Merge openvpn from Debian unstable for 22.04

Bug #1946884 reported by Bryce Harrington
26
This bug affects 2 people
Affects Status Importance Assigned to Milestone
openvpn (Ubuntu)
Fix Released
Undecided
Sergio Durigan Junior

Bug Description

Upstream: 2.5.4
Debian: 2.5.1-3
Ubuntu: 2.5.1-3ubuntu1

Debian typically updates openvpn every month or so on average, but it was last updated 21.05 and looks overdue. Check back in on this monthly.

There is a new upstream version, however, so may be worth going ahead of
debian and/or updating it in Debian and syncing it.

Please also note LP: #1945980 "openvpn: Fail to build against OpenSSL 3.0", which will need addressed for the upcoming OpenSSL transition.

### New Debian Changes ###

openvpn (2.5.1-3) unstable; urgency=medium

  * Fix autopkgtest (Closes: #983662)
    - adapt autopkgtest output to 2.5 (from Ubuntu)
    - Fix easyrsa batch mode invocation
  * Cherry-Pick 'Fix condition to generate session keys' (Closes: #988478)

 -- Bernhard Schmidt <email address hidden> Fri, 14 May 2021 09:40:04 +0200

openvpn (2.5.1-2) unstable; urgency=high

  * Cherry-Pick 3 (+ 1 predependency) patches from upstream to fix
    authentication bypass with deferred authentication
    (CVE-2020-15078) (Closes: #987380)

 -- Bernhard Schmidt <email address hidden> Wed, 28 Apr 2021 14:41:58 +0200

openvpn (2.5.1-1) unstable; urgency=medium

  * New upstream version 2.5.1 (bugfix release)

 -- Bernhard Schmidt <email address hidden> Wed, 24 Feb 2021 19:54:34 +0100

openvpn (2.5.0-1) unstable; urgency=medium

  * New upstream version 2.5.0 - final release

 -- Bernhard Schmidt <email address hidden> Wed, 28 Oct 2020 19:37:34 +0100

openvpn (2.5~rc3-1) unstable; urgency=medium

  * New upstream version 2.5~rc3

 -- Bernhard Schmidt <email address hidden> Tue, 20 Oct 2020 19:17:43 +0200

openvpn (2.5~rc2-1) unstable; urgency=medium

  * Downgrade debhelper-compat to 12 for easier backports
  * New upstream version 2.5~rc2

 -- Bernhard Schmidt <email address hidden> Wed, 30 Sep 2020 21:12:11 +0200

openvpn (2.5~beta3-1) unstable; urgency=medium

  * Release to unstable.

  [ Lucas Kanashiro ]
  * Add two DEP-8 test cases for the server side
  * Drop reload support from systemd unit files (LP: #1868127)

  [ Bernhard Schmidt ]
  * Revert 'd/gbp.conf for experimental 2.5 branch'
  * New upstream version 2.5~beta3

 -- Bernhard Schmidt <email address hidden> Tue, 01 Sep 2020 16:53:43 +0200

openvpn (2.5~beta1-3) experimental; urgency=medium

  * Disable iproute2 support in favour of the new netlink based default.
    Thanks to Fabio Pedretti

 -- Bernhard Schmidt <email address hidden> Sun, 16 Aug 2020 14:04:11 +0200

openvpn (2.5~beta1-2) experimental; urgency=medium

  * Set Build-Conflicts: systemctl, see Bug#959828

 -- Bernhard Schmidt <email address hidden> Sun, 16 Aug 2020 10:33:47 +0200

openvpn (2.5~beta1-1) experimental; urgency=medium

  * d/gbp.conf for experimental 2.5 branch
  * New upstream version 2.5~beta1
  * Adjust patches for new major upstream version
  * Add python3-docutils to build-depends for manpage generation

 -- Bernhard Schmidt <email address hidden> Sat, 15 Aug 2020 21:32:49 +0200

openvpn (2.4.9-3) unstable; urgency=medium

  [ Jörg Frings-Fürst ]
  * Fix the bug that occurs during the update (Closes: #959464):
    'ERROR: Cannot ioctl TUNSETIFF tunX: Device or resource busy (errno=16)'
    - debian/rules: Change dh_installsystemd from '--restart-after-upgrade' to
      '--no-restart-after-upgrade -r'.
    - Remove restart from debian/postinst.
    - Add hint to reboot if openvpn is running.
    - Add new chapter into debian/NEWS.
  * Migrate to debhelper 13.
  * debian/postinst:
    - Remove now useless code for version less than 2.3.2-6.
  * debina/copyright:
    - Add year 2020 to Bernhard Schmidt.

 -- Jörg Frings-Fürst <email address hidden> Sat, 02 May 2020 18:14:36 +0200

openvpn (2.4.9-2) unstable; urgency=medium

  * Cherry-Pick upstream patch to fix ssl_do_config error with
    invalid OpenSSL system configuration (Closes: #958296)

### Old Ubuntu Delta ###

openvpn (2.5.1-3ubuntu1) impish; urgency=medium

  * Merge with Debian unstable. Remaining changes:
    - d/control: Demote easy-rsa to Suggests (universe package).
    - debian/openvpn@.service: Add '--script-security 2' similar to what
      got added to debian/openvpn.init.d ages ago (LP #1454725)
    - d/p/openvpn-fips-2.4.patch: Allow MD5 for PRF in FIPS mode openssl.
  * Dropped changes:
    - d/t/server-setup-*: adapt tests to output of v2.5.0
      [Included in 2.5.1-3]

 -- Utkarsh Gupta <email address hidden> Mon, 17 May 2021 14:38:17 +0530

Related branches

Bryce Harrington (bryce)
Changed in openvpn (Ubuntu):
assignee: nobody → Bryce Harrington (bryce)
Bryce Harrington (bryce)
description: updated
description: updated
Changed in openvpn (Ubuntu):
milestone: none → ubuntu-21.12
Bryce Harrington (bryce)
description: updated
Revision history for this message
Bryce Harrington (bryce) wrote :

[No new version in Debian yet]

Changed in openvpn (Ubuntu):
status: New → Incomplete
Bryce Harrington (bryce)
Changed in openvpn (Ubuntu):
milestone: ubuntu-21.12 → ubuntu-22.01
Bryce Harrington (bryce)
Changed in openvpn (Ubuntu):
milestone: ubuntu-22.01 → ubuntu-22.02
Revision history for this message
Sergio Durigan Junior (sergiodj) wrote :

I coordinated with Bryce and will be doing the merge of openvpn in the next few hours.

Changed in openvpn (Ubuntu):
assignee: Bryce Harrington (bryce) → Sergio Durigan Junior (sergiodj)
Changed in openvpn (Ubuntu):
status: Incomplete → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package openvpn - 2.5.5-1ubuntu1

---------------
openvpn (2.5.5-1ubuntu1) jammy; urgency=medium

  * Merge with Debian unstable (LP: #1946884). Remaining changes:
    - d/control: Demote easy-rsa to Suggests (universe package).
    - debian/openvpn@.service: Add '--script-security 2' similar to what
      got added to debian/openvpn.init.d ages ago (LP #1454725)
    - d/p/openvpn-fips-2.4.patch: Allow MD5 for PRF in FIPS mode openssl.
    - d/p/OpenSSL3.patch: work around the deprecated algorithm mismatch between
      the OpenSSL3 branch and the OpenVPN 2.5 branch (LP #1945980)

 -- Sergio Durigan Junior <email address hidden> Wed, 23 Feb 2022 10:14:27 -0500

Changed in openvpn (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.