set bounties and close all of them down?
(21:53:25) cron2: okay
(21:53:37) mattock: we have a bunch open
(21:53:43) mattock: dazo: works for you?
(21:54:27) mattock: on the topic list: https://community.openvpn.net/openvpn/wiki/Topics-2020-12-09
(21:55:02) mattock: anyhow, buildbot: I think getting it nailed down around Christmas time looks realistic, possibly earlier
(21:55:11) mattock: it needs a focused effort of a couple of days
(21:55:22) mattock: with the Windows / tap-windows6 buildslave
(21:55:35) mattock: plus upgrade of the buildslaves
(21:55:43) cron2: with the *BSD zoo, the MacOS buildslave, the OpenSolaris buildslave :-) - yes
(21:56:04) cron2: just let me know, then, and "what do I need" - which packages, which versions, etc.
(21:56:11) ***cron2 <- python noob
(21:56:14) mattock: cron2: +1
(21:56:26) mattock: anything else for today?
(21:56:44) ordex: make ipv6 great again!
(21:57:24) cron2: there's a few ipv6 related bugs in trac... :-)
(21:57:26) cron2: but not today
(21:57:39) cron2: I wish you all a good evening! I hear my sofa calling!
(21:57:49) mattock: good evening everyone!
(21:57:55) syzzer_: hehe, good night all!
(21:57:55) mattock: I'll wrap up the summary and then head home
(21:58:02) cron2: *wave*
(21:58:12) ordex: good night !
(21:58:26) dazo: mattock: I think I suggested $50 for a one report ... and that was about it
(21:59:16) dazo: mattock: I tried to close down a lot of tickets .... was not aware there where that many left
(22:06:48) mattock: dazo: ok
^ permalink raw reply [flat|nested] 7+ messages in thread
* [Openvpn-devel] Summary of the community meeting (9th December 2020)
2020-12-03 19:30 [Openvpn-devel] Community meetings in December 2020
2020-12-03 20:09 ` [Openvpn-devel] Summary of the community meeting (3rd December 2020)
@ 2020-12-09 17:48 `
2020-12-09 18:11 ` Arne Schwabe
2020-12-10 23:48 ` [Openvpn-devel] Community meetings in December 2020 tincanteksup
2020-12-17 20:27 ` [Openvpn-devel] Summary of the community meeting (17th Dec 2020)
3 siblings, 1 reply; 7+ messages in thread
From: @ 2020-12-09 17:48 UTC (permalink / raw)
To: openvpn-devel
[-- Attachment #1: Type: text/plain, Size: 1993 bytes --]
Hi,
Here's the summary of the IRC meeting.
---
COMMUNITY MEETING
Place: #openvpn-meeting on irc.freenode.net
Date: Wed 9th December 2020
Time: 11:30 CET (10:30 UTC)
Planned meeting topics for this meeting were here:
<https://community.openvpn.net/openvpn/wiki/Topics-2020-12-09>
Your local meeting time is easy to check from services such as
<http://www.timeanddate.com/worldclock>
SUMMARY
cron2, dazo, mattock, ordex and plaisthos participated in
this meeting.
---
Noted that plaisthos has implemented AES-CCM.
---
Cron2 had tagged 2.4.10 before the meeting. It was released later the
same day.
---
Discussed the data-channel offload module (DCO) in context of OpenVPN
2.5. The current ovpn-dco only works with p2p but the current p2p model
is not easily extendable to p2mp. Therefore plaisthos and ordex agreed
that they will switch to a newer model in ovpn-dco that will also
support p2mp befor they continue with DCO and 2.5.
---
Discussed the OpenSSL bug fixed in OpenSSL 1.1.1i (CVE-2020-1971):
<https://www.openssl.org/news/vulnerabilities-1.1.1.html>
There seemed to be agreement that this does not really affect OpenVPN.
Basically somebody would have to be able to place a messed-up CRL on
your OpenVPN server, in which case you have bigger problems than a
vulnerable OpenSSL version. OpenVPN also does not download CRLs
dynamically, which reduces the impact.
Moreover, this problem is only a problem with OpenVPN running as server
on Windows. It is also possible, even if not very convenient, to replace
the OpenSSL library inside the OpenVPN installation directory
(C:\Program Files\OpenVPN) to patch this vulnerability.
Due to above the consensus (for the most part) was that we can wait
until 2.5.1 that is due in a few weeks before fixing this. If needed, we
can backpedal and do a separate OpenVPN 2.5.0 Windows installer release
before 2.5.1.
OpenVPN 2.4.10 has now been released - it has the fixed OpenSSL version
(1.1.1i).
---
Full chatlog attached
[-- Attachment #2: openvpn_irc_meeting_chatlog_2020-12-09.txt --]
[-- Type: text/plain, Size: 9566 bytes --]
(12:28:52) ordex: hi
(12:31:35) plaisthos: moin
(12:32:59) dazo: Hey!
(12:33:29) cron2: I am sort of here
(12:33:38) cron2: have the window open but focus is elsewhere sorry
(12:33:50) dazo: "sort of" is still better than not at all :)
(12:36:03) cron2: seems mattock got lost in the 2.4.10 windows build fight
(12:36:12) dazo: yeah ...
(12:36:17) dazo ha scelto come argomento: https://community.openvpn.net/openvpn/wiki/Topics-2020-12-09
(12:42:28) cron2: internal chat?
