We could make the same change for charon (actually setting it for charon in strongswan.conf.testing would work for charon-systemd too), however, there are dozens of test cases that currently set charondebug in ipsec.conf.
13 lines
372 B
Plaintext
Executable File
13 lines
372 B
Plaintext
Executable File
# /etc/strongswan.conf - strongSwan configuration file
|
|
|
|
swanctl {
|
|
load = pem pkcs1 x509 revocation constraints pubkey openssl mgf1 bliss random
|
|
}
|
|
|
|
charon-systemd {
|
|
load = random nonce sha1 sha2 sha3 aes chapoly newhope mgf1 bliss hmac pem pkcs1 x509 revocation pubkey gmp curl kernel-netlink socket-default updown vici
|
|
|
|
send_vendor_id = yes
|
|
fragment_size = 1500
|
|
}
|