Superb quality and spec AB-Com PULSe 4K SE. Crazy offer! Only £99! FREE UK DELIVERY! 4K UHD, Enigma 2, Multiboot 4 images & more!...
Superb quality and spec AB-Com PULSe 4K Rev II Twin Satellite tuner only £149! FREE UK DELIVERY! 4K UHD, Enigma 2, SATA HDD facility, Multiboot 4 images & more!...

[ViX_Misc] OpenVPN upgrade

finbarr

Forum Supporter
Donated Member
Joined
Jan 23, 2014
Messages
211
Reaction score
1
Points
0
Just wondering if it would be possible to update the version of OpenVPN that VIX uses. Currently it is set to 2.1.3 which dates back to 2010-2011.

2.3.2 is the latest, and it includes major changes even compared to latest 2.2.x release:

  • Full IPv6 support
  • SSL layer modularised, enabling easier implementation for other SSL libraries
  • PolarSSL support as a drop-in replacement for OpenSSL
  • New plug-in API providing direct certificate access, improved logging API and easier to extend in the future
  • Added 'dev_type' environment variable to scripts and plug-ins - which is set to 'TUN' or 'TAP'
  • New feature: --management-external-key - to provide access to the encryption keys via the management interface
  • New feature: --x509-track option, more fine grained access to X.509 fields in scripts and plug-ins
  • New feature: --client-nat support
  • New feature: --mark which can mark encrypted packets from the tunnel, suitable for more advanced routing and firewalling
  • New feature: --management-query-proxy - manage proxy settings via the management interface (supercedes --http-proxy-fallback)
  • New feature: --stale-routes-check, which cleans up the internal routing table
  • New feature: --x509-username-field, where other X.509v3 fields can be used for the authentication instead of Common Name
  • Improved client-kill management interface command
  • Improved UTF-8 support - and added --compat-names to provide backwards compatibility with older scripts/plug-ins
  • Improved auth-pam with COMMONNAME support, passing the certificate's common name in the PAM conversation
  • More options can now be used inside <connection> blocks
  • Completely new build system, enabling easier cross-compilation and Windows builds
  • Much of the code has been better documented
  • Many documentation updates
  • Plenty of bug fixes and other code clean-ups
 
Just wondering if it would be possible to update the version of OpenVPN that VIX uses. Currently it is set to 2.1.3 which dates back to 2010-2011.

2.3.2 is the latest, and it includes major changes even compared to latest 2.2.x release:

  • Full IPv6 support
  • SSL layer modularised, enabling easier implementation for other SSL libraries
  • PolarSSL support as a drop-in replacement for OpenSSL
  • New plug-in API providing direct certificate access, improved logging API and easier to extend in the future
  • Added 'dev_type' environment variable to scripts and plug-ins - which is set to 'TUN' or 'TAP'
  • New feature: --management-external-key - to provide access to the encryption keys via the management interface
  • New feature: --x509-track option, more fine grained access to X.509 fields in scripts and plug-ins
  • New feature: --client-nat support
  • New feature: --mark which can mark encrypted packets from the tunnel, suitable for more advanced routing and firewalling
  • New feature: --management-query-proxy - manage proxy settings via the management interface (supercedes --http-proxy-fallback)
  • New feature: --stale-routes-check, which cleans up the internal routing table
  • New feature: --x509-username-field, where other X.509v3 fields can be used for the authentication instead of Common Name
  • Improved client-kill management interface command
  • Improved UTF-8 support - and added --compat-names to provide backwards compatibility with older scripts/plug-ins
  • Improved auth-pam with COMMONNAME support, passing the certificate's common name in the PAM conversation
  • More options can now be used inside <connection> blocks
  • Completely new build system, enabling easier cross-compilation and Windows builds
  • Much of the code has been better documented
  • Many documentation updates
  • Plenty of bug fixes and other code clean-ups

i'll take a look, but i am rather busy atm. i presume a new config screen would be neeeded also, for the new options ?
 
No rush thanks Andy.

I don't think any UI changes would be needed. The current Start/Stop/Autostart options would be the exact same I imagine, and should hopefully still work with the /etc/init.d/openvpn script.

I tried to compile 2.3.2 myself yesterday, but I didn't get far.

Let me know if you need me to test the addon on my Duo2.
 
the openvpn HOWTO is located here:-
Code:
[url]http://openvpn.net/index.php/open-source/documentation/howto.html[/url]

andy, you should be able to update the download url in the bb with the new download link below, i have compiled + used new openvpns in oe a while back
Code:
[url]http://swupdate.openvpn.org/community/releases/openvpn-2.3.2.tar.gz[/url]
 
Looks like version 2.3.3 of OpenVPN has the Heartbleed fix. I would be anxious to get that running in Helios if at all possible due to the severity of the security hole.
 
Helios includes a updated version of OpenSSL that fixes the heartbleed issue.
 
OpenVPN working great in Helios thanks Andy.

FYI, I had to run this command (in addition to the tutorial) to get the server to run OK (source):
Code:
groupadd -g 1002 nobody
 
Sorry but i dont use OpenVPN so if you tell me where about in the tutorial you want this part added i'll amend it for you.
 
Guide should be fine without that Pheonix as

Step 7 has './build-ca' mentioned twice. The first can be removed.

Also step 11 has 'mv -r...' Maybe remove the -r as it
Is not needed In a unix move.
 
Also add a last step to remind people to comment out logging in Step 13 just jn case it fills up storage. Thanks!
 
Guide should be fine without that Pheonix as

Step 7 has './build-ca' mentioned twice. The first can be removed.

Also step 11 has 'mv -r...' Maybe remove the -r as it
Is not needed In a unix move.

Thanks for the clarification, if you ever do want it updating just let me know and i'll sort it for you.
 
Sorry my first post there was meant to read...

Guide should be fine without that line Pheonix as that command is only needed when adding extra security config options as per the OpenVPN HOWTO.
 
ive used openvpn for many years, different versions, on different os's and ive never had to use any extra commands to get it to work.
 
Hi Rossi, i have a vpn account that works perfect on my pc's at home, and yet on vix everthing is telling me its connecting..but its not working properly been pulling my hair out.

I have installed Openvpn, I get an "Initialization Sequence Completed" at the end of my log when starting it. In telnet I get a Tun0 device appearing if I do Ifconfig. The IP of the box also is confirmed as changing if i do "curl ipecho.net/plain", after starting openvpn it 100% correctly states my new vpn's ip as it should..stop openvpn and the ip reverts back.

On a pc I can connect to whatever I want and it uses the vpn to connect and is 100% superb. With the Tm nano-oe however it makes no difference i cannot connect to the same sites as I can on the pc using the same vpn... ie solar movies/primewire

It is almost as if the tun0 device is not in-fact being used by Tsmedia at all.

rossi/anybody shed any light on this matter at all? before i lose whats left of my sanity :)
 

OpenViX Feeds Status

Back
Top