(12:42:39) dazo: trying
(12:43:51) plaisthos: So I implemented AES-CCM :P
(12:46:44) cron2: that sounds like a 2.6 update :-)
(12:46:50) cron2: any news on dco? 2.5?
(12:47:02) plaisthos: But on a more serious note, I am considerinng introducing XOR-ing our packet id with a shared secret
(12:47:13) cron2: on the 2.4 front - I have tagged and pushed 2.4.10 this morning, and mattock is working on release building
(12:47:48) plaisthos: so an observer doesn't know how many packets have already been sent by looking a single packet
(12:48:23) plaisthos: and also avoids a purely theoretical precomputation attack ;)
(12:49:31) dazo: cron2: nice! I'll kick off the Fedora/EPEL builds once the tarball + sigs are in place
(12:49:51) plaisthos: I think I will look into the client with --bind bug next
(12:50:34) dazo: what's that bug?
(12:51:56) dazo: cron2: DCO ... I'm about to push out an updated openvpn3-linux client ... with TCP and IPv6 transport support implemented, just waiting for some regression testing to complete ... ordex might have more details on what else on his roadmap now :)
(12:52:20) plaisthos: new client connection reuses old context on the server and since we don't run the new connect logic we don't generate a key since the ncp code assumes that key_id==0 is always a new session
(12:52:32) dazo: ahh
(12:52:53) mattock: damn
(12:52:59) mattock: meeting slipped my mind completely
(12:53:20) ordex: *boom*
(12:53:27) mattock: anyhow, I will start the release machinery now, a surprise lunch interrupted that one
(12:54:07) ordex: not a bad surprise
(12:54:31) cron2: plaisthos: sounds good
(12:55:11) plaisthos: For DCO and 2.5, the current ovpn-dco only works with p2p but the current p2p model is not easily extendable to p2mp
(12:55:50) plaisthos: So ordex and I agree that we switch to a newer model in ovpn-dco that will also support p2mp beforr I continue with dco and 2.5
(12:56:02) ordex: things are undergoing big changes on the kernel side, to accommodate p2mp
(12:56:07) ordex: yap
(12:56:11) ordex: that's where I Am right now
(12:56:20) ordex: (which also simplifies the code, in a sense)
(12:56:29) cron2: good to know
(12:56:46) cron2: plaisthos: have you shared your repo with bz?
(12:56:53) cron2: (the RFC repo)
(12:57:07) plaisthos: I sent an invite
(12:58:29) plaisthos: https://bfy.tw/Psjf
(12:58:30) vpnHelper: Title: LMGTFY (at bfy.tw)
(12:58:33) plaisthos: https://bfy.tw/Psjf
(12:58:35) plaisthos: https://bfy.tw/Psjf
(12:58:37) plaisthos: https://bfy.tw/Psjf
(12:59:06) plaisthos: argh
(12:59:28) cron2: plaisthos: thanks. Haven't heard anything, just wanted to be sure its not stuck on our side
(12:59:31) plaisthos: right mouse click windows terminal and nonsense in cliboard
(12:59:43) ordex: :D
(12:59:58) ordex: that was not nonsense
(13:00:07) dazo: :D
(13:04:00) dazo: so ... that's all for 2.5/2.6 updates?
(13:04:05) cron2: a bit nonsense-ish it was :)
(13:04:30) cron2: well, there is this openssl bug and "does it affect us, do we need a 2.5 (re-)release"?
(13:05:12) dazo: ahh, right!
(13:12:12) cron2: anyone? plaisthos?
(13:15:01) dazo: https://www.openssl.org/news/vulnerabilities-1.1.1.html ... so the 1.1.1i release yesterday seems at first glance to be critical for us
(13:15:01) vpnHelper: Title: /news/vulnerabilities-1.1.1.html (at www.openssl.org)
(13:15:38) plaisthos: it is one of these. I not sure what exactly needs to be done to crash issues
(13:15:59) becm [~becm@...2589...] è entrato nella stanza.
(13:16:18) plaisthos: probably not an issue in most setups but I am not understanding the issue well enough to say "we don't that openssl version"
(13:16:38) ordex: hm it seems the attacker also needs to control the CRL format
(13:16:49) ordex: so for locally generated CRLs this is not a very big deal
(13:16:55) ordex: IIUC
(13:18:42) cron2: that was my assessment of the writeup - "if someone can put a messed-up CRL on your openvpn server and have openvpn read it, your old openssl might not be your biggest problem"
(13:19:08) cron2: so - no 2.5.0 re-release? and 2.5.1 "in a few weeks"?
(13:21:23) plaisthos: since CRLs are not really usable that well in openvpn (you need to fetch them) manually, we are not really affected by this bug
(13:21:26) plaisthos: ;P
(13:21:58) dazo: I would say we should probably kick off a 2.5.0 update for Windows with a new OpenSSL .... " Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack." ... since OpenVPN often uses client cert based auth, we cannot trust the clients.
