Message ID | 20201125222603.23695-1-erik.kapfer@ipfire.org |
---|---|
State | Accepted |
Commit | 820edb2374ef3af02e8fa37a4b1acebefcc6317c |
Headers |
Return-Path: <development-bounces@lists.ipfire.org> Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-384) server-digest SHA384 client-signature ECDSA (P-384) client-digest SHA384) (Client CN "mail01.haj.ipfire.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4ChFpw1V0pz3wpq for <patchwork@web04.haj.ipfire.org>; Wed, 25 Nov 2020 22:26:16 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-384) client-signature ECDSA (P-384)) (Client CN "mail02.haj.ipfire.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mail01.ipfire.org (Postfix) with ESMTPS id 4ChFps5R0Dz1FR; Wed, 25 Nov 2020 22:26:13 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [127.0.0.1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4ChFps4Ndbz2xkx; Wed, 25 Nov 2020 22:26:13 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-384) server-digest SHA384 client-signature ECDSA (P-384) client-digest SHA384) (Client CN "mail01.haj.ipfire.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4ChFpr3qSyz2xjs for <development@lists.ipfire.org>; Wed, 25 Nov 2020 22:26:12 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-384) server-digest SHA384) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4ChFpp3ZLPzkm; Wed, 25 Nov 2020 22:26:10 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1606343170; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=p5UIYpos/h+K+EZGKc/jIdfVOHa0kTY8CAtap8HlUiA=; b=QfpcdiqO/Zw9cijh2I2TMfFLW1KCF/2H4bJJaOM5FnaYcHz5g+fEudTksFspv4tPQeWulK 6RhqPjk7e2mfPtAA== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1606343170; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=p5UIYpos/h+K+EZGKc/jIdfVOHa0kTY8CAtap8HlUiA=; b=n3Q/qV7t+Tc5KN74zZ9VnOWIVCfMr7WICvktb7tBSVkBwz0jBY2iWn4QhQ45oYyTHfdNQS 58deL1oh9CaLpe1hY4ZIeR8yaApj+E/ILn6xbwPlcuwaVoyNCFeS3mdKmDMFLE8/Rzfe6+ uW7H+bBT4jJ+em2FSJdrg22BYkYR9vSyucrjLrdPBsUFXSaYvZQVz5+F8jHv46Tg6EN14u d9jrzjKor8Lvqn9V2pL5SpODs0Y5KN4ls9wRql4TG4Hl6Bwo5hcdMURGuBTl2gAkI3NaSR DbdXwRYdpQkWRHKgzaKNjbd7S+YFNgmfKExvcUMDhBzucERQG/umgeFljAw6Mg== From: ummeegge <erik.kapfer@ipfire.org> To: development@lists.ipfire.org Subject: [PATCH] OpenVPN: Update to version 2.5.0 Date: Wed, 25 Nov 2020 22:26:03 +0000 Message-Id: <20201125222603.23695-1-erik.kapfer@ipfire.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: development@lists.ipfire.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: IPFire development talk <development.lists.ipfire.org> List-Unsubscribe: <https://lists.ipfire.org/mailman/options/development>, <mailto:development-request@lists.ipfire.org?subject=unsubscribe> List-Archive: <http://lists.ipfire.org/pipermail/development/> List-Post: <mailto:development@lists.ipfire.org> List-Help: <mailto:development-request@lists.ipfire.org?subject=help> List-Subscribe: <https://lists.ipfire.org/mailman/listinfo/development>, <mailto:development-request@lists.ipfire.org?subject=subscribe> Errors-To: development-bounces@lists.ipfire.org Sender: "Development" <development-bounces@lists.ipfire.org> |
Series |
OpenVPN: Update to version 2.5.0
|
|
Commit Message
Erik Kapfer
Nov. 25, 2020, 10:26 p.m. UTC
Signed-off-by: ummeegge <erik.kapfer@ipfire.org>
---
config/rootfiles/common/openvpn | 1 -
lfs/openvpn | 4 ++--
2 files changed, 2 insertions(+), 3 deletions(-)
Comments
Hello Erik, Am I right to assume that this cannot be merged without breaking anything? Best, -Michael > On 25 Nov 2020, at 22:26, ummeegge <erik.kapfer@ipfire.org> wrote: > > Signed-off-by: ummeegge <erik.kapfer@ipfire.org> > --- > config/rootfiles/common/openvpn | 1 - > lfs/openvpn | 4 ++-- > 2 files changed, 2 insertions(+), 3 deletions(-) > > diff --git a/config/rootfiles/common/openvpn b/config/rootfiles/common/openvpn > index 547842db3..41ccc885e 100644 > --- a/config/rootfiles/common/openvpn > +++ b/config/rootfiles/common/openvpn > @@ -19,7 +19,6 @@ usr/sbin/openvpn > #usr/share/doc/openvpn/README.down-root > #usr/share/doc/openvpn/README.mbedtls > #usr/share/doc/openvpn/management-notes.txt > -#usr/share/man/man8/openvpn.8 > var/ipfire/ovpn/ca > var/ipfire/ovpn/caconfig > var/ipfire/ovpn/ccd > diff --git a/lfs/openvpn b/lfs/openvpn > index 779bf5520..b026d515b 100644 > --- a/lfs/openvpn > +++ b/lfs/openvpn > @@ -24,7 +24,7 @@ > > include Config > > -VER = 2.4.9 > +VER = 2.5.0 > > THISAPP = openvpn-$(VER) > DL_FILE = $(THISAPP).tar.xz > @@ -40,7 +40,7 @@ objects = $(DL_FILE) > > $(DL_FILE) = $(DL_FROM)/$(DL_FILE) > > -$(DL_FILE)_MD5 = 446df6dc29364d00929ea9c725412cb8 > +$(DL_FILE)_MD5 = ba426e2217833b522810d6c06f7cc8f7 > > install : $(TARGET) > > -- > 2.20.1 >
