kernlpanic@dennis-eisele.de Dennis Eisele rndxelement@protonmail.com Philipp Rösner proxy-maint@gentoo.org Proxy Maintainers StrongSwan is direct descendant of the discontinued FreeS/WAN project. As an IPsec based VPN solution which is focused on security and ease of use, it fully implements the IKEv1/IKEv2 protocols, MOBIKE, NAT-Traversal via UDP encapsulation (incl. port floating) and Dead Peer Detection. It also fully supports the Linux 2.6 IPsec stack, IPv6, certificates/keys on Smartcards and virtual IP address pools. Enable advanced X.509 constraint checking plugin Enable server support for querying virtual IP addresses for clients from a DHCP server. (IKEv2 only) Enable support for the different EAP modules that are supported Enable faking of ARP responses for virtual IP addresses assigned to clients (IKEv2 only) Enable dev-libs/libgcrypt plugin which provides 3DES, AES, Blowfish, Camellia, CAST, DES, Serpent and Twofish ciphers along with MD4, MD5 and SHA1/2 hash algorithms, RSA and DH groups 1,2,5,14-18 and 22-24(4.4+). Also includes a software random number generator. Force IKEv1/IKEv2 daemons to normal user privileges. This might impose some restrictions mainly to the IKEv1 daemon. Disable only if you really require superuser privileges. Enable dev-libs/openssl plugin which is required for Elliptic Curve Cryptography (DH groups 19-21,25,26) and ECDSA. Also provides 3DES, AES, Blowfish, Camellia, CAST, DES, IDEA and RC5 ciphers along with MD2, MD4, MD5 and SHA1/2 hash algorithms, RSA and DH groups 1,2,5,14-18 and 22-24(4.4+) dev-libs/openssl has to be compiled with USE="-bindist". Enable pkcs11 support Enable support for X.509 attribute certificates Enable support for the addrblock crypto plugin Enable support for the aes plugin Enable support for Intel AES-NI crypto plugin Enable support for the AF_ALG Linux kernel crypto API Enable support for RSA/ECDSA private keys Enable support for the blowfish plugin Enable support for the botan library plugin Enable support for the bypass-lan plugin Enable support for the ccm plugin Enable ChaCha20/Poly1305 AEAD implementation and ChaCha20 XOF plugin Enable support for the cmac plugin Enable connmark plugin using conntrack based marks to select return path SA Enable support for the ctr plugin Enable support for X25519 DH group and Ed25519 public key uthentication Enable DES/3DES cipher implementation Enable support for parsing DNS public keys Enable support for the drgb plugin Enable EAP Radius plugin Enable support for the error-notify plugin Enable support for local file:// URIs Enable support for the fips-prf plugin Enable multicast and broadcast forwarding plugin Enable support for the gcm plugin Enable support for the ha plugin Enable support for the hmac plugin Enable support for the ipseckey plugin Enable support for the kdf plugin Enable support for the led plugin Enable support for the lookip plugin Enable support for the md4 plugin Enable support for the md5 plugin Enable support for the mgf1 plugin Enable support the nonce plugin Enable OCSP responder accessing OpenXPKI MySQL/MariaDB certificate database Enable support for the padlock plugin Enable support for the pem plugin Enable support for the pgp plugin Enable pkcs1 support Enable pkcs12 support Enable pkcs7 support Enable pkcs8 support Enable wrapper to handle raw public keys Enable RNG support with /dev/[u]random Enable plugin for RC2 support Enable support for the rdrand plugin Enable X.509 CRL/OCSP revocation checking Enable plugin that saves IKE and/or ESP keys to files compatible with Wireshark (for debugging) Enable plugin for SHA1 support Enable plugin for SHA2 support Enable plugin for SHA3 support Deprecated stroke configuration/control backend, to use with ipsec script and starter Enable libsoup based HTTP fetcher Enable SSH key decoding routines Enable support for the systime-fix plugin Enable set of test vectors for various algorithms Enable support for the unbound plugin Enable support for the unity plugin Enable support for the vici plugin Enable support for the whitelist plugin Enable plugin for advanced X.509 functionality Enable support for the xauth-noauth plugin Enable support for XCBC plugin cpe:/a:strongswan:strongswan strongswan/strongswan