OpenVPN 2.6.0 ื–ืžื™ืŸ

ืœืื—ืจ ืฉื ืชื™ื™ื ื•ื—ืฆื™ ืžืื– ืคืจืกื•ื ืกื ื™ืฃ 2.5, ื”ื•ื›ืŸ ืฉื—ืจื•ืจ OpenVPN 2.6.0, ื—ื‘ื™ืœื” ืœื™ืฆื™ืจืช ืจืฉืชื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืคืจื˜ื™ื•ืช ื”ืžืืคืฉืจืช ืœืืจื’ืŸ ื—ื™ื‘ื•ืจ ืžื•ืฆืคืŸ ื‘ื™ืŸ ืฉื ื™ ืžื›ื•ื ื•ืช ืœืงื•ื— ืื• ืœืกืคืง ืฉืจืช VPN ืžืจื›ื–ื™. ืœืคืขื•ืœื” ื‘ื• ื–ืžื ื™ืช ืฉืœ ืžืกืคืจ ืœืงื•ื—ื•ืช. ืงื•ื“ OpenVPN ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ GPLv2, ื—ื‘ื™ืœื•ืช ื‘ื™ื ืืจื™ื•ืช ืžื•ื›ื ื•ืช ื ื•ืฆืจื•ืช ืขื‘ื•ืจ Debian, Ubuntu, CentOS, RHEL ื•-Windows.

ื—ื™ื“ื•ืฉื™ื ืขื™ืงืจื™ื™ื:

  • ืžืกืคืง ืชืžื™ื›ื” ืœืžืกืคืจ ื‘ืœืชื™ ืžื•ื’ื‘ืœ ืฉืœ ื—ื™ื‘ื•ืจื™ื.
  • ืžื•ื“ื•ืœ ืœื™ื‘ืช ovpn-dco ื›ืœื•ืœ, ื”ืžืืคืฉืจ ืœืš ืœื”ืื™ืฅ ืžืฉืžืขื•ืชื™ืช ืืช ื‘ื™ืฆื•ืขื™ ื”-VPN. ื”ืืฆื” ืžื•ืฉื’ืช ืขืœ ื™ื“ื™ ื”ืขื‘ืจืช ื›ืœ ืคืขื•ืœื•ืช ื”ื”ืฆืคื ื”, ืขื™ื‘ื•ื“ ื”ืžื ื•ืช ื•ื ื™ื”ื•ืœ ืขืจื•ืฆื™ ื”ืชืงืฉื•ืจืช ืœืฆื“ ืœื™ื‘ืช ืœื™ื ื•ืงืก, ืžื” ืฉืžื‘ื˜ืœ ืืช ื”ืชืงื•ืจื” ื”ืงืฉื•ืจื” ืœืžืขื‘ืจ ื”ื”ืงืฉืจ, ืžืืคืฉืจ ืœื™ื™ืขืœ ืืช ื”ืขื‘ื•ื“ื” ืขืœ ื™ื“ื™ ื’ื™ืฉื” ื™ืฉื™ืจื” ืœืžืžืฉืงื™ ื”-API ื”ืคื ื™ืžื™ื™ื ืฉืœ ื”ืœื™ื‘ื” ื•ืžื‘ื˜ืœ ื”ืขื‘ืจืช ื ืชื•ื ื™ื ืื™ื˜ื™ืช ื‘ื™ืŸ ื”ืœื™ื‘ื” ื•ืžืจื—ื‘ ืžืฉืชืžืฉ (ื”ืฆืคื ื”, ืคืขื ื•ื— ื•ื ื™ืชื•ื‘ ืžืชื‘ืฆืขื™ื ืขืœ ื™ื“ื™ ื”ืžื•ื“ื•ืœ ืžื‘ืœื™ ืœืฉืœื•ื— ืชืขื‘ื•ืจื” ืœืžื˜ืคืœ ื‘ืžืจื—ื‘ ื”ืžืฉืชืžืฉ).

