{"id":56025,"date":"2020-02-03T00:00:00","date_gmt":"2020-02-02T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/v-yadro-linux-5-6-vklyuchili-vpn-wireguard"},"modified":"2020-02-18T14:04:11","modified_gmt":"2020-02-18T11:04:11","slug":"v-yadro-linux-5-6-vklyuchili-vpn-wireguard","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/v-yadro-linux-5-6-vklyuchili-vpn-wireguard","title":{"rendered":"VPN WireGuard included in the Linux kernel 5.6","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Today, Linus has merged the net-next branch with VPN interfaces. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.com\/\">WireGuard<\/a><\/noindex>This event is reported <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2020-January\/004906.html\">informed<\/a><\/noindex> in the WireGuard mailing list.<\/p>\n<p><img decoding=\"async\" alt=\"VPN WireGuard included in the Linux kernel 5.6\" src=\"\/wp-content\/uploads\/2020\/02\/d7a3107d3ba60f906fe446dceb3bdca6.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nCurrently, the code for the new Linux kernel 5.6 is being collected. WireGuard is a fast next-generation VPN that implements modern cryptography. It was initially developed as a simpler and more user-friendly alternative to existing VPNs. Its author is Canadian information security specialist Jason Donenfeld. In August 2018, WireGuard <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.openwall.net\/netdev\/2018\/08\/02\/124\">gained praise<\/a><\/noindex> from Linus Torvalds. Around the same time, work began to include the VPN in the Linux kernel. The process took a bit longer than expected.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\n\"I see that Jason has made a pull request to include WireGuard in the kernel,\" Linus wrote on August 2, 2018. \"Can I just once again state my love for this VPN and hope for a quick merge? The code may not be perfect, but I\u2019ve looked it over, and compared to the horrors of OpenVPN and IPSec, it's a true work of art.\"<\/p>\n<p>Despite Linus\u2019s wishes, the merge was delayed for a year and a half. The main issue was the reliance on proprietary implementations of cryptographic functions that were used for performance improvements. After lengthy negotiations, in September 2019, a <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2019-September\/004560.html\">compromise was reached<\/a><\/noindex> to port the patches to the existing kernel\u2019s Crypto API functions, to which WireGuard developers had performance and overall security concerns. However, it was decided to set apart the native crypto functions of WireGuard in a separate low-level Zinc API and gradually port them to the kernel. In November, kernel developers kept their promise and <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2019-November\/004614.html\">agreed<\/a><\/noindex> to transfer part of the code from Zinc into the main kernel. For instance, in Crypto API, <noindex><a rel=\"nofollow\" href=\"https:\/\/lore.kernel.org\/linux-crypto\/CAHmME9rxGp439vNYECm85bgibkVyrN7Qc+5v3r8QBmBXPZM=Dg@mail.gmail.com\/\">includes<\/a><\/noindex> the fast implementations of ChaCha20 and Poly1305 algorithms prepared in WireGuard.<\/p>\n<p>Eventually, on December 9, 2019, David Miller, responsible for the networking subsystem of the Linux kernel, <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2019-December\/004704.html\">accepted<\/a><\/noindex> into the net-next branch <noindex><a rel=\"nofollow\" href=\"https:\/\/lkml.org\/lkml\/2019\/12\/8\/240\">patches<\/a><\/noindex> merged the VPN interface from the WireGuard project.<\/p>\n<p>And today, on January 29, 2020, the changes were sent to Linus for inclusion in the kernel.<\/p>\n<p><img decoding=\"async\" alt=\"VPN WireGuard included in the Linux kernel 5.6\" src=\"\/wp-content\/uploads\/2020\/02\/49ea5f8ed5e0d36d3ccaa974e1514086.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe stated advantages of WireGuard over other VPN solutions are:<\/p>\n<ul>\n<li>Easy to use.\n<\/li>\n<li>Uses modern cryptography: Noise protocol framework, Curve25519, ChaCha20, Poly1305, BLAKE2, SipHash24, HKDF, etc.\n<\/li>\n<li>Compact, readable code, easier to audit for vulnerabilities.\n<\/li>\n<li>High performance.\n<\/li>\n<li>Clear and well-designed <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.com\/papers\/wireguard.pdf\">specification<\/a><\/noindex>.