OpenVPN 2.7_alpha2 released
Yuriy Darnobyt <[email protected]> Fri, 20 Jun 2025 22:09:51 +0300
| Newsgroups | gmane.network.openvpn.announce |
|---|---|
| Message-ID | <9F5CC7E1-D7A0-4C16-836D-DFFBD70D1E17__38126.2799188093$1750446931$gmane$org@openvpn.com> |
--===============0503463515384588439== Content-Type: multipart/alternative; boundary="Apple-Mail=_5CDB0EC6-CA17-4C33-959D-3BB5DEB6E3D0" --Apple-Mail=_5CDB0EC6-CA17-4C33-959D-3BB5DEB6E3D0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii The OpenVPN community project team is proud to release OpenVPN = 2.7_alpha2. This is the second Alpha release for the feature release 2.7.0. As the Alpha name implies this is an early release build, this is not = intended=20 for production use. This release include security fix for CVE-2025-50054 Highlights of this release include: * Multi-socket support for servers -- Handle multiple = addresses/ports/protocols=20 within one server * Improved Client support for DNS options * Client implementations for Linux/BSD, included with the default = install * New client implementation for Windows, adding support for features = like split=20 DNS and DNSSEC * Architectural improvements on Windows * The block-local flag is now enforced with WFP filters * Windows network adapters are now generated on demand * Windows automatic service now runs as an unprivileged user * Support for server mode in win-dco driver Note: Support for the wintun driver has been removed. win-dco is now the=20= default, tap-windows6 is the fallback solution for use-cases not covered = by win-dco. * Improved data channel * Enforcement of AES-GCM usage limit * Epoch data keys and packet format * Support for new upstream DCO Linux kernel module * This release supports the new ovpn DCO Linux kernel module which will = be=20 available in future upstream Linux kernel releases. Backports of the new = module=20 to current kernels are available via the ovpn-backports project. * TLS 1.3 support with bleeding-edge mbedTLS versions More details can be found in the Changes document: <https://github.com/OpenVPN/openvpn/blob/master/Changes.rst> Source code and Windows installers can be downloaded from our download = page: <https://openvpn.net/community-downloads/> Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are available in = the various official Community repositories: <https://community.openvpn.net/Pages/OpenVPN%20software%20repos> Kind regards, Yuriy Darnobyt --Apple-Mail=_5CDB0EC6-CA17-4C33-959D-3BB5DEB6E3D0 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=us-ascii <html><head><meta http-equiv=3D"content-type" content=3D"text/html; = charset=3Dus-ascii"></head><body style=3D"overflow-wrap: break-word; = -webkit-nbsp-mode: space; line-break: after-white-space;"><div><font = color=3D"#000000"><span style=3D"caret-color: rgb(0, 0, 0);">The OpenVPN = community project team is proud to release OpenVPN = 2.7_alpha2.</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">This is the second Alpha release = for the feature release 2.7.0.</span></font></div><div><font = color=3D"#000000"><span style=3D"caret-color: rgb(0, 0, 0);">As the = Alpha name implies this is an early release build, this is not = intended </span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">for production = use.</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);"><br></span></font></div><div><font = color=3D"#000000"><span style=3D"caret-color: rgb(0, 0, 0);">This = release include security fix for = CVE-2025-50054</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);"><br></span></font></div><div><font = color=3D"#000000"><span style=3D"caret-color: rgb(0, 0, 0);">Highlights = of this release include:</span></font></div><div><font = color=3D"#000000"><span style=3D"caret-color: rgb(0, 0, 0);">* = Multi-socket support for servers -- Handle multiple = addresses/ports/protocols </span></font></div><div><font = color=3D"#000000"><span style=3D"caret-color: rgb(0, 0, 0);">within one = server</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">* Improved Client support for DNS = options</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">* Client implementations for = Linux/BSD, included with the default = install</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">* New client implementation for = Windows, adding support for features like = split </span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">DNS and = DNSSEC</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">* Architectural improvements on = Windows</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">* The block-local flag is now = enforced with WFP filters</span></font></div><div><font = color=3D"#000000"><span style=3D"caret-color: rgb(0, 0, 0);">* Windows = network adapters are now generated on = demand</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">* Windows automatic service now = runs as an unprivileged user</span></font></div><div><font = color=3D"#000000"><span style=3D"caret-color: rgb(0, 0, 0);">* Support = for server mode in win-dco driver</span></font></div><div><font = color=3D"#000000"><span style=3D"caret-color: rgb(0, 0, 0);">Note: = Support for the wintun driver has been removed. win-dco is now = the </span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">default, tap-windows6 is the = fallback solution for use-cases not covered by = win-dco.</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">* Improved data = channel</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">* Enforcement of AES-GCM usage = limit</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">* Epoch data keys and packet = format</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">* Support for new upstream DCO = Linux kernel module</span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">* This release supports the new = ovpn DCO Linux kernel module which will = be </span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">available in future upstream Linux = kernel releases. Backports of the new = module </span></font></div><div><font color=3D"#000000"><span = style=3D"caret-color: rgb(0, 0, 0);">to current kernels are available = via the ovpn-backports project.</span></font></div><div><font = color=3D"#000000"><span style=3D"caret-color: rgb(0, 0, 0);">* TLS 1.3 = support with bleeding-edge mbedTLS versions</span></font></div><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">More details = can be found in the Changes document:</span><br style=3D"caret-color: = rgb(0, 0, 0); color: rgb(0, 0, 0);"><br style=3D"caret-color: rgb(0, 0, = 0); color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);"><</span><a = href=3D"https://github.com/OpenVPN/openvpn/blob/master/Changes.rst">https:= //github.com/OpenVPN/openvpn/blob/master/Changes.rst</a><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">></span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">Source code = and Windows installers can be downloaded from our download = page:</span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><</span><a = href=3D"https://openvpn.net/community-downloads/">https://openvpn.net/comm= unity-downloads/</a><span style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);">></span><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);">Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are = available in the various</span><br style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);">official Community repositories:</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><</span><a = href=3D"https://community.openvpn.net/Pages/OpenVPN%20software%20repos">ht= tps://community.openvpn.net/Pages/OpenVPN%20software%20repos</a><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">></span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">Kind = regards,</span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><font color=3D"#000000"><span style=3D"caret-color: rgb(0, 0, = 0);">Yuriy Darnobyt</span></font><br></body></html>= --Apple-Mail=_5CDB0EC6-CA17-4C33-959D-3BB5DEB6E3D0-- --===============0503463515384588439== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============0503463515384588439== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Openvpn-announce mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/openvpn-announce --===============0503463515384588439==--