# /etc/strongswan.conf - strongSwan configuration file

charon-systemd {
  load = random nonce x509 openssl pem pkcs1 revocation curl vici kernel-netlink socket-default eap-identity eap-ttls eap-tnc tnc-tnccs tnc-imc tnc-imv tnccs-20 updown

  multiple_authentication = no
  syslog {
    daemon {
      tnc = 2
      imc = 2
      imv = 2
    }
  }
  plugins {
    eap-ttls {
      request_peer_auth = yes
      phase2_piggyback = yes
      phase2_tnc =yes
    }
    tnccs-20 {
      mutual = yes
    }
  }
}

libtls {
  suites = TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
}

libimcv {
  plugins {
    imc-test {
      command = none
    }
    imv-test {
      rounds = 1
    }
  }
}