<\/li>\n<\/ul>\n<p>\nThe entire core logic of WireGuard comprises less than 4000 lines of code, while OpenVPN and IPSec consist of hundreds of thousands of lines. <\/p>\n<blockquote><p>WireGuard employs a concept of routing based on encryption keys, which involves binding a private key to each network interface and using it to link public keys. The exchange of public keys to establish a connection is similar to SSH. The Noise_IK mechanism is used for key agreement and connection without launching a separate user-space daemon. <noindex><a rel=\"nofollow\" href=\"http:\/\/noiseprotocol.org\/\">Noise Protocol Framework<\/a><\/noindex>, similar to maintaining authorized_keys in SSH. Data transmission is accomplished through encapsulation in UDP packets. It supports changing the IP address of the VPN server (roaming) without disconnecting, with automatic client reconfiguration. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51997\">writes<\/a><\/noindex> Opennet.<\/p>\n<p>For encryption <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.io\/protocol\/\">a layer<\/a><\/noindex> the stream cipher <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/chacha.html\">ChaCha20<\/a><\/noindex> and the message authentication algorithm (MAC) <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/mac.html\">Poly1305.<\/a><\/noindex>, developed by Daniel Bernstein (<noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/djb.html\">Daniel J. Bernstein<\/a><\/noindex>), Tanja Lange and Peter Schwabe. ChaCha20 and Poly1305 are positioned as faster and safer alternatives to AES-256-CTR and HMAC, the software implementation of which achieves consistent execution time without requiring special hardware support. The Diffie-Hellman protocol on elliptic curves is used to generate a shared secret key in implementation <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/ecdh.html\">Curve25519<\/a><\/noindex>, also proposed by Daniel Bernstein. The hashing algorithm used is <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=35676\">BLAKE2s (RFC7693)<\/a><\/noindex>\u00bb.<\/p><\/blockquote>\n<p>\nResults <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.com\/performance\/\">performance tests<\/a><\/noindex> from the official website:<\/p>\n<p><b>Throughput (megabits\/s)<\/b> <br \/>\n<img decoding=\"async\" alt=\"VPN WireGuard included in the Linux kernel 5.6\" src=\"\/wp-content\/uploads\/2020\/02\/62e73700bf3536fbc2d99ba92df4a67a.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>Ping (ms)<\/b> <br \/>\n<img decoding=\"async\" alt=\"VPN WireGuard included in the Linux kernel 5.6\" src=\"\/wp-content\/uploads\/2020\/02\/597df63e420cd6f44cd5678dbad81160.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h4>Test configuration:<\/h4>\n<p><\/p>\n<ul>\n<li>Intel Core i7-3820QM and Intel Core i7-5200U<\/li>\n<li>Gigabit Intel 82579LM and Intel I218LM cards<\/li>\n<li>Linux 4.6.1<\/li>\n<li>WireGuard configuration: 256-bit ChaCha20 with Poly1305 for MAC<\/li>\n<li>First IPsec configuration: 256-bit ChaCha20 with Poly1305 for MAC<\/li>\n<li>Second IPsec configuration: AES-256-GCM-128 (with AES-NI)<\/li>\n<li>OpenVPN configuration: equivalent cipher suite of 256-bit AES with HMAC-SHA2-256, UDP mode<\/li>\n<li>Performance was measured using <code>iperf3<\/code>, showing the average result over 30 minutes.<\/li>\n<\/ul>\n<p>\nTheoretically, after integration into the network stack, WireGuard should work even faster. However, in reality, this may not necessarily be the case due to the transition to kernel-integrated cryptographic functions of Crypto API. It is possible that not all of them are yet optimized to the performance level of native WireGuard.<\/p>\n<blockquote><p>\"From my perspective, WireGuard is perfect for the user. All low-level decisions are made in the specification, so the process of preparing a typical VPN infrastructure takes only a few minutes. It's practically impossible to mess up the configuration,\" <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/432686\/\">reported<\/a><\/noindex> as noted on Habr in 2018. \"The installation process <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.com\/install\/\">detailed description<\/a><\/noindex> on the official site, I want to particularly highlight the excellent <noindex><a rel=\"nofollow\" href=\"https:\/\/openwrt.org\/docs\/guide-user\/network\/tunneling_interface_protocols#protocol_wireguard_wireguard_vpn\">support for OpenWRT<\/a><\/noindex>This level of ease of use and the compactness of the codebase have been achieved by eliminating the distribution of keys. There is no complicated certificate system or all that corporate horror; short encryption keys are distributed much like SSH keys.<\/p><\/blockquote>\n<p>\nThe WireGuard project has been in development since 2015, and it has undergone an audit and <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.com\/formal-verification\/\">formal verification<\/a><\/noindex>. WireGuard support is integrated into NetworkManager and systemd, and kernel patches are included in the base distributions of Debian Unstable, Mageia, Alpine, Arch, Gentoo, OpenWrt, NixOS, Subgraph, and ALT.