From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4c0yJt2hb1z2ylb for ; Mon, 11 Aug 2025 14:51:58 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "R11" (verified OK)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4c0yJp5ltfz2y0C for ; Mon, 11 Aug 2025 14:51:54 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4c0yJn3nQvz1Cb for ; Mon, 11 Aug 2025 14:51:53 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1754923913; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=iDhCmozHxtDypwaLrg3uzkhtobdCVNHqurinMpq/hHY=; b=D3Vm/9hpS0Cyf6Zwkk0gAauXme6Q36wn1Gnvw+N4YU/aryN1LIKKYcJckTKdI7IIrtrh1e b/JantngXpHaI0CA== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1754923913; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=iDhCmozHxtDypwaLrg3uzkhtobdCVNHqurinMpq/hHY=; b=IiffJLBtt69CRnHYr3oySuvaWYAKZklcvowoDlUn2Y4O3L7mBQk2rla799wMCKABeSEgAL 0mfiFNt4BCenWM4/XbsmVpIco/6pkbBz0kIBhJm1+wYl0oyg234+7tTc+SJld0MT2O9AwO GYtbBs8DoLurNVS/x+Y0vuExm0HioK24ixu/vQ//DD2VQZVbVKX9uK44ClOHbPySJSI82w bc6+UnVKg6UlFZ7IQeTkHHPSAvPq/kOtxGb1t8jZw9/d7TNukWrsZy9iqDT5QbScTQQtQ+ uERH2vVZlWf5SMFwIzWO6AtTxPmG2rtCpNUEt9fTUAj7RnedFUe9PaSG8F2kSA== Message-ID: <29a112a2-0ada-43a1-b0c6-43f336745d43@ipfire.org> Date: Mon, 11 Aug 2025 16:51:50 +0200 Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 Subject: Re: IPFire 2.29 - Core Update 197 is available for testing From: Adolf Belka To: "IPFire: Development-List" References: <175490371612.107547.14288613781884197415.ipfire@ipfire.org> <8c5b754f-002b-4a80-b757-9a74aeb57f7e@ipfire.org> Content-Language: en-GB In-Reply-To: <8c5b754f-002b-4a80-b757-9a74aeb57f7e@ipfire.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Hi All, Further testing feedback of OpenVPN-2.6 I tested out the existing client connections to my android phone and my linux laptop. Both connections connected. Ping worked on the laptop but not on the android. Accessing the IPFire WUI via the openvpn rw tunnel worked for both android and laptop. I then created new client connections. The linux laptop connection worked without any issues. The android client did not want to work with the .ovpn file with the certificates built in. It said that it had obtained the required info from inline but the connection failed within a couple of lines in the log, so some problem. I then removed the inline certificate lines from the .ovpn file and used the .p12 and ta.key files, adding the appropriate lines into the .ovpn file to reference them. The connection worked without any problem. In addition the ping now worked with this android connection. Regards, Adolf. On 11/08/2025 16:01, Adolf Belka wrote: > Hi All, > > Have found a little issue. Not sure if it is critical or not. > > My existing connections on OpenVPN are working fine and the network topology has been changed in most places but not in the ccd files. > > I have a connection called ipfiretesting which before the upgrade had 10.110.30.5 and 10.110.30.6. > > After the upgrade to 197 if I edit the entry it shows that it is using 10.110.30.6 > > However if I look in /var/ipfire/ovpn/ccd/ipfiretesting it still has the line > > ifconfig-push 10.110.26.6 10.110.26.5 > > If I then create a new client connection then all the ccd files get updated and ipfiretesting now contains > > ifconfig-push 10.110.30.6 255.255.255.0 > > So if a user upgrades but doesn't create a new client connection all the ccd files will stay with the old format. Not sure what this would or wouldn't do for the connection but I think after the upgrade it would be good to update all the ccd files but not sure how to make that happen. > > Regards, > > Adolf. > > On 11/08/2025 11:28, IPFire Project wrote: >> **IPFire 2.29 – Core Update 197** is now available for testing. This release introduces a significant overhaul of OpenVPN, upgrading to version 2.6 with improved security, broader client compatibility, and a modernised codebase — all without requiring changes to existing configurations. System performance has also been optimised to allow the CPU to remain in power-saving states more often, reducing energy consumption. As with every release, this update includes a large number of package updates to ensure your system remains secure and reliable. >> ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ >> >> >>   IPFire_ >> >> >>   IPFire 2.29 - Core Update 197 is available for testing >> >> **IPFire 2.29 – Core Update 197** is now available for testing. This release introduces a significant overhaul of OpenVPN, upgrading to version 2.6 with improved security, broader client compatibility, and a modernised codebase — all without requiring changes to existing configurations. System performance has also been optimised to allow the CPU to remain in power-saving states more often, reducing energy consumption. As with every release, this update includes a large number of package updates to ensure your system remains secure and reliable. >> >> Read The Full Post On Our Blog >> >> The IPFire Project, c/o Lightning Wire Labs GmbH, Gerhardstraße 8, 45711 Datteln, Germany >> >> Unsubscribe >> >