(13:21:58) dazo: There might be a possibility that clients may send a malicious cert which might be able to abuse this to gain access
(13:22:04) mattock: I would say "2.5.1 in a few weeks"
(13:22:12) mattock: if possible, at least
(13:22:27) mattock: people will ask about this, so better have an explanation ready
(13:23:31) dazo: Which is why I'm voting for a re-spin of 2.5.0 on Windows with the latest OpenSSL update ... "We're not 100% convinced OpenVPN is affected by this bug, but we don't want to take any risks"
(13:24:30) dazo: I agree that most OpenVPN setups are most likely not affected, but the details and scope isn't that clear in the description
(13:25:01) ordex: that sentence about the unrelated bug is quite cryptic
(13:25:02) ordex: to me
(13:27:20) dazo: yes, and that's what makes me concerned
(13:29:45) ordex: by re-reading the upper part, I think this is simpl saying: openssl affected by this bug cannot really construct a working EDIPARTYNAME value, but if you try hard enough you can still do that and trigger the crash
(13:29:47) dazo: I know the windows building can be a hassle and that it's easy for me to say "re-spin" not being involved in the build process ... but I don't want to compromise the security for an unclear issue. This was important enough for OpenSSL to do a pre-announcement without any details last week
(13:30:00) ordex: but still under the assumption that you have provided both CRL *and* certificate to check
(13:30:54) ordex: so if the CRL is not malformed, there is nothing to crash in any case
(13:31:18) dazo: Unless the attacker manages to inject a malicious CRL
(13:31:40) ordex: right
(13:32:06) ordex: in the openvpn case, that means full access to the file system where the CRL is stored
(13:32:32) dazo: Yeah, we don't do CRL downloads on-the-fly, so that's "good"
(13:32:34) ordex: I can see that other apps may download the CRL from the web, so they don't know what they are using. but for openvpn I don't think that case exists
(13:32:39) ordex: right
(13:32:57) ordex: so imho this can wait for 2.5.1
(13:33:33) ordex: (and the problematic platform is OpenVPN ran as server on windows)
(13:33:41) ordex: conclusion? :D
(13:33:49) ordex: anybody in favour or re-doing 2.5.0 now?
(13:34:21) mattock: not me, because I would take the hit :D
(13:34:24) ordex: :D
(13:34:26) cron2: I do not read this as critical, but I'm not the one having to do the work either
(13:34:29) dazo: I'm still thinking "better safe than sorry"
(13:34:35) mattock: installers are easier than full release, but still an effort
(13:35:11) mattock: I could do 2.5.0 windows installer release later this week, if needed
(13:35:13) ordex: can't people update openssl on their own ?
(13:35:18) ordex: (on windows)
(13:35:23) mattock: they could, yes
(13:35:25) ordex: or will openvpn always use the bundled one?
(13:35:36) dazo: mattock: I'm considering to request Andrew to release you from all your work except improving and fully automating Windows builds
(13:35:47) mattock: I suppose you could put openssl you've obtained from openssl.org to openvpn directory
(13:35:55) mattock: dazo: that request will fail miserably
(13:36:00) mattock: that much I can tell :)
(13:36:03) ordex: ah ok - not super easy though
(13:36:09) ordex: anyway I have to run for lunch
(13:36:27) ordex: I'd sitck to "not upgrade now", but I leave to you the final decision
(13:36:30) dazo: mattock: I can be persistent in my requests if I want to :-P
(13:36:32) ordex: *stick
(13:36:46) mattock: dazo: you know how well cron2's IPv6 + community crusade has progressed, right?
(13:36:48) mattock: :P
(13:37:32) mattock: that said, it would be nice to get some help with automating openvpn 2.x releases and all that
(13:37:43) cron2: dazo: can I use that for my ipv6 crusade? :-)
(13:37:50) mattock: requesting that from andrew could be more beneficial than trying to detach me from ops work
(13:38:36) mattock: there are simply too many junior guys in the ops team, so a large part of the harder stuff lands on my plate anyways
(13:39:38) cron2: I need to leave now, sorry. I'll read the backlog, or bring up the other topics again later
(13:39:39) dazo: cron2: Core team has geared up the IPv6 attention and making more noise as well ... so the attention is increasing steadily
(13:39:46) cron2: \o/
(13:39:52) cron2: ok *wave*
(13:39:59) mattock: ok, let's end this thing
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [Openvpn-devel] Summary of the community meeting (9th December 2020)
2020-12-09 17:48 ` [Openvpn-devel] Summary of the community meeting (9th "
@ 2020-12-09 18:11 ` Arne Schwabe
0 siblings, 0 replies; 7+ messages in thread
From: Arne Schwabe @ 2020-12-09 18:11 UTC (permalink / raw)
> ---
>
> Discussed the data-channel offload module (DCO) in context of OpenVPN
> 2.5. The current ovpn-dco only works with p2p but the current p2p model
> is not easily extendable to p2mp. Therefore plaisthos and ordex agreed
> that they will switch to a newer model in ovpn-dco that will also
> support p2mp befor they continue with DCO and 2.5.
>
As a sidenote, 2.5 is more likely to be master/2.6 in this context.
Arne
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [Openvpn-devel] Community meetings in December 2020
2020-12-03 19:30 [Openvpn-devel] Community meetings in December 2020
2020-12-03 20:09 ` [Openvpn-devel] Summary of the community meeting (3rd December 2020)
2020-12-09 17:48 ` [Openvpn-devel] Summary of the community meeting (9th "
@ 2020-12-10 23:48 ` tincanteksup
2020-12-15 10:31 `
2020-12-17 20:27 ` [Openvpn-devel] Summary of the community meeting (17th Dec 2020)
3 siblings, 1 reply; 7+ messages in thread
From: tincanteksup @ 2020-12-10 23:48 UTC (permalink / raw)
To: openvpn-devel
Please discuss and resolve the fate of the OpenVPN-Legacy-Service for
Windows.
