Re: [Openvpn-devel] Preparing 2.4-beta1 upload to Debian (Experimental)

2017-01-04 Thread Alberto Gonzalez Iniesta
Thanks Arne! I'll fix this in the next upload. On Wed, Jan 04, 2017 at 07:21:07PM +0100, Arne Schwabe wrote: > Am 21.11.16 um 10:10 schrieb Alberto Gonzalez Iniesta: > > Hi, > > > > I'm preparing an upload to Debian Experimental of 2.4-beta1 in order to &g

Re: [Openvpn-devel] 2.4 sees all client certificates as expired when using crl-verify

2017-01-02 Thread Alberto Gonzalez Iniesta
On Mon, Jan 02, 2017 at 03:26:46PM +0100, Gert Doering wrote: > Hi, > > On Mon, Jan 02, 2017 at 03:17:23PM +0100, Alberto Gonzalez Iniesta wrote: > > I just got this [1] bug report on OpenVPN 2.4 threating all certs as > > expired when upgrading from 2.3. I find this quite we

[Openvpn-devel] 2.4 sees all client certificates as expired when using crl-verify

2017-01-02 Thread Alberto Gonzalez Iniesta
-- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico mailto/sip: a...@inittab.org | en GNU/Linux y software libre Encrypted mail preferred| http://inittab.com Key fingerprint = 5347 CBD8 3E30 A9EB 4D7D 4BF2 009B 3375 6B9A AA55

Re: [Openvpn-devel] OpenVPN 2.4.0 released

2016-12-27 Thread Alberto Gonzalez Iniesta
unstable now. If all goes well it'll be in Stretch in 10 days. -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico mailto/sip: a...@inittab.org | en GNU/Linux y software libre Encrypted mail preferred| http://inittab.com Key fingerprint = 5347 CBD8 3E30 A9EB

Re: [Openvpn-devel] [PATCH v3] Refactor setting close-on-exec for socket FDs

2016-12-07 Thread Alberto Gonzalez Iniesta
On Tue, Dec 06, 2016 at 01:36:04PM +0100, Arne Schwabe wrote: > Am 06.12.16 um 13:26 schrieb Gert Doering: > > The existing code can leak socket FDs to the "--up" script, which is > > not desired. Brought up by Alberto Gonzalez Iniesta, based on debian > > bug 3

Re: [Openvpn-devel] [PATCH] Refactor setting close-on-exec for socket FDs

2016-12-06 Thread Alberto Gonzalez Iniesta
On Mon, Dec 05, 2016 at 09:05:04PM +0100, Gert Doering wrote: > Hi, > > On Mon, Dec 05, 2016 at 08:01:14PM +0100, Alberto Gonzalez Iniesta wrote: > > The patch, after being adjusted to the new source, is not working anymore: > > > > Mon Dec 5 19:39:34 2016 Set FD_CLOE

Re: [Openvpn-devel] [PATCH] Refactor setting close-on-exec for socket FDs

2016-12-05 Thread Alberto Gonzalez Iniesta
On Wed, Nov 23, 2016 at 07:43:21PM +0100, Gert Doering wrote: > Hi, > > On Wed, Nov 23, 2016 at 11:20:18AM +0100, Gert Doering wrote: > > The existing code can leak socket FDs to the "--up" script, which is > > not desired. Brought up by Alberto Gonzalez Iniesta,

Re: [Openvpn-devel] Preparing 2.4-beta1 upload to Debian (Experimental)

2016-11-21 Thread Alberto Gonzalez Iniesta
On Mon, Nov 21, 2016 at 03:37:45PM +0100, David Sommerseth wrote: > On 21/11/16 14:32, Samuli Seppänen wrote: > > Il 21/11/2016 11:10, Alberto Gonzalez Iniesta ha scritto: > >> Hi, > >> > >> I'm preparing an upload to Debian Experimental of 2.4-beta1 in &g

[Openvpn-devel] Preparing 2.4-beta1 upload to Debian (Experimental)

2016-11-21 Thread Alberto Gonzalez Iniesta
/bugreport.cgi?att=1;bug=367716;filename=openvpn_367716.diff;msg=10 Fixing this: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=367716 Thanks, Alberto -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico mailto/sip: a...@inittab.org | en GNU/Linux y software libre Encr

