)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"cc8462bf7674fdbc4f4f44c87e9a828d28a3652e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"5119619c_4ca4738a","updated":"2023-12-12 07:33:13.000000000","message":"feature-ack, but the code is not fully there yet","commit_id":"5c56d0f006a1c7d0983d9d16715b61dd4a9c6379"},{"author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"84669ed683de44c01af4ab0b4fdcc5290ff93f5e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"1b42b6f6_65d734b8","updated":"2024-01-02 12:51:26.000000000","message":"Looks good now.  Will proceed to send mail and subject this patch to more testing.","commit_id":"ab1eac5a6871179aa223c3acb2e4c77f09a2ea23"},{"author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"6d1b9c0efaac3dc6cd3bbffa812b8ede9f26b2db","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"002450c9_f97b9e98","updated":"2024-01-03 22:45:10.000000000","message":"sorry... found another one :-(","commit_id":"ab1eac5a6871179aa223c3acb2e4c77f09a2ea23"},{"author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"f92c1785e2c09bb9206662fd3786a2b30fd23c30","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"de255ade_ed57cfba","updated":"2024-01-04 14:01:55.000000000","message":"back to +2 - manipulating expected_out or setting ret\u003d0 now leads to \"it failed!\" and the code as is pretends the PRF worked.  Didn\u0027t test FIPS mode, but \"set ret\u003d0\" as a test case should be good enough.","commit_id":"79aaea1f64e9d192fdf47e52898d6a58c22e1484"}],"src/openvpn/crypto.c":[{"author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"d7d08c7e98cd635313fb06ecd04f230904dd9642","unresolved":true,"context_lines":[{"line_number":1794,"context_line":"check_tls_prf_working(void)"},{"line_number":1795,"context_line":"{"},{"line_number":1796,"context_line":"    /* Modern TLS libraries might no longer support the TLS 1.0 PRF. This"},{"line_number":1797,"context_line":"     * limits our compatibility to other 2.6.x+ OpernVPN peers. Do a simple"},{"line_number":1798,"context_line":"     * dummy test here to see if it works. */"},{"line_number":1799,"context_line":"    const char *seed \u003d \"tls1-prf-test\";"},{"line_number":1800,"context_line":"    const char *secret \u003d \"tls1-prf-test-secret\";"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"2a674c0e_9a4fdc16","line":1797,"updated":"2023-11-28 11:21:56.000000000","message":"\"OpenVPN\"","commit_id":"d93b06d54bc5291c0a6c8c142dc224e6ca3f1a06"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"8ec89e4f6dacadb48b3be39c6c63b5a8dce605f7","unresolved":false,"context_lines":[{"line_number":1794,"context_line":"check_tls_prf_working(void)"},{"line_number":1795,"context_line":"{"},{"line_number":1796,"context_line":"    /* Modern TLS libraries might no longer support the TLS 1.0 PRF. This"},{"line_number":1797,"context_line":"     * limits our compatibility to other 2.6.x+ OpernVPN peers. Do a simple"},{"line_number":1798,"context_line":"     * dummy test here to see if it works. */"},{"line_number":1799,"context_line":"    const char *seed \u003d \"tls1-prf-test\";"},{"line_number":1800,"context_line":"    const char *secret \u003d \"tls1-prf-test-secret\";"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"cbdb8303_d315f0e5","line":1797,"in_reply_to":"2a674c0e_9a4fdc16","updated":"2023-11-28 13:39:57.000000000","message":"Done","commit_id":"d93b06d54bc5291c0a6c8c142dc224e6ca3f1a06"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"928130cf7e4120e66f0b3c722104b66963c0ce5c","unresolved":false,"context_lines":[{"line_number":1794,"context_line":"check_tls_prf_working(void)"},{"line_number":1795,"context_line":"{"},{"line_number":1796,"context_line":"    /* Modern TLS libraries might no longer support the TLS 1.0 PRF. This"},{"line_number":1797,"context_line":"     * limits our compatibility to other 2.6.x+ OpernVPN peers. Do a simple"},{"line_number":1798,"context_line":"     * dummy test here to see if it works. */"},{"line_number":1799,"context_line":"    const char *seed \u003d \"tls1-prf-test\";"},{"line_number":1800,"context_line":"    const char *secret \u003d \"tls1-prf-test-secret\";"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"25274dc5_732e6f85","line":1797,"in_reply_to":"b5d3ee6a_2c915e28","updated":"2023-12-01 12:13:28.000000000","message":"Now really done","commit_id":"d93b06d54bc5291c0a6c8c142dc224e6ca3f1a06"},{"author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"f66a4619ae92cbfede7847dfe6c79c187e96dbc8","unresolved":true,"context_lines":[{"line_number":1794,"context_line":"check_tls_prf_working(void)"},{"line_number":1795,"context_line":"{"},{"line_number":1796,"context_line":"    /* Modern TLS libraries might no longer support the TLS 1.0 PRF. This"},{"line_number":1797,"context_line":"     * limits our compatibility to other 2.6.x+ OpernVPN peers. Do a simple"},{"line_number":1798,"context_line":"     * dummy test here to see if it works. */"},{"line_number":1799,"context_line":"    const char *seed \u003d \"tls1-prf-test\";"},{"line_number":1800,"context_line":"    const char *secret \u003d \"tls1-prf-test-secret\";"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"b5d3ee6a_2c915e28","line":1797,"in_reply_to":"cbdb8303_d315f0e5","updated":"2023-12-01 11:06:19.000000000","message":"Not done","commit_id":"d93b06d54bc5291c0a6c8c142dc224e6ca3f1a06"},{"author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"f66a4619ae92cbfede7847dfe6c79c187e96dbc8","unresolved":true,"context_lines":[{"line_number":1794,"context_line":"check_tls_prf_working(void)"},{"line_number":1795,"context_line":"{"},{"line_number":1796,"context_line":"    /* Modern TLS libraries might no longer support the TLS 1.0 PRF. This"},{"line_number":1797,"context_line":"     * limits our compatibility to other 2.6.x+ OperVPN peers. Do a simple"},{"line_number":1798,"context_line":"     * dummy test here to see if it works. */"},{"line_number":1799,"context_line":"    const char *seed \u003d \"tls1-prf-test\";"},{"line_number":1800,"context_line":"    const char *secret \u003d \"tls1-prf-test-secret\";"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"ca315396_343fe5a4","line":1797,"updated":"2023-12-01 11:06:19.000000000","message":"Also, shouldn\u0027t that be \"pre-2.6.0 peers\" instead of \"2.6.x+ peers\"?","commit_id":"6ea483556f3177097c4de3b19c2047cffdb79ac9"},{"author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"1c3d2844a3cf62cf8012625add3fcd7fcc464eb8","unresolved":true,"context_lines":[{"line_number":1794,"context_line":"check_tls_prf_working(void)"},{"line_number":1795,"context_line":"{"},{"line_number":1796,"context_line":"    /* Modern TLS libraries might no longer support the TLS 1.0 PRF. This"},{"line_number":1797,"context_line":"     * limits our compatibility to other 2.6.x+ OperVPN peers. Do a simple"},{"line_number":1798,"context_line":"     * dummy test here to see if it works. */"},{"line_number":1799,"context_line":"    const char *seed \u003d \"tls1-prf-test\";"},{"line_number":1800,"context_line":"    const char *secret \u003d \"tls1-prf-test-secret\";"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"8d18aa2f_604e3d4b","line":1797,"in_reply_to":"5cda2246_a787261c","updated":"2023-12-01 12:28:54.000000000","message":"I think my problem is \"limits our compatibility to\". I find it difficult to parse that correctly. May I suggest to drop that? \"This only allows us to establish connections with peers that support keying material export (e.g. OpenVPN 2.6.0+).\"","commit_id":"6ea483556f3177097c4de3b19c2047cffdb79ac9"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"ebd1a56a14e5c22b370f05bb2a9255e6abfd108b","unresolved":false,"context_lines":[{"line_number":1794,"context_line":"check_tls_prf_working(void)"},{"line_number":1795,"context_line":"{"},{"line_number":1796,"context_line":"    /* Modern TLS libraries might no longer support the TLS 1.0 PRF. This"},{"line_number":1797,"context_line":"     * limits our compatibility to other 2.6.x+ OperVPN peers. Do a simple"},{"line_number":1798,"context_line":"     * dummy test here to see if it works. */"},{"line_number":1799,"context_line":"    