HomeFreeBSD

security/openvpn*: update to 2.6.0, keep openvpn25

Description

security/openvpn*: update to 2.6.0, keep openvpn25

  • copy openvpn to openvpn25, mark as deprecated and to expire March 31
  • update openvpn to openvpn 2.6.0, highlights from Frank Lichtenheld's release announcement e-mail, slightly edited:
    • Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD [14].
    • OpenSSL 3 support
    • Improved handling of tunnel MTU, including support for pushable MTU.
    • Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
    • Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
    • Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
    • Improved protocol negotiation, leading to faster connection setup.

ChangeLog: https://github.com/OpenVPN/openvpn/blob/v2.6.0/Changes.rst

Details

Provenance
mandreeAuthored on Jan 25 2023, 10:29 PM
Parents
R11:62dc56352444: news/nntpcache: Mark DEPRECATED
Branches
Unknown
Tags
Unknown