strongswan.conf 657 B

12345678910111213141516171819202122232425262728293031
  1. # /etc/strongswan.conf - strongSwan configuration file
  2. charon-systemd {
  3. load = random nonce aes sha1 sha2 md5 pem pkcs1 gmp hmac x509 revocation curl vici kernel-netlink socket-default eap-identity eap-ttls eap-md5 eap-tnc tnc-tnccs tnccs-dynamic tnccs-11 tnccs-20 tnc-imv updown
  4. multiple_authentication=no
  5. integrity_test = yes
  6. syslog {
  7. daemon {
  8. tnc = 3
  9. imv = 3
  10. }
  11. }
  12. plugins {
  13. eap-ttls {
  14. phase2_method = md5
  15. phase2_piggyback = yes
  16. phase2_tnc = yes
  17. phase2_tnc_method = tnc
  18. }
  19. eap-tnc {
  20. protocol = tnccs-dynamic
  21. }
  22. }
  23. }
  24. libtls {
  25. suites = TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
  26. }