5 ms·
Wireguard needs to put actual logging into the product before anyone should consider using it in production. I have to deal with it via a vendors product and h
by GABeech 7y ago
Wireguard needs to put actual logging into the product before anyone should consider using it in production.
I have to deal with it via a vendors product and have spend about 4 weeks in the past 6 months trying to fix a flaky connection by guessing and restarting a lot. Just like anything things will go wrong. But, with wireguard you have no idea what it could even be if it's not an obvious thing that you can diagnose with ping.
- big_chungus 7y agoWireguard also needs a better auth mechanism. I really like the simple secure key-based auth for small-scale stuff, but it's not viable for scaling at production levels. Things like user/pass auth (even if as an additional layer of security rather than displacing existing keys), 2FA, etc. will be important to get adoption at scale. I hope wireguard creates a module interface of sorts so people can extend the protocol as needed.
- pa7ch 7y agoWireguard doesn't need to change at the protocol level to add those features and I think thats the point. Userspace programs can be written to fetch keys from a server based on SSO or w/e.
- XMPPwocky 7y agoNo, I don't think it does. The thing about simple, key-based authentication is that it's very extensible, without changing the actual protocol. What? Well, what Wireguard's auth actually means is that you can use whatever authentication you want to communicate a shared secret to both ends. Want to authenticate with, say, SSH keys? Sure- SSH into a server, run a command that generates a new Wireguard key, connect in with that key. LDAP? Same situation. Whatever SSO you want- as long as you can stick up authentication in front of a service that's able to pull bits from /dev/urandom. Multifactor? Sure. Wireguard does one thing well. What's missing is not features in Wireguard- it's the ecosystem around it to actually handle key management. For enterprises, Hashicorp Vault or something should probably look into supporting Wireguard; for smaller situations, some SSH-based key exchange, like the way Mosh handles things, seems reasonable. Complex, pluggable authentication is sometimes necessary...but you want as few implementations of it as possible, and you sure don't want it in the kernel if you can help it.
- yardstick 7y agoThe problem is lots of organisations in the financial and medical worlds need 2FA. WireGuard needs a 2FA solution - It doesn’t have to be kernel based - but it does need to protect against someone grabbing a copy of the single factor auth in WireGuard (keypair). A solution that rotates/manages/provisions/etc these keypairs is still fundamentally single factor auth of the tunnel.
- tptacek 7y agoNobody is arguing that there shouldn't be IdP-based WireGuard management systems. The point is that they are out of scope for the WireGuard project itself. WireGuard has an extremely straightforward configuration interface; if Okta wanted to manage WireGuard, they'd likely have no problem doing it.
- yardstick 7y agoIs there any decent open source 2FA / IdP management systems at the moment that work with WireGuard?
- ficklepickle 7y agoIt has just landed in one distro. If there isn't yet, there certainly will be.
- yardstick 7y agoYou don’t need a distro for this, and WireGuard has been available and in use for several years. So in that time has anyone developed a practical 2FA solution that is compatible with it?
- tptacek 7y agoPeople have. I'm unaware of any published. It's not hard. Implementing a new IdP-integrated WireGuard authorizer is probably easier than understanding IPSEC or OpenVPN in sufficient detail to secure it.
- jrockway 7y agoI think you might like something like Tailscale: https://tailscale.com/ https://tailscale.com/
- big_chungus 7y agoIt looks quite good, but I don't see any information on: 1. Is it open-source? 2. When am I going to see the "you have to pay us now" screen, and how much will it cost? I realize it's a business and am fine with that, but want to know what I'm spending before setting stuff up.
- jrockway 7y agoI am not affiliated with Tailscale, I merely know that it exists. You should ask them the questions for an authoritative answer.
- zx2c4 7y ago> Wireguard needs to put actual logging into the product before anyone should consider using it in production. The kernel already has this: # modprobe wireguard && echo module wireguard +p > /sys/kernel/debug/dynamic_debug/control Then you'll get useful messages in your syslog.