bk99.de entertain the web since 1997

WireGuard merged into the main branch of the Linux kernel

Summary

In January 2020 Linus Torvalds merged the net-next branch, and with it the WireGuard VPN, into the main branch of the Linux kernel. This set WireGuard for Linux 5.6 in April, after Jason Donenfeld had proposed it for inclusion the previous summer. The network code comprises only around 7,000 lines, whereas OpenVPN and IPsec run to several hundred thousand.

Ideas

  • Small code is much easier to review than large VPN stacks.
  • WireGuard deliberately does without choices in cryptography.
  • The path into the kernel took several years and many discussions.
  • WireGuard appears as a normal network interface wg0 that the usual tools can manage.

Insights

  • Simplicity is a security feature because it makes review possible.
  • Inclusion in the kernel made WireGuard the standard option on all Linux systems.

Facts

  • WireGuard first appeared as stable with Linux 5.6.
  • The kernel developers adapted their own crypto API for WireGuard.

References

Critique

  • The report only compares lines of code and does not mention which features WireGuard deliberately leaves out compared with IPsec.

Recommendations

  • Use WireGuard for new site-to-site and remote access.
  • Manage WireGuard keys and peer configurations centrally, for example via configuration management.

Read the original article

Search the Web Archive