https://github.com/wiretrustee/wiretrustee Skip to content Sign up * Why GitHub? Features - + Mobile - + Actions - + Codespaces - + Packages - + Security - + Code review - + Issues - + Integrations - + GitHub Sponsors - + Customer stories- * Team * Enterprise * Explore + Explore GitHub - Learn and contribute + Topics - + Collections - + Trending - + Learning Lab - + Open source guides - Connect with others + The ReadME Project - + Events - + Community forum - + GitHub Education - + GitHub Stars program - * Marketplace * Pricing Plans - + Compare plans - + Contact Sales - + Education - [ ] [search-key] * # In this repository All GitHub | Jump to | * No suggested jump to results * # In this repository All GitHub | Jump to | * # In this organization All GitHub | Jump to | * # In this repository All GitHub | Jump to | Sign in Sign up {{ message }} wiretrustee / wiretrustee * Notifications * Star 861 * Fork 18 Connect your devices into a single secure private WireGuard(r)-based mesh network. wiretrustee.com BSD-3-Clause License 861 stars 18 forks Star Notifications * Code * Issues 14 * Pull requests 0 * Actions * Projects 2 * Wiki * Security * Insights More * Code * Issues * Pull requests * Actions * Projects * Wiki * Security * Insights main Switch branches/tags [ ] Branches Tags Could not load branches Nothing to show {{ refName }} default View all branches Could not load tags Nothing to show {{ refName }} default View all tags 1 branch 9 tags Code Clone HTTPS GitHub CLI [https://github.com/w] Use Git or checkout with SVN using the web URL. [gh repo clone wiretr] Work fast with our official CLI. Learn more. * Open with GitHub Desktop * Download ZIP Launching GitHub Desktop If nothing happens, download GitHub Desktop and try again. Go back Launching GitHub Desktop If nothing happens, download GitHub Desktop and try again. Go back Launching Xcode If nothing happens, download Xcode and try again. Go back Launching Visual Studio Code Your codespace will open once ready. There was a problem preparing your codespace, please try again. Latest commit @braginini braginini docs: add Wireguard trademark statement ... dd50f49 Jun 29, 2021 docs: add Wireguard trademark statement dd50f49 Git stats * 127 commits Files Permalink Failed to load latest commit information. Type Name Latest commit message Commit time .github/workflows Use go bin Jun 25, 2021 cmd set config path to avoid ci/cd limitations Jun 25, 2021 connection fix: golint errors Jun 24, 2021 iface debug port value Jun 25, 2021 infrastructure_files fix typo in directory name Jun 15, 2021 release_files chore: use config.json in teh service definition instead of wiretrust... May 6, 2021 signal fix: #35 peer Registration Race when client connects to the signal se... Jun 17, 2021 util fix doc May 15, 2021 .gitignore project init May 1, 2021 .goreleaser.yaml build windows Jun 6, 2021 AUTHORS add end of line May 11, 2021 Dockerfile Building docker images for signal service May 11, 2021 LICENSE license: correct license text May 11, 2021 README.md docs: add Wireguard trademark statement Jun 29, 2021 go.mod update go.mod with service command dependecies Jun 25, 2021 go.sum update go.mod with service command dependecies Jun 25, 2021 main.go project init May 1, 2021 manifest.xml Avoid prompt admin at every execution Jun 25, 2021 resources.rc Update resource file with requireAdministrator, added resources.rc an... Jun 22, 2021 resources_windows_amd64.syso Avoid prompt admin at every execution Jun 25, 2021 View code Wiretrustee Why using Wiretrustee? A bit on Wiretrustee internals What Wiretrustee is not doing: Product Roadmap Client Installation Linux MACOS Windows Client Configuration Running the Signal service Docker image Running Signal and Coturn Legal README.md Wiretrustee A WireGuard(r)-based mesh network that connects your devices into a single private network. Why using Wiretrustee? * Connect multiple devices to each other via a secure peer-to-peer Wireguard VPN tunnel. At home, the office, or anywhere else. * No need to open ports and expose public IPs