From 4b9453b9a4c865f5eb722761a1f7120d954a1b57 Mon Sep 17 00:00:00 2001 From: Martin Pecka Date: Sun, 7 Jan 2024 23:00:07 +0100 Subject: [PATCH] strongswan: Add support for send_cert option This option is required by some clients, e.g. iOS. Signed-off-by: Martin Pecka --- net/strongswan/files/swanctl.init | 3 +++ 1 file changed, 3 insertions(+) diff --git a/net/strongswan/files/swanctl.init b/net/strongswan/files/swanctl.init index 2469001595..b081f776f0 100644 --- a/net/strongswan/files/swanctl.init +++ b/net/strongswan/files/swanctl.init @@ -466,6 +466,7 @@ config_remote() { config_get ca_cert "$conf" ca_cert "" config_get rekeytime "$conf" rekeytime config_get overtime "$conf" overtime + config_get send_cert "$conf" send_cert config_list_foreach "$conf" local_sourceip append_var local_sourceip "," config_list_foreach "$conf" remote_ca_certs append_var remote_ca_certs "," @@ -560,6 +561,8 @@ config_remote() { ;; esac + [ -n "$send_cert" ] && swanctl_xappend2 "send_cert = $send_cert" + [ $mobike -eq 1 ] && swanctl_xappend2 "mobike = yes" || swanctl_xappend2 "mobike = no" if [ -n "$rekeytime" ]; then -- 2.30.2