const char *seed \u003d \"tls1-prf-test\";"},{"line_number":1800,"context_line":"    const char *secret \u003d \"tls1-prf-test-secret\";"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"e88d1a14_0f492b72","line":1797,"in_reply_to":"8d18aa2f_604e3d4b","updated":"2023-12-07 18:25:34.000000000","message":"Acknowledged","commit_id":"6ea483556f3177097c4de3b19c2047cffdb79ac9"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"928130cf7e4120e66f0b3c722104b66963c0ce5c","unresolved":false,"context_lines":[{"line_number":1794,"context_line":"check_tls_prf_working(void)"},{"line_number":1795,"context_line":"{"},{"line_number":1796,"context_line":"    /* Modern TLS libraries might no longer support the TLS 1.0 PRF. This"},{"line_number":1797,"context_line":"     * limits our compatibility to other 2.6.x+ OperVPN peers. Do a simple"},{"line_number":1798,"context_line":"     * dummy test here to see if it works. */"},{"line_number":1799,"context_line":"    const char *seed \u003d \"tls1-prf-test\";"},{"line_number":1800,"context_line":"    const char *secret \u003d \"tls1-prf-test-secret\";"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"5cda2246_a787261c","line":1797,"in_reply_to":"ca315396_343fe5a4","updated":"2023-12-01 12:13:28.000000000","message":"limits in the sense that we are limited to only 2.6.0+ peers. I will adjust the text to make a it a bit more clear.","commit_id":"6ea483556f3177097c4de3b19c2047cffdb79ac9"},{"author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"6d1b9c0efaac3dc6cd3bbffa812b8ede9f26b2db","unresolved":true,"context_lines":[{"line_number":1806,"context_line":"                           (uint8_t *)secret, (int) strlen(secret),"},{"line_number":1807,"context_line":"                           out, sizeof(out));"},{"line_number":1808,"context_line":""},{"line_number":1809,"context_line":"    return (ret \u0026\u0026 memcmp(out, expected_out, sizeof(out)) !\u003d 0);"},{"line_number":1810,"context_line":"}"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"131b2f38_d4640bad","line":1809,"updated":"2024-01-03 22:45:10.000000000","message":"It pains me to return to \"-2\" again, but there is something really weird going on here - to see what happens if the PRF fails, I changed \"expected_out[3] to \"2\" in my tree, and it still succeeds.  Wat.  So I look at the comparison, and we should be checking for `\u003d\u003d 0` here (\"out \u003d\u003d expected_out\", this is not strcmp()...).\n\nSo I fired up gdb with -O0, and this is what it says...\n\n```\n(gdb) print ret\n$1 \u003d 1\n(gdb) print out\n$2 \u003d \"qD\\376%@su\\225\"\n(gdb) print expected_out\n$3 \u003d \"\\340_\\037\\001\\000\\000\\000\"\n```","commit_id":"ab1eac5a6871179aa223c3acb2e4c77f09a2ea23"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"9da82d5bbfd80ad0194e0a33427060930bff1daa","unresolved":false,"context_lines":[{"line_number":1806,"context_line":"                           (uint8_t *)secret, (int) strlen(secret),"},{"line_number":1807,"context_line":"                           out, sizeof(out));"},{"line_number":1808,"context_line":""},{"line_number":1809,"context_line":"    return (ret \u0026\u0026 memcmp(out, expected_out, sizeof(out)) !\u003d 0);"},{"line_number":1810,"context_line":"}"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"46b9a5e4_f4d733cf","line":1809,"in_reply_to":"131b2f38_d4640bad","updated":"2024-01-04 12:45:54.000000000","message":"O my got I really butchered that one.","commit_id":"ab1eac5a6871179aa223c3acb2e4c77f09a2ea23"}],"src/openvpn/multi.c":[{"author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"cc8462bf7674fdbc4f4f44c87e9a828d28a3652e","unresolved":true,"context_lines":[{"line_number":1838,"context_line":"                               \"server. Keying Material Exporters (RFC 5705)\""},{"line_number":1839,"context_line":"                               \"support missing. Upgrade to a client that \""},{"line_number":1840,"context_line":"                               \"supports this feature (OpenVPN 2.6.0+).