4 ms·
While not totally awesome, OpenVPN is miles beyond Wireguard when it comes to credential management. There are several auth plugins, you can use "the usual stuf
by throwaway294566 4y ago
While not totally awesome, OpenVPN is miles beyond Wireguard when it comes to credential management. There are several auth plugins, you can use "the usual stuff" like PAM, and through that LDAP/Kerberos, ActiveDirectory, RADIUS, etc.. For higher security demands, client certificates are also possible and standardized X.509, PKCS#11/15 like CaC, Yubikeys and usual employee ID cards work. Also, OpenVPN supports at least some form of IP assignment and DNS/Route management.
Wireguard has none of that, not even the notion of a user. There are just keys in a special (unsupported by anything else) format that are assigned an IP address statically in a file. Oh, and the frigging software writes into that config file if you change anything.
Wireguard is a nightmare for any attempt at sane system administration.
- cpach 4y ago“Wireguard is a nightmare for any attempt at sane system administration.” It’s quite simple really: WireGuard is a building block. TFA mentions several systems built on top of WireGuard, that enables sophisticated handling of users/roles, authentication, ACLs, etc.
- throwaway294566 4y agoThe problem with the building block approach is that it usually compromises any supposed security advantages Wireguard may have. You get a supersecure bank safe where the key is handed to you in the baker's shop opposite if you ask nicely.
- cpach 4y agoI don’t believe that’s the case. However, the system on top of WireGuard cannot just spit out a key to the user and call it a day. The key (sorry…) is to make the system a) verify the identity of the users via an IdP (e.g. Okta or something similar) and then b) distribute short-lived keys, that can be revoked. If one reads how Tailscale handles user authentication and key rotation, one will notice that they have a solid system in place for handling the keys and the product is much more sophisticated than OpenVPN. I haven’t studied the approach of their competitors (e.g. Firezone) so I can’t comment on that. References/suggested reading: https://tailscale.com/kb/1028/key-expiry/ https://tailscale.com/kb/1028/key-expiry/ ⦁ https://tailscale.com/blog/tailscale-key-management/ https://tailscale.com/blog/tailscale-key-management/ ⦁ https://tailscale.com/customers/gini/ https://tailscale.com/customers/gini/ ⦁ https://tailscale.com/kb/1009/protect-ssh-servers/ https://tailscale.com/kb/1009/protect-ssh-servers/