WireGuard 1.0 reaches Linux 5.6
Summary
Jason A. Donenfeld announces WireGuard 1.0 and the inclusion of the lean VPN protocol in the mainline Linux kernel. Version 1.0 was announced on 29 March 2020. The protocol uses modern, fixed cryptography.
Ideas
- WireGuard identifies peers by their public keys.
- AllowedIPs combine routing decision and access rule.
- UDP transports encrypted packets without connection-oriented handshake state.
- A small protocol surface makes auditing and configuration easier.
Insights
- Cryptographic simplicity can improve usability and auditability at the same time.
- Key-based identity does not replace planning of networks and permissions.
- Inclusion in mainline simplifies maintenance across distributions.
Facts
- WireGuard appeared in the mainline kernel with Linux 5.6.
Recommendations
- Use separate keys per device and revoke lost peers immediately.
- Restrict AllowedIPs to the networks actually needed.
References
Links to the original source and the Web Archive open in a new tab.