Re: [Openvpn-devel] [PATCH] systemd: Improve the systemd unit files

2016-11-08 Thread Alberto Gonzalez Iniesta
ance to check if the stock openvpn version you had > installed ships with a pre-created /var/run/openvpn directory? (or > /run/openvpn, or whatever Debian uses as the runtime directory) > > Otherwise, great testing! > The Debian package creates /run/openvpn/. /var/run is a syml

[Openvpn-devel] Help with bug report

2016-11-02 Thread Alberto Gonzalez Iniesta
hanks, Alberto [1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=817797 -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico mailto/sip: a...@inittab.org | en GNU/Linux y software libre Encrypted mail preferred| http://inittab.com Key fingerprint = 5347 CBD8 3E30 A9EB

Re: [Openvpn-devel] OpenVPN v2.4 release progress

2016-11-02 Thread Alberto Gonzalez Iniesta
patches: The VRF patches I consider for v2.4 just > >> because this seems very useful and doesn't add a very complicated patch. > >> Considering that 2.4 will live in Debian for a long while, that > >> platform can make most out of this patch as we

Re: [Openvpn-devel] OpenVPN PolarSSL builds?

2014-04-14 Thread Alberto Gonzalez Iniesta
On Mon, Apr 14, 2014 at 11:42:23AM +0200, Gert Doering wrote: > Hi, > > On Mon, Apr 14, 2014 at 11:29:28AM +0200, Alberto Gonzalez Iniesta wrote: > > There're already packages for PolarSSL in Debian (and thus, in Ubuntu). > > So I don't think there's need to

Re: [Openvpn-devel] OpenVPN PolarSSL builds?

2014-04-14 Thread Alberto Gonzalez Iniesta
. Will look at it next week. BTW, openvpn-openssl & openvpn-polarssl (underscores not valid in package names :-) > Also, if we don't wish maintain our own set of PolarSSL .deb packages > we'd have to limit ourselves to fairly recent Debian/Ubuntu versions. When can always t

Re: [Openvpn-devel] OpenVPN PolarSSL builds?

2014-04-14 Thread Alberto Gonzalez Iniesta
> said, if we start maintaining PolarSSL debs, we might as well do it > upstream in the PolarSSL project instead of within the OpenVPN project. > We could of course publish the PolarSSL packages in our own apt repos to > make using them easier for our users. There're already

Re: [Openvpn-devel] Regarding pkcs11 support in our Debian/Ubuntu packages

2014-04-10 Thread Alberto Gonzalez Iniesta
> versions of OpenVPN software. > Hi Leroy, Mind this patch is only required for Samuli's (backported) packages. The packages in Debian (and later Ubuntu) do not need any patching, since the required version of pkcs11 is already present in the development and testing suites (si

[Openvpn-devel] Patch to make uppercasing x509-username-field optional

2013-09-11 Thread Alberto Gonzalez Iniesta
apitalized. Please consider its inclusion, or an alternative to address this matter. Thanks, Alberto [1] x509-username-field foo -> will look for a field named FOO x509-username-field [emailAddress] -> will look for emailAddress -- Alberto Gonzalez Iniesta| Formación, consultoría y sop

Re: [Openvpn-devel] Fix for CVE-2013-2061 breaks multihome?

2013-06-17 Thread Alberto Gonzalez Iniesta
On Mon, Jun 17, 2013 at 05:36:23PM +0200, Gert Doering wrote: > Hi, > > On Mon, Jun 17, 2013 at 04:36:44PM +0200, Alberto Gonzalez Iniesta wrote: > > Seems like "cmsg_len" went nuts... > > Seems your compiler grew too much smarts and optimized that bug to death

Re: [Openvpn-devel] Fix for CVE-2013-2061 breaks multihome?

2013-06-17 Thread Alberto Gonzalez Iniesta
On Mon, Jun 17, 2013 at 04:05:18PM +0200, Alberto Gonzalez Iniesta wrote: > On Mon, Jun 17, 2013 at 01:51:13PM +0200, Gert Doering wrote: > > Hi, > > > > On Mon, Jun 17, 2013 at 01:00:03PM +0200, Alberto Gonzalez Iniesta wrote: > > > I applied the fix for CVE-20

Re: [Openvpn-devel] Fix for CVE-2013-2061 breaks multihome?

