mirror of
https://github.com/strongswan/strongswan.git
synced 2025-10-03 00:00:24 -04:00
We now support OpenSSL's implementation in the openssl plugin. This makes sure our plugin is used on at least one of the hosts if we ever switch to an OpenSSL version that supports ML-KEM. In the ikev2/rw-mlkem scenario the logic is reversed. There the ml plugin is preferred on moon to test the responder side (and carol for the initiator) and dave will switch to OpenSSL if it ever provides ML-KEM.
12 lines
281 B
Plaintext
Executable File
12 lines
281 B
Plaintext
Executable File
# /etc/strongswan.conf - strongSwan configuration file
|
|
|
|
swanctl {
|
|
load = pem pkcs1 x509 revocation constraints pubkey openssl random
|
|
}
|
|
|
|
charon-systemd {
|
|
load = nonce ml openssl pem revocation constraints pubkey curl kernel-netlink socket-default updown vici
|
|
|
|
rsa_pss = yes
|
|
}
|