OpenSource IPsec-based VPN Solution
StrongSwan is an OpenSource IPsec-based VPN Solution for Linux
* runs both on Linux 2.4 (KLIPS IPsec) and Linux 2.6 (NETKEY IPsec) kernels
* implements both the IKEv1 and IKEv2 (RFC 4306) key exchange protocols
* Fully tested support of IPv6 IPsec tunnel and transport connections
* Dynamical IP address and interface update with IKEv2 MOBIKE (RFC 4555)
* Automatic insertion and deletion of IPsec-policy-based firewall rules
* Strong 128/192/256 bit AES or Camellia encryption, 3DES support
* NAT-Traversal via UDP encapsulation and port floating (RFC 3947)
* Dead Peer Detection (DPD, RFC 3706) takes care of dangling tunnels
* Static virtual IPs and IKEv1 ModeConfig pull and push modes
* XAUTH server and client functionality on top of IKEv1 Main Mode authentication
* Virtual IP address pool managed by IKE daemon or SQL database
* Secure IKEv2 EAP user authentication (EAP-SIM, EAP-AKA, EAP-MSCHAPv2, etc.)
* Optional relaying of EAP messages to AAA server via EAP-RADIUS plugin
* Support of IKEv2 Multiple Authentication Exchanges (RFC 4739)
* Authentication based on X.509 certificates or preshared keys
* Generation of a default self-signed certificate during first strongSwan startup
* Retrieval and local caching of Certificate Revocation Lists via HTTP or LDAP
* Full support of the Online Certificate Status Protocol (OCSP, RCF 2560).
* CA management (OCSP and CRL URIs, default LDAP server)
* Powerful IPsec policies based on wildcards or intermediate CAs
* Group policies based on X.509 attribute certificates (RFC 3281)
* Storage of RSA private keys and certificates on a smartcard (PKCS #11 interface)
* Modular plugins for crypto algorithms and relational database interfaces
* Support of elliptic curve DH groups and ECDSA certificates (Suite B, RFC 4869)
* Optional built-in integrity and crypto tests for plugins and libraries
* Smooth Linux desktop integration via the strongSwan NetworkManager applet
This package triggers the installation of both, IKEv1 and IKEv2 daemons.
- Sources inherited from project SUSE:SLE-12:Update
- Download package
-
Checkout Package
osc -A https://api.opensuse.org checkout SUSE:SLE-12-SP2:GA/strongswan && cd $_
- Create Badge
Source Files
Filename | Size | Changed |
---|---|---|
0005-restore-registration-algorithm-order.bug89751 |
0000011815 11.5 KB | |
0006-strongswan-5.1.2-5.2.1_modp_custom.CVE-2014-9 |
0000006246 6.1 KB | |
0008-strongswan-pkifix.918474.patch | 0000000571 571 Bytes | |
0009-strongswan-5.1.0-5.3.1_enforce_remote_auth.pa |
0000003032 2.96 KB | |
README.SUSE | 0000002342 2.29 KB | |
fips-enforce.conf | 0000000742 742 Bytes | |
fipscheck.sh.in | 0000001934 1.89 KB | |
strongswan-5.1.3-rpmlintrc | 0000000428 428 Bytes | |
strongswan-5.1.3.tar.bz2 | 0003807212 3.63 MB | |
strongswan-5.1.3.tar.bz2.sig | 0000000665 665 Bytes | |
strongswan-ikev2-cavs.patch | 0000016025 15.6 KB | |
strongswan-ikev2-cavs_driver.pl | 0000005580 5.45 KB | |
strongswan.changes | 0000068743 67.1 KB | |
strongswan.init.in | 0000008747 8.54 KB | |
strongswan.keyring | 0000003085 3.01 KB | |
strongswan.spec | 0000039658 38.7 KB | |
strongswan_fipscheck.patch | 0000001909 1.86 KB | |
strongswan_fipsfilter.patch | 0000007869 7.68 KB | |
strongswan_ipsec_service.patch | 0000000198 198 Bytes | |
strongswan_modprobe_syslog.patch | 0000001869 1.83 KB |
Revision 3 (latest revision is 12)
Set link to strongswan.657 via maintenance_release request
Comments 0