OpenVPN 2.7.7 Released with Seven Security Fixes
OpenVPN 2.7.7 is out with seven security fixes. If you run an OpenVPN server, patch it.
Why this cannot wait
A VPN daemon is in a uniquely bad position to have vulnerabilities. It is exposed to the internet by design, it processes packets from unauthenticated sources before any authentication completes, and it sits at the boundary between untrusted networks and the internal one.
A vulnerability in a web application compromises that application. A vulnerability in the VPN terminator compromises the network it terminates into.
# Debian and Ubuntu
sudo apt update && sudo apt install openvpn
# RHEL and derivatives
sudo dnf update openvpn
sudo systemctl restart openvpn-server@server
openvpn --version
Restarting drops client connections. Most clients reconnect automatically, and a brief reconnect is a reasonable price.
Patch clients too. Several classes of VPN vulnerability affect the client side, where a malicious or compromised server can attack connecting clients. If you connect to any VPN you do not personally operate, that matters to you.
While you are in there
A patch is a reasonable prompt to check the configuration, since OpenVPN deployments tend to be set up once and then left for years.
# what is listening
sudo ss -ulnp | grep openvpn
# recent connection activity
sudo journalctl -u openvpn-server@server --since "24 hours ago"
Things worth confirming: that you are on TLS 1.2 or better with modern ciphers, that tls-auth or tls-crypt is enabled (it makes the server invisible to scanners without the key, which removes a large amount of background noise), that certificates have not silently expired, and that revoked client certificates are actually in a CRL the server reads.
Our journalctl guide covers reading the logs properly.
OpenVPN against WireGuard
The comparison is unavoidable and the honest summary is that they are not competing for quite the same job.
WireGuard is roughly 4,000 lines against OpenVPN’s hundreds of thousands, runs in the kernel, is considerably faster, and has a vastly smaller attack surface. For a point-to-point tunnel or a small set of known peers, it is the better choice by a wide margin. Our WireGuard explainer and the config generator cover setting it up.
OpenVPN has features WireGuard deliberately does not: username and password authentication, PKI with certificate revocation, TCP transport for networks that block UDP, per-user access policies, and integration with LDAP and RADIUS. For a corporate VPN with hundreds of users who need individual revocable access, that matters.
If you are running OpenVPN for a handful of personal devices, WireGuard will be faster and simpler and give you less to patch. If you are running it because you need the authentication and policy features, stay where you are and keep it updated.
Details at openvpn.net.