strongswan: An IPsec implementation for Linux1
strongSwan is an OpenSource IPsec implementation for the Linux operating
system.
It is based on the discontinued FreeS/WAN project and the X.509 patch which
we developped over the last three years. In order to have a stable IPsec
platform to base our future extensions of the X.509 capability on, we
decided to lauch the strongSwan project.
The focus is on:
- simplicity of configuration
- strong encryption and authentication methods
- powerful IPsec policies supporting large and complex VPN networks
strongSwan features includes:
- both on Linux 2.4 (KLIPS) and Linux 2.6 (native IPsec) kernels.
- Fast connection startup and periodic update using ipsec starter
- Automatic insertion and deletion of IPsec policy based firewall rules
- strong 3DES, AES, Serpent, Twofish, or Blowfish encryption
- NAT-Traversal (RFC 3947) and support of virtual IPs and IKE Mode Config
- Dead Peer Detection (DPD, RFC 3706) takes care of dangling tunnels
- Authentication based on X.509 certificates or preshared keys
- Authentication based on X.509 certificates or preshared keys
- Generation of a default self-signed certificate during first strongSwan startup
- Retrieval and local caching of Certificate Revocation Lists via HTTP or LDAP
- Full support of the Online Certificate Status Protocol (OCSP, RCF 2560)
- CA management (OCSP and CRL URIs, default LDAP server)
- Powerful IPsec policies based on wildcards or intermediate CAs
- Group policies based on X.509 attribute certificates (RFC 3281)
- Optional storage of RSA private keys and certificates on a smartcard
- Smartcard access via standardized PKCS #11 interface
- PKCS #11 proxy function offering RSA decryption services via whack
... part of T2,
get it here
URL: https://www.strongswan.org/
Author: Andreas Steffen <andreas [dot] steffen [at] zhwin [dot] ch>
Maintainer: T2 Project <t2 [at] t2-project [dot] org>
License: GPL
Status: Stable
Version: 6.0.2
Remark: Does cross compile (as setup and patched in T2).
Download: http://download.strongswan.org/ strongswan-6.0.2.tar.bz2
T2 source: strongswan.cache
T2 source: strongswan.desc
T2 source: strongswan.init
Build time (on reference hardware): 40% (relative to binutils)2
Installed size (on reference hardware): 2.99 MB, 202 files
Dependencies (build time detected):
bash
bzip2
coreutils
diffutils
findutils
gawk
gmp
grep
linux-header
m4
make
sed
tar
Installed files (on reference hardware):
[show]
etc/rc.d/rcX.d/X85strongswan
etc/strongswan.conf
etc/strongswan.d
etc/strongswan.d/charon
etc/strongswan.d/charon-logging.conf
etc/strongswan.d/charon.conf
etc/strongswan.d/charon/attr.conf
etc/strongswan.d/charon/cmac.conf
etc/strongswan.d/charon/constraints.conf
etc/strongswan.d/charon/counters.conf
etc/strongswan.d/charon/dnskey.conf
etc/strongswan.d/charon/drbg.conf
etc/strongswan.d/charon/eap-aka-3gpp2.conf
etc/strongswan.d/charon/eap-aka.conf
etc/strongswan.d/charon/eap-identity.conf
etc/strongswan.d/charon/eap-md5.conf
etc/strongswan.d/charon/eap-sim-file.conf
etc/strongswan.d/charon/eap-sim.conf
etc/strongswan.d/charon/eap-simaka-pseudonym.conf
etc/strongswan.d/charon/eap-simaka-reauth.conf
etc/strongswan.d/charon/eap-tls.conf
etc/strongswan.d/charon/fips-prf.conf
etc/strongswan.d/charon/gmp.conf
etc/strongswan.d/charon/kdf.conf
etc/strongswan.d/charon/kernel-netlink.conf
etc/strongswan.d/charon/ldap.conf
etc/strongswan.d/charon/mgf1.conf
etc/strongswan.d/charon/nonce.conf
etc/strongswan.d/charon/openssl.conf
etc/strongswan.d/charon/pem.conf
etc/strongswan.d/charon/pgp.conf
etc/strongswan.d/charon/pkcs1.conf
etc/strongswan.d/charon/pkcs7.conf
etc/strongswan.d/charon/pkcs8.conf
