| Port details on branch 2026Q2 |
- strongswan Open Source IKEv2 IPsec-based VPN solution
- 6.0.7 security
=0 6.0.7Version of this port present on the latest quarterly branch. - Maintainer: strongswan@nanoteq.com
 - Port Added: 2026-04-06 22:48:09
- Last Update: 2026-06-08 15:23:45
- Commit Hash: 5a5c707
- Also Listed In: net-vpn
- License: GPLv2
- WWW:
- https://www.strongswan.org
- Description:
- Strongswan is an open source IPsec-based VPN solution.
Strongswan for FreeBSD implements both the IKEv1 and IKEv2 (RFC 5996) key
exchange protocols.
¦ ¦ ¦ ¦ 
- Manual pages:
-
- pkg-plist: as obtained via:
make generate-plist - USE_RC_SUBR (Service Scripts)
-
- Dependency lines:
-
- strongswan>0:security/strongswan
- To install the port:
- cd /usr/ports/security/strongswan/ && make install clean
- To add the package, run one of these commands:
- pkg install security/strongswan
- pkg install strongswan
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.- PKGNAME: strongswan
- Flavors: there is no flavor information for this port.
- distinfo:
- TIMESTAMP = 1780929769
SHA256 (strongswan-6.0.7.tar.bz2) = e518e34e159514f4c6ba80d1f926cb151e0dd4e3a1d94213171234b8b9ae6f55
SIZE (strongswan-6.0.7.tar.bz2) = 4939164
Packages (timestamps in pop-ups are UTC):
- Dependencies
- NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
- Build dependencies:
-
- pkgconf>=1.3.0_1 : devel/pkgconf
- Library dependencies:
-
- libcurl.so : ftp/curl
- There are no ports dependent upon this port
Configuration Options:
- ===> The following configuration options are available for strongswan-6.0.7:
CTR=off: Enable CTR cipher mode wrapper plugin
CURL=on: Enable CURL to fetch CRL/OCSP
DHCP=off: Enable DHCP based attribute provider plugin
EAPAKA3GPP2=off: Enable EAP AKA with 3gpp2 backend
EAPDYNAMIC=off: Enable EAP dynamic proxy module
EAPRADIUS=off: Enable EAP Radius proxy authentication
EAPSIMFILE=off: Enable EAP SIM with file backend
FARP=off: Enable farp plugin
FIPS_PRF=off: Enable FIPS PRF software implementation plugin
GCM=on: Enable GCM AEAD wrapper crypto plugin
IKEV1=on: Enable IKEv1 support
IPSECKEY=off: Enable authentication with IPSECKEY resource records with DNSSEC
KDF=on: Enable KDF (prf+) implementation plugin
KERNELLIBIPSEC=off: Enable IPSec userland backend
LDAP=off: LDAP protocol support
LOADTESTER=off: Enable load testing plugin
MEDIATION=off: Enable IKEv2 Mediation Extension
ML=on: Enable Module-Lattice-based crypto plugin
MYSQL=off: MySQL database support
PKCS11=off: Enable PKCS11 token support
PKI=on: Enable PKI tools
PYTHON=off: Python VICI protocol plugin
SMP=off: Enable XML-based management protocol (DEPRECATED)
SQLITE=off: SQLite database support
STROKE=off: Enable stroke management protcol (DEPRECATED)
SWANCTL=on: Install swanctl (requires VICI)
TESTVECTOR=off: Enable crypto test vectors
TPM=off: Enable TPM plugin
TSS2=off: Enable TPM 2.0 TSS2 library
UNBOUND=off: Enable DNSSEC-enabled resolver
UNITY=off: Enable Cisco Unity extension plugin
VICI=on: Enable VICI management protocol
XAUTH=off: Enable XAuth password verification
====> Options available for the single PRINTF_HOOKS: you have to select exactly one of them
BUILTIN=on: Use builtin printf hooks
LIBC=off: Use libc printf hooks
VSTR=off: Use devel/vstr printf hooks
===> Use 'make config' to modify these settings
- Options name:
- security_strongswan
- USES:
- cpe libtool:keepla pkgconfig ssl tar:bzip2
- pkg-message:
- For install:
- The default strongSwan configuration interface have been updated to vici since version 5.9.2_1.
