notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photos
All times are UTC
Ukraine
The recently imposed "must be logged in" restriction is a response to increased bot traffic on the site. This affects search, commits, and vuxml pages.
Search engines are not blocked. Try using "site:www.freshports.org" and your search terms.
After the ports freeze to fix some stuff, the freeze is over. I have some work to do before FreshPorts can start processing commits again before it can start processing again. I've created an issue for that.
Port details on branch 2026Q2
openvpn Secure IP/Ethernet tunnel daemon
2.7.5 security on this many watch lists=0 search for ports that depend on this port An older version of this port was marked as vulnerable. Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 2.7.5_1Version of this port present on the latest quarterly branch.
Maintainer: mandree@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2026-05-02 12:43:23
Last Update: 2026-07-01 20:17:34
Commit Hash: ca7f541
Also Listed In: net net-vpn
License: GPLv2
WWW:
https://openvpn.net/community/
Description:
OpenVPN is a robust, scalable and highly configurable VPN (Virtual Private Network) daemon which can be used to securely link two or more private networks using an encrypted tunnel over the internet. It can operate over UDP or TCP, can use SSL or a pre-shared secret to authenticate peers, and in SSL mode, one server can handle many clients.
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb - no subversion history for this port

Manual pages:
pkg-plist: as obtained via: make generate-plist
Expand this list (15 items)
Collapse this list.
  1. /usr/local/share/licenses/openvpn-2.7.5/catalog.mk
  2. /usr/local/share/licenses/openvpn-2.7.5/LICENSE
  3. /usr/local/share/licenses/openvpn-2.7.5/GPLv2
  4. include/openvpn-msg.h
  5. include/openvpn-plugin.h
  6. lib/openvpn/plugins/openvpn-plugin-auth-pam.so
  7. lib/openvpn/plugins/openvpn-plugin-down-root.so
  8. libexec/openvpn/dns-updown
  9. share/man/man5/openvpn-examples.5.gz
  10. share/man/man8/openvpn.8.gz
  11. sbin/openvpn
  12. sbin/openvpn-client
  13. @owner
  14. @group
  15. @mode
Collapse this list.
USE_RC_SUBR (Service Scripts)
  • openvpn
Dependency lines:
  • openvpn>0:security/openvpn
Conflicts:
CONFLICTS_INSTALL:
  • openvpn-devel
To install the port:
cd /usr/ports/security/openvpn/ && make install clean
To add the package, run one of these commands:
  • pkg install security/openvpn
  • pkg install openvpn
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: openvpn
Flavors: there is no flavor information for this port.
distinfo:
TIMESTAMP = 1782925053 SHA256 (openvpn-2.7.5.tar.gz) = c6864b3c7d4e059c7d6ce22d1b5fa646c8b379a06af872eeb9792b6083a44ac4 SIZE (openvpn-2.7.5.tar.gz) = 2101063

Packages (timestamps in pop-ups are UTC):
openvpn
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest2.7.12.7.22.5.02.6.152.7.2n/an/an/a
FreeBSD:13:quarterly2.6.192.6.192.6.52.6.142.6.19n/an/an/a
FreeBSD:14:latest2.7.52.7.5_12.5.82.6.14_12.7.5_12.6.5-2.6.5
FreeBSD:14:quarterly2.7.52.7.5_1-2.6.142.7.5_12.6.8_12.6.8_12.6.9
FreeBSD:15:latest2.7.5_12.7.5_1n/a-n/an/a2.6.8_22.6.9
FreeBSD:15:quarterly2.7.52.7.5_1n/a-n/an/a--
FreeBSD:16:latest2.7.5_12.7.5_1n/a-n/an/a--
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Build dependencies:
  1. cmocka>=0 : sysutils/cmocka
  2. rst2man : textproc/py-docutils@py311
  3. pkgconf>=1.3.0_1 : devel/pkgconf
  4. python3.11 : lang/python311
Test dependencies:
  1. fping : net/fping
Runtime dependencies:
  1. easy-rsa>=0 : security/easy-rsa
Library dependencies:
  1. liblz4.so : archivers/liblz4
  2. liblzo2.so : archivers/lzo2
  3. libpkcs11-helper.so : security/pkcs11-helper
There are no ports dependent upon this port

Configuration Options:
===> The following configuration options are available for openvpn-2.7.5: ASYNC_PUSH=off: Enable async-push support DCO=on: Data Channel Offload/ovpn(4) support->README.dco.md DOCS=on: Build and/or install documentation EASYRSA=on: Install security/easy-rsa RSA helper package EXAMPLES=on: Build and/or install examples LZ4=on: LZ4 compression support LZO=on: LZO compression (incompatible with LibreSSL) PKCS11=on: Use security/pkcs11-helper, needs same SSL lib! SMALL=off: Build a smaller executable with fewer features TEST=on: Build and/or run tests UNITTESTS=off: Enable unit tests X509ALTUSERNAME=off: Enable --x509-username-field ===> Use 'make config' to modify these settings
Options name:
security_openvpn
USES:
cpe libtool localbase:ldflags pkgconfig python:build shebangfix ssl
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (2 items)
Collapse this list.
  1. https://build.openvpn.net/downloads/releases/
  2. https://swupdate.openvpn.org/community/releases/
Collapse this list.

