| Flag | Description |
|---|---|
| static-libs |
| Flag | Description |
|---|---|
| gvisor | Build with gvisor tun stack |
| Flag | Description |
|---|---|
| doc |
| Flag | Description |
|---|---|
| af-alg | (Crypto) Enable AF_ALG Linux crypto API interface, provides ciphers/hashers/hmac/xcbc |
| aikgen | Build AIK generator for TPM 1.2 |
| botan | (Crypto) Enable crypto backend based on Botan, provides RSA/ECDSA/DH/ECDH/X25519/ciphers/hashers/HMAC/RNG |
| caps | |
| charon | Build the IKEv1/IKEv2 keying daemon charon |
| cmd | Build the command line IKE client charon-cmd |
| conftest | Build Suite B conformance test framework |
| curl | |
| debug | |
| eap | (Auth) Enable EAP methods |
| eap-simaka | (Auth) Enable EAP-SIM/AKA support |
| gcrypt | (Crypto) Enable crypto backend based on libgcrypt, provides RSA/DH/ciphers/hashers/rng |
| gmp | (Crypto) Enable RSA/DH crypto backend based on libgmp |
| ldap | |
| mysql | |
| networkmanager | Build NetworkManager backend |
| non-root | Force IKEv1/IKEv2 daemons to normal user privileges. Disable only if you really require superuser privileges. |
| openssl | (Crypto) Enable crypto backend based on OpenSSL, provides RSA/ECDSA/DH/ECDH/ciphers/hashers/HMAC/X.509/CRL/RNG |
| pam | (Auth) XAuth backend that uses PAM modules to verify passwords |
| pkcs11 | (Auth) PKCS#11 smartcard backend |
| pki | Build pki certificate utility |
| scepclient | Build SCEP client tool |
| selinux | |
| soup | libsoup based HTTP fetcher |
| sqlite | |
| strongswan_plugins_ | |
| strongswan_plugins_acert | (Auth) Enable support of X.509 attribute certificates |
| strongswan_plugins_addrblock | (Auth) Enable narrowing traffic selectors to RFC 3779 address blocks in X.509 certificates |
| strongswan_plugins_aes | (Crypto) Enable AES software implementation |
| strongswan_plugins_aesni | (Crypto) Enable Intel AES-NI |
| strongswan_plugins_agent | (Auth) Enable RSA/ECDSA private key backend connecting to SSH-Agent |
| strongswan_plugins_attr | Provides IKE attributes configured in strongswan.conf |
| strongswan_plugins_bliss | (Crypto) Enable Bimodal Lattice Signature Scheme (BLISS) post-quantum computer signature scheme |
| strongswan_plugins_blowfish | (Crypto) (Deprecated) Enable Blowfish cipher software implementation |
| strongswan_plugins_bypass-lan | Support of automatically installing and updating bypass policies for locally attached subnets |
| strongswan_plugins_ccm | (Crypto) Enable CCM cipher mode wrapper |
| strongswan_plugins_certexpire | Support of exporting expiration dates of used certificates |
| strongswan_plugins_chapoly | (Crypto) Enable ChaCha20/Poly1305 AEAD implementation and ChaCha20 XOF |
| strongswan_plugins_cmac | (Crypto) Enable CMAC cipher mode wrapper |
| strongswan_plugins_connmark | Plugin using Netfilter conntrack marks to handle multiple transport mode clients |
| strongswan_plugins_constraints | (Auth) Enable X.509 certificate advanced constraint checking |
| strongswan_plugins_coupling | (Auth) Enable permanent peer certificate coupling |
| strongswan_plugins_ctr | (Crypto) Enable CTR cipher mode wrapper |
| strongswan_plugins_curve25519 | (Crypto) Enable X25519 DH group and Ed25519 public key algorithms |
| strongswan_plugins_des | (Crypto) (Deprecated) Enable DES/3DES cipher software implementation |
| strongswan_plugins_dhcp | Support of requesting virtual IP address from a DHCP server |
| strongswan_plugins_dnscert | (Auth) Plugin providing authentication via CERT RRs protected by DNSSEC |
| strongswan_plugins_duplicheck | Support of advanced duplicate checking with liveness test and notifications |
| strongswan_plugins_error-notify | Enable notification about errors via UNIX socket |
| strongswan_plugins_ext-auth | (Auth) Enable invoking an external script for custom authorization rules |
