Full-featured SSL VPN solution using a TUN/TAP Interface

Edit Package openvpn

OpenVPN is a full-featured SSL VPN solution which can accommodate a wide
range of configurations, including remote access, site-to-site VPNs,
WiFi security, and enterprise-scale remote access solutions with load
balancing, failover, and fine-grained access-controls.

OpenVPN implements OSI layer 2 or 3 secure network extension using the
industry standard SSL/TLS protocol, supports flexible client
authentication methods based on certificates, smart cards, and/or
2-factor authentication, and allows user or group-specific access
control policies using firewall rules applied to the VPN virtual
interface.

OpenVPN runs on: Linux, Windows 2000/XP and higher, OpenBSD, FreeBSD,
NetBSD, Mac OS X, and Solaris.

OpenVPN is not a web application proxy and does not operate through a
web browser.

Refresh
Refresh
Source Files
Filename Size Changed
0001-preform-deferred-authentication-in-the-background.patch 0000004831 4.72 KB
client-netconfig.down 0000001043 1.02 KB
client-netconfig.up 0000002188 2.14 KB
openvpn-2.3-plugin-man.dif 0000000703 703 Bytes
openvpn-2.3.9-Fix-heap-overflow-on-getaddrinfo-result.patch 0000002614 2.55 KB
openvpn-2.3.x-fixed-multiple-low-severity-issues.patch 0000009478 9.26 KB
openvpn-2.4.11.tar.xz 0000970872 948 KB
openvpn-2.4.11.tar.xz.asc 0000000833 833 Bytes
openvpn-fips140-2.3.2.patch 0000003907 3.82 KB
openvpn-tmpfile.conf 0000000032 32 Bytes
openvpn.README.SUSE 0000000821 821 Bytes
openvpn.changes 0000061022 59.6 KB
openvpn.keyring 0000022838 22.3 KB
openvpn.service 0000000506 506 Bytes
openvpn.spec 0000009317 9.1 KB
openvpn.target 0000000097 97 Bytes
rcopenvpn 0000000535 535 Bytes
Revision 92 (latest revision is 115)
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 898085 from Reinhard Max's avatar Reinhard Max (rmax) (revision 92)
- update to 2.4.11 (bsc#1185279):
  * CVE-2020-15078 see https://community.openvpn.net/openvpn/wiki/SecurityAnnouncements
  * This bug allows - under very specific circumstances - to trick a server using
    delayed authentication (plugin or management) into returning a PUSH_REPLY
    before the AUTH_FAILED message, which can possibly be used to gather
    information about a VPN setup.
  * In combination with "--auth-gen-token" or an user-specific token auth
    solution it can be possible to get access to a VPN with an
    otherwise-invalid account.
  * Fix potential NULL ptr crash if compiled with DMALLOC
- drop sysv5 init support, it hasn't build successfully in ages
  and is build-disabled in devel project
Comments 0
openSUSE Build Service is sponsored by