To use the stroke interface by default either compile the port without the vici option or
set 'strongswan_interface="stroke"' in your rc.conf file.
- If upgrading from > 5.9.2_1:
- The default strongSwan configuration interface have been updated to vici.
To use the stroke interface by default either compile the port without the vici option or
set 'strongswan_interface="stroke"' in your rc.conf file.
- Master Sites:
|
Number of commits found: 4
| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
6.0.7 08 Jun 2026 15:23:45
    |
R. Christian McDonald (rcm)  |
security/strongswan: Update 6.0.6 => 6.0.7
Changelog:
https://github.com/strongswan/strongswan/releases/tag/6.0.7
PR: 295936
Approved by: blanket (fix CVE)
MFH: 2026Q2
Security: CVE-2026-47895
Sponsored by: Rubicon Communications, LLC ("Netgate")
(cherry picked from commit ab71842ed8cd8c3fa1e45093fc22e3efb05ccd9a) |
6.0.6 23 Apr 2026 17:25:00
    |
Vladimir Druzenko (vvd)  |
security/strongswan: Update 6.0.5 => 6.0.6 (fix 7 CVEs)
Changelog:
https://github.com/strongswan/strongswan/releases/tag/6.0.6
PR: 294718
Approved by: blanket (fix CVEs)
Security: CVE-2026-35328
Security: CVE-2026-35329
Security: CVE-2026-35330
Security: CVE-2026-35331
Security: CVE-2026-35332
Security: CVE-2026-35333
Security: CVE-2026-35334
Sponsored by: UNIS Labs
MFH: 2026Q2
(cherry picked from commit 3b628bd6b80f25100a96ba921c45c6d9e5878061) |
6.0.5_1 23 Apr 2026 17:24:54
    |
Vladimir Druzenko (vvd)  Author: Mike Bressem |
security/strongswan: Enable ML plugin by default to allow Post-Quantum Key
Exchange Methods
Currently ML-DSA (used for Digital Signatures) is a draft in strongswan
(ETA Version 6.1.0 or later). So CNSA 2.0 cannot be fully supported yet.
https://linux-ipsec.org/slides/2025/steffen-pqc-auth-for-ikev2.pdf
But most firewalls (Palo Alto / Fortigate) already support ML-KEM Key
Exchange in addition to standard proposals.
E.g. aes128gcm16-ecp256-ke1_mlkem512.
More details:
https://docs.strongswan.org/docs/latest/config/proposals.html
PR: 294305
Approved by: strongswan@Nanoteq.com (maintainer, timeout 2 weeks)
Sponsored by: UNIS Labs
(cherry picked from commit fb347f77757066e2bc0989fd66c8f02c9bf862d9) |
6.0.5 06 Apr 2026 22:47:03
    |
Vladimir Druzenko (vvd)  |
security/strongswan: Update 6.0.4 => 6.0.5 (CVE-2026-25075)
Changelog:
https://github.com/strongswan/strongswan/releases/tag/6.0.5
While here:
- Switch from post-install + "if PORT_OPTIONS:MVICI" to
post-install-VICI-on.
- Add option FIPS_PRF - software implementation plugin.
- Improve plist.
- Refresh patches.
Reported by: Mike Bressem <mike@bressem.com> (via email)
Approved by: blanket (fix CVE)
Security: CVE-2026-25075
Sponsored by: UNIS Labs
MFH: 2026Q2
(cherry picked from commit 2d6221ae7df33419e639c439a12c78fdea84e748) |
Number of commits found: 4
|