We could make the same change for charon (actually setting it for charon in strongswan.conf.testing would work for charon-systemd too), however, there are dozens of test cases that currently set charondebug in ipsec.conf.
18 lines
389 B
Plaintext
18 lines
389 B
Plaintext
# /etc/strongswan.conf - strongSwan configuration file
|
|
|
|
charon-systemd {
|
|
load = random nonce aes sha1 sha2 pem pkcs1 dnskey pubkey unbound ipseckey curve25519 gmp hmac vici kernel-netlink socket-default updown attr
|
|
|
|
dns1 = PH_IP_WINNETOU
|
|
dns2 = PH_IP_VENUS
|
|
|
|
plugins {
|
|
ipseckey {
|
|
enable = yes
|
|
}
|
|
unbound {
|
|
trust_anchors = /etc/swanctl/dnssec.keys
|
|
}
|
|
}
|
|
}
|