/srv/irclogs.ubuntu.com/2022/07/18/#ubuntu-server.txt

ahasenackwhen someone has some time, I'm writing wireguard docs for the ubuntu server guide14:46
ahasenackit's not finished already,14:46
ahasenackbut I could use a quick glance at these: 14:46
ahasenackintroduction: https://git.launchpad.net/~ahasenack/+git/serverguide/tree/wireguard/introduction.md?h=wireguard14:47
ahasenackpeer to site: https://git.launchpad.net/~ahasenack/+git/serverguide/tree/wireguard/peer-to-site-wg-on-router.md?h=wireguard14:47
ahasenackonce I start writing the other bits (site to site, peer to peer), I might decide there is too much in common between these chapters and change the layout14:47
ahasenackI don't think a full review is warranted at this point, when it's unfinished, but a quick glance and telling me about obvious spots would help14:48
=== oerheks is now known as Guest401
=== oerheks1 is now known as oerheks
sarnoldahasenack: I suggest changing the apt install wireguard to install wireguard-tools instead -- the 'wireguard' package is a metapackage that depends on dkms | kernel module; I think it's more useful in a debian context than ubuntu context18:04
sarnoldahasenack: consider 'according to the host' in 'name the key files according to the peer they were generated for'18:08
sarnoldahasenack: in the "putting it all together" section, we've jumped from having generated keys to having configured interfaces, but the commands to make that interface and configure it have been skipped entirely; perhaps this is just the "unfinished" bit you've mentioned :)18:09
sarnoldahasenack: ooh pretty diagrams! :D18:09
sarnoldahasenack: very nice :) my last few thoughts: it might be worth saying that wg-quick is just one way to bring up the interfaces, it can be managed via other tools if desired. also, I was left very curious which interfaces / addresses wireguard is listening on, when it's "listening". Does that show up in `ss` output? can it be configured to listen to thousands of ports? (hotel and airport wifi can 21:11
sarnoldbe brutal)21:11
=== ajfriesen1 is now known as ajfriesen
sarnoldahasenack: ooh ooh a new question! :D  I could imagine some people want an sshd or apache or nginx or samba or similar to listen ONLY on the wireguard interface, or interfaces, and not listen to the 'standard' addresses at all23:47

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!