Ref: https://community.openvpn.net/openvpn/ticket/1344
Official status of deprecation/removal requested.
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [Openvpn-devel] Community meetings in December 2020
2020-12-10 23:48 ` [Openvpn-devel] Community meetings in December 2020 tincanteksup
@ 2020-12-15 10:31 `
0 siblings, 0 replies; 7+ messages in thread
From: @ 2020-12-15 10:31 UTC (permalink / raw)
To: tincanteksup <tincanteksup@
Il 11/12/20 01:48, tincanteksup ha scritto:
> Please discuss and resolve the fate of the OpenVPN-Legacy-Service for
> Windows.
>
> Ref: https://community.openvpn.net/openvpn/ticket/1344
>
> Official status of deprecation/removal requested.
>
>
> _______________________________________________
> Openvpn-devel mailing list
> Openvpn-devel@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/openvpn-devel
Added to the agenda for Thursday:
https://community.openvpn.net/openvpn/wiki/Topics-2020-12-17
^ permalink raw reply [flat|nested] 7+ messages in thread
* [Openvpn-devel] Summary of the community meeting (17th Dec 2020)
2020-12-03 19:30 [Openvpn-devel] Community meetings in December 2020
` (2 preceding siblings ...)
2020-12-10 23:48 ` [Openvpn-devel] Community meetings in December 2020 tincanteksup
@ 2020-12-17 20:27 `
3 siblings, 0 replies; 7+ messages in thread
From: @ 2020-12-17 20:27 UTC (permalink / raw)
To: openvpn-devel
[-- Attachment #1: Type: text/plain, Size: 3900 bytes --]
Hi,
Here's the summary of the IRC meeting.
---
COMMUNITY MEETING
Place: #openvpn-meeting on irc.freenode.net
Date: Thu 17th December 2020
Time: 20:00 CET (19:00 UTC)
Planned meeting topics for this meeting were here:
<https://community.openvpn.net/openvpn/wiki/Topics-2020-12-17>
Your local meeting time is easy to check from services such as
<http://www.timeanddate.com/worldclock>
SUMMARY
becm, cron2, dazo, lev, mattock, plaisthos and Pippin participated in
this meeting.
---
We have received some bug reports and patches related to OpenVPN 2.5.
Some of them are minor, some are "strange corner cases", a few are "the
default is no longer iproute2, so my --iproute $script setup fails" and
"and all my systemd unit files look different". The
windows-register-dns-crash looks bad, but it only happens if you're not
using the iservice.
So nothing major or urgent has surfaced yet.
---
Noted that OpenVPN 2.4.10 release has been solid. Nothing to report.
---
For 2.6/master we have quite a few patches from plaisthos in patchwork
(#1549/1550, #1545/1544/1546). We also have the "pending authentication
improvements patchset:
<https://patchwork.openvpn.net/project/openvpn2/list/?series=962>
These would need review from someone who understands crypto.
---
Noted that it would be good to have community download numbers viewable
by community members. Mattock will relocate the page and see if the
metrics could be exposed publicly.
---
Talked about openvpn3-linux client. While it would be possible to port
it to FreeBSD most of those are servers, and openvpn3-linux really
targets the client (GUI) experience. So, the network-manager
improvements that are being worked on will make more people happy that a
FreeBSD port.
---
Cron2 announced a bounty of a "few pounds of chocolate" for having a
working NM OpenVPN client with tokens that survive suspend/resume and
network changes.
---
Planned the 2.5.1 release. There are a few bugfixes wrt auth-token and
TLS session handling that needs to go into 2.5.
A release in mid-January seems reasonable.
---
Talked about migrating to the new Wintun API. That is perfect material
for OpenVPN 2.6. If we're not forced by, say, a Wintun 0.8 security
issue, we should keep OpenVPN 2.5 at Wintun 0.8 to ensure stability.
That said, Lev will check if we could use WinTun 0.10 in OpenVPN 2.5
without changing the API.
---
Talked about officially deprecating OpenVPNServiceLegacy. We dropped it
silently in OpenVPN 2.5 and then somebody noticed:
<https://community.openvpn.net/openvpn/ticket/1344>
There is no reason (as far as we know) for using OpenVPNServiceLegacy in
this day and age. However, we should clearly document that it is gone
and will never come back. This documentation effort would include
- The Windows README that gets installed by the MSI
- Changes.rst
- Some articles in Trac
These should be done by OpenVPN 2.5.1 release time.
---
Noted that OpenVPN Connect tickets in Trac have been assigned to "yuriy"
but there has not been any visible movement there. Somebody will poke
him internally and ask what's up. In the worst case we can automatically
close OpenVPN Connect tickets with a message like "Open tickets for
OpenVPNConnect here: $URL".
---
Talked about OpenVPN exploding with "unknown option" if it encounters
an option in the configuration file that is not supported by the
platform (Windows, Linux, etc). We need to think about how to solve this
nicely.
---
Noted that
https://community.openvpn.net/openvpn/ticket/1345
requires a test installer. Potentially one of the NSIS-based 2.6
installers could be used:
<https://build.openvpn.net/downloads/snapshots/>
If not, lev or mattock can do a custom build.
