Show HN: VPNHome – 1-click, self-hosted OpenVPN deployment and management app
github.com
github.com
Have you considered doing a version of this for Wireguard? It's much, much better than OpenVPN.
However, Wireguard requires kernel module which is a bit tricky on VPSes and is not compatible with "it just works" mantra.
I've hard time installing Wireguard on a VPS.
Sorry for not staying on topic. VPNHome looks nifty.
Just use Wireguard.
Wireguard is great, but is not supported on many devices, and does not auto provision configuration files for all your devices. Please look into algo, it really is the best solution for 99% of people.
In a version I used, after TLS handshake it used a custom bulk data protocol and defaulted to blowfish for the crypto (these defaults might have changed since).
It runs in userspace so the speed is not good.
IPSec has better performance because it runs in the kernel, but the protocol is bad and the amount of code in the kernel is enormous, as much as all of openssl, and this cannot be audited by a single person.
Wireguard has good performance, has only ~4000 lines of code that need to be audited (designed to be audited by a single person) and uses very modern crypto.
I think the biggest problem is the lack of a simple GUI process to manage the connection.
I have scripts setup to run `wg-quick up` or down hanging out in my menubar (Mac), but that's not something that I'd expect everyone to be able to do or setup themselves. However, a "Enterprise" managed environment might be able to come up with something that works. This is something that the community could fix independently.
However, (at least for Macs) the install process requires installing Homebrew, installing a package at the command line, editing a config file with strange keys, etc... This could all be GUI-fied and made less intimidating.
But, the other (probably bigger) thing for corporate use is having a company behind the protocol to be able to buy products, support contracts, etc... I mean, a company isn't going to switch from an SSL VPN to Wireguard if you can't have an outside entity to sue if things go wrong. This is something that will just take time to build up the comfort and scale.
It's also open-source: https://github.com/tinfoil/openvpn_autoconfig
https://twitter.com/_rchase_/status/1074789686261022720
He's charging for this because he has some nice convenience features (like auto-rebuild server every day, week, etc), and then managing the VPS integration to make it one click rebuild anywhere in the world, etc.
Been using it for ~7-10 days and getting amazing speeds on my iPhone/Mac. Well worth the small fee he's charging for a dedicated VPN point that I can rebuild whenever on a different location.