\");"},{"line_number":1841,"context_line":"        return false;"},{"line_number":1842,"context_line":"    }"},{"line_number":1843,"context_line":"    if (proto \u0026 IV_PROTO_DYN_TLS_CRYPT)"},{"line_number":1844,"context_line":"    {"}],"source_content_type":"text/x-csrc","patch_set":5,"id":"a893a87b_2e6a6e2a","line":1841,"updated":"2023-12-12 07:33:13.000000000","message":"there is whitespace missing at the first and second line wrap (\"thisserver\" and \"(RFC 5705)support\"","commit_id":"5c56d0f006a1c7d0983d9d16715b61dd4a9c6379"},{"author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"66629491eb756ff36a31e0661039d61e9ef2bf15","unresolved":true,"context_lines":[{"line_number":1838,"context_line":"                               \"server. Keying Material Exporters (RFC 5705)\""},{"line_number":1839,"context_line":"                               \"support missing. Upgrade to a client that \""},{"line_number":1840,"context_line":"                               \"supports this feature (OpenVPN 2.6.0+).\");"},{"line_number":1841,"context_line":"        return false;"},{"line_number":1842,"context_line":"    }"},{"line_number":1843,"context_line":"    if (proto \u0026 IV_PROTO_DYN_TLS_CRYPT)"},{"line_number":1844,"context_line":"    {"}],"source_content_type":"text/x-csrc","patch_set":5,"id":"336c9224_c681507d","line":1841,"in_reply_to":"09e5b596_0004b9ee","updated":"2023-12-13 17:42:09.000000000","message":"done for \"(RFC 5705)support\", not done for \"thisserver\" (first line).","commit_id":"5c56d0f006a1c7d0983d9d16715b61dd4a9c6379"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"fb040cff3c316a52af493d7d6991299aae09fb72","unresolved":false,"context_lines":[{"line_number":1838,"context_line":"                               \"server. Keying Material Exporters (RFC 5705)\""},{"line_number":1839,"context_line":"                               \"support missing. Upgrade to a client that \""},{"line_number":1840,"context_line":"                               \"supports this feature (OpenVPN 2.6.0+).\");"},{"line_number":1841,"context_line":"        return false;"},{"line_number":1842,"context_line":"    }"},{"line_number":1843,"context_line":"    if (proto \u0026 IV_PROTO_DYN_TLS_CRYPT)"},{"line_number":1844,"context_line":"    {"}],"source_content_type":"text/x-csrc","patch_set":5,"id":"e38ba8a4_88fcee07","line":1841,"in_reply_to":"336c9224_c681507d","updated":"2024-01-01 19:04:40.000000000","message":"Done","commit_id":"5c56d0f006a1c7d0983d9d16715b61dd4a9c6379"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"f766972565fff824ed7c2b8a5688b816384ecf99","unresolved":false,"context_lines":[{"line_number":1838,"context_line":"                               \"server. Keying Material Exporters (RFC 5705)\""},{"line_number":1839,"context_line":"                               \"support missing. Upgrade to a client that \""},{"line_number":1840,"context_line":"                               \"supports this feature (OpenVPN 2.6.0+).\");"},{"line_number":1841,"context_line":"        return false;"},{"line_number":1842,"context_line":"    }"},{"line_number":1843,"context_line":"    if (proto \u0026 IV_PROTO_DYN_TLS_CRYPT)"},{"line_number":1844,"context_line":"    {"}],"source_content_type":"text/x-csrc","patch_set":5,"id":"09e5b596_0004b9ee","line":1841,"in_reply_to":"a893a87b_2e6a6e2a","updated":"2023-12-12 12:11:27.000000000","message":"Done","commit_id":"5c56d0f006a1c7d0983d9d16715b61dd4a9c6379"}],"src/openvpn/options.c":[{"author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"d7d08c7e98cd635313fb06ecd04f230904dd9642","unresolved":true,"context_lines":[{"line_number":2580,"context_line":"        {"},{"line_number":2581,"context_line":"            msg(M_USAGE, \"--mode server requires --tls-server\");"},{"line_number":2582,"context_line":"        }"},{"line_number":2583,"context_line":"        if (options-\u003eforce_key_material_export)"},{"line_number":2584,"context_line":"        {"},{"line_number":2585,"context_line":"            msg(M_USAGE, \"--force-tls-key-material-export requires --mode server\");"},{"line_number":2586,"context_line":"        }"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"d4124e62_ecf20def","line":2583,"updated":"2023-11-28 11:21:56.000000000","message":"This is in \"if (options-\u003emode \u003d\u003d MODE_SERVER)\" which is wrong.","commit_id":"d93b06d54bc5291c0a6c8c142dc224e6ca3f1a06"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"8ec89e4f6dacadb48b3be39c6c63b5a8dce605f7","unresolved":false,"context_lines":[{"line_number":2580,"context_line":"        {"},{"line_number":2581,"context_line":"            msg(M_USAGE, \"--mode server requires --tls-server\");"},{"line_number":2582,"context_line":"        }"},{"line_number":2583,"context_line":"        if (options-\u003eforce_key_material_export)"},{"line_number":2584,"context_line":"        {"},{"line_number":2585,"context_line":"            msg(M_USAGE, \"--force-tls-key-material-export requires --mode server\");"},{"line_number":2586,"context_line":"        }"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"ba9c2025_db846721","line":2583,"in_reply_to":"d4124e62_ecf20def","updated":"2023-11-28 13:39:57.000000000","message":"Done","commit_id":"d93b06d54bc5291c0a6c8c142dc224e6ca3f1a06"},{"author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"66629491eb756ff36a31e0661039d61e9ef2bf15","unresolved":true,"context_lines":[{"line_number":3646,"context_line":"    {"},{"line_number":3647,"context_line":""},{"line_number":3648,"context_line":"        msg(D_TLS_ERRORS, \"Warning: TLS 1.0 PRF with MD5+SHA1 PRF not supported \""},{"line_number":3649,"context_line":"            \"by TLS library. Your system does not support this calculation \""},{"line_number":3650,"context_line":"            \"anymore or your security policy (e.g. FIPS 140-2) forbids it. \""},{"line_number":3651,"context_line":"            \"Connections will only work with peers running OpenVPN 2.6.0 or \""},{"line_number":3652,"context_line":"            \"higher)\");"}],"source_content_type":"text/x-csrc","patch_set":5,"id":"850dc22b_4f3310f4","line":3649,"updated":"2023-12-13 17:42:09.000000000","message":"the change v5-\u003ev7 brought in a new whitespace error here, \"(FIPS 140-2)forbids\".","commit_id":"5c56d0f006a1c7d0983d9d16715b61dd4a9c6379"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"fb040cff3c316a52af493d7d6991299aae09fb72","unresolved":false,"context_lines":[{"line_number":3646,"context_line":"    {"},{"line_number":3647,"context_line":""},{"line_number":3648,"context_line":"        msg(D_TLS_ERRORS, \"Warning: TLS 1.0 PRF with MD5+SHA1 PRF not supported \""},{"line_number":3649,"context_line":"            \"by TLS library. Your system does not support this calculation \""},{"line_number":3650,"context_line":"            \"anymore or your security policy (e.g. FIPS 140-2) forbids it. \""},{"line_number":3651,"context_line":"            \"Connections will only work with peers running OpenVPN 2.6.0 or \""},{"line_number":3652,"context_line":"            \"higher)\");"}],"source_content_type":"text/x-csrc","patch_set":5,"id":"d0301600_10b5cb6d","line":3649,"in_reply_to":"850dc22b_4f3310f4","updated":"2024-01-01 19:04:40.000000000","message":"Done","commit_id":"5c56d0f006a1c7d0983d9d16715b61dd4a9c6379"},{"author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"cc8462bf7674fdbc4f4f44c87e9a828d28a3652e","unresolved":true,"context_lines":[{"line_number":3658,"context_line":"        {"},{"line_number":3659,"context_line":"            msg(M_WARN, \"Automatically enabling option \""},{"line_number":3660,"context_line":"                \"--force-tls-key-material-export\");"},{"line_number":3661,"context_line":"        }"},{"line_number":3662,"context_line":""},{"line_number":3663,"context_line":"    }"},{"line_number":3664,"context_line":"}"}],"source_content_type":"text/x-csrc","patch_set":5,"id":"34f227b9_5a68d2c6","line":3661,"updated":"2023-12-12 07:33:13.000000000","message":"I might need new glasses, but as far as I can see, this code does all the checks, and *claims* to enable the option - but the only place I can see where the option is actually turned on is \"if