We don't yet have MSI snapshot automation.
---
Next neeting is scheduled for January 6th 2021 (Wed) at the usual time.
---
Happy Holidays everyone!
--
Full chatlog attached
[-- Attachment #2: openvpn_irc_meeting_chatlog_2020-12-17.txt --]
[-- Type: text/plain, Size: 19109 bytes --]
(20:59:28) mattock: hi
(20:59:36) cron2: ho!
(20:59:37) mattock: not me
(21:00:15) dazo: Blame me!
(21:00:28) cron2: !blame
(21:00:43) cron2: (this certainly needs updating, over in the other channel)
(21:02:51) dazo: hehe
(21:04:22) cron2: are lev__ and ordex somewhere around?
(21:04:30) cron2: plaisthos already said he couldn't make it
(21:05:43) mattock: internal meeting ended, now I'm really here
(21:06:10) cron2: I've used the time to add stuff to the agenda :)
(21:06:28) mattock: shall we start?
(21:06:29) dazo: I'll ping them
(21:07:40) plaisthos: i am semi around actually
(21:08:15) dazo: Nice! I've pinged lev__ and ordex in our internal chat and privately .... warning them cron2 is looking for them :-P
(21:08:32) cron2: with every minute they are late, I will assign a trac ticket!
(21:08:59) mattock: you're making them an offer they can't refuse, basically :D
(21:09:08) cron2: which is actually somewhat starting the "updates on 2.5" section :-)
(21:09:46) dazo: hahaha
(21:10:07) cron2: so, people *are* using this, and we are receiving bug reports (and patches!). Some of these are minor, some are "some strange corner cases", a few are "the default is no longer iproute2, so my --iproute $script setup fails" and "and all my systemd unit files look different"
(21:10:20) cron2: but so far I haven't seen anything truly catastrophic
(21:10:47) cron2: the windows-register-dns-crash looks bad, but it only happens if you're not using the iservice, so "not really urgent"
(21:11:52) cron2: so, I'm not unhappy. Interest, and no catastrophes yet :-)
(21:12:10) dazo: Yeah, just skimmed through the tickets listed in the agenda .... all related to new code, so this is valuable, and we're seeing more corner cases - so nothing really surprising
(21:12:11) cron2: On the 2.4.10 front, I have not seen or heard anything (we did the release a week ago, IIRC).
(21:13:20) dazo: The 2.4.10 should be in the mail Fedora/EPEL repos for F32+33 and EPEL 7+8 (Fedora 34 got 2.5, which is still in development)
(21:13:33) cron2: nice
(21:13:55) cron2: FreeBSD and gentoo jumped from 2.4.9 to 2.5.0 :-)
(21:14:24) cron2: (so did NetBSD and "all the rest that uses pkgsrc")
(21:15:11) dazo: There are some repo downloads for the 2.5 release in Fedora Copr (for Feodra 32+33, EPEL 7+8) ... but just some hundreds per repo in average
(21:16:29) dazo: mattock: which brings back a question which re-surfaces from time to time .... download stats from the s3 buckets ... do we have that? To see Deb/Ubu downloads
(21:16:48) cron2: on the master->2.6 side of things, we have quite a few patches from plaisthos in patchwork, so some help from "someone who understands crypto" on #1549/1550, #1545/1544/1546 would be welcome...
(21:17:20) cron2: and the whole "pending authentication improvements" patchset (11 patches) starting here: https://patchwork.openvpn.net/project/openvpn2/list/?series=962
(21:17:21) vpnHelper: Title: OpenVPN 2 - Patchwork (at patchwork.openvpn.net)
(21:17:25) pippin__ [Pippin_@...2315.../vpn/protonvpn/pippin/x-75792076] è entrato nella stanza.
(21:17:25) Pippin_ ha abbandonato la stanza (quit: Killed (rothfuss.freenode.net (Nickname regained by services))).
(21:17:25) pippin__ è ora conosciuto come Pippin_
(21:17:40) mattock: dazo: yes we do, but I can't remember the URL
(21:17:44) cron2: syzzer wanted to look at that, but I think he's busy with work and family :-)
(21:18:00) mattock: we did check the swupdate numbers during 2.5 rc stage
(21:18:28) mattock: I'll have to ask for the URL again
(21:18:30) dazo: nice ... well, would be good to massage them and make them available for the community
(21:18:49) cron2: +1
(21:18:56) ***dazo likes https://patchwork.openvpn.net/patch/1487/
(21:19:19) cron2: nah, that's python
(21:19:32) cron2: (but besides this, yes, documentation and sample scripts are always great :-) )
(21:20:18) dazo: I see I need to try to port openvpn3-linux to FreeBSD and port the Python code to Perl code to get cron2's attention :-P
(21:20:37) cron2: haha :-)
(21:20:52) mattock: freebsd has dbus
(21:20:52) cron2: something simpler would also get my attention, like a perl module driving openvpn2 via the management API
(21:20:56) mattock: as an option at least
(21:21:17) cron2: mainly to test the API (which we don't do today)...
