Local USE flags

app-crypt

libscrypt

Flag Description
static-libs

net-proxy

mihomo

Flag Description
gvisor Build with gvisor tun stack

shadowsocks-simple-obfs

Flag Description
doc

net-vpn

strongswan

Flag Description
af-alg (Crypto) Enable AF_ALG Linux crypto API interface, provides ciphers/hashers/hmac/xcbc
aikgen Build AIK generator for TPM 1.2
botan (Crypto) Enable crypto backend based on Botan, provides RSA/ECDSA/DH/ECDH/X25519/ciphers/hashers/HMAC/RNG
caps
charon Build the IKEv1/IKEv2 keying daemon charon
cmd Build the command line IKE client charon-cmd
conftest Build Suite B conformance test framework
curl
debug
eap (Auth) Enable EAP methods
eap-simaka (Auth) Enable EAP-SIM/AKA support
gcrypt (Crypto) Enable crypto backend based on libgcrypt, provides RSA/DH/ciphers/hashers/rng
gmp (Crypto) Enable RSA/DH crypto backend based on libgmp
ldap
mysql
networkmanager Build NetworkManager backend
non-root Force IKEv1/IKEv2 daemons to normal user privileges. Disable only if you really require superuser privileges.
openssl (Crypto) Enable crypto backend based on OpenSSL, provides RSA/ECDSA/DH/ECDH/ciphers/hashers/HMAC/X.509/CRL/RNG
pam (Auth) XAuth backend that uses PAM modules to verify passwords
pkcs11 (Auth) PKCS#11 smartcard backend
pki Build pki certificate utility
scepclient Build SCEP client tool
selinux
soup libsoup based HTTP fetcher
sqlite
strongswan_plugins_
strongswan_plugins_acert (Auth) Enable support of X.509 attribute certificates
strongswan_plugins_addrblock (Auth) Enable narrowing traffic selectors to RFC 3779 address blocks in X.509 certificates
strongswan_plugins_aes (Crypto) Enable AES software implementation
strongswan_plugins_aesni (Crypto) Enable Intel AES-NI
strongswan_plugins_agent (Auth) Enable RSA/ECDSA private key backend connecting to SSH-Agent
strongswan_plugins_attr Provides IKE attributes configured in strongswan.conf
strongswan_plugins_bliss (Crypto) Enable Bimodal Lattice Signature Scheme (BLISS) post-quantum computer signature scheme
strongswan_plugins_blowfish (Crypto) (Deprecated) Enable Blowfish cipher software implementation
strongswan_plugins_bypass-lan Support of automatically installing and updating bypass policies for locally attached subnets
strongswan_plugins_ccm (Crypto) Enable CCM cipher mode wrapper
strongswan_plugins_certexpire Support of exporting expiration dates of used certificates
strongswan_plugins_chapoly (Crypto) Enable ChaCha20/Poly1305 AEAD implementation and ChaCha20 XOF
strongswan_plugins_cmac (Crypto) Enable CMAC cipher mode wrapper
strongswan_plugins_connmark Plugin using Netfilter conntrack marks to handle multiple transport mode clients
strongswan_plugins_constraints (Auth) Enable X.509 certificate advanced constraint checking
strongswan_plugins_coupling (Auth) Enable permanent peer certificate coupling
strongswan_plugins_ctr (Crypto) Enable CTR cipher mode wrapper
strongswan_plugins_curve25519 (Crypto) Enable X25519 DH group and Ed25519 public key algorithms
strongswan_plugins_des (Crypto) (Deprecated) Enable DES/3DES cipher software implementation
strongswan_plugins_dhcp Support of requesting virtual IP address from a DHCP server
strongswan_plugins_dnscert (Auth) Plugin providing authentication via CERT RRs protected by DNSSEC
strongswan_plugins_duplicheck Support of advanced duplicate checking with liveness test and notifications
strongswan_plugins_error-notify Enable notification about errors via UNIX socket
strongswan_plugins_ext-auth (Auth) Enable invoking an external script for custom authorization rules
