Re: WireGuard fails to build on CentOS 7.1908

2019-09-13 Thread Jason A. Donenfeld
Hey Dario, Thanks for the explanation. I released a new snapshot today that should include support for both RHEL 7.6 and 7.7. As soon as CentOS 7.7 comes out, I intend to drop 7.6 support entirely to continue with the policy of supporting the latest RHEL only. It seems like there's an awkward tran

[ANNOUNCE] WireGuard Snapshot `0.0.20190913` Available

2019-09-13 Thread Jason A. Donenfeld
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello, A new snapshot, `0.0.20190913`, has been tagged in the git repository. Please note that this snapshot is a snapshot rather than a final release that is considered secure and bug-free. WireGuard is generally thought to be fairly stable, and m

Re: Adding 2FA to WireGuard

2019-09-13 Thread Nico Schottelius
Hey Rémi, Rémi Lapeyre writes: > Hi Nico, yes pyotp is the implementation I use on the server, but anything > Compatible withrfc6238 should work. That sounds about right! >> We have written ungleich-otp [0] that extends the otp approach with >> realms similar to kerberos. > > This looks intere

Re: Adding 2FA to WireGuard

2019-09-13 Thread Nico Schottelius
Hey Rémi, that is very welcome news. We might actually also be interested in this. Are you by any change using pyotp for your server? We have written ungleich-otp [0] that extends the otp approach with realms similar to kerberos. In regard to faking the address: given that there are no other ro

Re: Routing between multiple wg interfaces

2019-09-13 Thread Michael B. Williams
I'm a bit confused about your configuration files - could you better organize them and present including the underlying host they are on? From the question, it's unclear as to whether there are multiple WireGuard servers or a single server. I see you reference pinging 192.168.1.0/24 but I do not se

Adding 2FA to WireGuard

2019-09-13 Thread Rémi Lapeyre
Hi everybody! We are using WireeGuard on Mac and Linux which works great but for compliance purpose, we would like to be able to add an OTP challenge on connection. I've been looking at the archive of the mailing list and at the various projects built around WireGuard and started writing an implem

Re: wg-quick invoking resolvectl instead of resolvconf on systems where that is appropriate?

2019-09-13 Thread Roy Marples
I'm not subbed to this list, so please include me directly in any replies. Disclaimer - I'm upstream for openresolv. Michael Biebl wrote this here: https://lists.zx2c4.com/pipermail/wireguard/2019-September/004524.html You absolutely correct in that resolvconf is not a standard Linux interface

error messages on Hyper-V..

2019-09-13 Thread Joachim Lindenberg
With .22 installed on Hyper-V I now get the following error message - repeatedly and very annoying. Regards, Joachim ___ WireGuard mailing list WireGuard@lists.zx2c4.com https://lists.zx2c4.com/mailman/listinfo/wireguard