Re: [Openvpn-devel] [PATCH] Post-initialization SELinux support for OpenVPN

2009-08-19 Thread James Yonan
Sebastien Raveau wrote: Hi everybody! OpenVPN already has support for dropping privileges and confining itself to a directory *after* startup (thanks to calls like setgid, setuid and chroot) which makes for much better management than if you had to respectively start OpenVPN unprivileged and ad

Re: [Openvpn-devel] nclients patch for 2.1_rc19

2009-08-19 Thread James Yonan
Thanks for noticing that. I've committed the patch. James Rob Lemley wrote: I noticed that building OpenVPN with --disable-server fails. Turns out to be a problem with the management server and the commands it allows. I've attached a simple patch which fixes it, not sure if it's "right" or not

Re: [Openvpn-devel] PATCH 2.1-RC*: critical fix for FreeBSD 8 in topology subnet mode.

2009-08-19 Thread James Yonan
Thanks Stefan and Matthias. I've committed the patch. James Matthias Andree wrote: Hi Jim, there has been a recent change in FreeBSD 8 BETA that will break OpenVPN 2.1's "topology subnet" mode by (rightfully!) rejecting the ifconfig command we're currently using (which incorrectly sets the lo