VPN WireGuard 1.0.0 iripo

Introduced landmark VPN kuburitswa WireGuard 1.0.0, iyo yakaratidza kuendeswa kweWireGuard zvikamu muhombe huru Linux 5.6 uye kugadzikana kwebudiriro. Kodhi inosanganisirwa muLinux kernel akapfuura Ongororo yekuwedzera yekuchengetedza yakaitwa nekambani yakazvimirira inyanzvi mukuongororwa kwakadaro. Odhiyo haina kuratidza chero dambudziko.

Sezvo WireGuard yave kugadzirwa muLinux kernel huru, nzvimbo yekuchengetera yakagadzirirwa kugoverwa uye vashandisi vanoramba vachishandisa shanduro dzekare dzekernel. wireguard-linux-Compat:. Iyo repository inosanganisira yakadzoserwa WireGuard kodhi uye compat.h layer kuti ive nechokwadi chekuenderana nekare kernels. Zvinocherechedzwa kuti chero bedzi vagadziri vaine mukana uye vashandisi vachichida, imwe yakaparadzana vhezheni yezvigamba ichatsigirwa mukushanda fomu. Mune chimiro chayo chazvino, yakamira vhezheni yeWireGuard inogona kushandiswa nekernels kubva Ubuntu 20.04 ΠΈ Debian 10 "Buster", uye inowanikwawo sezvigamba zveLinux kernels 5.4 ΠΈ 5.5. Kugovera uchishandisa azvino kernels akadai saArch, Gentoo uye
Fedora 32 ichakwanisa kushandisa WireGuard ine 5.6 kernel update.

Iyo huru yekuvandudza maitiro ikozvino inoitwa mune repository washington-linux.git, iyo inosanganisira iyo yakazara Linux kernel muti ine shanduko kubva kuWireguard chirongwa. Mapeche anobva pane ino repository anozoongororwa kuti abatanidzwe mu kernel huru uye anogara achisundirwa kumambure/mambure-anotevera mapazi. Kuvandudzwa kwezvishandiso uye zvinyorwa zvinomhanya munzvimbo yevashandisi, senge wg uye wg-nekukurumidza, inoitwa mune repository. neworleanscomber.git, iyo inogona kushandiswa kugadzira mapakeji mukugovera.

Ngatikuyeuchidzei kuti VPN WireGuard inoshandiswa pahwaro hwemazuva ano encryption nzira, inopa yakanyanya kukwirira kuita, iri nyore kushandisa, isina matambudziko uye yakazviratidza mune akati wandei e deployments anogadzira mavhoriyamu makuru emotokari. Iyo purojekiti yanga ichikura kubva 2015, yakaongororwa uye formal verification encryption nzira dzakashandiswa. Tsigiro yeWireGuard yakatobatanidzwa muNetworkManager uye systemd, uye kernel zvigamba zvinosanganisirwa mukugovera kwekutanga. Debian Haina Kugadzikana, Mageia, Alpine, Arch, Gentoo, OpenWrt, NixOS, Chikamu ΠΈ ALT.

WireGuard inoshandisa iyo pfungwa ye encryption kiyi nzira, iyo inosanganisira kubatanidza yakavanzika kiyi kune yega yega network interface uye kuishandisa kusunga makiyi eruzhinji. Makiyi eruzhinji anotsinhaniswa kuti amise chinongedzo nenzira yakafanana kune SSH. Kutaurirana makiyi uye kubatana pasina kumhanyisa daemon yakaparadzana munzvimbo yemushandisi, iyo Noise_IK michina kubva Noise Protocol Frameworkzvakafanana nekuchengetedza authorized_keys muSSH. Kuendesa data kunoitwa kuburikidza ne encapsulation muUDP mapaketi. Inotsigira kushandura IP kero yeVPN server (kutenderera) pasina kudzima kubatana neotomatiki mutengi kugadzirisa.

For encryption inoshandiswa ne stream cipher ChaCha20 uye meseji yekusimbisa algorithm (MAC) Poly1305, yakagadzirwa naDaniel Bernstein (Daniel J. Bernstein), Tanya Lange
(Tanja Lange) naPeter Schwabe. ChaCha20 nePoly1305 zvakamisikidzwa seanokurumidza uye akachengeteka analogues eAES-256-CTR neHMAC, iyo software yekumisikidza inobvumira kuwana yakatemwa yekuuraya nguva pasina kushandisa yakakosha Hardware rutsigiro. Kugadzira kiyi yakavanzika yakagovaniswa, iyo elliptic curve Diffie-Hellman protocol inoshandiswa mukuita Curve25519, zvakare yakakurudzirwa naDaniel Bernstein. Iyo algorithm inoshandiswa kune hashing ndeye BLAKE2s (RFC7693).

Pasi pekare kuyedza Performance WireGuard yakaratidza 3.9 nguva yakakwirira kupfuura uye 3.8 nguva yakakwirira kuterera kana ichienzaniswa neOpenVPN (256-bit AES ine HMAC-SHA2-256). Kuenzaniswa ne IPsec (256-bit ChaCha20 + Poly1305 uye AES-256-GCM-128), WireGuard inoratidza kuderera kwekuita zvishoma (13-18%) uye pasi latency (21-23%). Mhedzisiro yebvunzo yakatumirwa pawebhusaiti yeprojekiti inovhara iyo yekare yakamira yakamira yeWireGuard uye inomakwa seisina kukwana mhando yepamusoro. Kubva pakuyedzwa, iyo WireGuard uye IPsec kodhi yakagadziridzwa zvakare uye yave kukurumidza. Kumwe kuyedza kwakazara kunovhara kuisirwa kwakabatanidzwa mukernel hakusati kwaitwa. Nekudaro, zvinocherechedzwa kuti WireGuard ichiri kupfuura IPsec mune mamwe mamiriro nekuda kweakawanda-tambo, nepo OpenVPN inoramba ichinonoka.

VPN WireGuard 1.0.0 iripo

Source: opennet.ru

Voeg