2013-06-17 Thread Alberto Gonzalez Iniesta
On Mon, Jun 17, 2013 at 01:51:13PM +0200, Gert Doering wrote: > Hi, > > On Mon, Jun 17, 2013 at 01:00:03PM +0200, Alberto Gonzalez Iniesta wrote: > > I applied the fix for CVE-2013-2061 [0] to Debian's stable version of > > openvpn (2.2.1) [1]. When the new package was

[Openvpn-devel] Fix for CVE-2013-2061 breaks multihome?

2013-06-17 Thread Alberto Gonzalez Iniesta
made or should we go back to 2.2.1 without the patch to fix CVE-2013-2061? Thanks, Alberto [0] https://github.com/OpenVPN/openvpn/commit/11d21349a4e7e38a025849479b36ace7c2eec2ee [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=707329 [2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=71

Re: [Openvpn-devel] Repos for Debian Wheezy?

2013-05-30 Thread Alberto Gonzalez Iniesta
orian wrote: > I'll take a look at the one in unstable. I'm not sure what parts have been > back ported to 2.2 that I have been testing in the 2.3 branch. I would > have thought that 2.3 is mature enough to be in the debian repos by now. > > > On Wed, May 29, 2013 at

Re: [Openvpn-devel] Repos for Debian Wheezy?

2013-05-29 Thread Alberto Gonzalez Iniesta
orporating the IPv6 patches anyway that bring most of > the 2.3 ipv6 functionality to 2.2? Yes, it is. AFAIK. Anyway, I'll try to make a backport one of these days, but the one in unstable should work in Wheezy too. -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte téc

[Openvpn-devel] Using --mlock and --user makes openvpn "run out of memory"

2012-10-11 Thread Alberto Gonzalez Iniesta
ns a workaround (editing PAM limits) and a plea to document this behaviour. I guess it's better to document this (after verification of the facts) in OpenVPN's man page rather than just Debian's package. Regards, Alberto [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=40689

Re: [Openvpn-devel] New generic buildsystem: lzo enabled or disabled by default?

2012-03-16 Thread Alberto Gonzalez Iniesta
On Fri, Mar 16, 2012 at 02:09:44PM +0200, Alon Bar-Lev wrote: > On Fri, Mar 16, 2012 at 1:47 PM, Alberto Gonzalez Iniesta > wrote: > > Since support for LZO is enabled/disabled in runtime configuration, I > > don't see why disabling it on built time, thus limiting its

Re: [Openvpn-devel] New generic buildsystem: lzo enabled or disabled by default?

2012-03-16 Thread Alberto Gonzalez Iniesta
bian packages with LZO support (if I don't forget to set the option when upgrading to the new version). Since support for LZO is enabled/disabled in runtime configuration, I don't see why disabling it on built time, thus limiting its use later. Regards, Alberto -- Alberto Gonz

Re: [Openvpn-devel] Errors adding routes on Windows 7 with OpenVPN 2.1.3

2010-10-21 Thread Alberto Gonzalez Iniesta
sted the patch successfully. It works for me(tm). OpenVPN stopped adding those random routes, while it added the right one for the "remote_host". Thanks, Alberto -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software li

Re: [Openvpn-devel] Errors adding routes on Windows 7 with OpenVPN 2.1.3

2010-10-18 Thread Alberto Gonzalez Iniesta
g that with the IP of the VPN server and see if that fixes it in the meantime. Cheers, Alberto -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred| http://inittab.com Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

[Openvpn-devel] [PATCH] Fixed typo in manpage

2010-04-10 Thread Alberto Gonzalez Iniesta
Just a tiny fix. -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred| http://inittab.com Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3 Index: openvpn-2.1.0

Re: [Openvpn-devel] Tomorrow's meeting (18th March)

2010-03-17 Thread Alberto Gonzalez Iniesta
net/wiki/index.php/OpenVPN/IRC_meetings/Topics-2010-03-18 > > David (dazo) won't be able to attend, unfortunately. > Hi, I won't be able to attend either. I will next week, hopefully with news on Debian packages build daily/weekly. Regards, Alberto -- Alberto Gonzalez

Re: [Openvpn-devel] FQDN for routes should expand to all IPs

2009-10-25 Thread Alberto Gonzalez Iniesta
y other requests for it. Hi James, Just for the record, the same feature was requested in Debian [1] some 5 years ago :) Regards, Alberto [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=237251 -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debia

Re: [Openvpn-devel] [PATCH] openvpn over ipv6 support v0.4.9, rebased on 2.1_rc20 [was: v0.4.6]

2009-10-06 Thread Alberto Gonzalez Iniesta
x27;d[1] > and uploaded rc20 diffs [2]. Hi All! I just included the patch on the official Debian package. It will enter the Sid repository today, hopefully a bunch of new people will test it now. :) Regards, Alberto -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(init

Re: [Openvpn-devel] openvpn + utf8 ?

2009-10-06 Thread Alberto Gonzalez Iniesta
asswords with wrong charset or gets it at > all (echo $username:$password:TEST >> /var/log/openvpn/test) but it shows > nothing for the password. Hi, You need --script-security 3 in order to get passwords passed to scripts. Regards, Alberto -- Alberto Gonzalez Iniesta

[Openvpn-devel] Fwd: openvpn 2.1~rc11-1

2009-07-15 Thread Alberto Gonzalez Iniesta
Oliver Seufer - End forwarded message - -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred| http://inittab.com Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4

[Openvpn-devel] remote* enviroment variables wrongly set?

2009-04-30 Thread Alberto Gonzalez Iniesta
to -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred| http://inittab.com Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3 Index: openvpn-2.1

[Openvpn-devel] rc9 and external commands

2008-08-21 Thread Alberto Gonzalez Iniesta
a lot, Alberto [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494998 [2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495964 [3] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494998#10 -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred| http://inittab.com Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

Re: [Openvpn-devel] improve of documentation

2006-06-04 Thread Alberto Gonzalez Iniesta
truct, ... Denis, you forgot to attach your documentation/patches to solve this. Thanks, Alberto -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred| http://inittab.com Key fingerprin

[Openvpn-devel] Possible security bug

2006-04-03 Thread Alberto Gonzalez Iniesta
ss. A possible solution would be to prefix all pushed environment variables with something like 'OPENVPN_'. -- What's your opinion on this? Thanks, Alberto -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y

Re: [Openvpn-devel] OpenVPN 2.0 released

2005-04-20 Thread Alberto Gonzalez Iniesta
On Tue, Apr 19, 2005 at 12:32:20PM -0600, James Yonan wrote: > > On Tue, 19 Apr 2005, Alberto Gonzalez Iniesta wrote: > > > > And the second issue I don't know how to handle is this: > > - Start openvpn multiple times for a certain configuration. > > - After

Re: [Openvpn-devel] OpenVPN 2.0 released

2005-04-19 Thread Alberto Gonzalez Iniesta
leave a process running (one each). - Even killing the first (successful) instance, the rest of the processes will remain aroundi (doing nothing, I guess. Is that a desirable behavior? Thanks, Alberto -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab

Re: [Openvpn-devel] Re: Fwd: openvpn config parsing

2004-12-22 Thread Alberto Gonzalez Iniesta
On Wed, Dec 22, 2004 at 05:11:51AM -0700, James Yonan wrote: > On Wed, 22 Dec 2004, Charles Duffy wrote: > > > On Wed, 22 Dec 2004 11:00:09 +0100, Alberto Gonzalez Iniesta wrote: > > > Recent updates of openvpn appear to have changed the handling of > > > white

[Openvpn-devel] Fwd: openvpn config parsing

2004-12-22 Thread Alberto Gonzalez Iniesta
from Ron - From: Ron To: Alberto Gonzalez Iniesta Subject: openvpn config parsing List-Post: openvpn-devel@lists.sourceforge.net Date: Fri, 10 Dec 2004 12:09:42 +1030 X-CRM114-Version: 20040816.BlameClockworkOrange-auto.3 (regex: TRE 0.6.8) MF-A10FFB4C X-CRM114-Status: Good ( pR: 0.9831

Re: [Openvpn-devel] FW: Init script/Debian for OpenVPN

2004-12-03 Thread Alberto Gonzalez Iniesta
0 start > exit $? > ;; > > *) > echo "Usage: $0 {start|stop|reload|restart}" > exit 1 > ;; > esac > > if [ $? == 0 ]; then > exit 0 > else > exit 1 > fi > > > > > <<<<<<<<<

[Openvpn-devel] mssfix option changed its behaviour

2004-11-17 Thread Alberto Gonzalez Iniesta
1500 --fragment 1300 --mssfix -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred| http://inittab.org Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

