Your message dated Mon, 14 Sep 2026 21:40:19 +0200
with message-id <[email protected]>
and subject line Re: [Pkg-swan-devel] Bug#1147657: strongswan: Please continue
supporting IKEv1 (IKE version 1 not supported, --enable-ikev1)
has caused the Debian Bug report #1147657,
regarding strongswan: Please continue supporting IKEv1 (IKE version 1 not
supported, --enable-ikev1)
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1147657: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147657
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: strongswan-charon
Version: 6.1.0-2
Dear Debian folks,
Since last week I am unable to connect to the SoftEther VPN server. The
journal contains:
charon[31789]: 01[IKE] IKE version 1 not supported
The reason is the package upgrade to 6.1.0-1:
2026-09-08 08:06:58 upgrade strongswan-libcharon:amd64 6.0.7-1 6.1.0-1
and the documented default IKEv1 disablement in 6.1.0 [1][2]:
IKEv1 Disabled By Default
The IKEv1 protocol is now disabled by default. Support for the
protocol will be removed in a future release, likely within the next
year (there is no definitive timeline yet).
When building, IKEv1 has to be enabled explicitly via --enable-ikev1.
A warning about its impending removal is logged.
In the configuration, version now defaults to 2. If it is set to 0 or
1, a warning is logged when the configuration is loaded.
In our threat model at the institute, IKEv1 is sufficiently secure, and
it’d be great if the Debian package could still ship IKEv1 support.
Kind regards,
Paul
PS: systemd journal still contains:
Sep 12 09:10:15 abreu systemd[1]: Started
strongswan-starter.service - strongSwan IPsec IKEv1/IKEv2 daemon using
ipsec.conf.
[1]: https://strongswan.org/blog/2026/09/07/strongswan-6.1.0-released.html
[2]:
https://metadata.ftp-master.debian.org/changelogs//main/s/strongswan/strongswan_6.1.0-1_changelog
--- End Message ---
--- Begin Message ---
control: tag -1 wontfix
On Mon, 2026-09-14 at 11:37 +0200, Paul Menzel wrote:
> In our threat model at the institute, IKEv1 is sufficiently secure, and
> it’d be great if the Debian package could still ship IKEv1 support.
>
>
Hi Paul,
that's a discussion you really should have with upstream, because they intend
to *remove* the IKEv1 code in the upcoming months anyway.
At this point I don't really think there's a reason not to use IKEv2 (the
standard is old enough to drink), and keepign IKEv1 enabled means *all
strongSwan Debian users* have it enabled. So no, that's not really something
we'll divert from upstream.
>
>
> PS: systemd journal still contains:
>
> Sep 12 09:10:15 abreu systemd[1]: Started
> strongswan-starter.service - strongSwan IPsec IKEv1/IKEv2 daemon using
> ipsec.conf.
Good catch, we'll update that.
Regards,
--
Yves-Alexis
signature.asc
Description: This is a digitally signed message part
--- End Message ---