plugging into wireguard clients

Paymon paymon at encs.concordia.ca
Wed Dec 10 14:48:34 UTC 2025


hello,

posted a version of this earlier on #wireguard, posting here for those who
missed it? hope it is in good form.

> i'm pushing our organisation to use wireguard for vpn and the show stopper is
> compliance. what they use at the moment is fortinet and the main feature the
> windows admins are asking for is the compliance. what they care about is
> mainly the os version of the staff's own devices atm.
>
> one question i have is, do you know of any open source solution for this?
> (besides tailscale of course)

> i have looked into implementing it myself and the main issue is the windows
> platform, i'm unfamiliar with their package/distributing dance.
>
> nevertheless, i had a brief look into wireguard-windows and first thing i
> notices was `supportedOS` in manifest.xml
>
> one idea would be to repackage and distribute wireguard-windows, with the old
> version of os removed from that manifest file plus a logic that kicks in and
> onboard the user. i.e. authenticate them to the backend, generate a pair of
> keys for them and exchange it to the backend etc.
>
> i wonder what you think about this? in particular, any suggestion as to where
> would be a good entry point for this?
> i see fetcher has some comments related to intunes (not so much familiar with
> that), is that a good place to start?

-- 

               Paymon


More information about the WireGuard mailing list