![]() Wintun driver support, a faster alternative to tap-windows6.Netlink integration (OpenVPN no longer needs to execute ifconfig/route or ip commands).New option -block-ipv6 to reject all IPv6 packets (ICMPv6).Support IPv4 configs with /31 netmasks now.Asynchronous (deferred) support for client-connect scripts and plugins.Asynchronous (deferred) authentication support for auth-pam plugin.HMAC based auth-token support for seamless reconnects to standalone servers or a group of servers.Removal of BF-CBC support in default configuration (see below for possible incompatibilities).Improved Data channel cipher negotiation.Client-specific tls-crypt keys (-tls-crypt-v2).Improved TLS 1.3 support when using OpenSSL 1.1.1 or newer.ChaCha20-Poly1305 cipher in the OpenVPN data channel (Requires OpenSSL 1.1.0 or newer).This is mostly a bugfix release, but adds limited support for OpenSSL 3.0. The OpenVPN community project team is proud to release OpenVPN 2.5.7. Updated easy-rsa3 bundled with the installer on Windows.Included openvpn-gui updated to 11.36.0.0.Improved protocol negotiation, leading to faster connection setup.Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.Added -peer-fingerprint mode for a more simplistic certificate setup and verification.Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.Improved handling of tunnel MTU, including support for pushable MTU.Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.New features and improvements in 2.6.0 compared to 2.5.8: "-cryptoapicert ISSUER: " where is matched as a substring of the issuer (CA) name in the certificate.Certificate selection string can now specify a partial issuer name string as CryptoAPI (Windows): support issuer name as a selector.This ensure that only the previously authenticated peer can do trigger renegotiation and complete renegotiations. Dynamic TLS Crypt: When both peers are OpenVPN 2.6.1+, OpenVPN will dynamically create a tls-crypt key that is used for renegotiation.Fixed a regression with handling "user data" metadata on new instance launch on Amazon AWS.It does require some configuring, but ultimately it has no cost for the user. ![]() OpenVPN Connect has a free version but this version is limited to two connections. OpenVPN Connect is the commercial implementation of OpenVPN. OpenVPN is open source, completely free, and supported by the community. What is the difference between OpenVPN and OpenVPN Connect?
0 Comments
Leave a Reply. |