    ื‘ื‘ื“ื™ืงื•ืช ืฉื‘ื•ืฆืขื•, ื‘ื”ืฉื•ื•ืื” ืœืชืฆื•ืจื” ื”ืžื‘ื•ืกืกืช ืขืœ ืžืžืฉืง tun, ื”ืฉื™ืžื•ืฉ ื‘ืžื•ื“ื•ืœ ื‘ืฆื“ ื”ืœืงื•ื— ื•ื”ืฉืจืช ื‘ืืžืฆืขื•ืช ืฆื•ืคืŸ AES-256-GCM ืื™ืคืฉืจ ืœื”ื’ื™ืข ืœืขืœื™ื™ื” ืฉืœ ืคื™ 8 ื‘ืชืคื•ืงื” (ืž-370 Mbit/s ืขื“ 2950 Mbit/s). ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžื•ื“ื•ืœ ืจืง ื‘ืฆื“ ื”ืœืงื•ื—, ื”ืชืคื•ืงื” ื’ื“ืœื” ืคื™ ืฉืœื•ืฉื” ืขื‘ื•ืจ ืชืขื‘ื•ืจื” ื™ื•ืฆืืช ื•ืœื ื”ืฉืชื ืชื” ืขื‘ื•ืจ ืชืขื‘ื•ืจื” ื ื›ื ืกืช. ื‘ืฉื™ืžื•ืฉ ื‘ืžื•ื“ื•ืœ ืจืง ื‘ืฆื“ ื”ืฉืจืช, ื”ืชืคื•ืงื” ื’ื“ืœื” ืคื™ 4 ืขื‘ื•ืจ ืชืขื‘ื•ืจื” ื ื›ื ืกืช ื•ื‘-35% ืขื‘ื•ืจ ืชืขื‘ื•ืจื” ื™ื•ืฆืืช.

  • ืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ืžืฆื‘ TLS ืขื ืื™ืฉื•ืจื™ื ื‘ื—ืชื™ืžื” ืขืฆืžื™ืช (ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืืคืฉืจื•ืช "-peer-fingerprint", ื ื™ืชืŸ ืœื”ืฉืžื™ื˜ ืืช ื”ืคืจืžื˜ืจื™ื "-ca" ื•-"-capath" ื•ืœื”ื™ืžื ืข ืžื”ืคืขืœืช ืฉืจืช PKI ื”ืžื‘ื•ืกืก ืขืœ Easy-RSA ืื• ืชื•ื›ื ื” ื“ื•ืžื”).
  • ืฉืจืช UDP ืžื™ื™ืฉื ืžืฆื‘ ืžืฉื ื•ืžืชืŸ ืขืœ ื—ื™ื‘ื•ืจ ืžื‘ื•ืกืก Cookie, ื”ืžืฉืชืžืฉ ื‘ืขื•ื’ื™ื™ื” ืžื‘ื•ืกืกืช HMAC ื›ืžื–ื”ื” ื”ืคื’ื™ืฉื”, ืžื” ืฉืžืืคืฉืจ ืœืฉืจืช ืœื‘ืฆืข ืื™ืžื•ืช ื—ืกืจ ืžืฆื‘.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ื‘ื ื™ื™ื” ืขื ืกืคืจื™ื™ืช OpenSSL 3.0. ื ื•ืกืคื” ืืคืฉืจื•ืช "--tls-cert-profile insecure" ืœื‘ื—ื™ืจืช ืจืžืช ื”ืื‘ื˜ื—ื” ื”ืžื™ื ื™ืžืœื™ืช ืฉืœ OpenSSL.
  • ื ื•ืกืคื• ืคืงื•ื“ื•ืช ืฉืœื™ื˜ื” ื—ื“ืฉื•ืช ืžืจื—ื•ืง-entry-count ื•-remote-entry-get ื›ื“ื™ ืœืกืคื•ืจ ืืช ืžืกืคืจ ื”ื—ื™ื‘ื•ืจื™ื ื”ื—ื™ืฆื•ื ื™ื™ื ื•ืœื”ืฆื™ื’ ืจืฉื™ืžื” ืฉืœื”ื.
  • ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ืกื›ื ื”ืžืคืชื—, ืžื ื’ื ื•ืŸ ื”-EKM (Exported Keying Material, RFC 5705) ื”ื•ื ื›ืขืช ื”ืฉื™ื˜ื” ื”ืžื•ืขื“ืคืช ืœื”ืฉื’ืช ื—ื•ืžืจ ืœื™ื™ืฆื•ืจ ืžืคืชื—, ื‘ืžืงื•ื ืžื ื’ื ื•ืŸ PRF ื”ืกืคืฆื™ืคื™ ืœ-OpenVPN. ื›ื“ื™ ืœื”ืฉืชืžืฉ ื‘-EKM, ื™ืฉ ืฆื•ืจืš ื‘ืกืคืจื™ื™ืช OpenSSL ืื• mbed TLS 2.18+.
  • ืžืกื•ืคืงืช ืชืื™ืžื•ืช ืขื OpenSSL ื‘ืžืฆื‘ FIPS, ื”ืžืืคืฉืจืช ืฉื™ืžื•ืฉ ื‘-OpenVPN ื‘ืžืขืจื›ื•ืช ื”ืขื•ืžื“ื•ืช ื‘ื“ืจื™ืฉื•ืช ื”ืื‘ื˜ื—ื” ืฉืœ FIPS 140-2.
  • mlock ืžื™ื™ืฉืžืช ื‘ื“ื™ืงื” ื›ื“ื™ ืœื•ื•ื“ื ืฉืžืกืคื™ืง ื–ื™ื›ืจื•ืŸ ืฉืžื•ืจ. ื›ืืฉืจ ืคื—ื•ืช ืž-100 MB ืฉืœ ื–ื™ื›ืจื•ืŸ RAM ื–ืžื™ืŸ, setrlimit() ื ืงืจื ืœื”ื’ื“ื™ืœ ืืช ื”ืžื’ื‘ืœื”.
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "--peer-fingerprint" ืœื‘ื“ื™ืงืช ืชืงืคื•ืช ืื• ื›ืจื™ื›ื” ืฉืœ ืื™ืฉื•ืจ ื‘ืืžืฆืขื•ืช ื˜ื‘ื™ืขืช ืืฆื‘ืข ื”ืžื‘ื•ืกืกืช ืขืœ Hash SHA256, ืžื‘ืœื™ ืœื”ืฉืชืžืฉ ื‘-tls-verify.
  • ืกืงืจื™ืคื˜ื™ื ืžืกื•ืคืงื™ื ืขื ืืคืฉืจื•ืช ืฉืœ ืื™ืžื•ืช ื“ื—ื•ื™, ืžื™ื•ืฉื ื‘ืืžืฆืขื•ืช ืืคืฉืจื•ืช "-auth-user-pass-verify". ืชืžื™ื›ื” ืœื™ื™ื“ืข ืืช ื”ืœืงื•ื— ืœื’ื‘ื™ ืื™ืžื•ืช ืžืžืชื™ืŸ ื‘ืขืช โ€‹โ€‹ืฉื™ืžื•ืฉ ื‘ืื™ืžื•ืช ื“ื—ื•ื™ ื ื•ืกืคื” ืœืกืงืจื™ืคื˜ื™ื ื•ืชื•ืกืคื™ื.
  • ื ื•ืกืฃ ืžืฆื‘ ืชืื™ืžื•ืช (-compat-mode) ื›ื“ื™ ืœืืคืฉืจ ื—ื™ื‘ื•ืจื™ื ืœืฉืจืชื™ื ื™ืฉื ื™ื ื™ื•ืชืจ ืขื OpenVPN 2.3.x ืื• ื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ.
