[From nobody Mon Sep 14 20:41:07 2026
Received: (at submit) by bugs.debian.org; 14 Sep 2026 09:38:04 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-15.1 required=4.0 tests=BAYES_00,
 BODY_INCLUDES_PACKAGE,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,
 DKIM_VALID_EF,HAS_PACKAGE,RCVD_IN_DNSWL_MED,SPF_HELO_PASS,SPF_PASS
 autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 33; hammy, 149; neutral, 67; spammy,
 1. spammytokens:0.951-+--our
 hammytokens:0.000-+--UD:ftp-master.debian.org, 0.000-+--systemd,
 0.000-+--UD:metadata.ftp-master.debian.org,
 0.000-+--metadataftpmasterdebianorg,
 0.000-+--metadata.ftp-master.debian.org
Return-path: &lt;pmenzel@molgen.mpg.de&gt;
Received: from mx3.molgen.mpg.de ([141.14.17.11]:40875)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;pmenzel@molgen.mpg.de&gt;)
 id 1x638V-001083-07 for submit@bugs.debian.org;
 Mon, 14 Sep 2026 09:38:04 +0000
Received: from [141.14.220.42] (g42.guest.molgen.mpg.de [141.14.220.42])
 (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)
 key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256)
 (No client certificate requested) (Authenticated sender: pmenzel)
 by mx.molgen.mpg.de (Postfix) with ESMTPSA id 10CD34C2C37D63
 for &lt;submit@bugs.debian.org&gt;; Mon, 14 Sep 2026 11:37:53 +0200 (CEST)
Message-ID: &lt;232ff607-c395-4be5-884e-7b9353694603@molgen.mpg.de&gt;
Date: Mon, 14 Sep 2026 11:37:52 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-US
From: Paul Menzel &lt;pmenzel@molgen.mpg.de&gt;
Subject: strongswan: Please continue supporting IKEv1 (IKE version 1 not
 supported, --enable-ikev1)
To: submit@bugs.debian.org
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=molgen.mpg.de;
 s=20260906; t=1789378673; 
 h=from:from:subject:date:message-id:mime-version:content-type:content-transfer-encoding;
 bh=dUYrGpRCEZ/a8Wru5nzJAysuwLrpBki46f6Zjqcd46U=; 
 b=iHpsm7ierqpP99waIa2LnNBe57SBy7AzlvUG3E2kkru7Du7k17hAd2Uf0Xq6uaTFKAHIX/hy2Ocx
 va6lgPHJhnY1zLvCWlg9KAWijGhkGljkRDcyKmwXmpoVlmBLLnHJBjrpnQXdnzMtlByREul3aJoxFY
 iMtHGt86YOwHYgMhFnCEpMLL+c+b0348uG8b50uC9eaIG8MFlES59t3dawsyPuQLo/IL8e/n3mYnZ8
 zvLfJ2zR48uu+NyUhPm9ie0phyRRBDsVrN1oailiRMUtSX9P/UCuLin+6BiB+QiUHCOflqYhfwl/lN
 KOXLVw8syCoGsU25OO4CuikiiRI0aIkA==
Delivered-To: submit@bugs.debian.org

Package: strongswan-charon
Version: 6.1.0-2


Dear Debian folks,


Since last week I am unable to connect to the SoftEther VPN server. The 
journal contains:

     charon[31789]: 01[IKE] IKE version 1 not supported

The reason is the package upgrade to 6.1.0-1:

     2026-09-08 08:06:58 upgrade strongswan-libcharon:amd64 6.0.7-1 6.1.0-1

and the documented default IKEv1 disablement in 6.1.0 [1][2]:

&gt; IKEv1 Disabled By Default
&gt; 
&gt; The IKEv1 protocol is now disabled by default. Support for the
&gt; protocol will be removed in a future release, likely within the next
&gt; year (there is no definitive timeline yet).
&gt; 
&gt; When building, IKEv1 has to be enabled explicitly via --enable-ikev1.
&gt; A warning about its impending removal is logged.
&gt; 
&gt; In the configuration, version now defaults to 2. If it is set to 0 or
&gt; 1, a warning is logged when the configuration is loaded.

In our threat model at the institute, IKEv1 is sufficiently secure, and 
it’d be great if the Debian package could still ship IKEv1 support.


Kind regards,

Paul


PS: systemd journal still contains:

     Sep 12 09:10:15 abreu systemd[1]: Started 
strongswan-starter.service - strongSwan IPsec IKEv1/IKEv2 daemon using 
ipsec.conf.


[1]: https://strongswan.org/blog/2026/09/07/strongswan-6.1.0-released.html
[2]: 
https://metadata.ftp-master.debian.org/changelogs//main/s/strongswan/strongswan_6.1.0-1_changelog
]