[Pkg-swan-devel] Bug#1147657: strongswan: Please continue supporting IKEv1 (IKE version 1 not supported, --enable-ikev1)
Paul Menzel
pmenzel at molgen.mpg.de
Mon Sep 14 10:37:52 BST 2026
Package: strongswan-charon
Version: 6.1.0-2
Dear Debian folks,
Since last week I am unable to connect to the SoftEther VPN server. The
journal contains:
charon[31789]: 01[IKE] IKE version 1 not supported
The reason is the package upgrade to 6.1.0-1:
2026-09-08 08:06:58 upgrade strongswan-libcharon:amd64 6.0.7-1 6.1.0-1
and the documented default IKEv1 disablement in 6.1.0 [1][2]:
> IKEv1 Disabled By Default
>
> The IKEv1 protocol is now disabled by default. Support for the
> protocol will be removed in a future release, likely within the next
> year (there is no definitive timeline yet).
>
> When building, IKEv1 has to be enabled explicitly via --enable-ikev1.
> A warning about its impending removal is logged.
>
> In the configuration, version now defaults to 2. If it is set to 0 or
> 1, a warning is logged when the configuration is loaded.
In our threat model at the institute, IKEv1 is sufficiently secure, and
it’d be great if the Debian package could still ship IKEv1 support.
Kind regards,
Paul
PS: systemd journal still contains:
Sep 12 09:10:15 abreu systemd[1]: Started
strongswan-starter.service - strongSwan IPsec IKEv1/IKEv2 daemon using
ipsec.conf.
[1]: https://strongswan.org/blog/2026/09/07/strongswan-6.1.0-released.html
[2]:
https://metadata.ftp-master.debian.org/changelogs//main/s/strongswan/strongswan_6.1.0-1_changelog
More information about the Pkg-swan-devel
mailing list