Hi Michael, Am Mittwoch, den 25.11.2020, 22:43 +0000 schrieb Michael Tremer: > Hello Erik, > > Am I right to assume that this cannot be merged without breaking > anything? I think it can be merged without breaking something, two more already known warnings are presant with this update here but it broke nothing. Tests has been made with 2.4.x clients with a 2.5.0 server but 2.3.x clients should be OK with this too. Testings might be important. > > Best, > -Michael Best, Erik > > > On 25 Nov 2020, at 22:26, ummeegge <erik.kapfer@ipfire.org> wrote: > > > > Signed-off-by: ummeegge <erik.kapfer@ipfire.org> > > --- > > config/rootfiles/common/openvpn | 1 - > > lfs/openvpn | 4 ++-- > > 2 files changed, 2 insertions(+), 3 deletions(-) > > > > diff --git a/config/rootfiles/common/openvpn > > b/config/rootfiles/common/openvpn > > index 547842db3..41ccc885e 100644 > > --- a/config/rootfiles/common/openvpn > > +++ b/config/rootfiles/common/openvpn > > @@ -19,7 +19,6 @@ usr/sbin/openvpn > > #usr/share/doc/openvpn/README.down-root > > #usr/share/doc/openvpn/README.mbedtls > > #usr/share/doc/openvpn/management-notes.txt > > -#usr/share/man/man8/openvpn.8 > > var/ipfire/ovpn/ca > > var/ipfire/ovpn/caconfig > > var/ipfire/ovpn/ccd > > diff --git a/lfs/openvpn b/lfs/openvpn > > index 779bf5520..b026d515b 100644 > > --- a/lfs/openvpn > > +++ b/lfs/openvpn > > @@ -24,7 +24,7 @@ > > > > include Config > > > > -VER = 2.4.9 > > +VER = 2.5.0 > > > > THISAPP = openvpn-$(VER) > > DL_FILE = $(THISAPP).tar.xz > > @@ -40,7 +40,7 @@ objects = $(DL_FILE) > > > > $(DL_FILE) = $(DL_FROM)/$(DL_FILE) > > > > -$(DL_FILE)_MD5 = 446df6dc29364d00929ea9c725412cb8 > > +$(DL_FILE)_MD5 = ba426e2217833b522810d6c06f7cc8f7 > > > > install : $(TARGET) > > > > -- > > 2.20.1 > > >
Hello, I will leave this one then for the next core update where we hopefully have moved forward with some of the changes to the UI and more people have verified that this won’t break anything :) Best, -Michael > On 25 Nov 2020, at 23:20, ummeegge <ummeegge@ipfire.org> wrote: > > Hi Michael, > > Am Mittwoch, den 25.11.2020, 22:43 +0000 schrieb Michael Tremer: >> Hello Erik, >> >> Am I right to assume that this cannot be merged without breaking >> anything? > I think it can be merged without breaking something, two more already > known warnings are presant with this update here but it broke nothing. > Tests has been made with 2.4.x clients with a 2.5.0 server but 2.3.x > clients should be OK with this too. Testings might be important. > >> >> Best, >> -Michael > > Best, > > Erik > >> >>> On 25 Nov 2020, at 22:26, ummeegge <erik.kapfer@ipfire.org> wrote: >>> >>> Signed-off-by: ummeegge <erik.kapfer@ipfire.org> >>> --- >>> config/rootfiles/common/openvpn | 1 - >>> lfs/openvpn | 4 ++-- >>> 2 files changed, 2 insertions(+), 3 deletions(-) >>> >>> diff --git a/config/rootfiles/common/openvpn >>> b/config/rootfiles/common/openvpn >>> index 547842db3..41ccc885e 100644 >>> --- a/config/rootfiles/common/openvpn >>> +++ b/config/rootfiles/common/openvpn >>> @@ -19,7 +19,6 @@ usr/sbin/openvpn >>> #usr/share/doc/openvpn/README.down-root >>> #usr/share/doc/openvpn/README.mbedtls >>> #usr/share/doc/openvpn/management-notes.txt >>> -#usr/share/man/man8/openvpn.8 >>> var/ipfire/ovpn/ca >>> var/ipfire/ovpn/caconfig >>> var/ipfire/ovpn/ccd >>> diff --git a/lfs/openvpn b/lfs/openvpn >>> index 779bf5520..b026d515b 100644 >>> --- a/lfs/openvpn >>> +++ b/lfs/openvpn >>> @@ -24,7 +24,7 @@ >>> >>> include Config >>> >>> -VER = 2.4.9 >>> +VER = 2.5.0 >>> >>> THISAPP = openvpn-$(VER) >>> DL_FILE = $(THISAPP).tar.xz >>> @@ -40,7 +40,7 @@ objects = $(DL_FILE) >>> >>> $(DL_FILE) = $(DL_FROM)/$(DL_FILE) >>> >>> -$(DL_FILE)_MD5 = 446df6dc29364d00929ea9c725412cb8 >>> +$(DL_FILE)_MD5 = ba426e2217833b522810d6c06f7cc8f7 >>> >>> install : $(TARGET) >>> >>> -- >>> 2.20.1 >>> >> > >