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/dcmiran\/blog\/486046\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u041b\u0438\u043d\u0443\u0441 \u043f\u0435\u0440\u0435\u043d\u0451\u0441 \u043a \u0441\u0435\u0431\u0435 \u0432\u0435\u0442\u043a\u0443 net-next \u0441 VPN-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430\u043c\u0438 WireGuard. \u041e\u0431 \u044d\u0442\u043e\u043c \u0441\u043e\u0431\u044b\u0442\u0438\u0438 \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0438 \u0432 \u0441\u043f\u0438\u0441\u043a\u0435 \u0440\u0430\u0441\u0441\u044b\u043b\u043a\u0438 WireGuard. \u0412 \u0434\u0430\u043d\u043d\u044b\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u0435\u0442\u0441\u044f \u0441\u0431\u043e\u0440 \u043a\u043e\u0434\u0430 \u0434\u043b\u044f \u043d\u043e\u0432\u043e\u0433\u043e \u044f\u0434\u0440\u0430 Linux 5.6. WireGuard \u2014 \u0431\u044b\u0441\u0442\u0440\u044b\u0439 VPN \u043d\u043e\u0432\u043e\u0433\u043e \u043f\u043e\u043a\u043e\u043b\u0435\u043d\u0438\u044f, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u0430 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u0430\u044f \u043a\u0440\u0438\u043f\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u044f. \u041e\u043d \u0438\u0437\u043d\u0430\u0447\u0430\u043b\u044c\u043d\u043e \u0440\u0430\u0437\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u043b\u0441\u044f \u043a\u0430\u043a \u0431\u043e\u043b\u0435\u0435 \u043f\u0440\u043e\u0441\u0442\u0430\u044f \u0438 \u0443\u0434\u043e\u0431\u043d\u0430\u044f \u0430\u043b\u044c\u0442\u0435\u0440\u043d\u0430\u0442\u0438\u0432\u0430 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u043c VPN. \u0410\u0432\u0442\u043e\u0440\u00a0\u2014 \u043a\u0430\u043d\u0430\u0434\u0441\u043a\u0438\u0439 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442 \u043f\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-56025","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u041b\u0438\u043d\u0443\u0441 \u043f\u0435\u0440\u0435\u043d\u0451\u0441 \u043a \u0441\u0435\u0431\u0435 \u0432\u0435\u0442\u043a\u0443 net-next \u0441 VPN-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430\u043c\u0438 WireGuard.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/v-yadro-linux-5-6-vklyuchili-vpn-wireguard\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 \u044f\u0434\u0440\u043e Linux 5.6 \u0432\u043a\u043b\u044e\u0447\u0438\u043b\u0438 VPN WireGuard | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u041b\u0438\u043d\u0443\u0441 \u043f\u0435\u0440\u0435\u043d\u0451\u0441 \u043a \u0441\u0435\u0431\u0435 \u0432\u0435\u0442\u043a\u0443 net-next \u0441 VPN-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430\u043c\u0438 WireGuard.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/v-yadro-linux-5-6-vklyuchili-vpn-wireguard\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-02T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:04:11+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47VPN WireGuard has been included in Linux kernel 5.6 | ProHoster","description":"Today, Linus has moved the net-next branch with WireGuard VPN interfaces into his repository.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/v-yadro-linux-5-6-vklyuchili-vpn-wireguard","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 \u044f\u0434\u0440\u043e Linux 5.6 \u0432\u043a\u043b\u044e\u0447\u0438\u043b\u0438 VPN WireGuard | ProHoster","og:description":"\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u041b\u0438\u043d\u0443\u0441 \u043f\u0435\u0440\u0435\u043d\u0451\u0441 \u043a \u0441\u0435\u0431\u0435 \u0432\u0435\u0442\u043a\u0443 net-next \u0441 VPN-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430\u043c\u0438 WireGuard.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/v-yadro-linux-5-6-vklyuchili-vpn-wireguard","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-02T21:00:00+00:00","article:modified_time":"2020-02-18T11:04:11+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"56025","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:32:32","updated":"2022-10-08 09:55:18","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/56025","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=56025"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/56025\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=56025"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=56025"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=56025"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}