headscale icon indicating copy to clipboard operation
headscale copied to clipboard

Request for Configuration of --verify-clients Parameter in Built-in DERP

Open zsio opened this issue 11 months ago • 7 comments

I am currently using the built-in DERP in Headscale and I noticed that the --verify-clients parameter is not configurable. This situation implies that the DERP I am using could be publicly accessible, which raises security concerns.

I am writing to inquire if there is a possibility to restrict the use of the built-in DERP to my clients only. This feature will greatly enhance the security of my connections and ensure that only authorized clients can use the DERP.

Looking forward to your response and potential solutions to this issue.

zsio avatar Mar 18 '24 05:03 zsio

I am considering migrating from Tailscale to Headscale, but I hesitated when I suddenly notice this issue because I cannot tolerate others freeloading on my server without my permission.

StudyingLover avatar Mar 21 '24 13:03 StudyingLover

Also interested in this future as using my own DERP server...

masterwishx avatar Mar 23 '24 07:03 masterwishx

When researching tailscale I noticed this fairly subtle codepath being used for it, it requires an active embedded tailscale client to be sending peer updates to the derp server, apparantly.

ShadowJonathan avatar Mar 28 '24 12:03 ShadowJonathan

This issue is stale because it has been open for 90 days with no activity.

github-actions[bot] avatar Jun 27 '24 01:06 github-actions[bot]

No.

https://nostalebots.xyz/

ShadowJonathan avatar Jun 27 '24 07:06 ShadowJonathan

I would like to inquire if there is any new progress on this issue? This version hasn't been updated for more than a year. Will this problem be improved in the upcoming release?

zsio avatar Aug 16 '24 05:08 zsio

There are pull requests open, but we dont have the capacity to review and take in the amount of code for this release. I will try to review if to for the next cycle, but not sure if it will be included.

kradalby avatar Aug 16 '24 09:08 kradalby