Hi Michael, Am Donnerstag, den 26.11.2020, 12:05 +0000 schrieb Michael Tremer: > Hello, > > I will leave this one then for the next core update where we > hopefully have moved forward with some of the changes to the UI and > more people have verified that this won’t break anything :) OK. According to the work on the WUI, i have pushed all i currently have which can be found in here --> https://git.ipfire.org/?p=people/ummeegge/ipfire-2.x.git;a=commit;h=34af1d714178b2cd0c27e8c39052a8c7ce87d116 Best, Erik Best, -Michael > On 25 Nov 2020, at 23:20, ummeegge <ummeegge@ipfire.org> wrote: > > Hi Michael, > > Am Mittwoch, den 25.11.2020, 22:43 +0000 schrieb Michael Tremer: > > Hello Erik, > > > > Am I right to assume that this cannot be merged without breaking > > anything? > I think it can be merged without breaking something, two more already > known warnings are presant with this update here but it broke > nothing. > Tests has been made with 2.4.x clients with a 2.5.0 server but 2.3.x > clients should be OK with this too. Testings might be important. > > > > > Best, > > -Michael > > Best, > > Erik > > > > > > On 25 Nov 2020, at 22:26, ummeegge <erik.kapfer@ipfire.org> > > > wrote: > > > > > > Signed-off-by: ummeegge <erik.kapfer@ipfire.org> > > > --- > > > config/rootfiles/common/openvpn | 1 - > > > lfs/openvpn | 4 ++-- > > > 2 files changed, 2 insertions(+), 3 deletions(-) > > > > > > diff --git a/config/rootfiles/common/openvpn > > > b/config/rootfiles/common/openvpn > > > index 547842db3..41ccc885e 100644 > > > --- a/config/rootfiles/common/openvpn > > > +++ b/config/rootfiles/common/openvpn > > > @@ -19,7 +19,6 @@ usr/sbin/openvpn > > > #usr/share/doc/openvpn/README.down-root > > > #usr/share/doc/openvpn/README.mbedtls > > > #usr/share/doc/openvpn/management-notes.txt > > > -#usr/share/man/man8/openvpn.8 > > > var/ipfire/ovpn/ca > > > var/ipfire/ovpn/caconfig > > > var/ipfire/ovpn/ccd > > > diff --git a/lfs/openvpn b/lfs/openvpn > > > index 779bf5520..b026d515b 100644 > > > --- a/lfs/openvpn > > > +++ b/lfs/openvpn > > > @@ -24,7 +24,7 @@ > > > > > > include Config > > > > > > -VER = 2.4.9 > > > +VER = 2.5.0 > > > > > > THISAPP = openvpn-$(VER) > > > DL_FILE = $(THISAPP).tar.xz > > > @@ -40,7 +40,7 @@ objects = $(DL_FILE) > > > > > > $(DL_FILE) = $(DL_FROM)/$(DL_FILE) > > > > > > -$(DL_FILE)_MD5 = 446df6dc29364d00929ea9c725412cb8 > > > +$(DL_FILE)_MD5 = ba426e2217833b522810d6c06f7cc8f7 > > > > > > install : $(TARGET) > > > > > > -- > > > 2.20.1 > > > > > > >
Hi Erik and *, I have installed the OpenVPN 2.5.0 binary on my system and can confirm that all my clients, mobile and laptop, were able to successfully connect. Regards, Adolf. On 26/11/2020 20:19, ummeegge wrote: > Hi Michael, > > Am Donnerstag, den 26.11.2020, 12:05 +0000 schrieb Michael Tremer: >> Hello, >> >> I will leave this one then for the next core update where we >> hopefully have moved forward with some of the changes to the UI and >> more people have verified that this won’t break anything :) > OK. According to the work on the WUI, i have pushed all i currently > have which can be found in here --> > https://git.ipfire.org/?p=people/ummeegge/ipfire-2.x.git;a=commit;h=34af1d714178b2cd0c27e8c39052a8c7ce87d116 > > Best, > > Erik > > > Best, > -Michael > >> On 25 Nov 2020, at 23:20, ummeegge <ummeegge@ipfire.org> wrote: >> >> Hi Michael, >> >> Am Mittwoch, den 25.11.2020, 22:43 +0000 schrieb Michael Tremer: >>> Hello Erik, >>> >>> Am I right to assume that this cannot be merged without breaking >>> anything? >> I think it can be merged without breaking something, two more already >> known warnings are presant with this update here but it broke >> nothing. >> Tests has been made with 2.4.x clients with a 2.5.0 server but 2.3.x >> clients should be OK with this too. Testings might be important. >> >>> >>> Best, >>> -Michael >> >> Best, >> >> Erik >> >>> >>>> On 25 Nov 2020, at 22:26, ummeegge <erik.kapfer@ipfire.org> >>>> wrote: >>>> >>>> Signed-off-by: ummeegge <erik.kapfer@ipfire.org> >>>> --- >>>> config/rootfiles/common/openvpn | 1 - >>>> lfs/openvpn | 4 ++-- >>>> 2 files changed, 2 insertions(+), 3 deletions(-) >>>> >>>> diff --git a/config/rootfiles/common/openvpn >>>> b/config/rootfiles/common/openvpn >>>> index 547842db3..41ccc885e 100644 >>>> --- a/config/rootfiles/common/openvpn >>>> +++ b/config/rootfiles/common/openvpn >>>> @@ -19,7 +19,6 @@ usr/sbin/openvpn >>>> #usr/share/doc/openvpn/README.down-root >>>> #usr/share/doc/openvpn/README.mbedtls >>>> #usr/share/doc/openvpn/management-notes.txt >>>> -#usr/share/man/man8/openvpn.8 >>>> var/ipfire/ovpn/ca >>>> var/ipfire/ovpn/caconfig >>>> var/ipfire/ovpn/ccd >>>> diff --git a/lfs/openvpn b/lfs/openvpn >>>> index 779bf5520..b026d515b 100644 >>>> --- a/lfs/openvpn >>>> +++ b/lfs/openvpn >>>> @@ -24,7 +24,7 @@ >>>> >>>> include Config >>>> >>>> -VER = 2.4.9 >>>> +VER = 2.5.0 >>>> >>>> THISAPP = openvpn-$(VER) >>>> DL_FILE = $(THISAPP).tar.xz >>>> @@ -40,7 +40,7 @@ objects = $(DL_FILE) >>>> >>>> $(DL_FILE) = $(DL_FROM)/$(DL_FILE) >>>> >>>> -$(DL_FILE)_MD5 = 446df6dc29364d00929ea9c725412cb8 >>>> +$(DL_FILE)_MD5 = ba426e2217833b522810d6c06f7cc8f7 >>>> >>>> install : $(TARGET) >>>> >>>> -- >>>> 2.20.1 >>>> >>> >> >> > > >
Hello, Well in that case I will change my mind and merge this patch. This is enough of a second opinion to move things forward a step. Best, -Michael > On 29 Nov 2020, at 12:42, Adolf Belka <ahb.ipfire@gmail.com> wrote: > > Hi Erik and *, > > I have installed the OpenVPN 2.5.0 binary on my system and can confirm that all my clients, mobile and laptop, were able to successfully connect. > > Regards, > > Adolf. > > > On 26/11/2020 20:19, ummeegge wrote: >> Hi Michael, >> Am Donnerstag, den 26.11.2020, 12:05 +0000 schrieb Michael Tremer: >>> Hello, >>> >>> I will leave this one then for the next core update where we >>> hopefully have moved forward with some of the changes to the UI and >>> more people have verified that this won’t break anything :) >> OK. According to the work on the WUI, i have pushed all i currently >> have which can be found in here --> >> https://git.ipfire.org/?p=people/ummeegge/ipfire-2.x.git;a=commit;h=34af1d714178b2cd0c27e8c39052a8c7ce87d116 >> Best, >> Erik >> Best, >> -Michael >>> On 25 Nov 2020, at 23:20, ummeegge <ummeegge@ipfire.org> wrote: >>> >>> Hi Michael, >>> >>> Am Mittwoch, den 25.11.2020, 22:43 +0000 schrieb Michael Tremer: >>>> Hello Erik, >>>> >>>> Am I right to assume that this cannot be merged without breaking >>>> anything? >>> I think it can be merged without breaking something, two more already >>> known warnings are presant with this update here but it broke >>> nothing. >>> Tests has been made with 2.4.x clients with a 2.5.0 server but 2.3.x >>> clients should be OK with this too. Testings might be important. >>> >>>> >>>> Best, >>>> -Michael >>> >>> Best, >>> >>> Erik >>> >>>> >>>>> On 25 Nov 2020, at 22:26, ummeegge <erik.kapfer@ipfire.org> >>>>> wrote: >>>>> >>>>> Signed-off-by: ummeegge <erik.kapfer@ipfire.org> >>>>> --- >>>>> config/rootfiles/common/openvpn | 1 - >>>>> lfs/openvpn | 4 ++-- >>>>> 2 files changed, 2 insertions(+), 3 deletions(-) >>>>> >>>>> diff --git a/config/rootfiles/common/openvpn >>>>> b/config/rootfiles/common/openvpn >>>>> index 547842db3..41ccc885e 100644 >>>>> --- a/config/rootfiles/common/openvpn >>>>> +++ b/config/rootfiles/common/openvpn >>>>> @@ -19,7 +19,6 @@ usr/sbin/openvpn >>>>> #usr/share/doc/openvpn/README.down-root >>>>> #usr/share/doc/openvpn/README.mbedtls >>>>> #usr/share/doc/openvpn/management-notes.txt >>>>> -#usr/share/man/man8/openvpn.8 >>>>> var/ipfire/ovpn/ca >>>>> var/ipfire/ovpn/caconfig >>>>> var/ipfire/ovpn/ccd >>>>> diff --git a/lfs/openvpn b/lfs/openvpn >>>>> index 779bf5520..b026d515b 100644 >>>>> --- a/lfs/openvpn >>>>> +++ b/lfs/openvpn >>>>> @@ -24,7 +24,7 @@ >>>>> >>>>> include Config >>>>> >>>>> -VER = 2.4.9 >>>>> +VER = 2.5.0 >>>>> >>>>> THISAPP = openvpn-$(VER) >>>>> DL_FILE = $(THISAPP).tar.xz >>>>> @@ -40,7 +40,7 @@ objects = $(DL_FILE) >>>>> >>>>> $(DL_FILE) = $(DL_FROM)/$(DL_FILE) >>>>> >>>>> -$(DL_FILE)_MD5 = 446df6dc29364d00929ea9c725412cb8 >>>>> +$(DL_FILE)_MD5 = ba426e2217833b522810d6c06f7cc8f7 >>>>> >>>>> install : $(TARGET) >>>>> >>>>> -- >>>>> 2.20.1 >>>>> >>>> >>> >>>