strongswan_plugins_farp Enable faking ARP responses for requests to a virtual IP address assigned to a peer
strongswan_plugins_files Enable fetcher for local file:// URIs
strongswan_plugins_forecast Plugin providing multicast and broadcast forwarding
strongswan_plugins_gcm (Crypto) Enable GCM cipher mode wrapper
strongswan_plugins_ha Enable High-Availability clustering
strongswan_plugins_hmac (Crypto) Enable HMAC wrapper using various hashers
strongswan_plugins_ipseckey (Auth) Plugin providing authentication via IPSECKEY RRs protected by DNSSEC
strongswan_plugins_kernel-libipsec Enable IPsec "kernel" interface in user-space using libipsec
strongswan_plugins_kernel-pfkey IPsec kernel interface using PF_KEY
strongswan_plugins_led Support of letting Linux LED subsystem LEDs blink on IKE activity
strongswan_plugins_lookip Support virtual IP lookup facility using a UNIX socket
strongswan_plugins_md5 (Crypto) (Deprecated) Enable MD5 hasher software implementation
strongswan_plugins_newhope (Crypto) Enable key exchange based on post-quantum computer New Hope algorithm
strongswan_plugins_ntru (Crypto) Enable key exchange based on post-quantum computer NTRU encryption
strongswan_plugins_p-cscf Plugin that requests P-CSCF server addresses from an ePDG via IKEv2
strongswan_plugins_padlock (Crypto) Enable VIA padlock crypto backend, provides AES128/SHA1
strongswan_plugins_radattr Plugin to inject and process custom RADIUS attributes as IKEv2 client
strongswan_plugins_random (Crypto) Enable RNG reading from /dev/[u]random
strongswan_plugins_rc2 (Crypto) Enable RC2 cipher software implementation
strongswan_plugins_rdrand (Crypto) Enable high quality / high performance random source using the Intel rdrand instruction
strongswan_plugins_resolve Enable writing name servers received via IKE to a resolv.conf file or installs them via resolvconf(8)
strongswan_plugins_revocation (Auth) Enable X.509 CRL/OCSP revocation checking
strongswan_plugins_save-keys Development/Debugging plugin that saves IKE and/or ESP keys to files compatible with Wireshark
strongswan_plugins_sha1 (Crypto) Enable SHA1 hasher software implementation
strongswan_plugins_sha2 (Crypto) Enable SHA2_224/SHA2_256/SHA2_384/SHA2_512 hasher software implementation
strongswan_plugins_sha3 (Crypto) Enable SHA3_224/SHA3_256/SHA3_384/SHA3_512 hasher software implementation and SHAKE128/SHAKE256 XOF
strongswan_plugins_socket-default Default socket implementation for IKE messages
strongswan_plugins_socket-dynamic Dynamic binding socket implementation, capable of sending IKE messages on any port
strongswan_plugins_systime-fix Handle invalid system time when checking certificates
strongswan_plugins_tpm (Auth) Access persistent RSA and ECDSA private keys bound to Trusted Platform Module 2.0
strongswan_plugins_unity Enable Cisco Unity extensions for IKEv1
strongswan_plugins_updown Enable shell script invocation during tunnel up/down events
strongswan_plugins_whitelist (Auth) Enable checking authenticated identities against a whitelist
strongswan_plugins_xauth-generic (Auth) Generic XAuth backend that provides passwords from ipsec.secrets and other credential sets
strongswan_plugins_xauth-noauth (Auth) XAuth backend that does not do any authentication
strongswan_plugins_xcbc (Crypto) Enable XCBC wrapper using various ciphers
swanctl Build swanctl configuration and control tool
systemd Build systemd specific IKE daemon charon-systemd
tnc Support Trusted Network Connect
unbound DNSSEC enabled resolver using libunbound