[Openvpn-devel] [PATCH applied] Re: Fix OpenSSL error stack handling of tls_ctx_add_extra_certs

2020-04-02 Thread Gert Doering
Your patch has been applied to the master and release/2.4 branch (bugfix). Looked at code and IRC discussion, makes all sense to me. Tested a 2.4 client build on linux and freebsd, mbedtls and openssl (build + t_client), just for extra sanity checking. commit 3608d890583549dbdbefc40ed41bf617fa

Re: [Openvpn-devel] [PATCH v2 2/2] When auth-user-pass file has no password, query the management

2020-04-02 Thread Selva Nair
Hi, On Thu, Apr 2, 2020 at 12:56 PM Jonathan K. Bullard wrote: > Hi, > > On Mon, Mar 30, 2020 at 2:06 PM wrote: > > > > From: Selva Nair > > > > When only username is found in the file, redirect the auth-user-pass > > query to the management if management-query-passwords is enabled. > > Otherw

Re: [Openvpn-devel] [PATCH v2 2/2] When auth-user-pass file has no password, query the management

2020-04-02 Thread Jonathan K. Bullard
Hi, On Mon, Mar 30, 2020 at 2:06 PM wrote: > > From: Selva Nair > > When only username is found in the file, redirect the auth-user-pass > query to the management if management-query-passwords is enabled. > Otherwise the user is prompted on console, if available, as before. > > This changes the

Re: [Openvpn-devel] [PATCH] OpenSSL: Fix --crl-verify not loading multiple CRLs in one file

2020-04-02 Thread Arne Schwabe
>> Feature-ACK but some changes to the code required. > Thank you for the feedback! How should I send a new patch version? As a reply > (with [PATCH v2]) to this thread, or as an independent message? I'm new to > contributing patches through e-mail. >>> +    X509_CRL *crl = PEM_read_bio_X509

Re: [Openvpn-devel] [PATCH] OpenSSL: Fix --crl-verify not loading multiple CRLs in one file

2020-04-02 Thread WGH
On 4/2/20 1:28 AM, Arne Schwabe wrote: > Am 01.04.20 um 23:50 schrieb w...@torlan.ru: >> From: Maxim Plotnikov >> >> Lack of this led people accepting multiple CAs to use capath, >> which already supports multiple CRLs. But capath mode itself >> is somewhat ugly: you have to create new file/symlin

Re: [Openvpn-devel] [PATCH v3] Fix OpenSSL error stack handling of tls_ctx_add_extra_certs

2020-04-02 Thread Antonio Quartulli
Hi, On 02/04/2020 15:15, Antonio Quartulli wrote: > Hi, > > On 02/04/2020 12:38, Arne Schwabe wrote: >> Commit f67efa94 exposed that tls_ctx_add_extra_certs will always leave >> an error of PEM_R_NO_START_LINE on the stack that will printed the next >> time that the error is printed. >> >> Fix th

Re: [Openvpn-devel] [PATCH v3] Fix OpenSSL error stack handling of tls_ctx_add_extra_certs

2020-04-02 Thread Antonio Quartulli
Hi, On 02/04/2020 12:38, Arne Schwabe wrote: > Commit f67efa94 exposed that tls_ctx_add_extra_certs will always leave > an error of PEM_R_NO_START_LINE on the stack that will printed the next > time that the error is printed. > > Fix this by discarding this error. Also clean up the logic to repor

[Openvpn-devel] [PATCH v3] Fix OpenSSL error stack handling of tls_ctx_add_extra_certs

2020-04-02 Thread Arne Schwabe
Commit f67efa94 exposed that tls_ctx_add_extra_certs will always leave an error of PEM_R_NO_START_LINE on the stack that will printed the next time that the error is printed. Fix this by discarding this error. Also clean up the logic to report real error on other errors and also the no start line

[Openvpn-devel] [PATCH v2] Fix OpenSSL error stack handling of tls_ctx_add_extra_certs

2020-04-02 Thread Arne Schwabe
Commit f67efa94 exposed that tls_ctx_add_extra_certs will always leave an error of PEM_R_NO_START_LINE on the stack that will printed the next time that the error is printed. Fix this by discarding this error. Also clean up the logic to report real error on other errors and also the no start line

[Openvpn-devel] [PATCH v2] Fix OpenSSL error stack handling of tls_ctx_add_extra_certs

2020-04-02 Thread Arne Schwabe
Commit f67efa94 exposed that tls_ctx_add_extra_certs will always leave an error of PEM_R_NO_START_LINE on the stack that will printed the next time that the error is printed. Fix this by discarding this error. Also clean up the logic to report real error on other errors and also the no start line

[Openvpn-devel] [PATCH] Fix OpenSSL error stack handling of tls_ctx_add_extra_certs

2020-04-02 Thread Arne Schwabe
Commit f67efa94 exposed that tls_ctx_add_extra_certs will always leave an error of PEM_R_NO_START_LINE on the stack that will printed the next time that the error is printed. Fix this by discarding this error. Also clean up the logic to report real error on other errors and also the no start line

[Openvpn-devel] [PATCH] Fetch OpenSSL versions via source/old links

2020-04-02 Thread Arne Schwabe
New versions are already available as source/old but old version at some point disappear from the normal download path. Use the source/old path for all OpenSSL versions to avoid this problem. Signed-off-by: Arne Schwabe --- .travis/build-deps.sh | 4 +++- 1 file changed, 3 insertions(+), 1 delet

[Openvpn-devel] Community meetings in April 2020

2020-04-02 Thread Samuli Seppänen
Hi, Our community meetings will alternate between Wed 11:30 CET and Thu 20:00 CET. Next meetings have been scheduled to - Thu 9th April 20:00 CET - Wed 15th April 11:30 CET - Thu 23rd April 20:00 CET - Wed 29th April 11:30 CET The place is #openvpn-meeting IRC channel at Freenode. Meeting agend