{"id":53760,"date":"2019-12-09T00:00:00","date_gmt":"2019-12-08T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6"},"modified":"2020-02-18T14:01:41","modified_gmt":"2020-02-18T11:01:41","slug":"vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6","title":{"rendered":"VPN WireGuard has been accepted into the net-next branch and is set to be included in the Linux kernel 5.6","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>David Miller (<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/David_S._Miller\">David S. Miller<\/a><\/noindex>), responsible for the Linux kernel's network subsystem, <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2019-December\/004704.html\">accepted<\/a><\/noindex> into the net-next branch <noindex><a rel=\"nofollow\" href=\"https:\/\/lkml.org\/lkml\/2019\/12\/8\/240\">patches<\/a><\/noindex> implementing a VPN interface from the project <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.io\/\">WireGuard<\/a><\/noindex>. Early next year, the changes accumulated in the net-next branch will form the basis for the Linux kernel 5.6 release. <\/p>\n<p>Efforts to promote the WireGuard code into the mainline kernel have been made over the last few years, but these have remained unsuccessful due to reliance on custom implementations of cryptographic functions used to enhance performance. Initially, these functions were <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49064\">are offered<\/a><\/noindex> introduced to the kernel as an additional low-level API Zinc, which could eventually replace the standard Crypto API. <\/p>\n<p>After discussions at the Kernel Recipes conference, the creators of WireGuard in September <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2019-September\/004560.html\">reached a compromise decision<\/a><\/noindex> to transition their patches to use the existing Crypto API in the kernel, which the WireGuard developers have concerns about regarding performance and overall security. The Zinc API is planned to continue being developed as a separate project.<\/p>\n<p>In November, the kernel developers <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2019-November\/004614.html\">reached<\/a><\/noindex> a reciprocal compromise and agreed to incorporate part of the Zinc code into the main kernel. Essentially, some components of Zinc will be transferred to the kernel, but not as a separate API, rather as part of the Crypto API subsystem. For instance, in the Crypto API, <noindex><a rel=\"nofollow\" href=\"https:\/\/lore.kernel.org\/linux-crypto\/CAHmME9rxGp439vNYECm85bgibkVyrN7Qc+5v3r8QBmBXPZM=Dg@mail.gmail.com\/\">includes<\/a><\/noindex> the fast implementations of the ChaCha20 and Poly1305 algorithms prepared in WireGuard are already available.<\/p>\n<p>In light of the upcoming inclusion of WireGuard in the main kernel, the project founder <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2019-December\/004711.html\">announced<\/a><\/noindex> on the restructuring of the repository. To simplify development, the monolithic repository 'WireGuard.git', which was designed for isolated existence, will be replaced by three separate repositories that are better suited for organizing work with the core code: <\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/zx2c4\/wireguard-linux.git\/\">wireguard-linux.git<\/a><\/noindex> \u2014 the complete core tree with changes from the Wireguard project, patches from which will be reviewed for inclusion in the core and regularly merged into the net\/net-next branches.\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/zx2c4\/wireguard-tools.git\/\">wireguard-tools.git<\/a><\/noindex> \u2014 a repository for user-space utilities and scripts, such as wg and wg-quick. This repository can be used to create packages for distributions.\n<li class=\"l\">  <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/zx2c4\/wireguard-linux-compat.git\/\">wireguard-linux-compat.git<\/a><\/noindex> \u2014 a repository with a module variant provided separately from the core, including the compat.h layer to ensure compatibility with older kernels. The main development will be carried out in the wireguard-linux.git repository, but while there is a need from users, a separate variant of the patches will also be supported.\n<\/ul>\n<p>Let us remind you that the WireGuard VPN is built on modern encryption methods, providing very high performance, simplicity of use, and a lack of complexity, and has proven itself in several large deployments handling significant traffic volumes. The project has been evolving since 2015, has passed an audit and <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.com\/formal-verification\/\">formal verification<\/a><\/noindex> of the employed encryption methods. Support for WireGuard has already been integrated into NetworkManager and systemd, and kernel patches are included in the base of the distributions <noindex><a rel=\"nofollow\" href=\"https:\/\/wiki.debian.org\/Wireguard\">Debian Unstable<\/a><\/noindex>, Mageia, Alpine, Arch, Gentoo, OpenWrt, NixOS, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47266\">Subgraph<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/packages.altlinux.org\/ru\/search?query=kernel-modules-wireguard\">ALT<\/a><\/noindex>.<\/p>\n<p>WireGuard uses the concept of key-based routing, which implies binding a private key to each network interface and using it to link public keys. The exchange of public keys for establishing a connection is done similarly to SSH. Key agreement and connection establishment without launching a separate daemon in user space is achieved using the Noise_IK mechanism from <noindex><a rel=\"nofollow\" href=\"http:\/\/noiseprotocol.org\/\">Noise Protocol Framework<\/a><\/noindex>, similar to maintaining authorized_keys in SSH. Data transmission is carried out through encapsulation in UDP packets. The switching of the VPN server's IP address (roaming) is supported without breaking the connection and with automatic client reconfiguration.