(21:21:23) dazo: yeah
(21:22:15) dazo: mattock: yeah, and D-Bus is the most important system dependency of the openvpn3-linux project ... the rest shouldn't be that tricky
(21:22:42) mattock: I'm sure openvpn3-linux would break in interested ways when ported to FreeBSD
(21:22:45) mattock: interesting
(21:22:59) cron2: FreeBSD has python as well, which is one of the reasons why it annoys me... it's so much work to maintain with their py2/py3 incompatibilities and packages depending on one or the other only
(21:23:05) mattock: but a port would probably within the realm of possibility
(21:23:14) dazo: You believe my code got bugs, mattock !?! blasphemy! :-D
(21:23:36) cron2: dazo: penguins, more likely
(21:23:37) mattock: dazo: everyone's code has bugs, one per line on average
(21:24:08) dazo: :-P
(21:24:27) mattock: I suppose a FreeBSD port is not even looming in the horizon or is it?
(21:25:25) dazo: No, I want to get NM integration in place, and preferably replace the glib2 gdbus implementation with something more C++-ish
(21:25:26) cron2: not sure there is much interest. I think openvpn3-linux really targets "the GUI user experience", while most FreeBSD systems I'm aware of are "server style"
(21:25:44) cron2: yep, good NM integration would make many more people happy than a FreeBSD port
(21:26:40) cron2: ohyes. Having a working NM client with tokens that survive suspend/resume and network changes would certainly be worth a few pounds of chocolate
(21:26:53) ***cron2 hereby declares this a bounty
(21:27:11) dazo: well, openvpn3-linux got some advantages for servers connecting to other VPN servers ... it's quite a bit harder to tilt over and disconnect than openvpn 2 - at least in some configs/setups I've seen
(21:27:44) dazo: connecting as client to other VPN servers
(21:27:52) cron2: I only get to see the bugs when it falls over and screams when fed a normal .ovpn config :-)
(21:28:20) dazo: hehe :)
(21:29:26) cron2: so, is there an upper limit how many tickets to assign to lev__ and ordex?
(21:29:42) dazo: I'd say, "the sky is the limit" *ducks*
(21:30:21) cron2: we do have 445 open tickets in the system... so, 222 each (and I keep one of mine)
(21:30:55) cron2: fun aside - shall we have a look at the next agenda points? (unless there's more updates on 2.4/2.5/2.6)
(21:31:03) cron2: ah, maybe one thing
(21:31:09) cron2: 2.5.1 planning
(21:31:54) mattock: 2.5.1 sounds good
(21:31:59) cron2: there are a few bugfixes wrt auth-token and TLS session handling and this that are current in master, and that really should go into 2.5 as well - we do not have them yet (plaisthos is working on that area) but we could do a releas like "mid january"
(21:32:07) cron2: ish
(21:33:07) dazo: that makes sense ... the auth-token stuff isn't worse than it's been before, and is more annoying than really critical ... so that makes sense
(21:33:34) cron2: right, this is not "new bugs" but "we just didn't manage to finish them before 2.5.0"
(21:34:36) dazo: exactly
(21:35:06) cron2: mattock: what do you think?
(21:35:32) mattock: mid-January = good
(21:35:41) cron2: good :-)
(21:36:11) mattock: any other OpenVPN x.x updates?
(21:36:40) becm: adaption to new Wintun API, more a 2.6 or 2.5.x thing?
(21:37:02) dazo: becm: that's more a 2.6 thing, how I see it
(21:37:21) dazo: we try to keep 2.5 as stable as possible
(21:37:32) plaisthos: I am not really happy to deviate from our 'we build all from source' concept
(21:37:39) cron2: it's not a 2.5.1 thing, I think
(21:37:53) plaisthos: the new api sounds like we need to include 3rd party binary libraries from Wireguard
(21:37:55) cron2: so we need to look long and hard and then plan
(21:38:21) plaisthos: and I haven't had time to have a real look at the license
(21:38:24) dazo: agreed
(21:38:35) becm: and hope nothing forces our hand with a critical 0.8-bug
(21:38:41) cron2: we need to have a plan, though... - exactly
(21:39:11) dazo: yeah, if anything really critical appears in 0.8, we'll reconsider ... but that's a different scenario
(21:40:05) becm: from a "sane" approach, I'd have also categorized this as "2.6". but it's still 2020 :)
(21:40:06) dazo: as long as the current code works stable, safe and secure ... there's not much to gain from adding new code into a stable branch now
(21:40:37) lev__: I will check if it currently works with 0.10 without changing API
(21:41:01) dazo: thx!
(21:41:19) dazo: That's a reasonable middle-ground for 2.5 at least
(21:41:56) cron2: lev__: ah, just in time, so you only earned 35 bonus tickets
(21:42:15) mattock: lev: see the beginning of the meeting
(21:42:21) mattock: :)
(21:42:34) cron2: but let's spend the last minutes on these tickets, shall we?
(21:42:38) mattock: but you can earn "some pounds of chocolate" if you pay your cards right
(21:42:44) cron2: indeed!
(21:43:03) mattock: what about the openvpnservicelegacy deprecation?
(21:43:08) mattock: did we do it officially already?
(21:43:14) cron2: de-facto
(21:43:23) cron2: the msi installer does not install the service anymore
(21:43:26) mattock: do we have it in Changes.rst?
(21:43:37) cron2: (the *binary* is there, as it's in openvpnserv.exe, but it is not "installed")
(21:43:37) mattock: and/or trac
(21:43:43) mattock: yeah
(21:43:44) cron2: no, and sort-of
(21:44:01) mattock: maybe put it into Changes.rst so that people may accidentally find it?
