# /etc/strongswan.conf - strongSwan configuration file charon { load = pem pkcs1 pkcs8 random nonce x509 revocation openssl curl stroke kernel-libipsec kernel-netlink socket-default updown initiator_only = yes plugins { openssl { fips_mode = 2 } } }