on the device. * Automatically reconnects in case of network failures or switches. * Automatic NAT traversal. * Relay server fallback in case of an unsuccessful peer-to-peer connection. * Private key never leaves your device. * Works on ARM devices (e.g. Raspberry Pi). A bit on Wiretrustee internals * Wiretrustee uses WebRTC ICE implemented in pion/ice library to discover connection candidates when establishing a peer-to-peer connection between devices. * A connection session negotiation between peers is achieved with the Wiretrustee Signalling server signal * Contents of the messages sent between peers through the signaling server are encrypted with Wireguard keys, making it impossible to inspect them. The routing of the messages on a Signalling server is based on public Wireguard keys. * Occasionally, the NAT-traversal is unsuccessful due to strict NATs (e.g. mobile carrier-grade NAT). For that matter, there is support for a relay server fallback (TURN) and a secure Wireguard tunnel is established via TURN server. Coturn is the one that has been successfully used for STUN and TURN in Wiretrustee setups. What Wiretrustee is not doing: * Wireguard key management. In consequence, you need to generate peer keys and specify them on Wiretrustee initialization step. This feature is on the roadmap. * Peer address management. You have to specify a unique peer local address (e.g. 10.30.30.1/24) when configuring Wiretrustee. This feature is on the roadmap. Product Roadmap * Public Roadmap * Public Roadmap Progress Tracking Client Installation Linux 1. Checkout Wiretrustee releases 2. Download the latest release (Switch VERSION to the latest): Debian packages wget https://github.com/wiretrustee/wiretrustee/releases/download/v/wiretrustee__linux_amd64.deb 3. Install the package sudo dpkg -i wiretrustee__linux_amd64.deb Fedora/Centos packages wget https://github.com/wiretrustee/wiretrustee/releases/download/v/wiretrustee__linux_amd64.rpm 3. Install the package sudo rpm -i wiretrustee__linux_amd64.rpm MACOS 1. Checkout Wiretrustee releases 2. Download the latest release (Switch VERSION to the latest): curl -o ./wiretrustee__darwin_amd64.tar.gz https://github.com/wiretrustee/wiretrustee/releases/download/v/wiretrustee__darwin_amd64.tar.gz 3. Decompress tar xcf ./wiretrustee__darwin_amd64.tar.gz sudo mv wiretrusee /usr/local/bin/wiretrustee chmod +x /usr/local/bin/wiretrustee After that you may need to add /usr/local/bin in your MAC's PATH environment variable: export PATH=$PATH:/usr/local/bin Windows 1. Checkout Wiretrustee releases 2. Download the latest Windows release wiretrustee_ _windows_amd64.tar.gz (Switch VERSION to the latest): 3. Decompress and move to a more fixed path in your system 4. Open Powershell 5. For Windows systems, we can use the service command to configure Wiretrustee as a service by running the following commands in Powershell: cd C:\path\to\wiretrustee\bin .\wiretrustee.exe service --help .\wiretrustee.exe service install # This will prompt for administrator permissions in order to install a new service You may need to run Powershell as Administrator 6. After installing you can follow the Client Configuration steps. 7. To uninstall the service simple run the command above with the uninstall flag: .\wiretrustee.exe service uninstall Client Configuration 1. Initialize Wiretrustee: For Unix systems: sudo wiretrustee init \ --stunURLs stun:stun.wiretrustee.com:3468,stun:stun.l.google.com:19302 \ --turnURLs :@turn:stun.wiretrustee.com:3468 \ --signalAddr signal.wiretrustee.com:10000 \ --wgLocalAddr 10.30.30.1/24 \ --log-level info For Windows systems: .\wiretrustee.exe init ` --stunURLs stun:stun.wiretrustee.com:3468,stun:stun.l.google.com:19302 ` --turnURLs :@turn:stun.wiretrustee.com:3468 ` --signalAddr signal.wiretrustee.com:10000 ` --wgLocalAddr 10.30.30.1/24 ` --log-level info It is important to mention that the wgLocalAddr parameter has to be unique across your network. E.g. if you have Peer A with wgLocalAddr= 10.30.30.1/24 then another Peer B can have wgLocalAddr=10.30.30.2/24 If for some reason, you already have a generated Wireguard key, you can specify it with the --wgKey parameter. If not specified, then a new one will be generated, and its corresponding public key will be output to the log. A new config will be generated and stored under / etc/wiretrustee/config.json 2. Add a peer to connect to. For Unix systems: sudo wiretrustee add-peer --allowedIPs 10.30.30.2/32 --key '' For Windows systems: .