plugging into wireguard clients

Paymon <[email protected]> Wed, 10 Dec 2025 09:48:28 -0500
Newsgroups com.zx2c4.lists.wireguard
Message-ID <3a43yktovcw425zm7lexmqsysj35skly7f7emftcyirbwarkus@gocmz2oxt4l2>
hello,

posted a version of this earlier on #wireguard, posting here for those who
missed it? hope it is in good form.

> i'm pushing our organisation to use wireguard for vpn and the show stopper is
> compliance. what they use at the moment is fortinet and the main feature the
> windows admins are asking for is the compliance. what they care about is
> mainly the os version of the staff's own devices atm.
>
> one question i have is, do you know of any open source solution for this?
> (besides tailscale of course)

> i have looked into implementing it myself and the main issue is the windows
> platform, i'm unfamiliar with their package/distributing dance.
>
> nevertheless, i had a brief look into wireguard-windows and first thing i
> notices was `supportedOS` in manifest.xml
>
> one idea would be to repackage and distribute wireguard-windows, with the old
> version of os removed from that manifest file plus a logic that kicks in and
> onboard the user. i.e. authenticate them to the backend, generate a pair of
> keys for them and exchange it to the backend etc.
>
> i wonder what you think about this? in particular, any suggestion as to where
> would be a good entry point for this?
> i see fetcher has some comments related to intunes (not so much familiar with
> that), is that a good place to start?

-- 

               Paymon