Identity management for WireGuard
Identity management for WireGuard
Posted Oct 19, 2022 1:26 UTC (Wed) by wahern (subscriber, #37304)In reply to: Identity management for WireGuard by atnot
Parent article: Identity management for WireGuard
On balance WireGuard is clearly a better transport than IPSec, at least for tunneled VPNs. But IKE is much more mature and proven. IKE is complex, but unlike transport, key management has always been the most irreducibly complex part of the equation, especially without the ability to leverage WebPKI's centralized trust anchors.
Using OpenIKED, in just a few lines I can configure the server-side of a VPN which works trivially with the native IKE clients on Windows, macOS, Android, and iPhone. All these ad hoc WireGuard solutions will never get to that point, at least not without a formal standard.
Posted Oct 19, 2022 14:51 UTC (Wed)
by terom (guest, #55278)
[Link]
Some people just like to watch the world burn...
Identity management for WireGuard
