public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
From: Michael Tremer <michael.tremer@ipfire.org>
To: Adolf Belka <adolf.belka@ipfire.org>
Cc: "IPFire: Development-List" <development@lists.ipfire.org>,
	ummeegge <ummeegge@ipfire.org>
Subject: Re: OpenVPN-2.7.1
Date: Mon, 13 Apr 2026 10:17:09 +0100	[thread overview]
Message-ID: <134019CD-5C20-4999-A640-DCAD50564FBA@ipfire.org> (raw)
In-Reply-To: <9bf52d4d-a127-40c9-b850-6d2e38100072@ipfire.org>

Hello Adolf,

Thanks for raising this.

I suppose we should be fine. I would just leave what we have in our configuration right now and eventually remove it. By then, it should already not be used by any client at all. At the moment, I cannot think of a client implementation that would so old that it would rely on plain old DH to work. But it wouldn’t do us any harm to leave it in there since we already have it.

I just merged the branch. Thanks for working on this. I am not feeling very scared about this update, but it is yet another large one very briefly after the previous 2.6 release in IPFire. Fingers crossed that we caught everything right the first time and that we will now be able to earn the fruits of our hard work.

Best,
-Michael

> On 11 Apr 2026, at 13:02, Adolf Belka <adolf.belka@ipfire.org> wrote:
> 
> Hi Michael & Erik,
> 
> I have submitted a patch set for the update to openvpn-2.7.1
> 
> One thing I noticed when scanning through the changelog notes is the following two entries.
> 
> ** Use of --dh dh2048.pem in all sample configs has been replaced with --dh none. The dh2048.pem file has been removed.
> 
> ** --dh none is now the default if --dh is not specified. Modern TLS implementations will prefer ECDH and other more modern algorithms anyway. And finite field Diffie Hellman is in the proces of being deprecated (see draft-ietf-tls-deprecate-obsolete-kex)
> 
> We are not using dh2048, we are using ffdhe4096 which looks to me like it might be a finite field Diffie Hellman. If that is the case then at some time in the future it looks like it will be deprecated. Looking through that draft ietf document I was unable to determine if this deprecation will only apply to 2048 that is mentioned in the openvpn-2.7.0 changelog or if it will also apply to our use of 4096 bit.
> 
> I thought I would flag it so that others more knowledgeable than me could decide.
> 
> I thought it would be good to know early if this was going to affect us so that it can be decided how to manage that before it becomes a requirement (if that is in fact the case).
> 
> Regards,
> 
> Adolf.
> 
> 



  reply	other threads:[~2026-04-13  9:17 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-11-06 21:19 openvpn-2.7_rc1 Adolf Belka
2025-11-07 14:18 ` openvpn-2.7_rc1 Michael Tremer
2025-12-20 18:05 ` openvpn-2.7_rc1 ummeegge
2025-12-23 11:27   ` openvpn-2.7_rc1 Michael Tremer
2025-12-23 16:13     ` openvpn-2.7_rc1 ummeegge
2025-12-28 12:18       ` openvpn-2.7_rc1 Michael Tremer
2025-12-30 11:17         ` openvpn-2.7_rc1 ummeegge
2026-02-19 15:03 ` openvpn-2.7_rc1 ummeegge
2026-02-19 16:04   ` openvpn-2.7_rc1 Adolf Belka
2026-02-19 17:25     ` openvpn-2.7_rc1 ummeegge
2026-02-19 17:38       ` openvpn-2.7_rc1 Adolf Belka
2026-02-20 11:28         ` openvpn-2.7_rc1 Michael Tremer
2026-02-21 16:50           ` openvpn-2.7_rc1 ummeegge
2026-02-23 14:52             ` openvpn-2.7_rc1 Michael Tremer
2026-02-25 16:34               ` openvpn-2.7_rc1 Michael Tremer
2026-04-11 12:02                 ` OpenVPN-2.7.1 Adolf Belka
2026-04-13  9:17                   ` Michael Tremer [this message]
2026-02-19 15:43 ` openvpn-2.7_rc1 ummeegge

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=134019CD-5C20-4999-A640-DCAD50564FBA@ipfire.org \
    --to=michael.tremer@ipfire.org \
    --cc=adolf.belka@ipfire.org \
    --cc=development@lists.ipfire.org \
    --cc=ummeegge@ipfire.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox