# /etc/strongswan.conf - strongSwan configuration file swanctl { load = random pem pkcs1 openssl revocation constraints pubkey } charon-systemd { load = random nonce openssl pem pkcs1 revocation constraints pubkey curl eap-tls kernel-netlink socket-default updown vici } libtls { version_max = 1.3 }