(21:44:09) cron2: so, the ticket complains about "IT IS GOOONE!", I said "yeah, this is what it is, we just forgot to document it", and got yelled at :-)
(21:44:45) cron2: so maybe we should put it in that README which the windows version presents after installing... (I have no idea what is in there)
(21:44:58) mattock: ok, yeah, that is reasonable
(21:45:14) mattock: I can add that to my 2.5.1 release ticket
(21:45:19) mattock: which I shall create now
(21:45:36) cron2: plus changes.rst :-) - and I think the wiki should have some documentation about "what if I use the legacy service now, how can I use the openvpnsrv2 instead?"
(21:45:46) cron2: do we have something for that already?
(21:46:05) mattock: probably not, because we assumed nobody would be using OpenVPNServiceLegacy at this point
(21:46:13) mattock: I mean, it is _Legacy_
(21:46:29) mattock: and has been so since 2.4 (or earlier?)
(21:46:33) mattock: for some years
(21:46:46) mattock: I think Changes.rst and the Windows readme would be enough
(21:48:40) mattock: done
(21:48:44) mattock: the ticket, that is :D
(21:49:01) dazo: agreed
(21:49:03) cron2: I think we want to at least look at where our trac mentions the service, and update :-) - I'll put that in the ticket, as "this is what we want" (and no, you won#t get it back)
(21:49:43) cron2: done
(21:49:49) dazo: and when people complain about it, we really need to get them to explain why the legacy way was better (except "I don't need to change anything")
(21:50:07) cron2: right, mattock already asked for that in the ticket
(21:50:31) mattock: no response -> no reason
(21:50:42) mattock: I really don't think there is a single valid reason for it
(21:50:44) cron2: as well :-) - "publically documented"
(21:50:58) dazo: yupp
(21:50:59) mattock: OpenVPNService is way superior
(21:51:05) cron2: I have no idea
(21:51:39) dazo: just like systemd is way superior over init.d + scripts + scripts + scripts + scripts + scripts + scripts :-P
(21:52:06) dazo: (sorry, I just had to!
(21:52:09) cron2: yeah, systemd is totally like windows, just less documentation
(21:52:20) Pippin_: :)
(21:52:43) dazo: huh!? You haven't found the systemd man pages?
(21:52:44) cron2: and I've heard it's actually much harder to build
(21:53:07) dazo: you don't need to build it (unless you want to develop it) ... it comes prebuilt ;-)
(21:53:12) dazo: by default!
(21:53:15) dazo: ;-)
(21:53:16) cron2: (a colleague was hacking stuff into systemd-networkd, and was cursing like days in a row...)
(21:53:36) dazo: ahh, well, that's development .... we also curse a lot when hacking openvpn :-P
(21:53:49) cron2: ah, yes :-)
(21:53:53) cron2: so, next: yuriy
(21:54:33) cron2: I see some activity in trac on "yuriy assigned" tickets, but also new "OpenVPN Connect" related stuff which isn't seeing attention... (well, our tickets are not either, but Connect is someone else's problem)
(21:54:43) cron2: so what's the current method of operation with Connect tickets?
(21:55:06) lev__: didn't we have dedicated guy from Connect team to handle those
(21:55:07) dazo: I can try to follow up internally, so that the guy who should follow up knows what to do
(21:55:12) cron2: I assign them to "yuriy" as I haven't heard anything else
(21:55:33) dazo: as long as we do that, we should consider our task done
(21:55:54) dazo: we could probably update our trac reports to exclude tickets assigned to yuriy
(21:56:04) mattock: maybe we could poke "yuriy" about those tickets
(21:56:10) mattock: maybe he does not know what to do with them
(21:56:12) cron2: I actually want them to be worked-on and closed :)
(21:56:14) mattock: maybe they're even resolved
(21:56:16) mattock: +1
(21:56:21) dazo: yeah, agreed
(21:56:54) cron2: if the canned answer is "this is the wrong ticket system, I have copied over the ticket to $corpbugzilla" that would be perfectly fine
(21:57:22) dazo: otherwise we could apply some automation if nothing improves .... automatically close tickets related to OpenVPN Connect with a message in the ticket "Open tickets for OpenVPNConnect here: $URL"
(21:58:00) mattock: dazo: yeah, that could serve as a fallback
(21:58:02) cron2: or that. If we have said URL :-)
(21:58:32) cron2: so, time is running short... #1342 need a reply from lev__
(21:59:19) lev__: yeah sounds doable for 2.5.1
(21:59:31) cron2: this is about people creating .ovpn configs for their users, including "--windows-driver wintun", and then some users import those to linux or tunnelblick and it dies with "unknown option"
(22:00:05) cron2: we generally do not ignore "windows-only" options on other platforms, but generally those options are *pushed*, and then openvpn ignores unknown options anyway
(22:00:15) lev__: I didn't think that --windows-driver could be pushable
(22:00:22) cron2: it isn't
(22:00:40) cron2: (well, it could be, but I'm not sure that makes much sense)
(22:00:45) cron2: mmmh
(22:00:54) mattock: so basically ignore options non-windows can't handle?
(22:01:09) cron2: we did have a trick for "I want to put this option in my .ovpn, but openvpn should ignore it if it does not understand it"
(22:01:29) cron2: something with fancy setenv, I think...