\wiretrustee.exe add-peer --allowedIPs 10.30.30.2/32 --key '' 3. Restart Wiretrustee to reload changes For MACOS you will just start the service: sudo wiretrustee up --log-level info # or sudo wiretrustee up --log-level info & # to run it in background For Linux systems: sudo systemctl restart wiretrustee.service sudo systemctl status wiretrustee.service For Windows systems: .\wiretrustee.exe service start You may need to run Powershell as Administrator Running the Signal service After installing the application, you can run the signal using the command below: /usr/local/bin/wiretrustee signal --log-level INFO This will launch the Signal server on port 10000, in case you want to change the port, use the flag --port. Docker image We have packed the Signal server into docker image. You can pull the image from Docker Hub and execute it with the following commands: docker pull wiretrustee/wiretrustee:signal-latest docker run -d --name wiretrustee-signal -p 10000:10000 wiretrustee/wiretrustee:signal-latest The default log-level is set to INFO, if you need you can change it using by updating the docker cmd as followed: docker run -d --name wiretrustee-signal -p 10000:10000 wiretrustee/wiretrustee:signal-latest --log-level DEBUG Running Signal and Coturn Under infrastructure_files we have a docker-compose example to run both, Wiretrustee Signal server and an instance of Coturn, it also provides a turnserver.conf file as a simple example of Coturn configuration. You can edit the turnserver.conf file and change its Realm setting (defaults to wiretrustee.com) to your own domain and user setting (defaults to username1:password1) to proper credentials. The example is set to use the official images from Wiretrustee and Coturn, you can find our documentation to run the signal server in docker in [Running the Signal service](#Running the Signal service) and the Coturn official documentation here. Run Coturn at your own risk, we are just providing an example, be sure to follow security best practices and to configure proper credentials as this service can be exploited and you may face large data transfer charges. Also, if you have an SSL certificate you can modify the docker-compose.yml file to point to its files in your host machine, then switch the domainname to your own SSL domain. If you don't already have an SSL certificate, you can follow Certbot's official documentation to generate one from Let's Encrypt, or, we found that the example provided by BigBlueButton covers the basics to configure Coturn with Let's Encrypt certs. Simple docker-composer execution: cd infrastructure_files docker-compose up -d You can check logs by running: cd infrastructure_files docker-compose logs signal docker-compose logs coturn If you need to stop the services, run the following: cd infrastructure_files docker-compose down Legal WireGuard is a registered trademark of Jason A. Donenfeld. About Connect your devices into a single secure private WireGuard(r)-based mesh network. wiretrustee.com Topics golang mesh-networks nat-traversal vpn mesh wireguard wireguard-vpn wiretrustee Resources Readme License BSD-3-Clause License Releases 9 v0.0.8 Latest Jun 29, 2021 + 8 releases Packages 1 Contributors 4 * @braginini braginini Mikhail Bragin * @mlsmaycon mlsmaycon Maycon Santos * @stv0g stv0g Steffen Vogel * @andpar83 andpar83 Languages * Go 97.3% * Shell 2.5% * Dockerfile 0.2% * (c) 2021 GitHub, Inc. * Terms * Privacy * Security * Status * Docs * Contact GitHub * Pricing * API * Training * Blog * About You can't perform that action at this time. You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session.