[Pkg-swan-devel] Bug#1147657: strongswan: Please continue supporting IKEv1 (IKE version 1 not supported, --enable-ikev1)

Paul Menzel pmenzel at molgen.mpg.de
Mon Sep 14 10:37:52 BST 2026


Package: strongswan-charon
Version: 6.1.0-2


Dear Debian folks,


Since last week I am unable to connect to the SoftEther VPN server. The 
journal contains:

     charon[31789]: 01[IKE] IKE version 1 not supported

The reason is the package upgrade to 6.1.0-1:

     2026-09-08 08:06:58 upgrade strongswan-libcharon:amd64 6.0.7-1 6.1.0-1

and the documented default IKEv1 disablement in 6.1.0 [1][2]:

> IKEv1 Disabled By Default
> 
> The IKEv1 protocol is now disabled by default. Support for the
> protocol will be removed in a future release, likely within the next
> year (there is no definitive timeline yet).
> 
> When building, IKEv1 has to be enabled explicitly via --enable-ikev1.
> A warning about its impending removal is logged.
> 
> In the configuration, version now defaults to 2. If it is set to 0 or
> 1, a warning is logged when the configuration is loaded.

In our threat model at the institute, IKEv1 is sufficiently secure, and 
it’d be great if the Debian package could still ship IKEv1 support.


Kind regards,

Paul


PS: systemd journal still contains:

     Sep 12 09:10:15 abreu systemd[1]: Started 
strongswan-starter.service - strongSwan IPsec IKEv1/IKEv2 daemon using 
ipsec.conf.


[1]: https://strongswan.org/blog/2026/09/07/strongswan-6.1.0-released.html
[2]: 
https://metadata.ftp-master.debian.org/changelogs//main/s/strongswan/strongswan_6.1.0-1_changelog



More information about the Pkg-swan-devel mailing list