Re: [Openvpn-devel] When the link used for openvpn goes down, the daemon hangs

2004-11-03 Thread Alberto Gonzalez Iniesta
On Wed, Nov 03, 2004 at 12:24:15PM -0700, James Yonan wrote: > On Tue, 2 Nov 2004, Alberto Gonzalez Iniesta wrote: > > > Hi again, > > > > Another bug report received in the Debian BTS [1]. Quoting: > > |when the link which was used for openvpn transport goes do

[Openvpn-devel] When the link used for openvpn goes down, the daemon hangs

2004-11-02 Thread Alberto Gonzalez Iniesta
(eg. |wavemon) can handle this situation more sanely. Regards, Alberto [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278933 -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred

[Openvpn-devel] The "Assertion failed" problem and a minor patch

2004-11-02 Thread Alberto Gonzalez Iniesta
[2] Trey Kelso [3] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278302 -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred| http://inittab.org Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

[Openvpn-devel] Posible bogus bug report, qualified answer required

2004-10-23 Thread Alberto Gonzalez Iniesta
debian.org/277838 -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred| http://inittab.org Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

Re: [Openvpn-devel] OpenVPN 2.0 and udev

2004-10-17 Thread Alberto Gonzalez Iniesta
On Sun, Oct 17, 2004 at 06:15:06PM +0200, Alberto Gonzalez Iniesta wrote: > On Sun, Oct 17, 2004 at 01:36:33PM -, James Yonan wrote: > > Alberto Gonzalez Iniesta said: > > > > > Hi all, > > > > > > After I decided to push OpenVPN 2.0 into Debian

Re: [Openvpn-devel] OpenVPN 2.0 and udev

2004-10-17 Thread Alberto Gonzalez Iniesta
On Sun, Oct 17, 2004 at 01:36:33PM -, James Yonan wrote: > Alberto Gonzalez Iniesta said: > > > Hi all, > > > > After I decided to push OpenVPN 2.0 into Debian for future inclusion in > > Sarge, I got this [1] bug report from one Debian user. It seems that

[Openvpn-devel] OpenVPN 2.0 and udev

2004-10-17 Thread Alberto Gonzalez Iniesta
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=265632 -- Alberto Gonzalez Iniesta| BOFH excuse #175: agi@(inittab.org|debian.org)| OS swapped to disk Encrypted mail preferred| Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

[Openvpn-devel] Assertion failed at crypto.c:147

2004-09-10 Thread Alberto Gonzalez Iniesta
i-bin/bugreport.cgi?bug=265632 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=270005 -- Alberto Gonzalez Iniesta | BOFH excuse #178: agi@(agi.as|debian.org)| short leg on process table Encrypted mail preferred | Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

[Openvpn-devel] route option deleting routes it didn't set

2004-05-28 Thread Alberto Gonzalez Iniesta
route deleted from. [1] http://bugs.debian.org/251304 -- Alberto Gonzalez Iniesta | BOFH excuse #263: agi@(agi.as|debian.org)| It's stuck in the Web. Encrypted mail preferred | Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

[Openvpn-devel] verify-cn script

2004-05-27 Thread Alberto Gonzalez Iniesta
on things OpenVPN depends on (i.e. not requiring Perl). I haven't tested this one (see attach) thoroughly but it seems to do the job. Thoughts? -- Alberto Gonzalez Iniesta | BOFH excuse #5: agi@(agi.as|debian.org)| static from plastic slide rules Encrypted mail preferred | Key fin

Re: [Openvpn-devel] OpenVPN 2.0 -- Project Update and Release Notes

2004-03-31 Thread Alberto Gonzalez Iniesta
On Wed, Mar 31, 2004 at 12:31:13PM +0200, Alberto Gonzalez Iniesta wrote: > Debian package available (for testing/unstable) at: > > http://tmp.inittab.org/~agi/openvpn_2.0_beta18-1_i386.deb > Sorry, that should read: http://tmp.inittab.org/~agi/openvpn_2.0_test18-1_i386.deb

Re: [Openvpn-devel] OpenVPN 2.0 -- Project Update and Release Notes

2004-03-31 Thread Alberto Gonzalez Iniesta
der it Beta, and report bugs to openvpn-devel@lists.sourceforge.net (in case of openvpn related problem) or me (in case of packaging errors). -- Alberto Gonzalez Iniesta | BOFH excuse #191: agi@(agi.as|debian.org)| Just type 'mv * /dev/null'. Encrypted mail preferred | Key

