Apocrypha

strongswan

IPsec-based VPN solution, supporting IKEv1/IKEv2 and MOBIKE

StrongSwan is direct descendant of the discontinued FreeS/WAN project. As an IPsec based VPN solution which is focused on security and ease of use, it fully implements the IKEv1/IKEv2 protocols, MOBIKE, NAT-Traversal via UDP encapsulation (incl. port floating) and Dead Peer Detection. It also fully supports the Linux 2.6 IPsec stack, IPv6, certificates/keys on Smartcards and virtual IP address pools.

⚠ Security advisories affect this package: GLSA 202507-04, GLSA 202405-08

Available in

OverlayNewestEbuildsLast activity
gentoo gitweb ↗ 6.0.7 5 15 h details ›
fol4 GitLab ↗ 5.8.1_rc1 1 22 d details ›
moexiami GitHub ↗ 5.7.1-r2 1 12 mo details ›

Versions & arches

VersionOverlay amd64arm64x86ppc64riscvarmppc Committed
6.0.7 gentoo amd64 stable arm64 testing x86 testing ppc64 testing riscv testing arm testing ppc testing view · download · history ↗
6.0.6 gentoo amd64 testing arm64 testing x86 testing ppc64 testing riscv testing arm testing ppc testing view · download · history ↗
6.0.4-r1 gentoo amd64 testing arm64 testing x86 testing ppc64 testing riscv testing arm testing ppc testing view · download · history ↗
6.0.4 gentoo amd64 testing arm64 testing x86 testing ppc64 testing riscv testing arm testing ppc testing view · download · history ↗
6.0.3 gentoo amd64 stable arm64 testing x86 stable ppc64 testing riscv testing arm testing ppc testing view · download · history ↗
5.8.1_rc1 fol4 amd64 stable arm64 untested x86 stable ppc64 testing riscv untested arm stable ppc stable 22 mo view · download · history ↗
5.7.1-r2 moexiami amd64 testing arm64 untested x86 testing ppc64 testing riscv untested arm testing ppc testing 12 mo view · download · history ↗