Hello Erik, This is a massive commit again. Do you have them broken down somewhere? Best, -Michael > On 26 Nov 2020, at 19:19, ummeegge <ummeegge@ipfire.org> wrote: > > Hi Michael, > > Am Donnerstag, den 26.11.2020, 12:05 +0000 schrieb Michael Tremer: >> Hello, >> >> I will leave this one then for the next core update where we >> hopefully have moved forward with some of the changes to the UI and >> more people have verified that this won’t break anything :) > OK. According to the work on the WUI, i have pushed all i currently > have which can be found in here --> > https://git.ipfire.org/?p=people/ummeegge/ipfire-2.x.git;a=commit;h=34af1d714178b2cd0c27e8c39052a8c7ce87d116 > > Best, > > Erik > > > Best, > -Michael > >> On 25 Nov 2020, at 23:20, ummeegge <ummeegge@ipfire.org> wrote: >> >> Hi Michael, >> >> Am Mittwoch, den 25.11.2020, 22:43 +0000 schrieb Michael Tremer: >>> Hello Erik, >>> >>> Am I right to assume that this cannot be merged without breaking >>> anything? >> I think it can be merged without breaking something, two more already >> known warnings are presant with this update here but it broke >> nothing. >> Tests has been made with 2.4.x clients with a 2.5.0 server but 2.3.x >> clients should be OK with this too. Testings might be important. >> >>> >>> Best, >>> -Michael >> >> Best, >> >> Erik >> >>> >>>> On 25 Nov 2020, at 22:26, ummeegge <erik.kapfer@ipfire.org> >>>> wrote: >>>> >>>> Signed-off-by: ummeegge <erik.kapfer@ipfire.org> >>>> --- >>>> config/rootfiles/common/openvpn | 1 - >>>> lfs/openvpn | 4 ++-- >>>> 2 files changed, 2 insertions(+), 3 deletions(-) >>>> >>>> diff --git a/config/rootfiles/common/openvpn >>>> b/config/rootfiles/common/openvpn >>>> index 547842db3..41ccc885e 100644 >>>> --- a/config/rootfiles/common/openvpn >>>> +++ b/config/rootfiles/common/openvpn >>>> @@ -19,7 +19,6 @@ usr/sbin/openvpn >>>> #usr/share/doc/openvpn/README.down-root >>>> #usr/share/doc/openvpn/README.mbedtls >>>> #usr/share/doc/openvpn/management-notes.txt >>>> -#usr/share/man/man8/openvpn.8 >>>> var/ipfire/ovpn/ca >>>> var/ipfire/ovpn/caconfig >>>> var/ipfire/ovpn/ccd >>>> diff --git a/lfs/openvpn b/lfs/openvpn >>>> index 779bf5520..b026d515b 100644 >>>> --- a/lfs/openvpn >>>> +++ b/lfs/openvpn >>>> @@ -24,7 +24,7 @@ >>>> >>>> include Config >>>> >>>> -VER = 2.4.9 >>>> +VER = 2.5.0 >>>> >>>> THISAPP = openvpn-$(VER) >>>> DL_FILE = $(THISAPP).tar.xz >>>> @@ -40,7 +40,7 @@ objects = $(DL_FILE) >>>> >>>> $(DL_FILE) = $(DL_FROM)/$(DL_FILE) >>>> >>>> -$(DL_FILE)_MD5 = 446df6dc29364d00929ea9c725412cb8 >>>> +$(DL_FILE)_MD5 = ba426e2217833b522810d6c06f7cc8f7 >>>> >>>> install : $(TARGET) >>>> >>>> -- >>>> 2.20.1 >>>> >>> >> >> > > >
Hi Michael, Am Dienstag, den 01.12.2020, 16:14 +0000 schrieb Michael Tremer: > Hello Erik, > > This is a massive commit again. Yes indeed. > > Do you have them broken down somewhere? Yes shure, i can send them e.g. like sorted in the CGI, e.g. first the data-cipher{-fallback} selection, second tls-cipher selection and the last one the authentication ? As an idea. Have made also a little more progress in here, it is now also possible to reconfigure the clients which are may updated via a checkbox on = clients >=2.5.0 and off clients <2.5.0 . So from my side, i think this very development should be ready. What currently is missing is a check if 64bit block ciphers are in usage to print a warning in the WUI that they will be deleted in a near future but am on it too and this might also be an extra commit... Best, Erik > > Best, > -Michael > > > On 26 Nov 2020, at 19:19, ummeegge <ummeegge@ipfire.org> wrote: > > > > Hi Michael, > > > > Am Donnerstag, den 26.11.2020, 12:05 +0000 schrieb Michael Tremer: > > > Hello, > > > > > > I will leave this one then for the next core update where we > > > hopefully have moved forward with some of the changes to the UI > > > and > > > more people have verified that this won’t break anything :) > > OK. According to the work on the WUI, i have pushed all i currently > > have which can be found in here --> > > > > https://git.ipfire.org/?p=people/ummeegge/ipfire-2.x.git;a=commit;h=34af1d714178b2cd0c27e8c39052a8c7ce87d116 > > > > Best, > > > > Erik > > > > > > Best, > > -Michael > > > > > On 25 Nov 2020, at 23:20, ummeegge <ummeegge@ipfire.org> wrote: > > > > > > Hi Michael, > > > > > > Am Mittwoch, den 25.11.2020, 22:43 +0000 schrieb Michael Tremer: > > > > Hello Erik, > > > > > > > > Am