etc/strongswan.d/charon/pubkey.conf
etc/strongswan.d/charon/random.conf
etc/strongswan.d/charon/resolve.conf
etc/strongswan.d/charon/revocation.conf
etc/strongswan.d/charon/socket-default.conf
etc/strongswan.d/charon/sshkey.conf
etc/strongswan.d/charon/updown.conf
etc/strongswan.d/charon/vici.conf
etc/strongswan.d/charon/wolfssl.conf
etc/strongswan.d/charon/x509.conf
etc/strongswan.d/charon/xauth-generic.conf
etc/strongswan.d/charon/xcbc.conf
etc/strongswan.d/pki.conf
etc/strongswan.d/swanctl.conf
etc/swanctl
etc/swanctl/conf.d
etc/swanctl/ecdsa
etc/swanctl/pkcs12
etc/swanctl/pkcs8
etc/swanctl/private
etc/swanctl/pubkey
etc/swanctl/rsa
etc/swanctl/swanctl.conf
etc/swanctl/x509
etc/swanctl/x509aa
etc/swanctl/x509ac
etc/swanctl/x509ca
etc/swanctl/x509crl
etc/swanctl/x509ocsp
sbin/init.d/strongswan
usr/bin/pki
usr/lib64/ipsec
usr/lib64/ipsec/libcharon.so
usr/lib64/ipsec/libcharon.so.0
usr/lib64/ipsec/libcharon.so.0.0.0
usr/lib64/ipsec/libsimaka.so
usr/lib64/ipsec/libsimaka.so.0
usr/lib64/ipsec/libsimaka.so.0.0.0
usr/lib64/ipsec/libstrongswan.so
usr/lib64/ipsec/libstrongswan.so.0
usr/lib64/ipsec/libstrongswan.so.0.0.0
usr/lib64/ipsec/libtls.so
usr/lib64/ipsec/libtls.so.0
usr/lib64/ipsec/libtls.so.0.0.0
usr/lib64/ipsec/libvici.so
usr/lib64/ipsec/libvici.so.0
usr/lib64/ipsec/libvici.so.0.0.0
usr/lib64/ipsec/plugins
usr/lib64/ipsec/plugins/libstrongswan-attr.so
usr/lib64/ipsec/plugins/libstrongswan-cmac.so
usr/lib64/ipsec/plugins/libstrongswan-constraints.so
usr/lib64/ipsec/plugins/libstrongswan-counters.so
usr/lib64/ipsec/plugins/libstrongswan-dnskey.so
usr/lib64/ipsec/plugins/libstrongswan-drbg.so
usr/lib64/ipsec/plugins/libstrongswan-eap-aka-3gpp2.so
usr/lib64/ipsec/plugins/libstrongswan-eap-aka.so
usr/lib64/ipsec/plugins/libstrongswan-eap-identity.so
usr/lib64/ipsec/plugins/libstrongswan-eap-md5.so
usr/lib64/ipsec/plugins/libstrongswan-eap-sim-file.so
usr/lib64/ipsec/plugins/libstrongswan-eap-sim.so
usr/lib64/ipsec/plugins/libstrongswan-eap-simaka-pseudonym.so
usr/lib64/ipsec/plugins/libstrongswan-eap-simaka-reauth.so
usr/lib64/ipsec/plugins/libstrongswan-eap-tls.so
usr/lib64/ipsec/plugins/libstrongswan-fips-prf.so
usr/lib64/ipsec/plugins/libstrongswan-gmp.so
usr/lib64/ipsec/plugins/libstrongswan-kdf.so
usr/lib64/ipsec/plugins/libstrongswan-kernel-netlink.so
usr/lib64/ipsec/plugins/libstrongswan-ldap.so
usr/lib64/ipsec/plugins/libstrongswan-mgf1.so
usr/lib64/ipsec/plugins/libstrongswan-nonce.so
usr/lib64/ipsec/plugins/libstrongswan-openssl.so
usr/lib64/ipsec/plugins/libstrongswan-pem.so
usr/lib64/ipsec/plugins/libstrongswan-pgp.so
usr/lib64/ipsec/plugins/libstrongswan-pkcs1.so
usr/lib64/ipsec/plugins/libstrongswan-pkcs7.so
usr/lib64/ipsec/plugins/libstrongswan-pkcs8.so
usr/lib64/ipsec/plugins/libstrongswan-pubkey.so
usr/lib64/ipsec/plugins/libstrongswan-random.so
usr/lib64/ipsec/plugins/libstrongswan-resolve.so
usr/lib64/ipsec/plugins/libstrongswan-revocation.so
usr/lib64/ipsec/plugins/libstrongswan-socket-default.so
usr/lib64/ipsec/plugins/libstrongswan-sshkey.so
usr/lib64/ipsec/plugins/libstrongswan-updown.so
usr/lib64/ipsec/plugins/libstrongswan-vici.so
usr/lib64/ipsec/plugins/libstrongswan-wolfssl.so
usr/lib64/ipsec/plugins/libstrongswan-x509.so
usr/lib64/ipsec/plugins/libstrongswan-xauth-generic.so
usr/lib64/ipsec/plugins/libstrongswan-xcbc.so
usr/libexec/ipsec
usr/libexec/ipsec/_updown
usr/libexec/ipsec/charon
usr/libexec/ipsec/xfrmi
usr/sbin/swanctl
usr/share/man/man1/pki---acert.1
usr/share/man/man1/pki---dn.1
usr/share/man/man1/pki---est.1
usr/share/man/man1/pki---estca.1
usr/share/man/man1/pki---gen.1
usr/share/man/man1/pki---issue.1
usr/share/man/man1/pki---keyid.1
usr/share/man/man1/pki---ocsp.1
