strongswan: swanctl: Add support for send_certreq
authorKevin Locke <redacted>
Sat, 30 Nov 2024 21:36:49 +0000 (14:36 -0700)
committerPhilip Prindeville <redacted>
Sun, 18 May 2025 17:35:35 +0000 (11:35 -0600)
commit5be8d85937352e4edb5bedc8d9f09511e60ab817
treeb67dcffe35487fd394f74834ae9b64037ffb3d16
parent7c268c3ac2cc3e3fb259c057036ec7032cc16395
strongswan: swanctl: Add support for send_certreq

Support the [send_certreq] connection configuration option to disable
offering trusted root CA certificates and reduce the size of the initial
IKE packets.

This work is based on a patch by @aleks-mariusz in
https://forum.openwrt.org/t/confusion-regarding-setting-up-ikev2-vpn-service-with-strongswan-using-ipsec-and-swanctl/169587/9

[send_certreq]: https://docs.strongswan.org/docs/latest/swanctl/swanctlConf.html#_connections

Signed-off-by: Kevin Locke <redacted>
net/strongswan/Makefile
net/strongswan/files/swanctl.init
git clone https://git.99rst.org/PROJECT