# /etc/strongswan.conf - strongSwan configuration file swanctl { load = pem pkcs1 pubkey openssl random } charon-systemd { load = random nonce openssl pem pkcs1 revocation kernel-netlink socket-default updown vici # delete rekeyed CHILD_SAs quickly so we can reauthenticate the IKE_SA delete_rekeyed_delay = 1 syslog { daemon { cfg = 2 } } }