Use flags of 6.0.7

  • +caps Use Linux capabilities library to control privilege
  • curl Add support for client-side URL transfer library
  • +constraints Enable advanced X.509 constraint checking plugin
  • debug Enable extra debug codepaths, like asserts and extra output. If you want to get meaningful backtraces see https://wiki.gentoo.org/wiki/Project:Quality_Assurance/Backtraces
  • dhcp Enable server support for querying virtual IP addresses for clients from a DHCP server. (IKEv2 only)
  • eap Enable support for the different EAP modules that are supported
  • farp Enable faking of ARP responses for virtual IP addresses assigned to clients (IKEv2 only)
  • gcrypt Enable dev-libs/libgcrypt plugin which provides 3DES, AES, Blowfish, Camellia, CAST, DES, Serpent and Twofish ciphers along with MD4, MD5 and SHA1/2 hash algorithms, RSA and DH groups 1,2,5,14-18 and 22-24(4.4+). Also includes a software random number generator.
  • +gmp Add support for dev-libs/gmp (GNU MP library)
  • ldap Add LDAP support (Lightweight Directory Access Protocol)
  • mysql Add mySQL Database support
  • networkmanager Enable net-misc/networkmanager support
  • +non-root Force IKEv1/IKEv2 daemons to normal user privileges. This might impose some restrictions mainly to the IKEv1 daemon. Disable only if you really require superuser privileges.
  • +openssl Enable dev-libs/openssl plugin which is required for Elliptic Curve Cryptography (DH groups 19-21,25,26) and ECDSA. Also provides 3DES, AES, Blowfish, Camellia, CAST, DES, IDEA and RC5 ciphers along with MD2, MD4, MD5 and SHA1/2 hash algorithms, RSA and DH groups 1,2,5,14-18 and 22-24(4.4+) dev-libs/openssl has to be compiled with USE="-bindist".
  • selinux !!internal use only!! Security Enhanced Linux support, this must be set by the selinux profile or breakage will occur
  • sqlite Add support for sqlite - embedded sql database
  • systemd Enable use of systemd-specific libraries and features like socket activation or session tracking
  • pam Add support for PAM (Pluggable Authentication Modules) - DANGEROUS to arbitrarily flip
  • pkcs11 Enable pkcs11 support
  • +strongswan_plugins_aes Enable support for the aes plugin
  • +strongswan_plugins_cmac Enable support for the cmac plugin
  • +strongswan_plugins_curve25519 Enable support for X25519 DH group and Ed25519 public key uthentication
  • +strongswan_plugins_des Enable DES/3DES cipher implementation
  • +strongswan_plugins_dnskey Enable support for parsing DNS public keys
  • +strongswan_plugins_drbg Enable support for the drgb plugin
  • +strongswan_plugins_eap-radius Enable EAP Radius plugin
  • +strongswan_plugins_fips-prf Enable support for the fips-prf plugin
  • +strongswan_plugins_gcm Enable support for the gcm plugin
  • +strongswan_plugins_hmac Enable support for the hmac plugin
  • +strongswan_plugins_led Enable support for the led plugin
  • +strongswan_plugins_lookip Enable support for the lookip plugin
  • +strongswan_plugins_md5 Enable support for the md5 plugin
  • +strongswan_plugins_nonce Enable support the nonce plugin
  • +strongswan_plugins_pem Enable support for the pem plugin
  • +strongswan_plugins_pgp Enable support for the pgp plugin
  • +strongswan_plugins_pkcs1 Enable pkcs1 support
  • +strongswan_plugins_pkcs7 Enable pkcs7 support
  • +strongswan_plugins_pkcs8 Enable pkcs8 support
  • +strongswan_plugins_pkcs12 Enable pkcs12 support
  • +strongswan_plugins_pubkey Enable wrapper to handle raw public keys
  • +strongswan_plugins_random Enable RNG support with /dev/[u]random
  • +strongswan_plugins_rc2 Enable plugin for RC2 support
  • +strongswan_plugins_revocation Enable X.509 CRL/OCSP revocation checking
  • +strongswan_plugins_sha1 Enable plugin for SHA1 support
  • +strongswan_plugins_sha2 Enable plugin for SHA2 support
  • +strongswan_plugins_sshkey Enable SSH key decoding routines
  • +strongswan_plugins_systime-fix Enable support for the systime-fix plugin
  • +strongswan_plugins_stroke Deprecated stroke configuration/control backend, to use with ipsec script and starter
  • +strongswan_plugins_unity Enable support for the unity plugin
  • +strongswan_plugins_vici Enable support for the vici plugin
  • +strongswan_plugins_x509 Enable plugin for advanced X.509 functionality
  • +strongswan_plugins_xcbc Enable support for XCBC plugin
  • strongswan_plugins_kdf Enable support for the kdf plugin
  • strongswan_plugins_acert Enable support for X.509 attribute certificates
  • strongswan_plugins_af-alg Enable support for the AF_ALG Linux kernel crypto API
  • strongswan_plugins_agent Enable support for RSA/ECDSA private keys
  • strongswan_plugins_addrblock Enable support for the addrblock crypto plugin
  • strongswan_plugins_aesni Enable support for Intel AES-NI crypto plugin
  • strongswan_plugins_botan Enable support for the botan library plugin
  • strongswan_plugins_blowfish Enable support for the blowfish plugin
  • strongswan_plugins_bypass-lan Enable support for the bypass-lan plugin
  • strongswan_plugins_ccm Enable support for the ccm plugin
  • strongswan_plugins_chapoly Enable ChaCha20/Poly1305 AEAD implementation and ChaCha20 XOF plugin
  • strongswan_plugins_connmark Enable connmark plugin using conntrack based marks to select return path SA
  • strongswan_plugins_ctr Enable support for the ctr plugin
  • strongswan_plugins_error-notify Enable support for the error-notify plugin
  • strongswan_plugins_forecast Enable multicast and broadcast forwarding plugin
  • strongswan_plugins_files Enable support for local file:// URIs
  • strongswan_plugins_ha Enable support for the ha plugin
  • strongswan_plugins_ipseckey Enable support for the ipseckey plugin
  • strongswan_plugins_md4 Enable support for the md4 plugin
  • strongswan_plugins_mgf1 Enable support for the mgf1 plugin
  • strongswan_plugins_openxpki Enable OCSP responder accessing OpenXPKI MySQL/MariaDB certificate database
  • strongswan_plugins_padlock Enable support for the padlock plugin
  • strongswan_plugins_rdrand Enable support for the rdrand plugin
  • strongswan_plugins_save-keys Enable plugin that saves IKE and/or ESP keys to files compatible with Wireshark (for debugging)
  • strongswan_plugins_sha3 Enable plugin for SHA3 support
  • strongswan_plugins_soup Enable libsoup based HTTP fetcher
  • strongswan_plugins_test-vectors Enable set of test vectors for various algorithms
  • strongswan_plugins_unbound Enable support for the unbound plugin
  • strongswan_plugins_whitelist Enable support for the whitelist plugin
  • strongswan_plugins_xauth-noauth Enable support for the xauth-noauth plugin
  • verify-sig Verify upstream signatures on distfiles

Runtime dependencies of 6.0.7

show 61 lines
non-root? (
)
gmp? (
)
gcrypt? (
)
caps? (
)
curl? (
)
ldap? (
)
openssl? (
)
mysql? (
)
sqlite? (
)
systemd? (
)
networkmanager? (
)
pam? (
)
strongswan_plugins_botan? (
)
strongswan_plugins_connmark? (
)
strongswan_plugins_forecast? (
)
strongswan_plugins_soup? (
)
strongswan_plugins_unbound? (
)
selinux? (
)