| strongswan_plugins_farp | Enable faking ARP responses for requests to a virtual IP address assigned to a peer |
| strongswan_plugins_files | Enable fetcher for local file:// URIs |
| strongswan_plugins_forecast | Plugin providing multicast and broadcast forwarding |
| strongswan_plugins_gcm | (Crypto) Enable GCM cipher mode wrapper |
| strongswan_plugins_ha | Enable High-Availability clustering |
| strongswan_plugins_hmac | (Crypto) Enable HMAC wrapper using various hashers |
| strongswan_plugins_ipseckey | (Auth) Plugin providing authentication via IPSECKEY RRs protected by DNSSEC |
| strongswan_plugins_kernel-libipsec | Enable IPsec "kernel" interface in user-space using libipsec |
| strongswan_plugins_kernel-pfkey | IPsec kernel interface using PF_KEY |
| strongswan_plugins_led | Support of letting Linux LED subsystem LEDs blink on IKE activity |
| strongswan_plugins_lookip | Support virtual IP lookup facility using a UNIX socket |
| strongswan_plugins_md5 | (Crypto) (Deprecated) Enable MD5 hasher software implementation |
| strongswan_plugins_newhope | (Crypto) Enable key exchange based on post-quantum computer New Hope algorithm |
| strongswan_plugins_ntru | (Crypto) Enable key exchange based on post-quantum computer NTRU encryption |
| strongswan_plugins_p-cscf | Plugin that requests P-CSCF server addresses from an ePDG via IKEv2 |
| strongswan_plugins_padlock | (Crypto) Enable VIA padlock crypto backend, provides AES128/SHA1 |
| strongswan_plugins_radattr | Plugin to inject and process custom RADIUS attributes as IKEv2 client |
| strongswan_plugins_random | (Crypto) Enable RNG reading from /dev/[u]random |
| strongswan_plugins_rc2 | (Crypto) Enable RC2 cipher software implementation |
| strongswan_plugins_rdrand | (Crypto) Enable high quality / high performance random source using the Intel rdrand instruction |
| strongswan_plugins_resolve | Enable writing name servers received via IKE to a resolv.conf file or installs them via resolvconf(8) |
| strongswan_plugins_revocation | (Auth) Enable X.509 CRL/OCSP revocation checking |
| strongswan_plugins_save-keys | Development/Debugging plugin that saves IKE and/or ESP keys to files compatible with Wireshark |
| strongswan_plugins_sha1 | (Crypto) Enable SHA1 hasher software implementation |
| strongswan_plugins_sha2 | (Crypto) Enable SHA2_224/SHA2_256/SHA2_384/SHA2_512 hasher software implementation |
| strongswan_plugins_sha3 | (Crypto) Enable SHA3_224/SHA3_256/SHA3_384/SHA3_512 hasher software implementation and SHAKE128/SHAKE256 XOF |
| strongswan_plugins_socket-default | Default socket implementation for IKE messages |
| strongswan_plugins_socket-dynamic | Dynamic binding socket implementation, capable of sending IKE messages on any port |
| strongswan_plugins_systime-fix | Handle invalid system time when checking certificates |
| strongswan_plugins_tpm | (Auth) Access persistent RSA and ECDSA private keys bound to Trusted Platform Module 2.0 |
| strongswan_plugins_unity | Enable Cisco Unity extensions for IKEv1 |
| strongswan_plugins_updown | Enable shell script invocation during tunnel up/down events |
| strongswan_plugins_whitelist | (Auth) Enable checking authenticated identities against a whitelist |
| strongswan_plugins_xauth-generic | (Auth) Generic XAuth backend that provides passwords from ipsec.secrets and other credential sets |
| strongswan_plugins_xauth-noauth | (Auth) XAuth backend that does not do any authentication |
| strongswan_plugins_xcbc | (Crypto) Enable XCBC wrapper using various ciphers |
| swanctl | Build swanctl configuration and control tool |
| systemd | Build systemd specific IKE daemon charon-systemd |
| tnc | Support Trusted Network Connect |
| unbound | DNSSEC enabled resolver using libunbound |