it\u0027s passed on the command line\"...?","commit_id":"5c56d0f006a1c7d0983d9d16715b61dd4a9c6379"},{"author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"167831cfc494d5878420985fef0a80106f8fcc49","unresolved":true,"context_lines":[{"line_number":3658,"context_line":"        {"},{"line_number":3659,"context_line":"            msg(M_WARN, \"Automatically enabling option \""},{"line_number":3660,"context_line":"                \"--force-tls-key-material-export\");"},{"line_number":3661,"context_line":"        }"},{"line_number":3662,"context_line":""},{"line_number":3663,"context_line":"    }"},{"line_number":3664,"context_line":"}"}],"source_content_type":"text/x-csrc","patch_set":5,"id":"c97bbfa5_d626d157","line":3661,"in_reply_to":"34f227b9_5a68d2c6","updated":"2023-12-12 10:41:31.000000000","message":"D\u0027oh. Sorry for missing that.","commit_id":"5c56d0f006a1c7d0983d9d16715b61dd4a9c6379"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"f766972565fff824ed7c2b8a5688b816384ecf99","unresolved":false,"context_lines":[{"line_number":3658,"context_line":"        {"},{"line_number":3659,"context_line":"            msg(M_WARN, \"Automatically enabling option \""},{"line_number":3660,"context_line":"                \"--force-tls-key-material-export\");"},{"line_number":3661,"context_line":"        }"},{"line_number":3662,"context_line":""},{"line_number":3663,"context_line":"    }"},{"line_number":3664,"context_line":"}"}],"source_content_type":"text/x-csrc","patch_set":5,"id":"4bde8b54_2a323d2b","line":3661,"in_reply_to":"c97bbfa5_d626d157","updated":"2023-12-12 12:11:27.000000000","message":"whoops sorry for that. My bash history also shows that I still had the option on the command line, so I totally missed that. 😞","commit_id":"5c56d0f006a1c7d0983d9d16715b61dd4a9c6379"},{"author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"acdd264cac397bf68cd33d14c335620bfb1f67c2","unresolved":true,"context_lines":[{"line_number":3647,"context_line":"        msg(D_TLS_ERRORS, \"Warning: TLS 1.0 PRF with MD5+SHA1 PRF is not \""},{"line_number":3648,"context_line":"            \"supported by the TLS library. Your system does not support this \""},{"line_number":3649,"context_line":"            \"calculation anymore or your security policy (e.g. FIPS 140-2)\""},{"line_number":3650,"context_line":"            \"forbids it. Connections will only work with peers running \""},{"line_number":3651,"context_line":"            \"OpenVPN 2.6.0 or higher)\");"},{"line_number":3652,"context_line":"#ifndef HAVE_EXPORT_KEYING_MATERIAL"},{"line_number":3653,"context_line":"        msg(M_FATAL, \"Keying Material Exporters (RFC 5705) not available either. \""}],"source_content_type":"text/x-csrc","patch_set":7,"id":"9107bf4d_53ba32a8","line":3650,"updated":"2023-12-30 16:45:07.000000000","message":"Here\u0027s the location with \"... FIPS 140-2)forbids it\", missing whitespace.","commit_id":"57116e5b6e40659680c98cfd7ed1cc0b9171f4e0"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"8bc4efc1b9793b1824760c7a138eb05cf02d8287","unresolved":false,"context_lines":[{"line_number":3647,"context_line":"        msg(D_TLS_ERRORS, \"Warning: TLS 1.0 PRF with MD5+SHA1 PRF is not \""},{"line_number":3648,"context_line":"            \"supported by the TLS library. Your system does not support this \""},{"line_number":3649,"context_line":"            \"calculation anymore or your security policy (e.g. FIPS 140-2)\""},{"line_number":3650,"context_line":"            \"forbids it. Connections will only work with peers running \""},{"line_number":3651,"context_line":"            \"OpenVPN 2.6.0 or higher)\");"},{"line_number":3652,"context_line":"#ifndef HAVE_EXPORT_KEYING_MATERIAL"},{"line_number":3653,"context_line":"        msg(M_FATAL, \"Keying Material Exporters (RFC 5705) not available either. \""}],"source_content_type":"text/x-csrc","patch_set":7,"id":"b61da8f3_c652d84a","line":3650,"in_reply_to":"9107bf4d_53ba32a8","updated":"2024-01-01 19:17:22.000000000","message":"Done","commit_id":"57116e5b6e40659680c98cfd7ed1cc0b9171f4e0"}]}