I right to assume that this cannot be merged without > > > > breaking > > > > anything? > > > I think it can be merged without breaking something, two more > > > already > > > known warnings are presant with this update here but it broke > > > nothing. > > > Tests has been made with 2.4.x clients with a 2.5.0 server but > > > 2.3.x > > > clients should be OK with this too. Testings might be important. > > > > > > > > > > > Best, > > > > -Michael > > > > > > Best, > > > > > > Erik > > > > > > > > > > > > On 25 Nov 2020, at 22:26, ummeegge <erik.kapfer@ipfire.org> > > > > > wrote: > > > > > > > > > > Signed-off-by: ummeegge <erik.kapfer@ipfire.org> > > > > > --- > > > > > config/rootfiles/common/openvpn | 1 - > > > > > lfs/openvpn | 4 ++-- > > > > > 2 files changed, 2 insertions(+), 3 deletions(-) > > > > > > > > > > diff --git a/config/rootfiles/common/openvpn > > > > > b/config/rootfiles/common/openvpn > > > > > index 547842db3..41ccc885e 100644 > > > > > --- a/config/rootfiles/common/openvpn > > > > > +++ b/config/rootfiles/common/openvpn > > > > > @@ -19,7 +19,6 @@ usr/sbin/openvpn > > > > > #usr/share/doc/openvpn/README.down-root > > > > > #usr/share/doc/openvpn/README.mbedtls > > > > > #usr/share/doc/openvpn/management-notes.txt > > > > > -#usr/share/man/man8/openvpn.8 > > > > > var/ipfire/ovpn/ca > > > > > var/ipfire/ovpn/caconfig > > > > > var/ipfire/ovpn/ccd > > > > > diff --git a/lfs/openvpn b/lfs/openvpn > > > > > index 779bf5520..b026d515b 100644 > > > > > --- a/lfs/openvpn > > > > > +++ b/lfs/openvpn > > > > > @@ -24,7 +24,7 @@ > > > > > > > > > > include Config > > > > > > > > > > -VER = 2.4.9 > > > > > +VER = 2.5.0 > > > > > > > > > > THISAPP = openvpn-$(VER) > > > > > DL_FILE = $(THISAPP).tar.xz > > > > > @@ -40,7 +40,7 @@ objects = $(DL_FILE) > > > > > > > > > > $(DL_FILE) = $(DL_FROM)/$(DL_FILE) > > > > > > > > > > -$(DL_FILE)_MD5 = 446df6dc29364d00929ea9c725412cb8 > > > > > +$(DL_FILE)_MD5 = ba426e2217833b522810d6c06f7cc8f7 > > > > > > > > > > install : $(TARGET) > > > > > > > > > > -- > > > > > 2.20.1 > > > > > > > > > > > > > > > > > > > > > >
Hi Erik, As my OpenVPN setup uses the strongest encryption I am able to use (currently AES-GCM (256 bit)), I thought I should also test the IPFire OpenVPN-2.5.0 binary with weaker encryption clients and see how that worked with my setup. I did this for both my laptop (using Network Manager with OpenVPN plugin) and my Android phone using the OpenVPN for Android App. Both the laptop and Android phone are using OpenVPN-2.5.0 I evaluated AES-CBC (128 bit), DES-EDE3-CBC (192 bit) and BF-CBC (128 bit). The clients were created in IPFire with OpenVPN-2.4.9 binary. They were then imported into the laptop and phone with no modification. In all three cases on both the laptop and mobile phone the OpenVPN connection was successfully made with the OpenVPN server running with 2.4.9 and 2.5.0. With the weaker encryption options there was a lot of input in the client logs about using weak ciphers. This occurred whether the IPFire server was running with 2.4.9 or 2.5.0. So at least with my clients there was no problem with even the very weak ciphers with running clients after changing IPFire to 2.5.0 binary. Regards, Adolf. On 29/11/2020 13:42, Adolf Belka wrote: > Hi Erik and *, > > I have installed the OpenVPN 2.5.0 binary on my system and can confirm that all my clients, mobile and laptop, were able to successfully connect. > > Regards, > > Adolf. > > > On 26/11/2020 20:19, ummeegge wrote: >> Hi Michael, >> >> Am Donnerstag, den 26.11.2020, 12:05 +0000 schrieb Michael Tremer: >>> Hello, >>> >>> I will leave this one then for the next core update where we >>> hopefully have moved forward with some of the changes to the UI and >>> more people have verified that this won’t break anything :) >> OK. According to the work on the WUI, i have pushed all i currently >> have which can be found in here --> >> https://git.ipfire.org/?p=people/ummeegge/ipfire-2.x.git;a=commit;h=34af1d714178b2cd0c27e8c39052a8c7ce87d116 >> >> Best, >> >> Erik >> >> >> Best, >> -Michael >> >>> On 25 Nov 2020, at 23:20, ummeegge <ummeegge@ipfire.org> wrote: >>> >>> Hi Michael, >>> >>> Am Mittwoch, den 25.11.2020, 22:43 +0000 schrieb Michael Tremer: >>>> Hello Erik, >>>> >>>> Am I right to assume that this cannot be merged without breaking >>>> anything? >>> I think it can be merged without breaking something, two more already >>> known warnings are presant with this update here but it broke >>> nothing. >>> Tests has been made with 2.4.x clients with a 2.5.0 server but 2.3.x >>> clients should be OK with this too. Testings might be important. >>> >>>> >>>> Best, >>>> -Michael >>> >>> Best, >>> >>> Erik >>> >>>> >>>>> On 25 Nov 2020, at 22:26, ummeegge <erik.kapfer@ipfire.org> >>>>> wrote: >>>>> >>>>> Signed-off-by: ummeegge <erik.kapfer@ipfire.org> >>>>> --- >>>>> config/rootfiles/common/openvpn | 1 - >>>>> lfs/openvpn | 4 ++-- >>>>> 2 files changed, 2 insertions(+), 3 deletions(-) >>>>> >>>>> diff --git a/config/rootfiles/common/openvpn >>>>> b/config/rootfiles/common/openvpn >>>>> index 547842db3..41ccc885e 100644 >>>>> --- a/config/rootfiles/common/openvpn >>>>> +++ b/config/rootfiles/common/openvpn >>>>> @@ -19,7 +19,6 @@ usr/sbin/openvpn >>>>> #usr/share/doc/openvpn/README.down-root >>>>> #usr/share/doc/openvpn/README.mbedtls >>>>> #usr/share/doc/openvpn/management-notes.txt >>>>> -#usr/share/man/man8/openvpn.8 >>>>> var/ipfire/ovpn/ca >>>>> var/ipfire/ovpn/caconfig >>>>> var/ipfire/ovpn/ccd >>>>> diff --git a/lfs/openvpn b/lfs/openvpn >>>>> index 779bf5520..b026d515b 100644 >>>>> --- a/lfs/openvpn >>>>> +++ b/lfs/openvpn >>>>> @@ -24,7 +24,7 @@ >>>>> >>>>> include Config >>>>> >>>>> -VER = 2.4.9 >>>>> +VER = 2.5.0 >>>>> >>>>> THISAPP = openvpn-$(VER) >>>>> DL_FILE = $(THISAPP).tar.xz >>>>> @@ -40,7 +40,7 @@ objects = $(DL_FILE) >>>>> >>>>> $(DL_FILE) = $(DL_FROM)/$(DL_FILE) >>>>> >>>>> -$(DL_FILE)_MD5 = 446df6dc29364d00929ea9c725412cb8 >>>>> +$(DL_FILE)_MD5 = ba426e2217833b522810d6c06f7cc8f7 >>>>> >>>>> install : $(TARGET) >>>>> >>>>> -- >>>>> 2.20.1 >>>>> >>>> >>> >>> >> >> >>
Hi Adolf, Am Mittwoch, den 02.12.2020, 22:31 +0100 schrieb Adolf Belka: > Hi Erik, > > As my OpenVPN setup uses the strongest encryption I am able to use > (currently AES-GCM (256 bit)), I thought I should also test the > IPFire OpenVPN-2.5.0 binary with weaker encryption clients and see > how that worked with my setup. > > I did this for both my laptop (using Network Manager with OpenVPN > plugin) and my Android phone using the OpenVPN for Android App. Both > the laptop and Android phone are using OpenVPN-2.5.0 > > I evaluated AES-CBC (128 bit), DES-EDE3-CBC (192 bit) and BF-CBC (128 > bit). Thats great that you go also into this. The backward compatibility is very important but also the testing in the smart?phone segment is great since i do not use one. > > The clients were created in IPFire with OpenVPN-2.4.9 binary. They > were then imported into the laptop and phone with no modification. > > In all three cases on both the laptop and mobile phone the OpenVPN > connection was successfully made with the OpenVPN server running with > 2.4.9 and 2.5.0. > > With the weaker encryption options there was a lot of input in the > client logs about using weak ciphers. This occurred whether the > IPFire server was running with 2.4.9 or 2.5.0. Yes, also the session key should be renewed after 64MB data transfer for BF and DES (CAST too) since those are 64bit block cipher and are vunerable via Sweet32. Am thinking about to integrate also reneg-sec, reneg-bytes and reneg- pkts later on... but am not sure about this. > > > So at least with my clients there was no problem with even the very > weak ciphers with running clients after changing IPFire to 2.5.0 > binary. Great testing thanks for that. Am also ready now to send the patchset, have found some other things which needed to be fixed/enhanced but also a new possibility while client creation or client editing to integrate the new directive --data-ciphers which can now be done via a checkbox so older clients can also be renewed by editing. --tls-cipher and tls- ciphersuites are now also integrated in client.ovpn but in general no default settings for those which might be better for the first, --tls- ciphersuites will not be written if the client is <=2.5.0 and some other smaller things has been done. Best, Erik > > > Regards, > > > Adolf. > > > On 29/11/2020 13:42, Adolf Belka wrote: > > Hi