[Openvpn-devel] [PATCH 1/3] auth-token: Fix building with --disable-server

2019-09-27 Thread David Sommerseth
The final patches of the auth-token hmac support patches had a typo in the P2MP_SERVER fencing breaking --disable-server builds. It used #if instead of #ifdef. While at it, also fix another missing P2MP_SERVER fencing causing the compiler to complain about an unused variable in push.c Signed-off

[Openvpn-devel] [PATCH 2/3] auth-token: Fix compiler complaints with --disable-management

2019-09-27 Thread David Sommerseth
When building with --disable-management, the compiler complains with implicit declaration of function ‘ssl_clean_auth_token’. This is due to the ssl_clean_auth_token() function being declared inside an #ifdef ENABLE_MANAGEMENT fence where it should not be. Signed-off-by: David Sommerseth --- sr

[Openvpn-devel] [PATCH 3/3] Improve the comments related to auth-token-hmac patches

2019-09-27 Thread David Sommerseth
A couple of places the documentation was not clear enough or not even correct. Just improve this to avoid confusion later on. Signed-off-by: David Sommerseth --- src/openvpn/auth_token.h | 2 -- src/openvpn/ssl_common.h | 2 +- 2 files changed, 1 insertion(+), 3 deletions(-) diff --git a/src/o

[Openvpn-devel] [PATCH 0/3] Last-minute fixes to auth-token-hmac patch series

2019-09-27 Thread David Sommerseth
During the review of the auth-token-hmac patches from Arne Schwabe, there were still a few minor issues left out. To avoid holding back further inclusion, we decided to add these patches on top of the patches from Arne. The first patch, --disable-server fix, is only needed when running ./configur

Re: [Openvpn-devel] [PATCH v7 5/7] Implement a permanent session id in auth-token

2019-09-27 Thread David Sommerseth
On 17/09/2019 14:10, Arne Schwabe wrote: > From: Arne Schwabe > > This allows an external authentication method > (e.g. management interface) to track the connection and distinguish a > reconnection from multiple connections. > > Addtionally this now also checks to workaround a problem with > Op

Re: [Openvpn-devel] [PATCH v7 4/7] Rewrite auth-token-gen to be based on HMAC based tokens

2019-09-27 Thread David Sommerseth
On 17/09/2019 14:10, Arne Schwabe wrote: > The previous auth-token implementation had a serious problem, especially when > paired with an unpatched OpenVPN client that keeps trying the auth-token > (commit e61b401a). > > The auth-token-gen implementation forgot the auth-token on reconnect, this >

[Openvpn-devel] Community meetings in October 2019

2019-09-27 Thread Samuli Seppänen
Hi, Our community meetings will alternate between Wed 11:30 CEST and Thu 20:00 CEST. Next meetings have been scheduled to - Wed 2nd October 11:30 CEST - Thu 10th October 20:00 CEST - Wed 16th October 11:30 CEST - Thu 24th October 20:00 CEST - Wed 30th October 11:30 CEST The place is #openvpn-me