{"id":53760,"date":"2019-12-09T00:00:00","date_gmt":"2019-12-08T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6"},"modified":"2020-02-18T14:01:41","modified_gmt":"2020-02-18T11:01:41","slug":"vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6","title":{"rendered":"VPN WireGuard \u00e8 stato accettato nel ramo net-next ed \u00e8 previsto per l'inclusione nel kernel Linux 5.6","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>David Miller (<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/David_S._Miller\">David S. Miller<\/a><\/noindex>), responsabile del sottosistema di rete del kernel Linux, <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2019-December\/004704.html\">ha accolto<\/a><\/noindex> ha incluso nella branch net-next <noindex><a rel=\"nofollow\" href=\"https:\/\/lkml.org\/lkml\/2019\/12\/8\/240\">patch<\/a><\/noindex> con l'implementazione dell'interfaccia VPN del progetto <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.io\/\">WireGuard<\/a><\/noindex>. All'inizio del prossimo anno, le modifiche accumulate nel ramo net-next costituiranno la base per il rilascio del kernel Linux 5.6. <\/p>\n<p>Negli ultimi anni ci sono stati tentativi di integrare il codice di WireGuard nel kernel principale, ma senza successo a causa della dipendenza dalle proprie implementazioni delle funzioni crittografiche, che erano progettate per migliorarne le performance. Inizialmente, queste funzioni erano <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49064\">sono offerti<\/a><\/noindex> per il kernel come API di basso livello aggiuntiva, Zinc, che nel tempo potrebbe sostituire l'SSL Crypto API standard. <\/p>\n<p>Dopo negoziazioni alla conferenza Kernel Recipes, i creatori di WireGuard a settembre <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2019-September\/004560.html\">hanno preso una decisione compromissoria<\/a><\/noindex> per convertire le loro patch all'uso del Crypto API esistente nel kernel, a cui gli sviluppatori di WireGuard avevano sollevato preoccupazioni riguardo alle performance e alla sicurezza generale. Si \u00e8 deciso di continuare a sviluppare API Zinc, ma come progetto a s\u00e9 stante.<\/p>\n<p>A novembre, gli sviluppatori del kernel <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2019-November\/004614.html\">hanno adottato<\/a><\/noindex> hanno risposto con un compromesso e hanno accettato di trasferire parti del codice da Zinc nel kernel principale. In sostanza, alcuni componenti di Zinc saranno trasferiti nel kernel, ma non come API separata, bens\u00ec come parte del Crypto API. Ad esempio, nel Crypto API sono gi\u00e0 <noindex><a rel=\"nofollow\" href=\"https:\/\/lore.kernel.org\/linux-crypto\/CAHmME9rxGp439vNYECm85bgibkVyrN7Qc+5v3r8QBmBXPZM=Dg@mail.gmail.com\/\">sono inclusi<\/a><\/noindex> preparate in WireGuard implementazioni rapide degli algoritmi ChaCha20 e Poly1305.<\/p>\n<p>In vista del previsto inserimento di WireGuard nel kernel principale, il fondatore del progetto <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.zx2c4.com\/pipermail\/wireguard\/2019-December\/004711.html\">ha annunciato<\/a><\/noindex> sulla ristrutturazione del repository. Per semplificare lo sviluppo, il monolitico repository &#171;WireGuard.git&#187;, concepito per un'esistenza autonoma, sar\u00e0 sostituito da tre repository separati, pi\u00f9 adatti per organizzare il lavoro con il codice nel nucleo principale: <\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/zx2c4\/wireguard-linux.git\/\">wireguard-linux.git<\/a><\/noindex> &#8212; l'albero completo del nucleo con le modifiche del progetto Wireguard, i cui patch saranno revisionati per l'inclusione nel nucleo e regolarmente trasferiti nei rami net\/net-next.\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/zx2c4\/wireguard-tools.git\/\">wireguard-tools.git<\/a><\/noindex> &#8212; un repository per utilit\u00e0 e script eseguibili nello spazio utente, come wg e wg-quick. Il repository pu\u00f2 essere utilizzato per creare pacchetti per le distribuzioni.\n<li class=\"l\">  <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/zx2c4\/wireguard-linux-compat.git\/\">wireguard-linux-compat.git<\/a><\/noindex> &#8212; un repository con una variante del modulo, distribuita separatamente dal nucleo e includente un livello compat.h per garantire la compatibilit\u00e0 con i vecchi nuclei. Lo sviluppo principale sar\u00e0 condotto nel repository wireguard-linux.git, ma finch\u00e9 ci sar\u00e0 la possibilit\u00e0 e la necessit\u00e0 da parte degli utenti, la variante separata dei patch sar\u00e0 mantenuta in una forma funzionante.\n<\/ul>\n<p>Ricordiamo che il VPN WireGuard \u00e8 implementato utilizzando tecniche di crittografia moderne, garantisce prestazioni molto elevate, \u00e8 facile da usare, privo di complicazioni e ha dimostrato la sua efficacia in vari grandi implementazioni che gestiscono elevate quantit\u00e0 di traffico. Il progetto \u00e8 in sviluppo dal 2015, ha superato un audit e <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.com\/formal-verification\/\">la verifica formale<\/a><\/noindex> metodi di crittografia applicati. Il supporto per WireGuard \u00e8 gi\u00e0 integrato in NetworkManager e systemd, e le patch per il kernel sono incluse nel core delle distribuzioni <noindex><a rel=\"nofollow\" href=\"https:\/\/wiki.debian.org\/Wireguard\">Debian Unstable<\/a><\/noindex>, Mageia, Alpine, Arch, Gentoo, OpenWrt, NixOS, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47266\">Subgraph<\/a><\/noindex> e <noindex><a rel=\"nofollow\" href=\"https:\/\/packages.altlinux.org\/ru\/search?query=kernel-modules-wireguard\">ALT<\/a><\/noindex>.<\/p>\n<p>In WireGuard, the concept of routing by encryption keys is applied, which involves binding a private key to each network interface and using it to link public keys. The exchange of public keys to establish a connection is analogous to SSH. To negotiate keys and connect without launching a separate user-space daemon, the Noise_IK mechanism is used from <noindex><a rel=\"nofollow\" href=\"http:\/\/noiseprotocol.org\/\">Noise Protocol Framework<\/a><\/noindex>, simile al mantenimento di authorized_keys in SSH. Il trasferimento dei dati avviene tramite incapsulamento in pacchetti UDP. \u00c8 supportato il cambio dell'indirizzo IP del server VPN (roaming) senza interrompere la connessione e una riassegnazione automatica del client.<\/p>\n<p>Per la crittografia <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.io\/protocol\/\">viene utilizzato<\/a><\/noindex>  il cifrario a flusso <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/chacha.html\">ChaCha20<\/a><\/noindex> e l'algoritmo di autenticazione dei messaggi (MAC) <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/mac.html\">Poly1305<\/a><\/noindex>, sviluppati da Daniel Bernstein (<noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/djb.html\">Daniel J. Bernstein<\/a><\/noindex>), Tanja Lange<br \/>\n(Tanja Lange) and Peter Schwabe. ChaCha20 and Poly1305 are positioned as faster and more secure alternatives to AES-256-CTR and HMAC, with a software implementation that allows achieving fixed execution time without requiring special hardware support. The Diffie-Hellman protocol on elliptic curves is used for generating a shared secret key in the implementation of <noindex><a rel=\"nofollow\" href=\"http:\/\/cr.yp.to\/ecdh.html\">Curve25519<\/a><\/noindex>, proposta anche da Daniel Bernstein. Per l'hashing viene utilizzato l'algoritmo <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=35676\">BLAKE2s (RFC7693)<\/a><\/noindex>. <\/p>\n<p>Durante <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.com\/performance\/\">testing<\/a><\/noindex> le prestazioni di WireGuard hanno dimostrato un throughput superiore di 3,9 volte e una reattivit\u00e0 3,8 volte migliore rispetto a OpenVPN (AES a 256 bit con HMAC-SHA2-256). Rispetto a IPsec (ChaCha20+Poly1305 a 256 bit e AES-256-GCM-128), WireGuard mostra un leggero vantaggio prestazionale (13-18%) e una riduzione della latenza (21-23%). I test sono stati eseguiti utilizzando implementazioni rapide degli algoritmi di crittografia sviluppati dal progetto &#8212; la transizione al Crypto API standard del nucleo potrebbe portare a un deterioramento delle prestazioni.