Current Series Release Notes

29.0.0.0rc1-6

New Features

  • Added support for swanctl (VICI protocol) as an alternative to the legacy stroke/starter interface in the strongSwan device driver. Operators can now enable swanctl mode by setting use_swanctl = True under the [strongswan] configuration section. This enables compatibility with modern Linux distributions (Fedora, RHEL 9+, recent Ubuntu/Debian) that ship strongSwan without the deprecated stroke plugin.

  • Added support for the vpn-aes-ccm-gcm API extension. This extension advertises support for AES CCM and AES GCM encryption algorithms in VPN IKE and IPsec policies.

  • Added support for the vpn-no-sha1-3des API extension. When this extension is loaded, the deprecated sha1 authentication algorithm and 3des encryption algorithm are removed from VPN IKE and IPsec policy choices, and the default auth_algorithm changes from sha1 to sha256.