Package: strongswan-charon
Version: 6.1.0-2

Dear Debian folks,


Since last week I am unable to connect to the SoftEther VPN server. The journal contains:

    charon[31789]: 01[IKE] IKE version 1 not supported

The reason is the package upgrade to 6.1.0-1:

    2026-09-08 08:06:58 upgrade strongswan-libcharon:amd64 6.0.7-1 6.1.0-1

and the documented default IKEv1 disablement in 6.1.0 [1][2]:

IKEv1 Disabled By Default

The IKEv1 protocol is now disabled by default. Support for the
protocol will be removed in a future release, likely within the next
year (there is no definitive timeline yet).

When building, IKEv1 has to be enabled explicitly via --enable-ikev1.
A warning about its impending removal is logged.

In the configuration, version now defaults to 2. If it is set to 0 or
1, a warning is logged when the configuration is loaded.

In our threat model at the institute, IKEv1 is sufficiently secure, and it’d be great if the Debian package could still ship IKEv1 support.


Kind regards,

Paul


PS: systemd journal still contains:

Sep 12 09:10:15 abreu systemd[1]: Started strongswan-starter.service - strongSwan IPsec IKEv1/IKEv2 daemon using ipsec.conf.


[1]: https://strongswan.org/blog/2026/09/07/strongswan-6.1.0-released.html
[2]: https://metadata.ftp-master.debian.org/changelogs//main/s/strongswan/strongswan_6.1.0-1_changelog

Reply via email to