WireGuard merged into the main branch of the Linux kernel
Summary
In January 2020 Linus Torvalds merged the net-next branch, and with it the WireGuard VPN, into the main branch of the Linux kernel. This set WireGuard for Linux 5.6 in April, after Jason Donenfeld had proposed it for inclusion the previous summer. The network code comprises only around 7,000 lines, whereas OpenVPN and IPsec run to several hundred thousand.
Ideas
- Small code is much easier to review than large VPN stacks.
- WireGuard deliberately does without choices in cryptography.
- The path into the kernel took several years and many discussions.
- WireGuard appears as a normal network interface wg0 that the usual tools can manage.
Insights
- Simplicity is a security feature because it makes review possible.
- Inclusion in the kernel made WireGuard the standard option on all Linux systems.
Facts
- WireGuard first appeared as stable with Linux 5.6.
- The kernel developers adapted their own crypto API for WireGuard.
References
Critique
- The report only compares lines of code and does not mention which features WireGuard deliberately leaves out compared with IPsec.
Recommendations
- Use WireGuard for new site-to-site and remote access.
- Manage WireGuard keys and peer configurations centrally, for example via configuration management.
Links to the original source and the Web Archive open in a new tab.