[Openvpn-devel] route option only adds route for first IP resolved for a hostname (with many)

2004-03-10 Thread Alberto Gonzalez Iniesta
Be (tm) Any thoughts? [1] http://bugs.debian.org/237251 -- Alberto Gonzalez Iniesta | BOFH excuse #304: agi@(agi.as|debian.org)| routing problems on the neural net Encrypted mail preferred | Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

Re: [Openvpn-devel] Fwd: Bug#182020: openvpn needs dynamic choice on HAVE_LINUX_IF_TUN_H

2003-05-08 Thread Alberto Gonzalez Iniesta
On Thu, May 08, 2003 at 08:30:34AM -, James Yonan wrote: > Alberto Gonzalez Iniesta said: > > > When compiled with 2.4.* kernel headers (libc6-dev 2.2.5-14.3 headers) > > it detects this header file and defines HAVE_LINUX_IF_TUN_H. This allow > > openvpn to work corre

[Openvpn-devel] Fwd: Bug#182020: openvpn needs dynamic choice on HAVE_LINUX_IF_TUN_H

2003-05-07 Thread Alberto Gonzalez Iniesta
(Robert de Bath ) <http://www.cix.co.uk/~mayday> Google Homepage: http://www.google.com/search?btnI&q=Robert+de+Bath ----- End forwarded message - -- Alberto Gonzalez Iniesta | BOFH excuse #2: agi@(agi.as|debian.org)| s

[Openvpn-devel] Fwd: Re: Compiling and/or linking liblzo with OpenSSL

2003-05-04 Thread Alberto Gonzalez Iniesta
Here's my last email with Markus about this subject. I'm forwarding it as he requested. Maybe we should quote his exception somewhere in the tarball, James? - Forwarded message from "Markus F.X.J. Oberhumer" - From: "Markus F.X.J. Oberhumer" To: Alberto

[Openvpn-devel] Fwd: Re: Compiling and/or linking liblzo with OpenSSL

2003-05-03 Thread Alberto Gonzalez Iniesta
rded message from "Markus F.X.J. Oberhumer" - From: "Markus F.X.J. Oberhumer" To: Alberto Gonzalez Iniesta Subject: Re: Compiling and/or linking liblzo with OpenSSL List-Post: openvpn-devel@lists.sourceforge.net Date: Thu, 1 May 2003 20:02:55 +0200 X-no-Archive: yes X-GPG-K

Re: [Openvpn-devel] Fwd: Re: comp-lzo and licensing issues

2003-05-03 Thread Alberto Gonzalez Iniesta
On Fri, May 02, 2003 at 06:07:07PM +0200, Matthias Andree wrote: > On Mon, 28 Apr 2003, Alberto Gonzalez Iniesta wrote: > > > Sorry for the huge forward, but everything needed to understand this > > problem should be there :) > > FYI: > > My post of the FreeBSD-p

Re: [Openvpn-devel] Openvpn for RH62 - eek!

2003-05-02 Thread Alberto Gonzalez Iniesta
On Fri, May 02, 2003 at 11:25:46AM +0200, Alberto Gonzalez Iniesta wrote: > Anyway, I'm attaching Debian's init.d script in case you want to take a > look at it. > Doh! I ALWAYS forget to attach files! Sorry :) -- Alberto Gonzalez Iniesta | They that give up es

Re: [Openvpn-devel] Openvpn for RH62 - eek!

2003-05-02 Thread Alberto Gonzalez Iniesta
or problem as my RH62 box started up: > > > > > $Starting openvpn: /etc/rc.d/init.d/openvpn: [: ==: binary operator > > > expected > > > > That's two distinct, common errors: > > - $localization stuff that doesn't work on bash1 > > - an == in a []

Re: [Openvpn-devel] 2nd release candidate for 1.4.0

2003-04-30 Thread Alberto Gonzalez Iniesta
___ > Openvpn-devel mailing list > Openvpn-devel@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/openvpn-devel -- Alberto Gonzalez Iniesta | They that give up essential liberty agi@(agi.as|debian.org)| to obtain a little temporary