<\/p>\n<p>For encryption <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.io\/protocol\/\">a layer<\/a><\/noindex>  the stream cipher <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/chacha.html\">ChaCha20<\/a><\/noindex> and the message authentication algorithm (MAC) <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/mac.html\">Poly1305.<\/a><\/noindex>, developed by Daniel Bernstein (<noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/djb.html\">Daniel J. Bernstein<\/a><\/noindex>), Tanja Lange<br \/>\n(Tanja Lange) and Peter Schwabe (Peter Schwabe). ChaCha20 and Poly1305 are presented as faster and safer alternatives to AES-256-CTR and HMAC, with software implementation allowing fixed execution time without requiring specialized hardware support. For generating a shared secret key, the elliptic curve Diffie-Hellman protocol is used, implemented in <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/ecdh.html\">Curve25519<\/a><\/noindex>, also proposed by Daniel Bernstein. The hashing algorithm used is <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=35676\">BLAKE2s (RFC7693)<\/a><\/noindex>. <\/p>\n<p>Upon <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.com\/performance\/\">testing<\/a><\/noindex> the performance of WireGuard demonstrated 3.9 times higher throughput and 3.8 times higher responsiveness compared to OpenVPN (256-bit AES with HMAC-SHA2-256). Compared to IPsec (256-bit ChaCha20+Poly1305 and AES-256-GCM-128), WireGuard shows a slight performance advantage (13-18%) and lower latencies (21-23%). Tests were carried out using fast implementations of encryption algorithms developed by the project\u2014migration to the standard kernel Crypto API may lead to reduced performance.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.io\/performance\/\"><img decoding=\"async\" alt=\"VPN WireGuard has been accepted into the net-next branch and is set to be included in the Linux kernel 5.6\" src=\"\/wp-content\/uploads\/2019\/12\/f459682e9003ba807a78995f678188a2.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51997\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u044d\u0432\u0438\u0434 \u041c\u0438\u043b\u043b\u0435\u0440 (David S. Miller), \u043e\u0442\u0432\u0435\u0447\u0430\u044e\u0449\u0438\u0439 \u0437\u0430 \u0441\u0435\u0442\u0435\u0432\u0443\u044e \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u044f\u0434\u0440\u0430 Linux, \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0432\u0435\u0442\u043a\u0438 net-next \u043f\u0430\u0442\u0447\u0438 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 VPN-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430 \u043e\u0442 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 WireGuard. \u0412 \u043d\u0430\u0447\u0430\u043b\u0435 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0433\u043e \u0433\u043e\u0434\u0430 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f, \u043d\u0430\u043a\u0430\u043f\u043b\u0438\u0432\u0430\u0435\u043c\u044b\u0435 \u0432 \u0432\u0435\u0442\u043a\u0435 net-next, \u043b\u044f\u0433\u0443\u0442 \u0432 \u043e\u0441\u043d\u043e\u0432\u0443 \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u044f\u0434\u0440\u0430 Linux 5.6. \u041f\u043e\u043f\u044b\u0442\u043a\u0438 \u043f\u0440\u043e\u0434\u0432\u0438\u0436\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 WireGuard \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 \u043f\u0440\u0435\u0434\u043f\u0440\u0438\u043d\u0438\u043c\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043b\u0435\u0442, \u043d\u043e \u043e\u0441\u0442\u0430\u0432\u0430\u043b\u0438\u0441\u044c \u0431\u0435\u0437 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":53761,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-53760","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u044d\u0432\u0438\u0434 \u041c\u0438\u043b\u043b\u0435\u0440 (David S.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47VPN WireGuard \u043f\u0440\u0438\u043d\u044f\u0442 \u0432 \u0432\u0435\u0442\u043a\u0443 net-next \u0438 \u043d\u0430\u043c\u0435\u0447\u0435\u043d \u0434\u043b\u044f \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0432 \u044f\u0434\u0440\u043e Linux 5.6 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u044d\u0432\u0438\u0434 \u041c\u0438\u043b\u043b\u0435\u0440 (David S.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-08T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:01:41+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47VPN WireGuard has been accepted into the net-next branch and is slated for inclusion in the Linux kernel 5.6 | ProHoster","description":"David Miller (David S.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47VPN WireGuard \u043f\u0440\u0438\u043d\u044f\u0442 \u0432 \u0432\u0435\u0442\u043a\u0443 net-next \u0438 \u043d\u0430\u043c\u0435\u0447\u0435\u043d \u0434\u043b\u044f \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0432 \u044f\u0434\u0440\u043e Linux 5.6 | ProHoster","og:description":"\u0414\u044d\u0432\u0438\u0434 \u041c\u0438\u043b\u043b\u0435\u0440 (David S.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-08T21:00:00+00:00","article:modified_time":"2020-02-18T11:01:41+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53760","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 08:40:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:01:26","updated":"2026-01-24 08:40:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/53760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=53760"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/53760\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/53761"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=53760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=53760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=53760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}