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireguard.io\/performance\/\"><img decoding=\"async\" alt=\"VPN WireGuard \u00e8 stato accettato nel ramo net-next ed \u00e8 previsto per l&#039;inclusione nel kernel Linux 5.6\" src=\"\/wp-content\/uploads\/2019\/12\/f459682e9003ba807a78995f678188a2.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51997\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u044d\u0432\u0438\u0434 \u041c\u0438\u043b\u043b\u0435\u0440 (David S. Miller), \u043e\u0442\u0432\u0435\u0447\u0430\u044e\u0449\u0438\u0439 \u0437\u0430 \u0441\u0435\u0442\u0435\u0432\u0443\u044e \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u044f\u0434\u0440\u0430 Linux, \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0432\u0435\u0442\u043a\u0438 net-next \u043f\u0430\u0442\u0447\u0438 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 VPN-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430 \u043e\u0442 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 WireGuard. \u0412 \u043d\u0430\u0447\u0430\u043b\u0435 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0433\u043e \u0433\u043e\u0434\u0430 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f, \u043d\u0430\u043a\u0430\u043f\u043b\u0438\u0432\u0430\u0435\u043c\u044b\u0435 \u0432 \u0432\u0435\u0442\u043a\u0435 net-next, \u043b\u044f\u0433\u0443\u0442 \u0432 \u043e\u0441\u043d\u043e\u0432\u0443 \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u044f\u0434\u0440\u0430 Linux 5.6. \u041f\u043e\u043f\u044b\u0442\u043a\u0438 \u043f\u0440\u043e\u0434\u0432\u0438\u0436\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 WireGuard \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 \u043f\u0440\u0435\u0434\u043f\u0440\u0438\u043d\u0438\u043c\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043b\u0435\u0442, \u043d\u043e \u043e\u0441\u0442\u0430\u0432\u0430\u043b\u0438\u0441\u044c \u0431\u0435\u0437 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":53761,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-53760","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u044d\u0432\u0438\u0434 \u041c\u0438\u043b\u043b\u0435\u0440 (David S.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47VPN WireGuard \u043f\u0440\u0438\u043d\u044f\u0442 \u0432 \u0432\u0435\u0442\u043a\u0443 net-next \u0438 \u043d\u0430\u043c\u0435\u0447\u0435\u043d \u0434\u043b\u044f \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0432 \u044f\u0434\u0440\u043e Linux 5.6 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u044d\u0432\u0438\u0434 \u041c\u0438\u043b\u043b\u0435\u0440 (David S.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-08T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:01:41+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47VPN WireGuard accettato nel ramo net-next e previsto per l'inclusione nel kernel Linux 5.6 | ProHoster","description":"David Miller (David S.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47VPN WireGuard \u043f\u0440\u0438\u043d\u044f\u0442 \u0432 \u0432\u0435\u0442\u043a\u0443 net-next \u0438 \u043d\u0430\u043c\u0435\u0447\u0435\u043d \u0434\u043b\u044f \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0432 \u044f\u0434\u0440\u043e Linux 5.6 | ProHoster","og:description":"\u0414\u044d\u0432\u0438\u0434 \u041c\u0438\u043b\u043b\u0435\u0440 (David S.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/vpn-wireguard-prinyat-v-vetku-net-next-i-namechen-dlya-vklyucheniya-v-yadro-linux-5-6","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-08T21:00:00+00:00","article:modified_time":"2020-02-18T11:01:41+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53760","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 08:40:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:01:26","updated":"2026-01-24 08:40:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/53760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=53760"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/53760\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/53761"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=53760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=53760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=53760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}