usr/share/man/man1/pki---pkcs7.1
usr/share/man/man1/pki---print.1
usr/share/man/man1/pki---pub.1
usr/share/man/man1/pki---req.1
usr/share/man/man1/pki---scep.1
usr/share/man/man1/pki---scepca.1
usr/share/man/man1/pki---self.1
usr/share/man/man1/pki---signcrl.1
usr/share/man/man1/pki---verify.1
usr/share/man/man1/pki.1
usr/share/man/man5/strongswan.conf.5
usr/share/man/man5/swanctl.conf.5
usr/share/man/man8/swanctl.8
usr/share/strongswan
usr/share/strongswan/templates
usr/share/strongswan/templates/config
usr/share/strongswan/templates/config/plugins
usr/share/strongswan/templates/config/plugins/attr.conf
usr/share/strongswan/templates/config/plugins/cmac.conf
usr/share/strongswan/templates/config/plugins/constraints.conf
usr/share/strongswan/templates/config/plugins/counters.conf
usr/share/strongswan/templates/config/plugins/dnskey.conf
usr/share/strongswan/templates/config/plugins/drbg.conf
usr/share/strongswan/templates/config/plugins/eap-aka-3gpp2.conf
usr/share/strongswan/templates/config/plugins/eap-aka.conf
usr/share/strongswan/templates/config/plugins/eap-identity.conf
usr/share/strongswan/templates/config/plugins/eap-md5.conf
usr/share/strongswan/templates/config/plugins/eap-sim-file.conf
usr/share/strongswan/templates/config/plugins/eap-sim.conf
usr/share/strongswan/templates/config/plugins/eap-simaka-pseudonym.conf
usr/share/strongswan/templates/config/plugins/eap-simaka-reauth.conf
usr/share/strongswan/templates/config/plugins/eap-tls.conf
usr/share/strongswan/templates/config/plugins/fips-prf.conf
usr/share/strongswan/templates/config/plugins/gmp.conf
usr/share/strongswan/templates/config/plugins/kdf.conf
usr/share/strongswan/templates/config/plugins/kernel-netlink.conf
usr/share/strongswan/templates/config/plugins/ldap.conf
usr/share/strongswan/templates/config/plugins/mgf1.conf
usr/share/strongswan/templates/config/plugins/nonce.conf
usr/share/strongswan/templates/config/plugins/openssl.conf
usr/share/strongswan/templates/config/plugins/pem.conf
usr/share/strongswan/templates/config/plugins/pgp.conf
usr/share/strongswan/templates/config/plugins/pkcs1.conf
usr/share/strongswan/templates/config/plugins/pkcs7.conf
usr/share/strongswan/templates/config/plugins/pkcs8.conf
usr/share/strongswan/templates/config/plugins/pubkey.conf
usr/share/strongswan/templates/config/plugins/random.conf
usr/share/strongswan/templates/config/plugins/resolve.conf
usr/share/strongswan/templates/config/plugins/revocation.conf
usr/share/strongswan/templates/config/plugins/socket-default.conf
usr/share/strongswan/templates/config/plugins/sshkey.conf
usr/share/strongswan/templates/config/plugins/updown.conf
usr/share/strongswan/templates/config/plugins/vici.conf
usr/share/strongswan/templates/config/plugins/wolfssl.conf
usr/share/strongswan/templates/config/plugins/x509.conf
usr/share/strongswan/templates/config/plugins/xauth-generic.conf
usr/share/strongswan/templates/config/plugins/xcbc.conf
usr/share/strongswan/templates/config/strongswan.conf
usr/share/strongswan/templates/config/strongswan.d
usr/share/strongswan/templates/config/strongswan.d/charon-logging.conf
usr/share/strongswan/templates/config/strongswan.d/charon.conf
usr/share/strongswan/templates/config/strongswan.d/pki.conf
usr/share/strongswan/templates/config/strongswan.d/swanctl.conf
var/adm/dependencies/strongswan
var/adm/descs/strongswan
var/adm/flists/strongswan
var/adm/md5sums/strongswan
var/adm/packages/strongswan
1) This page was automatically generated from the T2
package source. Corrections, such as dead links, URL changes or typos
need to be performed directly on that source.
2) Compatible with Linux From Scratch's
"Standard Build Unit" (SBU).