[Openvpn-devel] Fwd: Re: comp-lzo and licensing issues

2003-04-28 Thread Alberto Gonzalez Iniesta
ng to get lots of feedback, Alberto [1] http://www.openssl.org/support/faq.html#LEGAL2 [2] Yes, it's a joke - Forwarded message from James Yonan - From: James Yonan To: Alberto Gonzalez Iniesta Subject: Re: comp-lzo and licensing issues List-Post: openvpn-devel@lists.sourceforg

Re: [Openvpn-devel] Fwd: RE: Multi-channel VPN

2003-04-20 Thread Alberto Gonzalez Iniesta
nux and FreeBSD, it's not easy but it's possible. Let each tool do its job, and only that. -- Alberto Gonzalez Iniesta | They that give up essential liberty agi@(agi.as|debian.org)| to obtain a little temporary safety Encrypted mail preferred | deserve neither liberty n

Re: [Openvpn-devel] Opened file descriptors in script calls

2003-02-10 Thread Alberto Gonzalez Iniesta
acker, but I think this should be better: for(x = 3; x < 100; x++) Since the first 3 fds (stdin, stdout and stderr) should be kept open. Regards, Alberto -- Alberto Gonzalez Iniesta | They that give up essential liberty agi@(agi.as|debian.org)| to obtain a little temporary safety Encrypted mail preferred | deserve neither liberty nor safety. Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

[Openvpn-devel] Opened file descriptors in script calls

2003-02-06 Thread Alberto Gonzalez Iniesta
You can see the report here: http://bugs.debian.org/179551 Thanks. -- Alberto Gonzalez Iniesta | They that give up essential liberty agi@(agi.as|debian.org)| to obtain a little temporary safety Encrypted mail preferred | deserve neither liberty nor safety. Key fingerprint = 9782

[Openvpn-devel] Trimmed down permissions for generated keys

2003-02-05 Thread Alberto Gonzalez Iniesta
orry James) -- Alberto Gonzalez Iniesta | They that give up essential liberty agi@(agi.as|debian.org)| to obtain a little temporary safety Encrypted mail preferred | deserve neither liberty nor safety. Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

[Openvpn-devel] Fwd: Bug#158404: openvpn: Improper error handling

2002-08-27 Thread Alberto Gonzalez Iniesta
ion library. ii libssl0.9.60.9.6g-2 SSL shared libraries - End forwarded message ----- -- Alberto Gonzalez Iniesta | They that give up essential liberty a...@agi.as | to obtain a little temporary safety Encrypted mail preferred | deserve neither liberty n

Re: [Openvpn-devel] Replay attacks

2002-07-18 Thread Alberto Gonzalez Iniesta
On Thu, Jul 18, 2002 at 05:04:30PM -0500, Michael Grigoriev wrote: > Hi all, > > I am wondering how OpenVPN overcomes the inherit vulnerability of UDP > comunications to "replay" or "cut-and-paste" attacks, since it is > impossible to implement cipher block chaining. > Also, if anybody could poi

Re: [Openvpn-devel] Protocol Change policy

2002-07-03 Thread Alberto Gonzalez Iniesta
sions. (I don't know if I'm clear in this point, some times my English level seems not enough :-) Regards, Alberto -- Alberto Gonzalez Iniesta | They that give up essential liberty a...@agi.as | to obtain a little temporary safety Encrypted mail preferred | deserve neither liberty nor safety. Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3

Re: [Openvpn-devel] Features comments/request

2002-06-27 Thread Alberto Gonzalez Iniesta
e > privilege using --user and/or --group. That means that when an OpenVPN > daemon is ready to exit, it might lack the privilege to delete its own > pidfile. I've seen other daemons deal with this by chowning the pid file to > the user/group that the daemon plans to setuid/se

[Openvpn-devel] Features comments/request

2002-06-25 Thread Alberto Gonzalez Iniesta
t was that very same daemon that created it. It has no sense to have the init.d scripts deleting these files (and stoping nonexistent daemons) since the daemon could have been killed before the init.d script tried to stop it. Thanks in advance for any comments. Best regards. -- Alberto Gonzalez

Re: [Openvpn-devel] New OpenVPN beta available for testing

2002-06-02 Thread Alberto Gonzalez Iniesta
c +++ openvpn-1.2.0/configure.ac @@ -284,7 +284,7 @@ CFLAGS="$CFLAGS -pthread" ;; *) - CFLAGS="$CFLAGS -pthread" + CFLAGS="$CFLAGS -lpthread" ;; The new configure* scripts work flawlessly :-) Regards, Albe