[eduVPN-deploy] [2020-09-09] Package Updates

François Kooman fkooman at tuxed.net
Wed Sep 9 10:31:04 CEST 2020


Hi all,

* vpn-user-portal: 2.3.4 [1]
* vpn-server-node: 2.2.4 [2]
* vpn-server-api: 2.2.7 [3]
* vpn-ca: 3.1.0 [4]

This time, a lot of relatively small changes under the hood in the JWT 
and session library, next to the changes linked to above and a couple of 
small fixes and tweaks to the (default) theme.

We added support for client certificate authentication for the portal, 
which potentially removes the need to integrate with IdMs depending on 
your organization [5].

The CA used for generating OpenVPN client certificates now supports 
ECDSA (on CentOS, Debian, Fedora) and EdDSA (On Debian 10, Fedora). This 
can be beneficial if you run a VPN server with many users where 
generating RSA keys just takes too long. Currently, we have are still 
having issues with the Windows eduVPN/Let's Connect! app in combination 
with ECDSA, so we do not recommend switching at the moment, but the 
server is ready for it. After testing and making sure all clients works 
properly we'll officially support other key types than RSA and also 
provide documentation. Currently all we have is [6].

Let me know if you have any questions!

Regards,
François

[1] 
https://github.com/eduvpn/vpn-user-portal/blob/v2/CHANGES.md#234-2020-09-08
[2] 
https://github.com/eduvpn/vpn-server-node/blob/v2/CHANGES.md#224-2020-09-08
[3] 
https://github.com/eduvpn/vpn-server-api/blob/v2/CHANGES.md#227-2020-09-08
[4] 
https://github.com/letsconnectvpn/vpn-ca/blob/main/CHANGES.md#310-2020-09-08
[5] https://github.com/eduvpn/documentation/blob/v2/CLIENT_CERT_AUTH.md
[6] https://github.com/eduvpn/vpn-server-api/blob/v2/CONFIG_CHANGES.md#227



More information about the eduVPN-deploy mailing list