cb59f07662
- update to 2.5.8: * allow running a default configuration with TLS libraries without BF-CBC (even if TLS cipher negotiation would not actually use BF-CBC, the long-term compatibility "default cipher BF-CBC" would trigger an error on such TLS libraries) * ``--auth-nocache'' was not always correctly clearing username+password after a renegotiation * ensure that auth-token received from server is cleared if requested by the management interface ("forget password" or automatically via ``--management-forget-disconnect'') * in a setup without username+password, but with auth-token and auth-token-username pushed by the server, OpenVPN would start asking for username+password on token expiry. Fix. * using ``--auth-token`` together with ``--management-client-auth`` (on the server) would lead to TLS keys getting out of sync and client being disconnected. Fix. * management interface would sometimes get stuck if client and server try to write something simultaneously. Fix by allowing a limited level of recursion in virtual_output_callback() * fix management interface not returning ERROR:/SUCCESS: response on "signal SIGxxx" commands when in HOLD state * tls-crypt-v2: abort connection if client-key is too short * make man page agree with actual code on replay-window backtrag log message * remove useless empty line from CR_RESPONSE message OBS-URL: https://build.opensuse.org/request/show/1036732 OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=181 |
||
---|---|---|
.gitattributes | ||
.gitignore | ||
client-netconfig.down | ||
client-netconfig.up | ||
openvpn-2.3-plugin-man.dif | ||
openvpn-2.5.8.tar.gz | ||
openvpn-2.5.8.tar.gz.asc | ||
openvpn-fips140-2.3.2.patch | ||
openvpn-tmpfile.conf | ||
openvpn.changes | ||
openvpn.keyring | ||
openvpn.README.SUSE | ||
openvpn.service | ||
openvpn.spec | ||
openvpn.target | ||
rcopenvpn |