{"id":92348,"date":"2020-08-25T19:42:57","date_gmt":"2020-08-25T17:42:57","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-yadro-netbsd-dobavlena-podderzhka-vpn-wireguard"},"modified":"2020-08-25T19:42:57","modified_gmt":"2020-08-25T17:42:57","slug":"v-yadro-netbsd-dobavlena-podderzhka-vpn-wireguard","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/v-yadro-netbsd-dobavlena-podderzhka-vpn-wireguard","title":{"rendered":"Support for VPN WireGuard has been added to the NetBSD kernel","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>The developers of the NetBSD project <noindex><a rel=\"nofollow\" href=\"https:\/\/mail-index.netbsd.org\/current-users\/2020\/08\/20\/msg039393.html\">informed<\/a><\/noindex> about the inclusion of the wg driver implementing the WireGuard protocol into the main NetBSD kernel. NetBSD has become the third operating system after Linux and OpenBSD to offer integrated support for WireGuard. Additionally, related commands for VPN configuration\u2014wg-keygen and wgconfig\u2014have been proposed. In the default kernel configuration (GENERIC), the driver is not yet activated and requires explicit specification in the settings 'pseudo-device wg'.<\/p>\n<p>Additionally, it can be noted <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2020-August\/005780.html\">publication<\/a><\/noindex> a corrective update to the wireguard-tools package 1.0.20200820, which includes user-space utilities such as wg and wg-quick. The new release has prepared IPC for the upcoming support of WireGuard in the FreeBSD operating system. It has separated platform-specific code into different files. Support for the 'reload' command has been added to the systemd unit file, allowing commands like 'systemctl reload wg-quick at wgnet0' to be executed.<\/p>\n<p>Let us remind you that the WireGuard VPN is built on modern encryption methods, providing very high performance, simplicity of use, and a lack of complexity, and has proven itself in several large deployments handling significant traffic volumes. The project has been evolving since 2015, has passed an audit and <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.com\/formal-verification\/\">formal verification<\/a><\/noindex> of the employed encryption methods. Support for WireGuard has already been integrated into NetworkManager and systemd, and kernel patches are included in the base of the distributions <noindex><a rel=\"nofollow\" href=\"https:\/\/wiki.debian.org\/Wireguard\">Debian Unstable<\/a><\/noindex>, Mageia, Alpine, Arch, Gentoo, OpenWrt, NixOS, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47266\">Subgraph<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/packages.altlinux.org\/ru\/search?query=kernel-modules-wireguard\">ALT<\/a><\/noindex>.<\/p>\n<p>WireGuard uses the concept of key-based routing, which implies binding a private key to each network interface and using it to link public keys. The exchange of public keys for establishing a connection is done similarly to SSH. Key agreement and connection establishment without launching a separate daemon in user space is achieved using the Noise_IK mechanism from <noindex><a rel=\"nofollow\" href=\"http:\/\/noiseprotocol.org\/\">Noise Protocol Framework<\/a><\/noindex>, similar to maintaining authorized_keys in SSH. Data is transmitted via encapsulation in UDP packets. Support is provided for changing the VPN server's IP address (roaming) without breaking the connection, with automatic client reconfiguration.<\/p>\n<p>For encryption <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.io\/protocol\/\">a layer<\/a><\/noindex>  the stream cipher <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/chacha.html\">ChaCha20<\/a><\/noindex> and the message authentication algorithm (MAC) <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/mac.html\">Poly1305.<\/a><\/noindex>, developed by Daniel Bernstein (<noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/djb.html\">Daniel J. Bernstein<\/a><\/noindex>), Tanja Lange<br \/>\n(Tanja Lange) and Peter Schwabe (Peter Schwabe). ChaCha20 and Poly1305 are presented as faster and safer alternatives to AES-256-CTR and HMAC, with software implementation allowing fixed execution time without requiring specialized hardware support. For generating a shared secret key, the elliptic curve Diffie-Hellman protocol is used, implemented in <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/ecdh.html\">Curve25519<\/a><\/noindex>, also proposed by Daniel Bernstein. The hashing algorithm used is <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=35676\">BLAKE2s (RFC7693)<\/a><\/noindex>. <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53596\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 NetBSD \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0438 \u043e \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 NetBSD \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 wg \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 WireGuard. NetBSD \u0441\u0442\u0430\u043b\u0430 \u0442\u0440\u0435\u0442\u044c\u0435\u0439 \u041e\u0421 \u043f\u043e\u0441\u043b\u0435 Linux \u0438 OpenBSD \u0441 \u0438\u043d\u0442\u0435\u0433\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u043e\u0439 WireGuard. \u0422\u0430\u043a\u0436\u0435 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u044b \u0441\u043e\u043f\u0443\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u044b \u0434\u043b\u044f \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 VPN &#8212; wg-keygen \u0438 wgconfig. \u0412 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u044f\u0434\u0440\u0430 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e (GENERIC) \u0434\u0440\u0430\u0439\u0432\u0435\u0440 \u043f\u043e\u043a\u0430 \u043d\u0435 \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u043e\u0432\u0430\u043d \u0438 \u0442\u0440\u0435\u0431\u0443\u0435\u0442 \u044f\u0432\u043d\u043e\u0433\u043e \u0443\u043a\u0430\u0437\u0430\u043d\u0438\u044f \u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-92348","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 NetBSD \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0438 \u043e \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 NetBSD \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 wg \u0441.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/v-yadro-netbsd-dobavlena-podderzhka-vpn-wireguard\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 \u044f\u0434\u0440\u043e NetBSD \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0430 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 VPN WireGuard | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 NetBSD \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0438 \u043e \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 NetBSD \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 wg \u0441.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/v-yadro-netbsd-dobavlena-podderzhka-vpn-wireguard\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-25T17:42:57+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-25T17:42:57+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Support for VPN WireGuard has been added to the NetBSD kernel | ProHoster","description":"The developers of the NetBSD project reported the inclusion of the wg driver in the main NetBSD kernel.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/v-yadro-netbsd-dobavlena-podderzhka-vpn-wireguard","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 \u044f\u0434\u0440\u043e NetBSD \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0430 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 VPN WireGuard | ProHoster","og:description":"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 NetBSD \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0438 \u043e \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 NetBSD \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 wg \u0441.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/v-yadro-netbsd-dobavlena-podderzhka-vpn-wireguard","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-25T17:42:57+00:00","article:modified_time":"2020-08-25T17:42:57+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"92348","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:10:22","updated":"2022-09-28 01:30:46","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/92348","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=92348"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/92348\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=92348"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=92348"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=92348"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}