Number of commits found: 5

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
2.7.5
01 Jul 2026 20:17:34
commit hash: ca7f5416e529ce5967fdb2b19a0572d7ee52d520commit hash: ca7f5416e529ce5967fdb2b19a0572d7ee52d520commit hash: ca7f5416e529ce5967fdb2b19a0572d7ee52d520commit hash: ca7f5416e529ce5967fdb2b19a0572d7ee52d520 files touched by this commit
Vladimir Druzenko (vvd) search for other commits by this committer
Author: Matthias Andree
security/openvpn: Update 2.7.4 => 2.7.5 (fix 6 CVEs)

Changelog:
https://github.com/OpenVPN/openvpn/blob/v2.7.5/Changes.rst

The upstream's signing sub-key expired yesterday, new key provided via
https://swupdate.openvpn.net/community/keys/gpgkey-F554A3687412CFFEBDEFE0A312F5F7B42F2B01E7.gpg

PR:		296429
Security:	ffa897a0-756f-11f1-b291-a74de6bb0320
Security:	CVE-2026-11771
Security:	CVE-2026-12932
Security:	CVE-2026-12996
Security:	CVE-2026-13117
Security:	CVE-2026-13122
Security:	CVE-2026-13698
Sponsored by:	UNIS Labs
MFH:		2026Q2

(cherry picked from commit 7bcce8a1bb5c23d738b378619625289403dffe37)
2.7.4
01 Jul 2026 20:17:30
commit hash: 15f6f743434d37eb358d36b64341c5fce9449734commit hash: 15f6f743434d37eb358d36b64341c5fce9449734commit hash: 15f6f743434d37eb358d36b64341c5fce9449734commit hash: 15f6f743434d37eb358d36b64341c5fce9449734 files touched by this commit This port version is marked as vulnerable.
Vladimir Druzenko (vvd) search for other commits by this committer
Author: Matthias Andree
security/openvpn: Update to bugfix release 2.7.4

Remove --enable-strict option, now unsupported upstream

Changelog: https://github.com/OpenVPN/openvpn/blob/v2.7.4/Changes.rst

Obtained from:	GitHub repo

(cherry picked from commit 68035ac676e92b0eeb2965baaae02b6f6d676c11)
2.7.2
01 Jul 2026 20:17:24
commit hash: a3cfb87a5c46b7a98223a1f089e92739360a5434commit hash: a3cfb87a5c46b7a98223a1f089e92739360a5434commit hash: a3cfb87a5c46b7a98223a1f089e92739360a5434commit hash: a3cfb87a5c46b7a98223a1f089e92739360a5434 files touched by this commit This port version is marked as vulnerable.
Vladimir Druzenko (vvd) search for other commits by this committer
Author: Matthias Andree
security/openvpn: security update to 2.7.2

(also includes OpenSSL 4.0 support, improved error messages and others)

Changelog:	https://github.com/OpenVPN/openvpn/blob/v2.7.2/Changes.rst
Security:       549313db-3e93-11f1-8d38-7fbbe0285610
Security:       CVE-2026-35058
Security:       CVE-2026-40215
MFH:		2026Q2
PR:		294714
(cherry picked from commit 1c4a6954619f73bf001ec6799699282ecf61de0c)
2.7.1
01 Jul 2026 20:16:46
commit hash: 1af78340d07c0fb3936ecb44e424faf9181dfc74commit hash: 1af78340d07c0fb3936ecb44e424faf9181dfc74commit hash: 1af78340d07c0fb3936ecb44e424faf9181dfc74commit hash: 1af78340d07c0fb3936ecb44e424faf9181dfc74 files touched by this commit This port version is marked as vulnerable.
Vladimir Druzenko (vvd) search for other commits by this committer
Author: Matthias Andree
security/openvpn: Update to 2.7.1

This changes installed scripts, openvpn-client.up and .down scripts
are no longer installed into libexec/, but instead a dns-updown script
is placed into libexec/openvpn/ (all under $PREFIX).

Based on a patch provided by Marek Zarychta.

Changelog:	https://github.com/OpenVPN/openvpn/releases/tag/v2.7.1

PR:		293138, 286263
(cherry picked from commit 51f1036a07509a1e3eb50cf6e7904a88f55bb451)
2.6.20
02 May 2026 12:36:19
commit hash: 8625e76159d85c5544c296a1951e79e2e99158a1commit hash: 8625e76159d85c5544c296a1951e79e2e99158a1commit hash: 8625e76159d85c5544c296a1951e79e2e99158a1commit hash: 8625e76159d85c5544c296a1951e79e2e99158a1 files touched by this commit This port version is marked as vulnerable.
Gleb Popov (arrowd) search for other commits by this committer
Author: Matthias Andree
security/openvpn: security update to 2.6.20

Changelog:	https://github.com/OpenVPN/openvpn/releases/tag/v2.6.20
Security:       549313db-3e93-11f1-8d38-7fbbe0285610
Security:       CVE-2026-35058
Security:       CVE-2026-40215
PR:             294714
Pull Request:	https://github.com/freebsd/freebsd-ports/pull/511

(direct commit to quarterly, branches have diverged)

Number of commits found: 5