  • ื‘ืจืฉื™ืžื” ื”ืžื•ืขื‘ืจืช ื“ืจืš ื”ืคืจืžื˜ืจ "--data-ciphers", ื”ืงื™ื“ื•ืžืช "?" ืžื•ืชืจืช. ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืฆืคื ื™ื ืื•ืคืฆื™ื•ื ืœื™ื™ื ืฉื™ืฉืžืฉื• ืจืง ืื ื ืชืžื›ื™ื ื‘ืกืคืจื™ื™ืช SSL.
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "-session-timeout" ืฉื‘ืืžืฆืขื•ืชื” ื ื™ืชืŸ ืœื”ื’ื‘ื™ืœ ืืช ื–ืžืŸ ื”ื”ืคืขืœื” ื”ืžืงืกื™ืžืœื™.
  • ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ืžืืคืฉืจ ืœืฆื™ื™ืŸ ืฉื ื•ืกื™ืกืžื” ื‘ืืžืฆืขื•ืช ื”ืชื’ .
  • ื ื™ืชื ืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ื‘ืื•ืคืŸ ื“ื™ื ืžื™ ืืช ื”-MTU ืฉืœ ื”ืœืงื•ื—, ื‘ื”ืชื‘ืกืก ืขืœ ื ืชื•ื ื™ ื”-MTU ื”ืžื•ืขื‘ืจื™ื ืขืœ ื™ื“ื™ ื”ืฉืจืช. ื›ื“ื™ ืœืฉื ื•ืช ืืช ื’ื•ื“ืœ ื”-MTU ื”ืžืงืกื™ืžืœื™, ื ื•ืกืคื” ื”ืืคืฉืจื•ืช "-tun-mtu-max" (ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ื™ื 1600).
  • ื ื•ืกืฃ ืคืจืžื˜ืจ "--max-packet-size" ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื”ื’ื•ื“ืœ ื”ืžืจื‘ื™ ืฉืœ ืžื ื•ืช ื”ื‘ืงืจื”.
  • ื”ื•ืกืจื” ื”ืชืžื™ื›ื” ื‘ืžืฆื‘ ื”ืฉืงืช OpenVPN ื“ืจืš inetd. ื”ืืคืฉืจื•ืช ncp-disable ื”ื•ืกืจื”. ืืคืฉืจื•ืช ื”-Verify-hash ื•ืžืฆื‘ ืžืคืชื— ืกื˜ื˜ื™ ื”ื•ืฆืื• ืžืฉื™ืžื•ืฉ (ืจืง TLS ื ืฉืžืจ). ื”ืคืจื•ื˜ื•ืงื•ืœื™ื TLS 1.0 ื•-1.1 ื”ื•ืฆืื• ืžืฉื™ืžื•ืฉ (ืคืจืžื˜ืจ tls-version-min ืžื•ื’ื“ืจ ืœ-1.2 ื›ื‘ืจื™ืจืช ืžื—ื“ืœ). ื”ื™ื™ืฉื•ื ื”ืžื•ื‘ื ื” ืฉืœ ืžื—ื•ืœืœ ื”ืžืกืคืจื™ื ื”ืคืกืื•ื“ื•-ืืงืจืื™ื™ื (-prng) ื”ื•ืกืจ; ื™ืฉ ืœื”ืฉืชืžืฉ ื‘ื™ื™ืฉื•ื PRNG ืžืกืคืจื™ื•ืช ื”ื”ืฆืคื ื” mbed TLS ืื• OpenSSL. ื”ืชืžื™ื›ื” ื‘-PF (Packet Filtering) ื”ื•ืคืกืงื”. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”ื“ื—ื™ืกื” ืžื•ืฉื‘ืชืช (--allow-compression=no).
  • ื”ื•ืกื™ืฃ ืืช CHACHA20-POLY1305 ืœืจืฉื™ืžืช ื”ืฆืคื ื™ื ื”ืžื•ื’ื“ืจืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”