Erik and *, > > > > I have installed the OpenVPN 2.5.0 binary on my system and can > > confirm that all my clients, mobile and laptop, were able to > > successfully connect. > > > > Regards, > > > > Adolf. > > > > > > On 26/11/2020 20:19, ummeegge wrote: > > > Hi Michael, > > > > > > Am Donnerstag, den 26.11.2020, 12:05 +0000 schrieb Michael > > > Tremer: > > > > Hello, > > > > > > > > I will leave this one then for the next core update where we > > > > hopefully have moved forward with some of the changes to the UI > > > > and > > > > more people have verified that this won’t break anything :) > > > OK. According to the work on the WUI, i have pushed all i > > > currently > > > have which can be found in here --> > > > > > > https://git.ipfire.org/?p=people/ummeegge/ipfire-2.x.git;a=commit;h=34af1d714178b2cd0c27e8c39052a8c7ce87d116 > > > > > > Best, > > > > > > Erik > > > > > > > > > Best, > > > -Michael > > > > > > > On 25 Nov 2020, at 23:20, ummeegge <ummeegge@ipfire.org> wrote: > > > > > > > > Hi Michael, > > > > > > > > Am Mittwoch, den 25.11.2020, 22:43 +0000 schrieb Michael > > > > Tremer: > > > > > Hello Erik, > > > > > > > > > > Am I right to assume that this cannot be merged without > > > > > breaking > > > > > anything? > > > > I think it can be merged without breaking something, two more > > > > already > > > > known warnings are presant with this update here but it broke > > > > nothing. > > > > Tests has been made with 2.4.x clients with a 2.5.0 server but > > > > 2.3.x > > > > clients should be OK with this too. Testings might be > > > > important. > > > > > > > > > > > > > > Best, > > > > > -Michael > > > > > > > > Best, > > > > > > > > Erik > > > > > > > > > > > > > > > On 25 Nov 2020, at 22:26, ummeegge <erik.kapfer@ipfire.org> > > > > > > wrote: > > > > > > > > > > > > Signed-off-by: ummeegge <erik.kapfer@ipfire.org> > > > > > > --- > > > > > > config/rootfiles/common/openvpn | 1 - > > > > > > lfs/openvpn | 4 ++-- > > > > > > 2 files changed, 2 insertions(+), 3 deletions(-) > > > > > > > > > > > > diff --git a/config/rootfiles/common/openvpn > > > > > > b/config/rootfiles/common/openvpn > > > > > > index 547842db3..41ccc885e 100644 > > > > > > --- a/config/rootfiles/common/openvpn > > > > > > +++ b/config/rootfiles/common/openvpn > > > > > > @@ -19,7 +19,6 @@ usr/sbin/openvpn > > > > > > #usr/share/doc/openvpn/README.down-root > > > > > > #usr/share/doc/openvpn/README.mbedtls > > > > > > #usr/share/doc/openvpn/management-notes.txt > > > > > > -#usr/share/man/man8/openvpn.8 > > > > > > var/ipfire/ovpn/ca > > > > > > var/ipfire/ovpn/caconfig > > > > > > var/ipfire/ovpn/ccd > > > > > > diff --git a/lfs/openvpn b/lfs/openvpn > > > > > > index 779bf5520..b026d515b 100644 > > > > > > --- a/lfs/openvpn > > > > > > +++ b/lfs/openvpn > > > > > > @@ -24,7 +24,7 @@ > > > > > > > > > > > > include Config > > > > > > > > > > > > -VER = 2.4.9 > > > > > > +VER = 2.5.0 > > > > > > > > > > > > THISAPP = openvpn-$(VER) > > > > > > DL_FILE = $(THISAPP).tar.xz > > > > > > @@ -40,7 +40,7 @@ objects = $(DL_FILE) > > > > > > > > > > > > $(DL_FILE) = $(DL_FROM)/$(DL_FILE) > > > > > > > > > > > > -$(DL_FILE)_MD5 = 446df6dc29364d00929ea9c725412cb8 > > > > > > +$(DL_FILE)_MD5 = ba426e2217833b522810d6c06f7cc8f7 > > > > > > > > > > > > install : $(TARGET) > > > > > > > > > > > > -- > > > > > > 2.20.1 > > > > > > > > > > > > > > > > > > > > > > > > > > > >
diff --git a/config/rootfiles/common/openvpn b/config/rootfiles/common/openvpn index 547842db3..41ccc885e 100644 --- a/config/rootfiles/common/openvpn +++ b/config/rootfiles/common/openvpn @@ -19,7 +19,6 @@ usr/sbin/openvpn #usr/share/doc/openvpn/README.down-root #usr/share/doc/openvpn/README.mbedtls #usr/share/doc/openvpn/management-notes.txt -#usr/share/man/man8/openvpn.8 var/ipfire/ovpn/ca var/ipfire/ovpn/caconfig var/ipfire/ovpn/ccd diff --git a/lfs/openvpn b/lfs/openvpn index 779bf5520..b026d515b 100644 --- a/lfs/openvpn +++ b/lfs/openvpn @@ -24,7 +24,7 @@ include Config -VER = 2.4.9 +VER = 2.5.0 THISAPP = openvpn-$(VER) DL_FILE = $(THISAPP).tar.xz @@ -40,7 +40,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_MD5 = 446df6dc29364d00929ea9c725412cb8 +$(DL_FILE)_MD5 = ba426e2217833b522810d6c06f7cc8f7 install : $(TARGET)