|
|
Subscribe / Log in / New account

Identity management for WireGuard

Identity management for WireGuard

Posted Oct 19, 2022 1:26 UTC (Wed) by wahern (subscriber, #37304)
In reply to: Identity management for WireGuard by atnot
Parent article: Identity management for WireGuard

At some point someone will realize everybody is just reinventing the wheel, and add WireGuard support to IKE. Then all will be right with the world.
On balance WireGuard is clearly a better transport than IPSec, at least for tunneled VPNs. But IKE is much more mature and proven. IKE is complex, but unlike transport, key management has always been the most irreducibly complex part of the equation, especially without the ability to leverage WebPKI's centralized trust anchors.

Using OpenIKED, in just a few lines I can configure the server-side of a VPN which works trivially with the native IKE clients on Windows, macOS, Android, and iPhone. All these ad hoc WireGuard solutions will never get to that point, at least not without a formal standard.


to post comments

Identity management for WireGuard

Posted Oct 19, 2022 14:51 UTC (Wed) by terom (guest, #55278) [Link]

> At some point someone will realize everybody is just reinventing the wheel, and add WireGuard support to IKE. Then all will be right with the world.

Some people just like to watch the world burn...


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds