# /etc/strongswan.conf - strongSwan configuration file swanctl { load = pem pkcs1 x509 revocation constraints pubkey openssl random } charon { dh_exponent_ansi_x9_42 = no load = sha1 sha2 md5 aes des hmac pem pkcs1 x509 revocation constraints pubkey gmp random nonce curl kernel-netlink socket-default updown sqlite attr-sql vici plugins { attr-sql { database = sqlite:///etc/ipsec.d/ipsec.db } } } pool { load = sqlite }