strongswan.conf 890 B

1234567891011121314151617181920212223242526272829303132333435363738394041424344
  1. # /etc/strongswan.conf - strongSwan configuration file
  2. charon-systemd {
  3. load = random nonce aes sha1 sha2 md5 gmp hmac pem pkcs1 x509 revocation curl vici kernel-netlink socket-default eap-identity eap-ttls eap-md5 eap-tnc tnc-imv tnc-tnccs tnccs-20 updown sqlite
  4. multiple_authentication = no
  5. syslog {
  6. daemon {
  7. tnc = 3
  8. imv = 3
  9. pts = 3
  10. }
  11. }
  12. plugins {
  13. eap-ttls {
  14. phase2_method = md5
  15. phase2_piggyback = yes
  16. phase2_tnc = yes
  17. }
  18. }
  19. }
  20. libtls {
  21. suites = TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
  22. }
  23. libimcv {
  24. database = sqlite:///etc/db.d/config.db
  25. policy_script = /usr/local/libexec/ipsec/imv_policy_manager
  26. plugins {
  27. imv-attestation {
  28. hash_algorithm = sha1
  29. dh_group = modp2048
  30. mandatory_dh_groups = no
  31. }
  32. }
  33. }
  34. attest {
  35. load = random nonce openssl sqlite
  36. database = sqlite:///etc/db.d/config.db
  37. }