After using WireGuard for 5 minutes I knew this was going to be a big thing.
IPsec has too many fucking knobs. It is it’s pitfall.
After using WireGuard for 5 minutes I knew this was going to be a big thing.
IPsec has too many fucking knobs. It is it’s pitfall.
I wonder if any specification group has ever thrown up their hands and said, “you know what? Fine. Let’s just create one named sub-protocol for the way each of you major players does things; and then have the clients of this protocol do a sub-protocol negotiation; and then have the client use a plugin specific to the sub-protocol that’s been negotiated. Then you don’t need any knobs; all the policy can be baked into the plugin.”
(Come to think of it, this is kind of how the authentication phase of SSH works, when configured to use PAM. “Pretend we’re MIT” (a.k.a. Kerberos); “pretend this is a Microsoft Active Directory domain” (a.k.a. NTLM auth); etc.