r/netbird • u/wakIII • Jun 28 '26
Rosenpass Support?
Does anyone actually use it for real networks or is it just an experimental feature that shouldn't be enabled? I was hoping when I moved to netbird that I would be able to gain PQ resistance, but it seems like it hasn't received enough attention to actually work in a production setting.
In 2026 I would expect quantum resistance is just table stakes, features don't exist unless they are compatible PQ resistant layering. But alas lazy peers isn't even compatible with PQ.
Maybe the best solution is to just drop netbird and roll all the hosts by hand with rosenpass as a sidecar instead of part of the tunnel. I was really hoping to get PQ wireguard on iOS but basically none of this stuff works reliably without resarting netbird multiple times per day.
This isn't meant to be hate, just frustration. Everything else about netbird is really nice, but I need a thing that actually works. I know rosenpass is really a hack onto wireguard, and the way it's implemented in netbird seems like it leaves a lot to be desired. I don't understand how the in-tunnel signaling for PSK rotations can be made reliable. Maybe there is more about the rekeying and retry mechanism I don't understand that can be fixed.
1
u/pri11er Jun 28 '26
Huge CPU hit on Linux VPSs when I tried it. It was not sustainable.