#1107240 network-manager-openvpn-gnome: GUI import/edit drops crucial "data-ciphers" option from config

Package:
network-manager-openvpn-gnome
Source:
network-manager-openvpn-gnome
Description:
network management framework (OpenVPN plugin GNOME GUI)
Submitter:
Florian Schlichting
Date:
2025-10-06 10:08:02 UTC
Severity:
normal
Tags:
#1107240#5
Date:
2025-06-03 15:44:53 UTC
From:
To:
Dear Maintainer,

I am a user of an OpenVPN service which uses the AES-256-CBC cipher,
meaning the --data-ciphers option needs to be used. Support for this
option in the network-manager-openvpn backend was added as part of the
fix for #1012664. However, the Gnome GUI (as opposed to nmcli) is still
unaware of this option, and will delete it from the configuration both
when creating a new connection via import of an ovpn file, as well as
when editing an existing working connection, for example one that has
been created from an ovpn file with nmcli.

There is an upstream bug about this:
https://gitlab.gnome.org/GNOME/NetworkManager-openvpn/-/issues/110
and it has a fairly simple patch / MR:
https://gitlab.gnome.org/GNOME/NetworkManager-openvpn/-/merge_requests/86

I can confirm that building network-manager-openvpn-gnome 1.12.0-2 with
this patch included fixes the issue: I can correctly import an opvn
config file containing data-ciphers, and I can edit an existing VPN
connection containing that option without it being deleted.

Looking at the lack of progress / upstream response on this issue (which
I think might have to do with their desire to support older openvpn
versions as well, needing more complex logic), I'm asking for this patch
to be included in the Debian package for the time being.

Thank you
Florian

#1107240#10
Date:
2025-10-06 10:07:07 UTC
From:
To:
Version: 1.12.2-1

This has been applied in
https://gitlab.gnome.org/GNOME/NetworkManager-openvpn/-/commit/ef27d6002bef58322051f594462e4655e2bd3ba5

The first debian version shipping that fix is 1.12.2-1, so closing for
that version.

Regards,
Michael