(22:02:10) cron2: setenv FORWARD_COMPATIBLE 1
(22:03:19) cron2: yeah, but that wasn't what I had in mind (this will make openvpn turn *all* config errors into warnings)
(22:03:20) lev__: I need to look more closely, but initial idea was to process this option only under _win32 define
(22:03:47) cron2: lev__: yes, the original approach totally makes sense, but "people did other things"
(22:03:58) lev__: I will take care of it
(22:04:08) cron2: ah!
(22:04:25) cron2: setenv opt windows-driver wintun
(22:04:32) becm: lev__: the "people" or the "option handling"? :)
(22:04:50) cron2: becm: well, "people doing configs for their users"
(22:05:38) dazo: but it would be good if windows options would just become NOOP on non-windows builds
(22:08:03) cron2: at last those that are used in "distributed by admin" .ovpn files, yes... pushed stuff is ignored (with warning) anyway
(22:08:13) ***cron2 does like "setenv opt" :-)
(22:09:23) dazo: yeah, setenv opt is fine for pushed options ... and pushed options can be fixed easier with, well, setenv opt ...
(22:09:39) cron2: no :-)
(22:09:51) cron2: setenv opt is particularily *not* intended for pushed options
(22:10:12) cron2: in push context, msglevel is M_WARN anyway, so it does not do anything
(22:10:28) cron2: push "explode" or push "setenv opt explode" would both log the same warning
(22:10:37) cron2: but if you put it in .ovpn
(22:10:41) cron2: expode -> explodes
(22:10:47) cron2: setenv opt explode -> warning
(22:11:12) mattock: 11 minutes overtime
(22:11:22) cron2: (I couldn't remember, so I went into options.c, add_option(), right at the start)
(22:11:22) mattock: any agreement on the windows-specific options?
(22:11:33) dazo: ahh, I see ... thx, cron2!
(22:11:44) mattock: or "we will think about this a bit more"?
(22:11:55) cron2: I think we need to return to the larger issue... the ticket at hand can be solved two ways, let's see what the author says
(22:12:15) cron2: "we will think about this a bit more" (we have linux-specific options as well)
(22:12:40) cron2: so, two very short ones... #1345 -> mattock/lev__: do you build snapshot installers people can test with?
(22:13:33) cron2: and #1355 -> "ordex may want to look into this" (mmmh, since lev__ showed up, all 445 tickets for ordex, then!)
(22:13:43) cron2: next meeting?
(22:14:48) lev__: I can be mattock 's backup for building snapshot installer
(22:15:24) mattock: we do have https://build.openvpn.net/downloads/snapshots/ where I see 2.6 NSI snapshots from Nov 29th
(22:15:26) vpnHelper: Title: Index of /downloads/snapshots/ (at build.openvpn.net)
(22:16:02) mattock: next meeting hmm
(22:16:13) dazo: next year, I think we concluded last time
(22:16:14) mattock: 6th (Wed) Jan?
(22:16:33) mattock: that would be according to our normal schedule
(22:17:06) cron2: mattock: so NSI snapshots are regularily built, MSI not yet (or "impossible to do")?
(22:17:18) dazo: mattock: Don't recall, what does our previous meeting minutes say? ;-)
(22:17:33) mattock: MSI is not yet, until there is a Windows buildslave capable of building MSI
(22:18:30) cron2: https://community.openvpn.net/openvpn/ticket/1368 is actually a tap-driver-related-yuriy-ticket :)
(22:18:35) mattock: oh, mail-archive is up finally
(22:19:07) mattock: Agreed to not have meeting on Dec 23rd or 31st. The last meeting this month will be on 17th.
(22:19:26) mattock: no decision on a January meeting
(22:19:29) mattock: I say 6th
(22:19:30) mattock: ok?
(22:19:35) cron2: wfm
(22:20:00) dazo: okay, then its fine :)
(22:20:03) mattock: +1
(22:20:06) mattock: anything else?
(22:20:17) dazo: happy holiday?!? ;-)
(22:20:57) cron2: stay safe and healthy
(22:21:19) cron2: and do not go crazy about lockdown with kids at home, no way to go skiing or anything else besides "sit at home"...
(22:21:44) dazo: +1
(22:21:49) mattock: yes, let us sit at home and bark at our respective family members
(22:21:56) mattock: that is a sure recipe for success :D
(22:22:18) dazo: Now it's not needed to argue what to watch on TV ... there's time to watch everything! :-P
(22:22:37) mattock: yep
(22:22:46) mattock: anyways, good night and happy holidays everyone!
(22:23:08) mattock: I will add that greeting to the summary as well
(22:25:19) dazo: thx!
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2020-12-17 20:27 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2020-12-03 19:30 [Openvpn-devel] Community meetings in December 2020
2020-12-03 20:09 ` [Openvpn-devel] Summary of the community meeting (3rd December 2020)
2020-12-09 17:48 ` [Openvpn-devel] Summary of the community meeting (9th "
2020-12-09 18:11 ` Arne Schwabe
2020-12-10 23:48 ` [Openvpn-devel] Community meetings in December 2020 tincanteksup
2020-12-15 10:31 `
2020-12-17 20:27 ` [Openvpn-devel] Summary of the community meeting (17th Dec 2020)
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.