bk99.de entertain the web since 1997

WireGuard 1.0 reaches Linux 5.6

Summary

Jason A. Donenfeld announces WireGuard 1.0 and the inclusion of the lean VPN protocol in the mainline Linux kernel. Version 1.0 was announced on 29 March 2020. The protocol uses modern, fixed cryptography.

Ideas

  • WireGuard identifies peers by their public keys.
  • AllowedIPs combine routing decision and access rule.
  • UDP transports encrypted packets without connection-oriented handshake state.
  • A small protocol surface makes auditing and configuration easier.

Insights

  • Cryptographic simplicity can improve usability and auditability at the same time.
  • Key-based identity does not replace planning of networks and permissions.
  • Inclusion in mainline simplifies maintenance across distributions.

Facts

  • WireGuard appeared in the mainline kernel with Linux 5.6.

Recommendations

  • Use separate keys per device and revoke lost peers immediately.
  • Restrict AllowedIPs to the networks actually needed.

References

Read the original article

Search the Web Archive